Cybersecurity incidents involving unauthorized access to non-sensitive customer information led to fraudulent lease-to-own agreements causing approximately $13 million in losses in Q2 2026. Mitigation measures implemented; investigation ong
Recent cybersecurity incidents 8-K filings
8-K filings disclosing material cybersecurity incidents (Item 1.05), the SEC-mandated disclosure, classified daily.
Unauthorized access to employee's company computer via social engineering on July 14, 2026. Threat actor exfiltrated files. Company contained incident; no PII accessed or other systems affected. No material impact expected.
Clover Health identified unauthorized access to three employee accounts on July 4, 2026 via social engineering. Accounts had access to member and health information but not financial or claims systems. Company contained the incident and doe
Unauthorized threat actor gained access to River Financial Corporation and River Bank & Trust network environment. Four class action lawsuits filed. Full scope and material impact undetermined as of July 17, 2026.
Fairlife LLC (Coca-Cola subsidiary) identified unauthorized third-party access to systems via ransomware on July 16, 2026. U.S. production temporarily suspended; Canada operations unaffected. Product safety intact. Scope and material impact
Unauthorized threat actor accessed network portions and removed certain data. Nature and scope of information, including PII involvement, under investigation. No fraud reports to date. Two class action lawsuits filed.
Unauthorized actor accessed certain files on Mercadien's servers containing Bank customer data including names, SSNs, account numbers, and identification documents. Bank systems and operations unaffected. Company notifying customers as requ
River Financial Corporation disclosed a cybersecurity incident with potentially impacted data. Investigation ongoing; no confirmed account impact to date. Full scope and materiality to be determined.
Third-party law firm experienced ransomware attack on June 8, 2026, exposing Company customer data including names, dates of birth, addresses, and Social Security numbers. Company systems unaffected. Notifications underway.
AdaptHealth Corp. experienced a material cybersecurity incident involving unauthorized access to cloud-based systems and exfiltration of patient data including PII and PHI. Incident contained as of June 27, 2026.
Aflac Japan discovered unauthorized third-party access to certain systems between June 15-25, 2026. Impacted files contain policy details, personal information, and bank account data. U.S. systems unaffected. Investigation ongoing.
Unauthorized threat actor accessed River Financial Corporation's network on or about June 16, 2026. Ransomware deployed across server portions. Detected June 19. Containment measures taken. Investigation ongoing to determine scope and PII i
Unauthorized third party exploited Klue Labs integration with Salesforce CRM on June 11-12, 2026, exfiltrating customer contract, opportunity, and contact information. Incident isolated to Salesforce; business operations unimpacted.
Company disclosed cyber phishing scam resulting in $3.2M loss of digital currency assets held with fraudulent custodian in 2024. Board formed special committee; investigation found no personal involvement by officers/directors. Shareholder
Unauthorized access to third-party-hosted business applications identified June 8, 2026. Data exfiltration confirmed including proprietary data and patient protected health information. Threat actor demanded payment. No impact to clinical s
Korean Personal Information Protection Commission announced $410 million in fines against Coupang Corp. for November 2025 data incident and separate data protection violations. Fines to be recognized in Q2 2026 results.
Third-party processor Evertec experienced cybersecurity incident affecting BPPR customer data including debit card numbers. Corporation's systems not accessed. Company has contractual right to reimbursement and does not expect material impa
EVERTEC disclosed unauthorized access to customer data discovered May 13, 2026. Third-party support platform breach exposed transaction records, payment card numbers, and customer information for Puerto Rico financial institution clients. I
Cybersecurity incident affecting vendor software service provider detected May 20, 2026. Unauthorized third-party access to Company systems including patient data. Company operations continuing; investigation ongoing; no material impact rep
West Pharmaceutical Services experienced a material cybersecurity attack on May 7, 2026 involving data exfiltration and system encryption. Systems have been restored and the company is fully operational. No material financial impact expecte