2026 on cisonews.net
Everything we have on record from 2026.
16 incidents, 1 analysis, newest first. Incidents sit under the month their first disclosure was filed. The log went live on September 27, 2026; entries about earlier disclosures were compiled from the filings after that.
September 20263
- AnalysisTwo years of SEC cyber incident disclosures: what companies actually said
- IncidentAstrana Health reports social engineering calls that led to unauthorized data accessAstrana Health8-K Item 1.05Health care
- IncidentPark Dental Partners reports unauthorized network access with possible patient data exposurePark Dental Partners8-K Item 1.05Health care
August 20262
July 20263
- IncidentAmgen reports patient health information taken from third-party cloud environmentsAmgen8-K Item 1.05Life sciences & medical devices
- IncidentAdaptHealth reports patient data and billing passwords taken after a social engineering attackAdaptHealth8-K Item 1.05Health care
- IncidentNavient reports borrower data exposed in a ransomware attack on an outside law firmNavient8-K Item 1.05Financial services
June 20263
- IncidentRiver Financial reports ransomware across its server environment and files four amendmentsRiver Financial8-K Item 1.05Financial services
- Incident8x8 reports Salesforce data taken through a compromised Klue integration8x88-K Item 1.05Technology
- IncidentiRhythm reports data taken from third-party hosted business applications through social engineeringiRhythm Holdings8-K Item 1.05Life sciences & medical devices
May 20261
April 20261
March 20263
- IncidentCareCloud reports an eight-hour disruption to one electronic health record environmentCareCloud8-K Item 1.05Health care
- IncidentTrio-Tech International reports ransomware at a Singapore subsidiary that escalated to data disclosureTrio-Tech International8-K Item 1.05Technology
- IncidentStryker reports a global disruption and later files under Item 1.05 citing first-quarter impactStryker8-K Item 8.01; 8-K/A Item 1.05Life sciences & medical devices