July 2026 Data Breaches (So far)
01 Jul 2026
Major Cyber Attacks June 2026
If you think 2025 was the year of the breaches,2026 has already gotten worse. Modern-day attackers are now devising attacks that are undetectable even by sophisticated defense systems using AI-enabled tools and advanced social engineering methods.
Data breaches are now impacting global economies, and regulators have become stricter about what they expect from organizations. Organizations are now facing added pressure to timely and effectively manage security and compliance risk.
Let us look at some of the top data breaches of July 2026:
July latest data breach news
Let us look at some of the top data breaches of July 2026:
Victim: Rectron
About
Rectron is a South African ICT company that offers software, networking, data centre, surveillance, and cloud computing solutions to resellers, retailers, ISPs, and end-customers.
Industry
ICT
What happened?
Rectron informed its stakeholders that it identified a cyber incident on 15th July that affected its systems and operations.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
Victim: BH Security LLC
About
Brinks Home Security is a Dallas-based smart home technology provider known for its home security and alarm systems.
Industry
Home security
What happened?
BH Security LLC became a target of a ransomware attack that was carried out by the ShinyHunters ransomware group.
Impact
As per the ransomware group, over 4.9 million Salesforce records have been compromised, including PII.
Source
Victim: Braham water plant
About
Braham’s water plant is a primary water infrastructure for Braham, a city in Isanti and Kanabec Counties in Minnesota.
Industry
Public sector
What happened?
Braham reported at 9:30 AM that their water plant was offline due to a cyber attack on its systems.
Impact
The cyber attack affected 30 Minnesota community water systems. Other communities also reported attempted cyber attacks – Maple Plain, South St. Paul, and Plymouth.
Source
Victim: Stadler Rail
About
Stadler Rail AG is a Bussnang-based railway rolling stock manufacturer that is known for its multi-unit trains and trams. With a global team of 18000 people, it supplies rolling stock to railroad operators globally.
Industry
Public sector
What happened?
In mid-July, Stadler Rail AG became a victim of a ransomware attack that was carried out by the Everest ransomware group.
Impact
As per the company, the cyber attack didn’t affect any of its operations, and technical information has been stolen from a supplier.
Source
Victim: Department for Education, UK
About
The Department for Education is a governmental department that was formed in 2010. It is responsible for child protection, education, and other skills in the UK.
Industry
Public sector
What happened?
The Department for Education UK became a victim of a cyber attack that was orchestrated by a cybercriminal group called ExfilSquad.
Impact
Over 607000 records were exposed, containing the personal information of school leaders, government officials, and university staff, including names, work email IDs, and telephone numbers.
Source
Victim: Microsoft
About
Microsoft Corporation is a Washington-based multinational technology company that was founded in 1975. It is known for its software Windows and its wide range of services and products.
Industry
Information technology
What happened?
A cybercriminal group called ExfilSquad has claimed to have exfiltrated and compiled a large volume of data.
Impact
The group has claimed to have stolen 130 GB of data containing approximately 8 million records, including PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions.
Source
Victim: Craneware
About
Craneware is a Florida-based healthcare software solutions provider that was founded in 1999. It is known for its Trisus cloud-based analytics solution that helps healthcare organizations optimize performance.
Industry
Healthcare
What happened?
Craneware reported on 20th July that it identified and responded to a cybersecurity incident that involved unauthorized access to a subset of its data environment.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
Victim: Origin Energy
About
Origin Energy is a Sydney-based electricity and natural gas retailer that was founded in 2000. It operates Australia’s largest coal-fired power station in New South Wales.
Industry
Energy
What happened?
On 22nd July, Origin Energy disclosed to the Australian Stock Exchange that it became a victim of a cyber attack that may involve unauthorized access to its customers’ data.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
Victim: Clover Health
About
Clover Health Investments Corp. is a Tennessee-based healthcare company that was founded in 2014. It is known for its Medicare Advantage insurance plans.
Industry
Healthcare
What happened?
On July 4th, Clover Health discovered unauthorized access to its systems that may have impacted its members’ personal and protected health information.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
Victim: Sumner County School
About
Sumner County School is a Tennessee-based public school district that enrolls over 29000 students. It is the 8th largest school district in Tennessee.
Industry
Education
What happened?
Sumner County discovered a breach in its computer network in July that forced it to postpone its new student registration to August 10.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
Victim: Thialf ice skating stadium
About
Thialf is a Netherlands-based ice arena that is primarily used for short track speed skating, ice hockey, figure skating, and ice speedway. It is known for hosting speed skating competitions and will host Olympic long track speed skating in 2030.
Industry
Sports
What happened?
Thialf Ice Skating Stadium became a victim of a cyber attack that was orchestrated by the Gentlemen ransomware group.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
Victim: Bank of Baroda
About
Bank of Baroda is an Indian public sector bank based in Gujarat. It is the second largest bank in India and is ranked 455 on the Forbes Global 2000 list.
Industry
Banking
What happened?
According to several security researchers, a database belonging to Bank of Baroda was recently listed on the dark web by a threat actor.
Impact
The threat actor has claimed to have leaked nearly 1 TB of sensitive data. The bank has not yet confirmed the breach or the data compromised.
Source
Victim: Fluke corporation
About
Fluke Corporation is a Washington-based manufacturer of industrial test, measurement, and diagnostic equipment. It was founded in 1948 and operates with a team of over 2000 employees.
Industry
Industrial Test Products
What happened?
Fluke Corporation became a target of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.
Impact
As per the ransomware group, over 21 million Salesforce records, including some PII, were compromised.
Source
Victim: City of Dallas
About
The City of Dallas offers a range of information services to its residents, from payment-related services to public safety, state assistance to enforcement services.
Industry
Public sector
What happened?
On 20th July, the City of Dallas was forced to take its main government and police websites down due to a cyber attack that was detected by its automated security systems.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
Victim: Al Saidi Factory
About
Al-Saidi is a Damam-based manufacturing company that is known for its tailored chemical and logistics solutions for organizations in the Middle East. It also specializes in the manufacturing of chemicals for the oil and gas and petrochemical industries.
Industry
Manufacturing
What happened?
Al Saidi became a target of a ransomware attack orchestrated by the Dragonforce ransomware group.
Impact
The nature and quantity of data exposed and operations impacted are currently under investigation.
Source
Victim: Fairlife – A Coca-Cola company
About
Fairlife is a Chicago-based dairy manufacturer that is focused on offering low-sugar and nutrition-rich dairy products. It is a wholly owned subsidiary of the Coca-Cola Company.
Industry
Dairy
What happened?
Fairlife was forced to temporarily halt its milk production and other operations in the U.S due to a ransomware attack.
Impact
The nature and impact of the incident are currently under investigation.
Source
Victim: Lidl
About
Lidl is a Bad Wimpfen, Germany-based retail company that was founded in 1930. It is known for its discounted supermarkets across Germany and other parts of Europe. It is the largest food retailer in Europe.
Industry
Retail
What happened?
Lidl discovered unauthorized access in its systems and files containing customer data.
Impact
As per the company’s notification, the attackers stole information of online shop customers, including first & last names, telephone numbers, email addresses, dates of birth, and customer numbers.
Source
Victim: Abbott
About
Abbott is a Chicago-based healthcare service provider that was founded in 1888. It is known for its pharmaceutical, nutritional, diagnostic, and medical products.
Industry
Healthcare
What happened?
Abbott Laboratories became a victim of two data breaches. One that involved unauthorized access to its Cancer Diagnostics business and another involving its LabCenter portal. One attack is claimed by the ShinyHunters ransomware group, and another is claimed by the ShadowByt3$ ransomware group.
Impact
ShinyHunters claim that the stolen data includes internal documents, contracts, and customer information from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa. The group has claimed to have stolen 30 million rows of customer PII, including names, email addresses, phone numbers, dates of birth, and more than 1 million SSNs. Additionally, 22 million client notes, more than 20 million medical orders, and customer agreements have been stolen.
ShadowByt3$ has claimed to have stolen CE manufacturing certificates, regulatory documentation, product requirements archives, calibrator values, assignments, assay files, and other product documentation related to Abbott’s lab diagnostic systems.
Source
Victim: Cedar Crest College
About
Cedar College is a Pennsylvania-based private liberal arts women’s college that was founded in 1867.
Industry
Education
What happened?
On 16th July, Cedar Crest College reported that it was investigating a cybersecurity incident affecting portions of its technology environment. NightSpire ransomware group has claimed responsibility for the ransomware attack.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
Victim: Town of Milford
About
The Town of Milford offers multiple information services to the residents of New Hampshire, from making online payments, town meeting-related information, to employment opportunities.
Industry
Education
What happened?
The Town of Milford discovered unauthorized access to its systems in July.
Impact
The nature and quantity of data exposed and the impact of the incident are currently under investigation.
Source
Victim: Kyokuto Kaihatsu Kogyo
About
Kyokuto Kaihatsu Kogyo is an Osaka-based manufacturer of special-purpose vehicles that are made-to-order to fit the distinctive work environments. It was founded in 1955 and is one of the largest manufacturers of special-purpose vehicles in Japan.
Industry
Automotive
What happened?
Kyokuto Kaihatsu Kogyo has become a victim of a ransomware attack that was orchestrated by the INC ransomware group.
Impact
The nature and quantity of data compromised is currently under investigation.
Source
Victim: Nihon Kotsu – Japan’s largest taxi operator
About
Nihon Kotsu Co. Ltd. is a Chiyoda City-based taxi and limousine operator. It is the largest operator in Japan with a fleet of over 4000 vehicles and 2700 affiliated vehicles.
Industry
Cab services
What happened?
Nihon Kotsu reported that it became a victim of a cyber attack on 11th July that forced it to shut down its taxi dispatch system.
Impact
The cyber attack has affected multiple aspects of Nihon Kotsu’s operation, including car hire, web booking, reservation management, and the telephone dispatch service. It also affected the availability of its internal systems. The nature and quantity of data exposed is currently under investigation.
Source
Victim: Bosch
About
Bosch is a South West Germany-based engineering and technology company that was founded in 1886. It is known for its products and services in mobility, consumer goods, industrial technology, energy, and building technology sectors.
Industry
Conglomerate
What happened?
Bosch became a victim of a ransomware attack that was carried out by the D1R ransomware group.
Impact
The ransomware group has claimed to have stolen sensitive engineering data. The nature and quantity of data exposed is currently under investigation.
Source
Victim: Greene County Georgia
About
Greene County is situated in the central portion of the Lake County region of Georgia. It offers multiple information services to its residents, from trash collection, tax payments, getting building permits, to election-related information.
Industry
Public sector
What happened?
On July 9th, Greene County took its network and services offline after discovering a cybersecurity incident in its network.
Impact
The cyber attack disrupted its payment processing and services across tax, court, and administrative offices.
Source
Victim: TruStage
About
TruStage Financial Group is a Wisconsin-based mutual insurance provider that offers financial services to cooperatives, credit unions, and their members.
Industry
Insurance and finance
What happened?
TruStage reported on July 14th that its technology environment was affected by a cybersecurity incident.
Impact
The cybersecurity incident affected some of the services offered through credit union partners and forced the company to take its network offline.
Source
Victim: Jacksonville Texas
About
Jacksonville is an East Texas-based city. It offers its citizens (over 14,600 residents) multiple digital information services, from emergency alerts to reporting a concern.
Industry
Public sector
What happened?
Jacksonville, Texas, discovered suspicious network activity on July 3rd that forced it to take some of its systems offline.
Impact
The complete impact of the cyber attack is currently under investigation by cybersecurity experts.
Source
Victim: Pennington County State’s Attorney’s Office
About
The Pennington County State’s Attorney is the chief prosecutor of adult and juvenile crimes in Pennington County. It delivers a range of vital programs and services that support public safety and community well-being.
Industry
Public sector
What happened?
The Pennington County State’s Attorney’s Office discovered that it became a victim of a cyber attack on July 5th.
Impact
The complete impact of the cyber attack is currently under investigation by cybersecurity experts.
Source
Victim: Nayax
About
Nayax Ltd. is a fintech company that is based in Herzliya, Israel, and operates through its worldwide headquarters in Maryland. It is known for its payment products and services, especially its Point of Sale devices.
Industry
Fintech
What happened?
Nayax Ltd. became a victim of a ransomware attack that was orchestrated by the Syndicate ransomware group.
Impact
The group has claimed to have stolen over 100 TB of Nayax’s data.
Source
Victim: YMCA – Western North Carolina
About
YMCA Western North Carolina is a Carolina-based non-profit organization that is focused on providing community care through child care, education, and sports-related services.
Industry
Nonprofit
What happened?
YMCA Western North Carolina became a victim of a ransomware attack that was carried out by the Interlock ransomware group.
Source
Victim: Lifeline
About
Lifeline is a Sydney-based non-profit organization that is known for its 24-hour crisis support services in Australia. It also sells furniture, clothes, and bric-a-brac from over 250 retail outlets in Australia.
Industry
Non-profit
What happened?
Lifeline discovered that a hacker posted its staff data on the dark web in July.
Impact
The hacker has claimed to have stolen about 10,600 records, including names, DOBs, email addresses, phone numbers, and contact numbers.
Source
Victim: Deutsche Bank
About
Deutsche Bank is a Frankfurt-based multinational investment and financial services company that was founded in 1870 in Berlin. It operates in more than 58 countries globally with a major presence in the Americas, Asia, and Europe.
Industry
Banking
What happened?
Deutsche Bank became a target of a ransomware attack that was carried out by the Unsafe ransomware group.
Impact
The nature and quantity of data exposed is currently under investigation by security experts.
Source
Victim: Edgewood Police Department
About
The Edgewood Police Department is the primary enforcement agency responsible for ensuring public safety. It is operated by the Pierce County Sheriff’s Department.
Industry
Public sector
What happened?
Edgewood Police Department became a victim of a ransomware attack that was carried out by the Wallstreet ransomware group.
Impact
The nature and quantity of data exposed is currently under investigation by security experts.
Source
Victim: Accenture
About
Accenture PLC is a Dublin-based technology consulting company that was founded in 1989. It is known for its information technology and management consulting services across 120 countries globally.
Industry
Professional services
What happened?
Accenture became a target of a cyber attack that was carried out by a threat actor named 888.
Impact
The threat actor has claimed to have stolen 35 GB of source code, SSH keys, RSA keys, Azure Storage Access Keys, Azure Password Access Tokens (PAT), and configuration files.
Source
Victim: Ingram content
About
Ingram Content is a Tennessee-based publishing service provider that was founded in 2009. It is known for its book distribution services and is known to have the largest book inventory with access to over 7.5 million titles.
Industry
Publishing
What happened?
Ingram Content became a target of a ransomware attack that was carried out by the Shiny Hunters ransomware group.
Impact
The nature and quantity of data exposed in the breach are currently under investigation.
Source
Victim: Fluke corporation
About
Fluke Corporation is a Washington-based manufacturing company that was founded in 1948. It is known for its industrial test measurement and diagnostics equipment, including electronic test equipment
Industry
Industry Test Products
What happened?
Fluke Corporation became a victim of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.
Impact
The ransomware group has claimed to have stolen over 100GB of data, including 21 million Salesforce records, including personally identifiable information (PII).
Source
Victim: Indra Sistemas
About
Indra Sistemas S.A. is a Madrid-based information technology, transport technology, and defense company. It is one of the biggest defense contractors in Europe.
Industry
Information Technology
What happened?
Indra Sistemas became a target of a ransomware attack orchestrated by the Gentlemen ransomware group.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
Victim: Chamco
About
Chemco is a Calgary-based manufacturing company that was founded in 1962. It is known for its pump and compressor engineering expertise in industries including energy, logistics, oil & gas, and utilities.
Industry
Manufacturing
What happened?
Chemco became a target of a ransomware attack that was carried out by the Qilin ransomware group.
Impact
The complete nature and quantity of data exposed is currently under investigation.
Source
Victim: Ford Motor Company Mexico
About
Ford Motor Company Mexico manufactures and sells Lincoln pick-up trucks, utility vehicles, commercial vans, and luxury vehicles. Ford operates in multiple countries worldwide with approximately 175,000 employees.
Industry
Automotive
What happened?
As per security experts, Ford Motor Company was listed on a data breach forum as a victim of the Krybit ransomware group.
Impact
The nature and quantity of data exposed is currently under investigation.
Source
To be continued
In June, we saw how some of the most devastating data breaches impacted some of the biggest companies.
Keep checking this space as we update our list of June top data breaches with a closer look at how they happened and their impact.
Note: Our list only highlights the breaches that have either occurred in 2026 or reported/disclosed in 2026. All breaches reported in previous years, as of 2026, will be excluded from the list.