July 2026 Data Breaches (So far)

01 Jul 2026

Major Cyber Attacks June 2026

If you think 2025 was the year of the breaches,2026 has already gotten worse. Modern-day attackers are now devising attacks that are undetectable even by sophisticated defense systems using AI-enabled tools and advanced social engineering methods.  

 

Data breaches are now impacting global economies, and regulators have become stricter about what they expect from organizations. Organizations are now facing added pressure to timely and effectively manage security and compliance risk.

 

Let us look at some of the top data breaches of July 2026:

July latest data breach news

Let us look at some of the top data breaches of July 2026:

Victim: Rectron

About

Rectron is a South African ICT company that offers software, networking, data centre, surveillance, and cloud computing solutions to resellers, retailers, ISPs, and end-customers.

 

Industry

ICT

 

What happened?

Rectron informed its stakeholders that it identified a cyber incident on 15th July that affected its systems and operations.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: BH Security LLC

About

Brinks Home Security is a Dallas-based smart home technology provider known for its home security and alarm systems.

 

Industry

Home security

 

What happened?

BH Security LLC became a target of a ransomware attack that was carried out by the ShinyHunters ransomware group.

 

Impact

As per the ransomware group, over 4.9 million Salesforce records have been compromised, including PII.

Source


Victim: Braham water plant

About

Braham’s water plant is a primary water infrastructure for Braham, a city in Isanti and Kanabec Counties in Minnesota.

 

Industry

Public sector

 

What happened?

Braham reported at 9:30 AM that their water plant was offline due to a cyber attack on its systems.

 

Impact

The cyber attack affected 30 Minnesota community water systems. Other communities also reported attempted cyber attacks – Maple Plain, South St. Paul, and Plymouth.

Source


Victim: Stadler Rail

About

Stadler Rail AG is a Bussnang-based railway rolling stock manufacturer that is known for its multi-unit trains and trams. With a global team of 18000 people, it supplies rolling stock to railroad operators globally.

 

Industry

Public sector

 

What happened?

In mid-July, Stadler Rail AG became a victim of a ransomware attack that was carried out by the Everest ransomware group.

 

Impact

As per the company, the cyber attack didn’t affect any of its operations, and technical information has been stolen from a supplier.

Source


Victim: Department for Education, UK

About

The Department for Education is a governmental department that was formed in 2010. It is responsible for child protection, education, and other skills in the UK.

 

Industry

Public sector

 

What happened?

The Department for Education UK became a victim of a cyber attack that was orchestrated by a cybercriminal group called ExfilSquad.

 

Impact

Over 607000 records were exposed, containing the personal information of school leaders, government officials, and university staff, including names, work email IDs, and telephone numbers.

Source


Victim: Microsoft

About

Microsoft Corporation is a Washington-based multinational technology company that was founded in 1975. It is known for its software Windows and its wide range of services and products.

 

Industry

Information technology

 

What happened?

A cybercriminal group called ExfilSquad has claimed to have exfiltrated and compiled a large volume of data.

 

Impact

The group has claimed to have stolen 130 GB of data containing approximately 8 million records, including PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions.

Source

Victim: Craneware

About

Craneware is a Florida-based healthcare software solutions provider that was founded in 1999. It is known for its Trisus cloud-based analytics solution that helps healthcare organizations optimize performance.

 

Industry

Healthcare

 

What happened?

Craneware reported on 20th July that it identified and responded to a cybersecurity incident that involved unauthorized access to a subset of its data environment.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Origin Energy

About

Origin Energy is a Sydney-based electricity and natural gas retailer that was founded in 2000. It operates Australia’s largest coal-fired power station in New South Wales.

 

Industry

Energy

 

What happened?

On 22nd July, Origin Energy disclosed to the Australian Stock Exchange that it became a victim of a cyber attack that may involve unauthorized access to its customers’ data.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Clover Health

About

Clover Health Investments Corp. is a Tennessee-based healthcare company that was founded in 2014. It is known for its Medicare Advantage insurance plans.

 

Industry

Healthcare

 

What happened?

On July 4th, Clover Health discovered unauthorized access to its systems that may have impacted its members’ personal and protected health information.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Sumner County School

About

Sumner County School is a Tennessee-based public school district that enrolls over 29000 students. It is the 8th largest school district in Tennessee.

 

Industry

Education

 

What happened?

Sumner County discovered a breach in its computer network in July that forced it to postpone its new student registration to August 10.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Thialf ice skating stadium

About

Thialf is a Netherlands-based ice arena that is primarily used for short track speed skating, ice hockey, figure skating, and ice speedway. It is known for hosting speed skating competitions and will host Olympic long track speed skating in 2030.

 

Industry

Sports

 

What happened?

Thialf Ice Skating Stadium became a victim of a cyber attack that was orchestrated by the Gentlemen ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Bank of Baroda

About

Bank of Baroda is an Indian public sector bank based in Gujarat. It is the second largest bank in India and is ranked 455 on the Forbes Global 2000 list.

 

Industry

Banking

 

What happened?

According to several security researchers, a database belonging to Bank of Baroda was recently listed on the dark web by a threat actor.

 

Impact

The threat actor has claimed to have leaked nearly 1 TB of sensitive data. The bank has not yet confirmed the breach or the data compromised.

Source

Victim: Fluke corporation

About

Fluke Corporation is a Washington-based manufacturer of industrial test, measurement, and diagnostic equipment. It was founded in 1948 and operates with a team of over 2000 employees.

 

Industry

Industrial Test Products

 

What happened?

Fluke Corporation became a target of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.

 

Impact

As per the ransomware group, over 21 million Salesforce records, including some PII, were compromised.

Source

Victim: City of Dallas

About

The City of Dallas offers a range of information services to its residents, from payment-related services to public safety, state assistance to enforcement services.

 

Industry

Public sector

 

What happened?

On 20th July, the City of Dallas was forced to take its main government and police websites down due to a cyber attack that was detected by its automated security systems.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Al Saidi Factory

About

Al-Saidi is a Damam-based manufacturing company that is known for its tailored chemical and logistics solutions for organizations in the Middle East. It also specializes in the manufacturing of chemicals for the oil and gas and petrochemical industries.

 

Industry

Manufacturing

 

What happened?

Al Saidi became a target of a ransomware attack orchestrated by the Dragonforce ransomware group.

 

Impact

The nature and quantity of data exposed and operations impacted are currently under investigation.

Source


Victim: Fairlife – A Coca-Cola company

About

Fairlife is a Chicago-based dairy manufacturer that is focused on offering low-sugar and nutrition-rich dairy products. It is a wholly owned subsidiary of the Coca-Cola Company.

 

Industry

Dairy

 

What happened?

Fairlife was forced to temporarily halt its milk production and other operations in the U.S due to a ransomware attack.

 

Impact

The nature and impact of the incident are currently under investigation.

Source


Victim: Lidl

About

Lidl is a Bad Wimpfen, Germany-based retail company that was founded in 1930. It is known for its discounted supermarkets across Germany and other parts of Europe. It is the largest food retailer in Europe.

 

Industry

Retail

 

What happened?

Lidl discovered unauthorized access in its systems and files containing customer data.

 

Impact

As per the company’s notification, the attackers stole information of online shop customers, including first & last names, telephone numbers, email addresses, dates of birth, and customer numbers.

Source


Victim: Abbott

About

Abbott is a Chicago-based healthcare service provider that was founded in 1888. It is known for its pharmaceutical, nutritional, diagnostic, and medical products.

 

Industry

Healthcare

 

What happened?

Abbott Laboratories became a victim of two data breaches. One that involved unauthorized access to its Cancer Diagnostics business and another involving its LabCenter portal. One attack is claimed by the ShinyHunters ransomware group, and another is claimed by the ShadowByt3$ ransomware group.

 

Impact

ShinyHunters claim that the stolen data includes internal documents, contracts, and customer information from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa. The group has claimed to have stolen 30 million rows of customer PII, including names, email addresses, phone numbers, dates of birth, and more than 1 million SSNs. Additionally, 22 million client notes, more than 20 million medical orders, and customer agreements have been stolen.

 

ShadowByt3$ has claimed to have stolen CE manufacturing certificates, regulatory documentation, product requirements archives, calibrator values, assignments, assay files, and other product documentation related to Abbott’s lab diagnostic systems.

Source


Victim: Cedar Crest College

About

Cedar College is a Pennsylvania-based private liberal arts women’s college that was founded in 1867.

 

Industry

Education

 

What happened?

On 16th July, Cedar Crest College reported that it was investigating a cybersecurity incident affecting portions of its technology environment. NightSpire ransomware group has claimed responsibility for the ransomware attack.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source


Victim: Town of Milford

About

The Town of Milford offers multiple information services to the residents of New Hampshire, from making online payments, town meeting-related information, to employment opportunities.

 

Industry

Education

 

What happened?

The Town of Milford discovered unauthorized access to its systems in July.

 

Impact

The nature and quantity of data exposed and the impact of the incident are currently under investigation.

Source


Victim: Kyokuto Kaihatsu Kogyo

About

Kyokuto Kaihatsu Kogyo is an Osaka-based manufacturer of special-purpose vehicles that are made-to-order to fit the distinctive work environments. It was founded in 1955 and is one of the largest manufacturers of special-purpose vehicles in Japan.

 

Industry

Automotive

 

What happened?

Kyokuto Kaihatsu Kogyo has become a victim of a ransomware attack that was orchestrated by the INC ransomware group.

 

Impact

The nature and quantity of data compromised is currently under investigation.

Source

Victim: Nihon Kotsu – Japan’s largest taxi operator

About

Nihon Kotsu Co. Ltd. is a Chiyoda City-based taxi and limousine operator. It is the largest operator in Japan with a fleet of over 4000 vehicles and 2700 affiliated vehicles.

 

Industry

Cab services

 

What happened?

Nihon Kotsu reported that it became a victim of a cyber attack on 11th July that forced it to shut down its taxi dispatch system.

 

Impact

The cyber attack has affected multiple aspects of Nihon Kotsu’s operation, including car hire, web booking, reservation management, and the telephone dispatch service. It also affected the availability of its internal systems. The nature and quantity of data exposed is currently under investigation.

Source

Victim: Bosch

About

Bosch is a South West Germany-based engineering and technology company that was founded in 1886. It is known for its products and services in mobility, consumer goods, industrial technology, energy, and building technology sectors.

 

Industry

Conglomerate

 

What happened?

Bosch became a victim of a ransomware attack that was carried out by the D1R ransomware group.

 

Impact

The ransomware group has claimed to have stolen sensitive engineering data. The nature and quantity of data exposed is currently under investigation.

Source

Victim: Greene County Georgia

About

Greene County is situated in the central portion of the Lake County region of Georgia. It offers multiple information services to its residents, from trash collection, tax payments, getting building permits, to election-related information.

 

Industry

Public sector

 

What happened?

On July 9th, Greene County took its network and services offline after discovering a cybersecurity incident in its network.

 

Impact

The cyber attack disrupted its payment processing and services across tax, court, and administrative offices.

Source

Victim: TruStage

About

TruStage Financial Group is a Wisconsin-based mutual insurance provider that offers financial services to cooperatives, credit unions, and their members.

 

Industry

Insurance and finance

 

What happened?

TruStage reported on July 14th that its technology environment was affected by a cybersecurity incident.

 

Impact

The cybersecurity incident affected some of the services offered through credit union partners and forced the company to take its network offline.

Source

Victim: Jacksonville Texas

About

Jacksonville is an East Texas-based city. It offers its citizens (over 14,600 residents) multiple digital information services, from emergency alerts to reporting a concern.

 

Industry

Public sector

 

What happened?

Jacksonville, Texas, discovered suspicious network activity on July 3rd that forced it to take some of its systems offline.

 

Impact

The complete impact of the cyber attack is currently under investigation by cybersecurity experts.

Source

Victim: Pennington County State’s Attorney’s Office

About

The Pennington County State’s Attorney is the chief prosecutor of adult and juvenile crimes in Pennington County. It delivers a range of vital programs and services that support public safety and community well-being.

 

Industry

Public sector

 

What happened?

The Pennington County State’s Attorney’s Office discovered that it became a victim of a cyber attack on July 5th.

 

Impact

The complete impact of the cyber attack is currently under investigation by cybersecurity experts.

Source

Victim: Nayax

About

Nayax Ltd. is a fintech company that is based in Herzliya, Israel, and operates through its worldwide headquarters in Maryland. It is known for its payment products and services, especially its Point of Sale devices.

 

Industry

Fintech

 

What happened?

Nayax Ltd. became a victim of a ransomware attack that was orchestrated by the Syndicate ransomware group.

 

Impact

The group has claimed to have stolen over 100 TB of Nayax’s data.

Source

Victim: YMCA – Western North Carolina

About

YMCA Western North Carolina is a Carolina-based non-profit organization that is focused on providing community care through child care, education, and sports-related services.

 

Industry

Nonprofit

 

What happened?

YMCA Western North Carolina became a victim of a ransomware attack that was carried out by the Interlock ransomware group.

Source

Victim: Lifeline

About

Lifeline is a Sydney-based non-profit organization that is known for its 24-hour crisis support services in Australia. It also sells furniture, clothes, and bric-a-brac from over 250 retail outlets in Australia.

 

Industry

Non-profit

 

What happened?

Lifeline discovered that a hacker posted its staff data on the dark web in July.

 

Impact

The hacker has claimed to have stolen about 10,600 records, including names, DOBs, email addresses, phone numbers, and contact numbers.

Source

Victim: Deutsche Bank

About

Deutsche Bank is a Frankfurt-based multinational investment and financial services company that was founded in 1870 in Berlin. It operates in more than 58 countries globally with a major presence in the Americas, Asia, and Europe.

 

Industry

Banking

 

What happened?

Deutsche Bank became a target of a ransomware attack that was carried out by the Unsafe ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation by security experts.

Source

Victim: Edgewood Police Department

About

The Edgewood Police Department is the primary enforcement agency responsible for ensuring public safety. It is operated by the Pierce County Sheriff’s Department.

 

Industry

Public sector

 

What happened?

Edgewood Police Department became a victim of a ransomware attack that was carried out by the Wallstreet ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation by security experts.

Source

Victim: Accenture

About

Accenture PLC is a Dublin-based technology consulting company that was founded in 1989. It is known for its information technology and management consulting services across 120 countries globally.

 

Industry

Professional services

 

What happened?

Accenture became a target of a cyber attack that was carried out by a threat actor named 888.

 

Impact

The threat actor has claimed to have stolen 35 GB of source code, SSH keys, RSA keys, Azure Storage Access Keys, Azure Password Access Tokens (PAT), and configuration files.

Source

Victim: Ingram content

About

Ingram Content is a Tennessee-based publishing service provider that was founded in 2009. It is known for its book distribution services and is known to have the largest book inventory with access to over 7.5 million titles.

 

Industry

Publishing

 

What happened?

Ingram Content became a target of a ransomware attack that was carried out by the Shiny Hunters ransomware group.

 

Impact

The nature and quantity of data exposed in the breach are currently under investigation.

Source

Victim: Fluke corporation

About

Fluke Corporation is a Washington-based manufacturing company that was founded in 1948. It is known for its industrial test measurement and diagnostics equipment, including electronic test equipment

 

Industry

Industry Test Products

 

What happened?

Fluke Corporation became a victim of a ransomware attack that was orchestrated by the ShinyHunters ransomware group.

 

Impact

The ransomware group has claimed to have stolen over 100GB of data, including 21 million Salesforce records, including personally identifiable information (PII).

Source

Victim: Indra Sistemas

About

Indra Sistemas S.A. is a Madrid-based information technology, transport technology, and defense company. It is one of the biggest defense contractors in Europe.

 

Industry

Information Technology

 

What happened?

Indra Sistemas became a target of a ransomware attack orchestrated by the Gentlemen ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

Victim: Chamco

About

Chemco is a Calgary-based manufacturing company that was founded in 1962. It is known for its pump and compressor engineering expertise in industries including energy, logistics, oil & gas, and utilities.

 

Industry

Manufacturing

 

What happened?

Chemco became a target of a ransomware attack that was carried out by the Qilin ransomware group.

 

Impact

The complete nature and quantity of data exposed is currently under investigation.

Source

Victim: Ford Motor Company Mexico

About

Ford Motor Company Mexico manufactures and sells Lincoln pick-up trucks, utility vehicles, commercial vans, and luxury vehicles. Ford operates in multiple countries worldwide with approximately 175,000 employees.

 

Industry

Automotive

 

What happened?

As per security experts, Ford Motor Company was listed on a data breach forum as a victim of the Krybit ransomware group.

 

Impact

The nature and quantity of data exposed is currently under investigation.

Source

To be continued

In June, we saw how some of the most devastating data breaches impacted some of the biggest companies.

 

Keep checking this space as we update our list of June top data breaches with a closer look at how they happened and their impact.

 

Note: Our list only highlights the breaches that have either occurred in 2026 or reported/disclosed in 2026. All breaches reported in previous years, as of 2026, will be excluded from the list.

List of Data Breach August 2026

Here are some of the biggest data breaches of August 2026. Let us understand their impact through insights like how much data is compromised, the entities affected, regulatory fines, and ransom paid.

Read More