Data Breach: US Company Security Incidents — July 2026
90
July 2026
Security & Stability
A structured record of 90 confirmed data breaches exposing customer, user, or sensitive corporate data at US-based companies in July 2026. Each event captures the affected organisation, sector, breach type, number of records exposed where disclosed, the attack vector, and the regulatory notification or law enforcement action filed. Coverage focuses on breaches with formal breach notifications, regulatory disclosures, or confirmed law enforcement involvement.
Data breach or security incident exposing customer or user records reported at a company in the US
CISOs and enterprise security teams track US data breach events to benchmark their own exposure and identify threat actor patterns relevant to their sector. Cyber insurance underwriters use breach frequency and severity data to refine pricing models and assess the adequacy of current policy terms. Privacy lawyers and breach notification specialists monitor incidents to identify regulatory precedents and advise clients on disclosure obligations under state and federal law.
1331
<div style="overflow-x:auto;width:100%"><table class="catchall-table"><thead><tr><th style="min-width:40px">#</th><th style="min-width:240px">Event</th><th style="min-width:140px;white-space:nowrap">Incident Type</th><th style="min-width:140px;white-space:nowrap">Records Exposed</th><th style="min-width:140px;white-space:nowrap">Attack Vector</th><th style="min-width:140px;white-space:nowrap">Incident Date</th><th style="min-width:140px;white-space:nowrap">Data Types Exposed</th><th style="min-width:140px;white-space:nowrap">Response Actions</th><th style="min-width:140px;white-space:nowrap">Affected Company</th><th style="min-width:140px;white-space:nowrap">Location</th><th style="min-width:120px;white-space:nowrap">Source</th></tr></thead><tbody><tr><td>1</td><td style="min-width:240px">23andMe Data Breach Settlement and Legal Actions</td><td style="min-width:140px">Data Breach</td><td style="min-width:140px">6,900,000</td><td style="min-width:140px">credential stuffing, compromised accounts, failed to implement multifactor authentication, failed to investigate unusual login patterns</td><td style="min-width:140px">2023-10-01</td><td style="min-width:140px">genetic information, personal information, family ancestries, names, addresses, contact information, dates of birth, Social Security numbers, health-related risks, insurance-related risks, family connections</td><td style="min-width:140px">paid a $46.75 million settlement, sold assets with data security requirements</td><td style="min-width:140px">23andMe</td><td style="min-width:140px">Palo Alto, California</td><td style="white-space:nowrap"><a href="https://www.ktvu.com/news/23andme-data-breach-victims-receive-46-75-million-payout" target="_blank" rel="nofollow">https://www.ktvu.com/news/23andme-data-breach-victims-receive-46-75-million-payout</a></td></tr><tr><td>2</td><td style="min-width:240px">Law firm Greenbaum Rowe Smith and Davis data breach</td><td style="min-width:140px">Data Breach</td><td style="min-width:140px">12,801</td><td style="min-width:140px">compromised user account</td><td style="min-width:140px">2025-11-27</td><td style="min-width:140px">names, addresses, Social Security numbers, dates of birth, medical information, health insurance information</td><td style="min-width:140px">reset its passwords, notified law enforcement and launched an investigation, enhanced its cybersecurity, providing identity theft protection services and a dedicated call center</td><td style="min-width:140px">Greenbaum Rowe Smith and Davis</td><td style="min-width:140px">New Jersey</td><td style="white-space:nowrap"><a href="https://www.nj.com/healthfit/2026/07/law-firm-for-major-nj-health-systems-gets-hacked-exposing-personal-info-of-nearly-13k-patients.html" target="_blank" rel="nofollow">https://www.nj.com/healthfit/2026/07/law-firm-for-major-nj-health-systems-gets-hacked-exposing-personal-info-of-nearly-13k-patients.html</a></td></tr><tr><td>3</td><td style="min-width:240px">AssuranceAmerica Data Breach Exposes Millions of Driver's Licenses and SSNs</td><td style="min-width:140px">Data Breach</td><td style="min-width:140px">6,900,000</td><td style="min-width:140px">targeted employee, unauthorized access</td><td style="min-width:140px">2026-03-16</td><td style="min-width:140px">driver's license numbers, Social Security numbers, contact information, auto insurance policy or account details, driver or vehicle information, claims-related information, Tax ID information, names</td><td style="min-width:140px">disabled affected server devices, reset passwords, deployed enhanced monitoring and threat detection software, retrained staff on cybersecurity, notified law enforcement, notifying customers, engaged external computer forensic specialists</td><td style="min-width:140px">AssuranceAmerica</td><td style="min-width:140px">Atlanta</td><td style="white-space:nowrap"><a href="https://www.techlicious.com/blog/assuranceamerica-data-breach-what-to-do" target="_blank" rel="nofollow">https://www.techlicious.com/blog/assuranceamerica-data-breach-what-to-do</a></td></tr><tr><td>4</td><td style="min-width:240px">Kootenai County Ransomware Attack and Data Breach</td><td style="min-width:140px">Ransomware Attack</td><td style="min-width:140px">1</td><td style="min-width:140px">ransomware attack</td><td style="min-width:140px">2026-03-30</td><td style="min-width:140px">Social Security numbers, individual taxpayer identification numbers, drivers' license numbers, names, addresses, birthdays, medical information, health insurance information, payment card information, fingerprints</td><td style="min-width:140px">notified affected residents, launched an incident investigation with third-party data forensics consultants, contacted federal law enforcement, Idaho Chief Information Security Officer and Idaho Attorney General, deployed security tools, monitored network, conducted enterprise-wide password reset, sent out notice letters, and provided a dedicated assistance line.</td><td style="min-width:140px">Kootenai County</td><td style="min-width:140px">Kootenai County, Idaho</td><td style="white-space:nowrap"><a href="https://cdapress.com/news/2026/jul/24/cyberattack" target="_blank" rel="nofollow">https://cdapress.com/news/2026/jul/24/cyberattack</a></td></tr><tr><td>5</td><td style="min-width:240px">Missouri State Treasurer's Office Data Leak</td><td style="min-width:140px">Data Breach</td><td style="min-width:140px">20</td><td style="min-width:140px">system misconfiguration</td><td style="min-width:140px">2026-04-16</td><td style="min-width:140px">student names, parents' email addresses, schools, vendors paid, scholarship amounts, disability status</td><td style="min-width:140px">vulnerability was resolved, file pulled from internet archive sites, reports now published as PDFs, drafted a statement blaming its software contractor, sent draft statement to educational assistance organizations</td><td style="min-width:140px">Missouri State Treasurer's Office</td><td style="min-width:140px">Missouri</td><td style="white-space:nowrap"><a href="https://missouriindependent.com/tag/classwallet" target="_blank" rel="nofollow">https://missouriindependent.com/tag/classwallet</a></td></tr><tr><td>6</td><td style="min-width:240px">Ransomware attack on Lufkin accounting firm</td><td style="min-width:140px">Ransomware Attack</td><td style="min-width:140px">1</td><td style="min-width:140px">Ransomware</td><td style="min-width:140px">2026-06-30</td><td style="min-width:140px">client and employee data</td><td style="min-width:140px">The accounting firm has not commented to confirm the information breach, when contacted by news media.</td><td style="min-width:140px">Todd, Hamaker & Johnson</td><td style="min-width:140px">Lufkin, Texas</td><td style="white-space:nowrap"><a href="https://www.ketk.com/news/local-news/cyberattack-targets-sensitive-data-from-lufkin-accounting-firm-report-shows" target="_blank" rel="nofollow">https://www.ketk.com/news/local-news/cyberattack-targets-sensitive-data-from-lufkin-accounting-firm-report-shows</a></td></tr><tr><td>7</td><td style="min-width:240px">FTC Sues Hims & Hers Over Patient Data Sharing</td><td style="min-width:140px">Data Breach</td><td style="min-width:140px">1</td><td style="min-width:140px">third-party vendor</td><td style="min-width:140px">2026-07-29</td><td style="min-width:140px">sensitive data, medical history, patient information</td><td style="min-width:140px">responded to FTC allegations on social media, stated their privacy policy allows data use</td><td style="min-width:140px">Hims & Hers</td><td style="min-width:140px">San Francisco</td><td style="white-space:nowrap"><a href="https://973thedawg.com/hims-hers-patient-data-lawsuit" target="_blank" rel="nofollow">https://973thedawg.com/hims-hers-patient-data-lawsuit</a></td></tr><tr><td>8</td><td style="min-width:240px">Union County Ohio Pays $1M Ransom After Data Theft</td><td style="min-width:140px">Ransomware Attack</td><td style="min-width:140px">45,487</td><td style="min-width:140px">brute-force attack</td><td style="min-width:140px">2025-05-01</td><td style="min-width:140px">names, dates of birth, driver's license/state ID numbers, passport numbers, Social Security numbers, financial account details, fingerprint information, medical information, payment card details</td><td style="min-width:140px">paid a $1 million ransom, notified 45,487 individuals, received 'proof of deletion'</td><td style="min-width:140px">Union County, Ohio</td><td style="min-width:140px">Union County, Ohio</td><td style="white-space:nowrap"><a href="https://tech.yahoo.com/cybersecurity/articles/pay-hacker-ransom-chances-ll-152941369.html" target="_blank" rel="nofollow">https://tech.yahoo.com/cybersecurity/articles/pay-hacker-ransom-chances-ll-152941369.html</a></td></tr><tr><td>9</td><td style="min-width:240px">River Bank & Trust Ransomware Attack and Investigation</td><td style="min-width:140px">Ransomware Attack</td><td style="min-width:140px">1</td><td style="min-width:140px">ransomware</td><td style="min-width:140px">2026-06-16</td><td style="min-width:140px">personally identifiable information</td><td style="min-width:140px">filed a report with the U.S. Securities and Exchange Commission, disabled affected administrative accounts, took the system offline, investigating the nature and scope of information involved</td><td style="min-width:140px">River Bank & Trust</td><td style="min-width:140px">Alabama</td><td style="white-space:nowrap"><a href="https://dothaneagle.com/news/state-regional/alabama/article_60ad87f8-9349-537b-9be6-52b317c9c67d.html" target="_blank" rel="nofollow">https://dothaneagle.com/news/state-regional/alabama/article_60ad87f8-9349-537b-9be6-52b317c9c67d.html</a></td></tr><tr><td>10</td><td style="min-width:240px">Eyemart Express Data Breach Exposes Customer Data</td><td style="min-width:140px">Unauthorized Access</td><td style="min-width:140px">45,000</td><td style="min-width:140px">Ransomware Attack</td><td style="min-width:140px">2026-02-12</td><td style="min-width:140px">names, addresses, vision insurance information, dates of birth, eyeglass purchase, prescription, Social Security numbers, health plan details</td><td style="min-width:140px">notified affected customers, launched an investigation, secured systems, reviewing and updating processes and procedures, cooperating with federal law enforcement, offering credit monitoring, encouraging individuals to monitor account statements and review credit reports</td><td style="min-width:140px">Eyemart Express</td><td style="min-width:140px">Farmers Branch, Texas</td><td style="white-space:nowrap"><a href="https://www.yahoo.com/news/us/articles/texas-based-eyemart-express-warns-220314398.html" target="_blank" rel="nofollow">https://www.yahoo.com/news/us/articles/texas-based-eyemart-express-warns-220314398.html</a></td></tr><tr class="row-locked"><td>11</td><td style="min-width:240px">Connecticut DCF Phishing Incident Exposes Confidential Information</td><td style="min-width:140px">Phishing Attack</td><td style="min-width:140px">1</td><td style="min-width:140px">phishing email</td><td style="min-width:140px">2026-05-20</td><td style="min-width:140px">personal information, confidential records, Social Security numbers</td><td style="min-width:140px">expelled the attacker from state systems, removed malicious email from user inboxes, temporarily disabled compromised accounts, notifying impacted individuals, offering credit monitoring and identity theft protection services, notified law enforcement</td><td style="min-width:140px">Connecticut Department of Children and Families</td><td style="min-width:140px">Hartford, Connecticut</td><td style="white-space:nowrap"><a href="https://www.courant.com/2026/07/09/ct-dcf-falls-victim-to-cyber-attack-that-potentially-leaked-confidential-information" target="_blank" rel="nofollow">https://www.courant.com/2026/07/09/ct-dcf-falls-victim-to-cyber-attack-that-potentially-leaked-confidential-information</a></td></tr><tr class="row-locked"><td>12</td><td style="min-width:240px">Green Bay Water Utility Payment Portal Error Exposes Customer Data</td><td style="min-width:140px">System Misconfiguration</td><td style="min-width:140px">1</td><td style="min-width:140px">third-party vendor</td><td style="min-width:140px">2026-07-09</td><td style="min-width:140px">names, addresses, account numbers, billing details, water usage details</td><td style="min-width:140px">removed affected payment links, corrected the issue, restored online payment, advised customers to call with questions, apologized for the issue</td><td style="min-width:140px">Green Bay Water</td><td style="min-width:140px">Green Bay, Wisconsin</td><td style="white-space:nowrap"><a href="https://www.nbc26.com/greenbay/green-bay-water-acknowledges-payment-portal-error" target="_blank" rel="nofollow">https://www.nbc26.com/greenbay/green-bay-water-acknowledges-payment-portal-error</a></td></tr></tbody></table></div>
<h3>What evidence is required for inclusion?</h3><p>An event is included when a data breach has been publicly confirmed by the affected company, a regulatory body, or law enforcement — either through a formal breach notification or an official acknowledgement.</p><h3>Are breaches at non-US companies included?</h3><p>No. The dataset focuses specifically on data breaches reported at companies with primary operations in the US. Breaches at international subsidiaries of US companies may be included if the US entity is directly affected.</p><h3>Is the number of records exposed always available?</h3><p>No. Exposed record counts are captured where disclosed in breach notifications or official reports. Many breach disclosures do not include confirmed figures, particularly in early-stage notifications.</p><h3>How often is this dataset updated?</h3><p>We rerun this dataset once a month. You can create your own dataset that updates as frequently as every one hour on <a href="https://platform.newscatcherapi.com/catchall">platform.newscatcherapi.com/catchall</a></p>