Skip to main content

Geographic intelligence

United States cybersecurity signals

Follow 17 current cybersecurity signals linked to United States through an affected location, a profiled company's country, or both, with source reporting.

Affected-country links use structured victim-country data. Company-country links use a reviewed profile based on the organisation's headquarters or the local operating entity represented by its domain. A signal linked in both ways is counted once in the total; actor origin and locations inferred from prose remain excluded.

🇺🇸

Country context

About United States

Reference details that help place the cybersecurity reporting in its geographic and economic context.

Region
North America
Capital
Washington D.C.
Income group
High income
ISO codes
US / USA
ISO numeric
840

17

Total linked signals

Linked through an affected location, company headquarters, or both.

Not classified

Signals affecting this country

Victim-country data is unavailable in this reporting window.

17

Signals from companies based here

Based on reviewed company headquarters.

12

High or critical

Severity classifications among linked signals.

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to United States through an affected location, a profiled company's country, or both. Counts describe this reporting set, not overall incident prevalence.

Company-linked signals

Current reporting linked to United States

High

Jamf Affected by Klue Customer Data Incident

Jamf, a company specializing in Apple device management, was among roughly two dozen Klue customers impacted by a data incident. The incident, which became active on July 26, 2026, involved the Icarus threat group claiming responsibility for an attack. Further reports indicated that another hacking group might have obtained samples of the stolen Klue customer data and attempted to extort affected companies directly. While the full extent of Jamf's specific exposure through this third-party incident is not detailed, the broader event highlights the risks associated with supply chain compromises. Jamf's security efforts include initiatives like its Beacon threat-hunting service, which focuses on proactive detection and analysis of Mac threats, and its annual Security 360 report, which addresses key threats to Apple endpoints.

High

Coupang Data Breach: Authentication Failures Expose Customer Data in South Korea

South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January. South Korea's Deputy Minister for Cybersecurity and Network Policy publicly attributed the incident to management failures and authentication vulnerabilities during a press conference on July 24, 2026. The attacker exploited user authentication vulnerabilities to gain unauthorized access to accounts without proper login credentials, leading to a large-scale unauthorized information leak. South Korean authorities emphasized that the breach was not the result of highly sophisticated intrusion techniques, but rather stemmed from fundamental security weaknesses in authentication mechanisms and inadequate security management practices. The breach resulted in large-scale unauthorized access to customer information. The unauthorized access has since been terminated. This incident has also led to a record fine of $422 million by South Korea's Personal Information Protection Commission (PIPC) and ongoing diplomatic discussions between South Korea and the U.S. due to Coupang being an American-owned company operating in South Korea.

High

Qualtrics users impacted by Canvas (Instructure) nationwide data breach

A widespread security incident affecting Canvas, a learning management system by Instructure, impacted thousands of institutions, including Rutgers University, which utilizes the Qualtrics survey tool. Instructure notified Rutgers that while there was no indication of passwords, dates of birth, government identifiers, or financial information being involved, the specific Rutgers data compromised remains unclear. Instructure reportedly reached an agreement with the unauthorized threat actor, and the stolen data was returned and destroyed. Canvas remained operational throughout the incident.

High

Suno AI Music Generator Data Leak

A data leak at the AI music generator Suno, which occurred in November 2025, became public in July 2026. The breach exposed data from over 55 million unique email addresses and, for users who registered with their phone numbers, those numbers as well. A small portion of the dataset also included payment processor Stripe data, leading to the leak of names, physical addresses, purchase amounts, and certain credit card details (card type, expiration date, and last four digits) for tens of thousands of users. Suno confirmed it does not have access to full credit card numbers via Stripe.

High

FortiBleed gekoppeld aan ransomwaregroepen INC en Lynx

The 'FortiBleed' cyber campaign, which previously exposed login credentials for thousands of Fortinet firewalls, has now been linked to the ransomware groups INC and Lynx. Forensic investigations revealed evidence on a Windows server used in the attack infrastructure, showing administrators had access to negotiation portals of both ransomware groups. This suggests a strong connection between the credential theft and subsequent extortion campaigns. Researchers estimate that over 430,000 FortiGate firewalls worldwide were targeted, with sniffers installed on approximately 19,000 systems to intercept network traffic.

High

Xsolis Data Breach Exposes 1.4 Million Patient Records Across Eight Health Systems

A targeted phishing attack on healthcare AI company Xsolis has exposed the data of at least 1.4 million patients across eight U.S. health systems. Xsolis develops utilization management and care coordination technology widely used by hospitals and health systems. This breach now ranks among the most significant healthcare vendor cyberattacks of 2026. The U.S. Department of Health and Human Services (HHS) confirmed the patient impact figure on June 22, after Xsolis filed its breach report on June 5. Moreover, legal action over the incident has already been filed in at least one case, signaling growing accountability pressure on AI vendors handling sensitive patient data. The breach did not begin with the disclosure. Instead, the unauthorized access occurred months earlier. On January 20, 2026, an unidentified actor accessed portions of Xsolis’s IT environment. The attacker then acquired a limited number of files from within the system. Xsolis did not report the incident to HHS until June 5 — roughly four and a half months after the initial intrusion. This delay has drawn scrutiny. Furthermore, Hendrick Health in Abilene, Texas, faced a separate lawsuit specifically citing delayed patient notification as a key concern. Xsolis has stated the company is not currently aware of any misuse of the stolen data. However, the company has declined to specify which types of patient information were exposed. A spokesperson confirmed Xsolis is notifying affected individuals but is not commenting beyond its June 5 public statement. The following health systems have confirmed involvement in the Xsolis data breach : Rochester Regional Health — Rochester, N.Y. Together, these eight organizations collectively serve patients across six states. Consequently, the breach spans a wide geographic footprint — from the Pacific Northwest to the Southeast and Midwest. Xsolis took several steps after discovering the breach . First, the company reported the incident to HHS on June 5. Next, it began notifying affected patients directly. Additionally, Xsolis released a formal public statement through PR Newswire acknowledging the security incident. However, critics note that the five-month gap between the January intrusion and the June disclosure raises serious questions. Under HIPAA, covered entities and business associates generally must report breaches within 60 days of discovery. Health systems and regulators are now examining whether this timeline met legal standards. Why This Breach Matters for Healthcare AI This incident highlights a critical vulnerability in modern healthcare operations. Health systems increasingly rely on third-party AI vendors for functions like utilization management and care coordination. As a result, these vendors hold highly sensitive patient records — making them attractive targets for cybercriminals. Phishing attacks remain the leading method hackers use to gain unauthorized access. Notably, a single successful phishing email at a vendor like Xsolis can cascade into a breach affecting millions of patients at multiple health systems simultaneously. Third-Party Risk in Healthcare Is Growing Third-party vendor breaches now account for a rising share of healthcare data incidents. Therefore, health systems that outsource clinical and operational functions to AI companies must treat vendor cybersecurity as a direct extension of their own risk management. Regulators, including HHS’s Office for Civil Rights, actively scrutinize business associate agreements (BAAs) and breach timelines. Health systems found to lack adequate vendor oversight face fines and reputational harm alongside their vendors. Health system leaders should act quickly when a vendor breach occurs. First, they must verify whether their organization was part of the affected vendor’s client base. Next, they should request a full incident report from the vendor, including the timeline and scope of data access. Additionally, health systems must assess their own HIPAA obligations independently. Even when a vendor like Xsolis handles patient notifications, the covered health system retains compliance responsibility. Going forward, health systems should strengthen third-party risk programs. Key actions include conducting annual security assessments of all AI and health IT vendors, requiring vendors to carry cyber liability insurance, and including clear breach notification timelines in every BAA. Furthermore, phishing awareness training must extend beyond a health system’s own staff. Health systems should require vendors to demonstrate regular employee security training as a contract condition. Ultimately, a vendor’s security posture directly affects every patient record that vendor touches. Vendor breaches, regulatory shifts, and the governance gaps in between. Here's what happened this month in third-party risk management news. Financial institutions are legally accountable for what their vendors do with customer data. Outsourcing a function doesn't outsource the liability that comes with it — a principle that runs through GLBA Safeguards Rule requirements, state privacy laws, and open banking obligations under Part 1033. Vendor contracts need to do more than check a compliance box: they should specify permitted data uses, require breach notification within 24–48 hours, include audit rights, and address AI governance for any vendor using automated decision-making. Fourth-party risk also warrants explicit contract language requiring vendors to disclose and flow down obligations to their own subcontractors. A phishing attack on a healthcare AI vendor exposed 1.4 million patient records. Xsolis, which provides AI-powered utilization management to hospitals and health insurers, was breached through a single phishing email, exposing Social Security numbers, health insurance details, and medical treatment records across seven major hospital systems including Mayo Clinic. At least one organization — Rochester Regional Health — had ended its relationship with Xsolis in 2021, yet its patient data was still in scope at the time of the breach. Most of the 1.4 million affected had no idea the vendor held their information at all. Third-party vendor incidents now account for 58% of all healthcare data breaches, and this case is a concrete reminder that data deletion at offboarding is a risk control, not an administrative afterthought. The Klue breach reached LastPass customer data. Attackers used OAuth tokens stolen from Klue to access LastPass's Salesforce environment, exposing customer names, contact details, and support case records. Password vaults were unaffected, but the stolen data is enough to fuel targeted phishing. Fourth-party risk in practice: a vendor relationship several steps removed still produced direct customer harm. How to Avoid Common Third-Party Risk Management Mistakes

Medium

Healthcare AI Company Xsolis Suffers Data Breach Impacting 1.4 Million Individuals

Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information.  While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals.  The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519.  Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”. It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts.  Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolis’s hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.

Medium

AssuranceAmerica Managing General Agency data breach exposes policyholder data

AssuranceAmerica Managing General Agency, LLC, an Atlanta-based nonstandard auto insurance provider, reported a data breach to the South Carolina Department of Consumer Affairs on June 18, 2026. The breach, detected on March 17, 2026, involved an unauthorized third party accessing and copying files from its computer systems after targeting a single employee. A review completed on June 15, 2026, identified that names, contact details, insurance policy information, driver/vehicle information, claims data, driver's license numbers, tax ID information, and potentially Social Security numbers were exposed.

Medium

Microsoft Accused of Leaking Dutch Civil Servants' Data to US Government

Microsoft has been accused of leaking data belonging to Dutch civil servants, specifically those working for the Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP), to the US House of Representatives. The leaked data includes emails, minutes, and invitations with unredacted names.

High

Ongeautoriseerde toegang tot Anthropic's Claude Mythos AI via vendorlek

Anthropic, het bedrijf achter Claude Mythos AI, onderzoekt ongeautoriseerde toegang tot zijn AI-model via de omgeving van een externe leverancier. Dit incident vond plaats slechts twee weken na de introductie van Mythos. Een kleine groep gebruikers op een Discord-kanaal heeft naar verluidt toegang verkregen tot Mythos, met als primair doel het verzamelen van gegevens.

High

Anthropic's 'Claude Mythos' AI Model Details Leaked Due to CMS Configuration Error

Anthropic, an AI startup, experienced a data leak on March 27, 2026, where nearly 3,000 unpublished assets, including draft blog posts, images, and PDFs related to their upcoming 'Claude Mythos' AI model, were inadvertently left accessible in a public data cache. The leak was attributed to human error in configuring the company's content management system (CMS). Anthropic clarified that no core infrastructure, customer data, or security architecture was involved.

Medium

Coupang Data Breach Probe and Police Raid

South Korean e-commerce giant Coupang disclosed a significant data breach affecting approximately 33.7 million customers. On December 8, 2025, Seoul Police reportedly raided Coupang Headquarters as part of a probe into the data breach. Exposed data included names, email addresses, phone numbers, and shipping addresses.

Medium

Coupang Data Breach Exposes 33.7 Million Customer Accounts

South Korea's largest e-commerce platform, Coupang, disclosed a data breach that exposed personal information of approximately 33.7 million user accounts. The breach, attributed to a former employee who exploited unrevoked authentication keys, involved names, email and postal addresses, phone numbers, and order histories. No financial information or passwords were compromised. The incident led to a record fine from the Korean Personal Information Protection Commission (PIPC) and an investigation by South Korean authorities. Coupang initially released a statement on November 29, 2025, confirming unauthorized exposure of approximately 4,500 accounts, with a broader admission of 33.7 million accounts on November 30, 2025.

High

Coupang Data Breach: Authentication Failures Expose Customer Data in South Korea

South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January. South Korea's Deputy Minister for Cybersecurity and Network Policy publicly attributed the incident to management failures and authentication vulnerabilities during a press conference on July 24, 2026. The attacker exploited user authentication vulnerabilities to gain unauthorized access to accounts without proper login credentials, leading to a large-scale unauthorized information leak. South Korean authorities emphasized that the breach was not the result of highly sophisticated intrusion techniques, but rather stemmed from fundamental security weaknesses in authentication mechanisms and inadequate security management practices. The breach resulted in large-scale unauthorized access to customer information. The unauthorized access has since been terminated. This incident has also led to a record fine of $422 million by South Korea's Personal Information Protection Commission (PIPC) and ongoing diplomatic discussions between South Korea and the U.S. due to Coupang being an American-owned company operating in South Korea.

High

Amazon Confirms Employee Data Exposed in Third-Party MOVEit Breach

Amazon confirmed that employee data was compromised through a third-party property management vendor due to the lasting impact of the 2023 MOVEit vulnerability. The breach, revealed by a threat actor known as "Nam3L3ss," exposed approximately 2.8 million lines of employee data, including work contact information, email addresses, desk phone numbers, and building locations. The disclosure occurred on November 11, 2024.

FAQ

Questions about United States cybersecurity signals

What is included on the United States page?

This page brings together current signals connected to United States through an affected location, a reviewed company profile, or both.

Does a signal prove the attacker is based in United States?

No. The country connection describes affected locations or profiled company locations. It does not claim actor origin unless a source explicitly establishes that separately.

Why can the number of signals change?

The page follows the rolling current-reporting window. Counts change as new incidents are added, evidence is reviewed, and older signals leave that window.