Data Breach Tracker: US Company Security Incidents
10
July 2026
Security & Stability
Confirmed data breaches and cyber security incidents reported by US companies each month, sourced from SEC 8-K filings, state attorney general breach notifications, cybersecurity news, and company disclosures. Each record covers the affected organisation, number of records exposed, data types compromised (personal information, financial data, health records), Incident Type where disclosed, and notification date. Only events confirmed by at least one authoritative source are included.
Data breach or security incident exposing customer or user records reported at a company in the US
CISOs and security teams use it to benchmark incident frequency by sector and identify systemic attack patterns across industries. Cyber insurance underwriters use it to assess risk exposure and loss trends. Legal and compliance teams track breach notification timelines and regulatory responses. Journalists and researchers covering cybersecurity use it as a structured, sourced record of confirmed incidents.
1537
<table class="catchall-table"><thead><tr><th style="min-width:40px">#</th><th style="min-width:280px">Event</th><th style="min-width:160px">Incident Date</th><th style="min-width:160px">Response Actions</th><th style="min-width:160px">Data Types Exposed</th><th style="min-width:160px">Affected Company</th><th style="min-width:160px">Location</th><th style="min-width:160px">Records Exposed</th><th style="min-width:160px">Attack Vector</th><th style="min-width:160px">Incident Type</th></tr></thead><tbody><tr><td style="min-width:40px">1</td><td style="min-width:280px">EBT Skimming Fraud in New York City</td><td style="min-width:160px">2026-07-23</td><td style="min-width:160px">HRA partnered with community organizations for education, Secret Service conducted operations, new chip-enabled EBT cards to be issued, and educational sessions held for SNAP participants.</td><td style="min-width:160px">EBT card information</td><td style="min-width:160px"></td><td style="min-width:160px">New York City, New York</td><td style="min-width:160px">34,532</td><td style="min-width:160px">skimming devices</td><td style="min-width:160px">unauthorized_access</td></tr><tr><td style="min-width:40px">2</td><td style="min-width:280px">Russian Hacking Group Exploits Zimbra Vulnerability for Espionage</td><td style="min-width:160px">2026-07-23</td><td style="min-width:160px">install the available security update immediately or migrate to an alternative email client</td><td style="min-width:160px">emails, passwords, authentication codes, email history, organizational contact directories, two-factor authentication tokens, newly generated application passcodes</td><td style="min-width:160px"></td><td style="min-width:160px">United States</td><td style="min-width:160px">1</td><td style="min-width:160px">cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite</td><td style="min-width:160px">unauthorized_access</td></tr><tr><td style="min-width:40px">3</td><td style="min-width:280px">Charges filed for unauthorized access to Connecticut corporation's data</td><td style="min-width:160px">2026-07-13</td><td style="min-width:160px"></td><td style="min-width:160px">names, corporate user IDs, passwords</td><td style="min-width:160px"></td><td style="min-width:160px">Connecticut</td><td style="min-width:160px">1</td><td style="min-width:160px">malware</td><td style="min-width:160px">unauthorized_access</td></tr><tr><td style="min-width:40px">4</td><td style="min-width:280px">Man pleads not guilty of credit card skimming scheme</td><td style="min-width:160px">2026-07-07</td><td style="min-width:160px"></td><td style="min-width:160px">credit card numbers</td><td style="min-width:160px"></td><td style="min-width:160px">Sioux City</td><td style="min-width:160px">1</td><td style="min-width:160px">credit card skimming</td><td style="min-width:160px">other</td></tr><tr><td style="min-width:40px">5</td><td style="min-width:280px">Dallas Credit Card Skimming Operation Sentences</td><td style="min-width:160px">2026-07-01</td><td style="min-width:160px"></td><td style="min-width:160px">debit card data, credit card data</td><td style="min-width:160px"></td><td style="min-width:160px">Dallas, Texas</td><td style="min-width:160px">783</td><td style="min-width:160px">credit card skimming devices on payment terminals</td><td style="min-width:160px">data_breach</td></tr><tr class="catchall-blurred"><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td></tr><tr class="catchall-blurred"><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td></tr><tr class="catchall-blurred"><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td><td>████████████</td></tr></tbody></table>
<h3>What is the difference between this and Have I Been Pwned?</h3><p>Have I Been Pwned focuses on individual credential exposure. This tracker covers corporate breach events – affected company, breach scope, attack type, and regulatory notification – making it suited to enterprise risk monitoring rather than personal account checks.</p><h3>Are healthcare and financial sector breaches included?</h3><p>Yes. HIPAA-covered healthcare breaches appear via HHS breach portal notifications; financial institution incidents come from SEC filings and sector-specific reporting.</p><h3>How does CatchAll validate a breach before including it?</h3><p>Inclusion requires at least one authoritative source – a regulatory filing, company press release, or official notification. Unconfirmed reports from security researchers or forums are excluded.</p><h3>What is the refresh rate of this dataset?</h3><p>We rerun this dataset once a month. You can create your own dataset that updates as frequently as every one hour on <a href="https://platform.newscatcherapi.com/catchall">platform.newscatcherapi.com/catchall</a></p>