United States
DentaQuest
The May 2026 ransomware attack on DentaQuest, one of the largest dental and vision benefits administrators in the U.S., has now been confirmed to have affected 15 million individuals.
The incident first came to light on May 20, and DentaQuest’s investigation determined that attackers had access to the organization’s network between May 17 and May 20. The victim count, now published on the Oregon Attorney General’s data breach reporting website, is almost six times higher than the number initially claimed by the ShinyHunters extortion gang. In May, the group published 234 GB of DentaQuest data on its dark web leak site, claiming it related to 2.6 million individuals.
The incident now ranks as the largest health care data breach reported so far in 2026 and the fourth largest among nearly 7,900 HIPAA data breaches reported since federal regulators began tracking such incidents in September 2009.
SourceHow it could affect your business
DentaQuest is one of a growing number of organizations across multiple sectors that have fallen victim to data theft attacks linked to the ShinyHunters gang, highlighting the increasing scale and persistence of modern ransomware and extortion campaigns. Organizations should strengthen their defenses through proactive threat monitoring, layered security controls and rapid incident detection, while maintaining ransomware-resilient backups and a robust business continuity and disaster recovery (BCDR) strategy to enable fast recovery and minimize operational disruption following an attack.
Australia & New Zealand
Origin Energy
Sydney-based energy provider Origin Energy believes the information of approximately 0.9 million current and former customers was accessed during a recent data security breach.
Origin Energy, one of Australia’s largest energy providers, supplies electricity, fossil gas, LPG and internet services to more than 4.8 million homes and businesses. The company said it first became aware of a potential security threat in early July but initially did not believe it was credible. After an initial review, Origin now estimates that a significant proportion of the approximately 900,000 affected individuals are former customers and says those impacted will be notified in the coming days.
According to Origin, the compromised information may include customers’ names, addresses, dates of birth, phone numbers and account information, as well as the last four digits of credit cards or the last three digits of bank account numbers.
SourceHow it could affect your business
A data exposure of this scale could fuel widespread spear-phishing campaigns, with attackers using stolen personal information to craft highly convincing emails, text messages and phone scams. Individuals should remain cautious of unsolicited communications requesting personal or financial information, avoid clicking on unexpected links or attachments and verify the authenticity of any requests before taking action.
United States
U.S. water utilities
The Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) have warned that hackers are breaking into internet-connected programmable logic controllers (PLCs) at water utilities, disrupting operations across multiple facilities in several U.S. states.
Without disclosing the full scope of the attacks or identifying all affected states, the FBI and EPA said in a joint statement that multiple incidents had occurred. According to the agencies, attackers remotely accessed internet-connected control systems, changed administrator passwords and caused operational disruptions, including flooding and pressure loss, which could allow untreated groundwater to seep into water pipes. Meanwhile, Minnesota and Michigan have confirmed attacks on several of their water facilities.
The warning comes just days after federal agencies updated an advisory on ongoing Iranian cyberthreats targeting U.S. critical infrastructure. However, investigators have not publicly linked the latest attacks on water utilities to Iran.
SourceHow it could affect your business
Cyberattacks on U.S. critical infrastructure have increased significantly in recent years, with water utilities, energy providers and other essential services becoming frequent targets. Organizations that work with government agencies or operate critical infrastructure should strengthen their cyber defenses through continuous monitoring, network segmentation, strong identity and access controls, timely patch management, secure remote access and regularly tested incident response and business continuity plans to improve resilience against evolving threats.
North America
Analog Devices
Semiconductor company Analog Devices disclosed a data breach that it detected in June after identifying unauthorized access to certain systems.
The Massachusetts-based chip manufacturer said in a filing with the U.S. Securities and Exchange Commission (SEC) that it detected the incident on June 23 and immediately activated its incident response process. An investigation conducted with the assistance of external cybersecurity experts determined that certain files had been exfiltrated, although the full scope of the breach remains under review. The company said the incident did not disrupt operations and that it is not aware of the stolen files being leaked or misused.
Meanwhile, the filing also referenced a separate cybersecurity incident unrelated to the June intrusion. Although Analog Devices did not provide additional details, reports suggest it may be linked to claims by the ExfilSquad ransomware group that it had stolen more than 570,000 records relating to Analog Devices customers.
SourceHow it could affect your business
Organizations should remember that a single cyberattack is not always the end of the story. Even if a ransom is paid or an incident is contained, attackers may return to exploit the same weaknesses, or another threat actor may compromise the network through a different vulnerability. The most effective defense is to continuously strengthen your cybersecurity posture through proactive monitoring, timely patching, strong access controls, layered security and regularly tested incident response and recovery plans.
North America
Omnicell
Several dark web monitoring sites are reporting that California-based health care technology company Omnicell has been named as the recent victim of a data breach.
According to posts by the Everest ransomware group, the attackers stole 1 TB of data from Omnicell, a provider of medication management and pharmacy automation systems used by health care organizations worldwide. The group claims the stolen archive includes source code, SQL databases, credentials, firmware, deployment packages and other sensitive assets. However, neither Omnicell nor independent cybersecurity researchers have confirmed the alleged breach, and no public proof of the stolen data has been released.
If the claims prove to be accurate, this will mark the second major cybersecurity incident affecting Omnicell in recent years. In 2022, the company suffered a ransomware attack that disrupted some of its products, services and internal systems.
SourceHow it could affect your business
Few users understand the step-by-step process behind how ransomware attacks unfold, even though phishing remains one of the most common entry points for these attacks. Educating employees on how ransomware campaigns work can significantly reduce organizational risk. Our Understanding phishing guide explains how ransomware attacks progress and the critical role phishing plays in enabling them, helping organizations strengthen user awareness and prevent ransomware from causing widespread operational damage.


