Compare shared topics, actors and incident patterns before opening the full signal.
Ahisd·Jun 26, 2026Same sectorSame impact area
Alamo Heights Independent School District (ISD) reported a data breach impacting over 26,000 people, disclosed to the Texas Attorney General's office on June 25, 2026 (published June 26, 2026 UTC). The breach was linked to a ransomware attack by the Qilin group, which occurred on April 9, 2026. The compromised information included names, Social Security numbers, driver's license numbers, and bank and medical information.
Qualtrics·Jul 15, 2026Same sectorSame impact area
A widespread security incident affecting Canvas, a learning management system by Instructure, impacted thousands of institutions, including Rutgers University, which utilizes the Qualtrics survey tool. Instructure notified Rutgers that while there was no indication of passwords, dates of birth, government identifiers, or financial information being involved, the specific Rutgers data compromised remains unclear. Instructure reportedly reached an agreement with the unauthorized threat actor, and the stolen data was returned and destroyed. Canvas remained operational throughout the incident.
Suno·Jul 11, 2026Same sectorSame impact area
A data leak at the AI music generator Suno, which occurred in November 2025, became public in July 2026. The breach exposed data from over 55 million unique email addresses and, for users who registered with their phone numbers, those numbers as well. A small portion of the dataset also included payment processor Stripe data, leading to the leak of names, physical addresses, purchase amounts, and certain credit card details (card type, expiration date, and last four digits) for tens of thousands of users. Suno confirmed it does not have access to full credit card numbers via Stripe.
Mercadien·Jul 10, 2026Same sectorSame impact area
Mercadien, P.C. CPAs, an internal audit service provider for SR Bancorp and Somerset Regal Bank, reported a data security incident on July 10, 2026. An unauthorized actor accessed and acquired files from Mercadien's servers containing sensitive customer data belonging to Somerset Regal Bank. The compromised data included customer names, Social Security numbers, account numbers, identification documents, and dates of birth. Importantly, SR Bancorp confirmed that its own business systems, payment systems, customer access to accounts, and core information technology infrastructure were not affected by the incident. The bank is coordinating with Mercadien to provide notifications to affected customers as required by federal and state laws and regulatory guidance. While the incident exposes customers to potential identity theft and fraud, SR Bancorp currently assesses the financial impact as immaterial to its consolidated financial condition or results of operations. This incident highlights the significant risks associated with third-party vendors handling sensitive customer information.
Srbancorp·Jul 10, 2026Same sectorSame impact area
SR Bancorp, Inc. reported a data security incident on July 10, 2026, involving its internal audit service provider, Mercadien, P.C. CPAs. An unauthorized actor accessed and acquired files from Mercadien's servers that contained sensitive customer data belonging to Somerset Regal Bank. The compromised information included customer names, Social Security numbers, account numbers, identification documents, and dates of birth. Importantly, SR Bancorp confirmed that the bank's own business systems, payment systems, customer access to accounts, and core information technology infrastructure were not directly impacted or disrupted by this incident. The company is coordinating customer notifications through Mercadien as required by applicable federal and state laws and regulatory guidance. While the incident exposes SR Bancorp to regulatory notification requirements, reputational risk, and potential legal liability, the company has initially assessed the financial impact as immaterial to its consolidated financial condition or results of operations. However, this assessment could change if the data is published or misused, or if further cybersecurity incidents occur. This event highlights the inherent risks associated with third-party vendors handling sensitive customer information.
Same sectorSame impact area
U.S. insurance provider AssuranceAmerica confirmed a data breach affecting the personal information and driver's license numbers of 6.9 million people. The company discovered hackers in its computer systems on March 17, 2026, and concluded its investigation on June 15, 2026, with notification letters scheduled to be sent out on July 10, 2026.