<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Obsidian Lake // US Data Breach Feed</title>
    <link>https://obsidian-lake.com/breach-feed.xml</link>
    <description>Curated rolling feed of significant US data breaches. Aggregated from public disclosures, regulatory filings, and the cypherpunk press.</description>
    <atom:link href="https://obsidian-lake.com/breach-feed.xml" rel="self"/>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>Obsidian Lake Breach Aggregator v1.0</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 14 Sep 2026 21:57:26 +0000</lastBuildDate>
    <item>
      <title>[INFO] Possible cyber incident disrupts Monroe schools in Wisconsin</title>
      <link>https://databreaches.net/2026/09/14/possible-cyber-incident-disrupts-monroe-schools-in-wisconsin/</link>
      <description>Joseph Topping reports an incident at the School District of Monroe in Wisconsin has resulted in the district pulling the plug on internet connections: Students powered down computers, school phone service failed and a scheduled ACT session was canceled after a possible network security issue disrupted the School District of Monroe in Wisconsin. Classes continued...
&lt;p&gt;&lt;a href="https://databreaches.net/2026/09/14/possible-cyber-incident-disrupts-monroe-schools-in-wisconsin/"&gt;Source&lt;/a&gt;&lt;/p&gt;

// Severity: info // Records (est.): 2,026 // Source: databreaches.net // Original: https://databreaches.net/2026/09/14/possible-cyber-incident-disrupts-monroe-schools-in-wisconsin/</description>
      <guid isPermaLink="false">obsidian-lake:breach:02b99bb8826495ef</guid>
      <category>info</category>
      <category>databreaches.net</category>
      <pubDate>Mon, 14 Sep 2026 17:44:59 +0000</pubDate>
    </item>
    <item>
      <title>[CRITICAL] Hacking Incident Affects 46,000 Hawaii Family Dental Patients</title>
      <link>https://www.hipaajournal.com/hacking-incident-hawaii-family-dental/</link>
      <description>&lt;p&gt;A hacking incident at Hawaii Family Dental has affected almost 46,000 individuals. Data breaches have also been announced by Life [&amp;#8230;]&lt;/p&gt;
&lt;p&gt;The post &lt;a href="https://www.hipaajournal.com/hacking-incident-hawaii-family-dental/"&gt;Hacking Incident Affects 46,000 Hawaii Family Dental Patients&lt;/a&gt; appeared first on &lt;a href="https://www.hipaajournal.com"&gt;The HIPAA Journal&lt;/a&gt;.&lt;/p&gt;

// Severity: critical // Records (est.): 46,000 // Source: hipaajournal // Original: https://www.hipaajournal.com/hacking-incident-hawaii-family-dental/</description>
      <guid isPermaLink="false">obsidian-lake:breach:4ced868b45a789f4</guid>
      <category>critical</category>
      <category>hipaajournal</category>
      <pubDate>Mon, 14 Sep 2026 15:27:35 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] FTC Rescinds 2021 Policy Statement on Health App Data Breaches</title>
      <link>https://www.hipaajournal.com/ftc-rescinds-policy-statement-health-app-data-breaches/</link>
      <description>&lt;p&gt;In September 2021, the U.S. Federal Trade Commission (FTC) issued a policy statement extending the FTC Health Breach Notification Rule [&amp;#8230;]&lt;/p&gt;
&lt;p&gt;The post &lt;a href="https://www.hipaajournal.com/ftc-rescinds-policy-statement-health-app-data-breaches/"&gt;FTC Rescinds 2021 Policy Statement on Health App Data Breaches&lt;/a&gt; appeared first on &lt;a href="https://www.hipaajournal.com"&gt;The HIPAA Journal&lt;/a&gt;.&lt;/p&gt;

// Severity: info // Records (est.): 8,230 // Source: hipaajournal // Original: https://www.hipaajournal.com/ftc-rescinds-policy-statement-health-app-data-breaches/</description>
      <guid isPermaLink="false">obsidian-lake:breach:0488257c389122c5</guid>
      <category>info</category>
      <category>hipaajournal</category>
      <pubDate>Mon, 14 Sep 2026 14:24:32 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Conti Ransomware Member Sentenced to 4 Years in Jail</title>
      <link>https://www.hipaajournal.com/conti-ransomware-member-sentenced-4-years/</link>
      <description>&lt;p&gt;A Ukrainian national who deployed Conti ransomware on the networks of at least 12 organizations in the United States and [&amp;#8230;]&lt;/p&gt;
&lt;p&gt;The post &lt;a href="https://www.hipaajournal.com/conti-ransomware-member-sentenced-4-years/"&gt;Conti Ransomware Member Sentenced to 4 Years in Jail&lt;/a&gt; appeared first on &lt;a href="https://www.hipaajournal.com"&gt;The HIPAA Journal&lt;/a&gt;.&lt;/p&gt;

// Severity: info // Records (est.): 8,230 // Source: hipaajournal // Original: https://www.hipaajournal.com/conti-ransomware-member-sentenced-4-years/</description>
      <guid isPermaLink="false">obsidian-lake:breach:871d8735e3a5fb3b</guid>
      <category>info</category>
      <category>hipaajournal</category>
      <pubDate>Mon, 14 Sep 2026 12:46:28 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Delaware Consumer Privacy and Data-Breach Law Updates</title>
      <link>https://databreaches.net/2026/09/13/delaware-consumer-privacy-and-data-breach-law-updates/</link>
      <description>Joseph J. Lazzarotti of JacksonLewis writes: On September 2, 2026, Delaware’s Governor signed House Bill (HB) 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), which was enacted in 2023 and became effective January 1, 2025. HB 381 separately amends Delaware’s computer security breach notification law. In short, what changes...
&lt;p&gt;&lt;a href="https://databreaches.net/2026/09/13/delaware-consumer-privacy-and-data-breach-law-updates/"&gt;Source&lt;/a&gt;&lt;/p&gt;

// Severity: info // Records (est.): 2,026 // Source: databreaches.net // Original: https://databreaches.net/2026/09/13/delaware-consumer-privacy-and-data-breach-law-updates/</description>
      <guid isPermaLink="false">obsidian-lake:breach:65b05c1ccc6b6b63</guid>
      <category>info</category>
      <category>databreaches.net</category>
      <pubDate>Sun, 13 Sep 2026 14:50:40 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] TX: Two Lamesa ISD employees arrested over security breach</title>
      <link>https://databreaches.net/2026/09/11/tx-two-lamesa-isd-employees-arrested-over-security-breach/</link>
      <description>Urijah Jaushlin reports: Two Lamesa ISD employees were arrested in connection with a law enforcement investigation involving allegations of a breach of computer security, according to a press release by the Lamesa Independent School District Friday morning. The Lamesa Police Department announced in a press release that authorities, along with the Texas Rangers, arrested 54-year-old...
&lt;p&gt;&lt;a href="https://databreaches.net/2026/09/11/tx-two-lamesa-isd-employees-arrested-over-security-breach/"&gt;Source&lt;/a&gt;&lt;/p&gt;

// Severity: info // Records (est.): 2,026 // Source: databreaches.net // Original: https://databreaches.net/2026/09/11/tx-two-lamesa-isd-employees-arrested-over-security-breach/</description>
      <guid isPermaLink="false">obsidian-lake:breach:ee71d6dcd5749f31</guid>
      <category>info</category>
      <category>databreaches.net</category>
      <pubDate>Fri, 11 Sep 2026 18:53:51 +0000</pubDate>
    </item>
    <item>
      <title>[CRITICAL] Central Maine Medical Center &amp; Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits</title>
      <link>https://www.hipaajournal.com/central-maine-medical-center-susan-b-allen-memorial-hospital-data-breach-settlements/</link>
      <description>&lt;p&gt;Central Maine Medical Center &amp;#38; Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data [&amp;#8230;]&lt;/p&gt;
&lt;p&gt;The post &lt;a href="https://www.hipaajournal.com/central-maine-medical-center-susan-b-allen-memorial-hospital-data-breach-settlements/"&gt;Central Maine Medical Center &amp;#038; Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits&lt;/a&gt; appeared first on &lt;a href="https://www.hipaajournal.com"&gt;The HIPAA Journal&lt;/a&gt;.&lt;/p&gt;

// Severity: critical // Records (est.): 8,230 // Source: hipaajournal // Original: https://www.hipaajournal.com/central-maine-medical-center-susan-b-allen-memorial-hospital-data-breach-settlements/</description>
      <guid isPermaLink="false">obsidian-lake:breach:05b43da569e71eb4</guid>
      <category>critical</category>
      <category>hipaajournal</category>
      <pubDate>Fri, 11 Sep 2026 10:00:28 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data</title>
      <link>https://www.hipaajournal.com/veradigm-data-breach-2026/</link>
      <description>&lt;p&gt;The Chicago, Illinois-based practice management and electronic health record company Veradigm (formerly Allscripts Healthcare Solutions) has disclosed a cybersecurity incident in [&amp;#8230;]&lt;/p&gt;
&lt;p&gt;The post &lt;a href="https://www.hipaajournal.com/veradigm-data-breach-2026/"&gt;Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data&lt;/a&gt; appeared first on &lt;a href="https://www.hipaajournal.com"&gt;The HIPAA Journal&lt;/a&gt;.&lt;/p&gt;

// Severity: info // Records (est.): 8,230 // Source: hipaajournal // Original: https://www.hipaajournal.com/veradigm-data-breach-2026/</description>
      <guid isPermaLink="false">obsidian-lake:breach:413f8188de5e057a</guid>
      <category>info</category>
      <category>hipaajournal</category>
      <pubDate>Thu, 10 Sep 2026 16:43:40 +0000</pubDate>
    </item>
    <item>
      <title>[HIGH] AdaptHealth Data Breach Affects 4.1 Million Individuals</title>
      <link>https://www.hipaajournal.com/adapthealth-data-breach/</link>
      <description>&lt;p&gt;In early July, we reported that AdaptHealth had notified the U.S. Securities and Exchange Commission that it had experienced a [&amp;#8230;]&lt;/p&gt;
&lt;p&gt;The post &lt;a href="https://www.hipaajournal.com/adapthealth-data-breach/"&gt;AdaptHealth Data Breach Affects 4.1 Million Individuals&lt;/a&gt; appeared first on &lt;a href="https://www.hipaajournal.com"&gt;The HIPAA Journal&lt;/a&gt;.&lt;/p&gt;

// Severity: high // Records (est.): 4,099,999 // Source: hipaajournal // Original: https://www.hipaajournal.com/adapthealth-data-breach/</description>
      <guid isPermaLink="false">obsidian-lake:breach:207c2eacc0b903ca</guid>
      <category>high</category>
      <category>hipaajournal</category>
      <pubDate>Thu, 10 Sep 2026 11:07:59 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Lessons Learned from CISA’s Recent GitHub Leak</title>
      <link>https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/</link>
      <description>The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.

// Severity: info // Records (est.): 0 // Source: krebsonsecurity // Original: https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/</description>
      <guid isPermaLink="false">obsidian-lake:breach:7112bb85f69498e7</guid>
      <category>info</category>
      <category>krebsonsecurity</category>
      <pubDate>Mon, 13 Jul 2026 15:03:28 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Lawmakers Demand Answers as CISA Tries to Contain Data Leak</title>
      <link>https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak/</link>
      <description>Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity &amp;#038; Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

// Severity: info // Records (est.): 38 // Source: krebsonsecurity // Original: https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak/</description>
      <guid isPermaLink="false">obsidian-lake:breach:3f8726550edb61ae</guid>
      <category>info</category>
      <category>krebsonsecurity</category>
      <pubDate>Fri, 22 May 2026 16:34:24 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] CISA Admin Leaked AWS GovCloud Keys on Github</title>
      <link>https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/</link>
      <description>Until this past weekend, a contractor for the Cybersecurity &amp;#038; Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

// Severity: info // Records (est.): 38 // Source: krebsonsecurity // Original: https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/</description>
      <guid isPermaLink="false">obsidian-lake:breach:5ec3d8398ea01bae</guid>
      <category>info</category>
      <category>krebsonsecurity</category>
      <pubDate>Mon, 18 May 2026 20:48:21 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Social Insecurity: Billions of Social Security Number and Passwords | UpGuard</title>
      <link>https://www.upguard.com/breaches/social-insecurity-billions-of-social-security-number-and-passwords</link>
      <description>UpGuard research found a trove of sensitive information in an exposed Elastic database. Getting to the bottom of what it meant led us down an interesting path.

// Severity: info // Records (est.): 0 // Source: upguard // Original: https://www.upguard.com/breaches/social-insecurity-billions-of-social-security-number-and-passwords</description>
      <guid isPermaLink="false">obsidian-lake:breach:13360d8d6761e847</guid>
      <category>info</category>
      <category>upguard</category>
      <pubDate>Thu, 19 Feb 2026 18:18:05 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] The Aggregate IQ Files, Part One: How a Political Engineering Firm Exposed Their Code Base | UpGuard</title>
      <link>https://www.upguard.com/breaches/aggregate-iq-part-one</link>
      <description>Political data firm AggregateIQ exposed IT assets that raise questions for society about how technology is being used in recent US political history.

// Severity: info // Records (est.): 0 // Source: upguard // Original: https://www.upguard.com/breaches/aggregate-iq-part-one</description>
      <guid isPermaLink="false">obsidian-lake:breach:838ecd902b27c5d2</guid>
      <category>info</category>
      <category>upguard</category>
      <pubDate>Sat, 26 Jul 2025 03:27:49 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Police Procedural: How South Carolina Arrest Records Were Exposed | UpGuard</title>
      <link>https://www.upguard.com/breaches/spartan-south-carolina-arrest-records-data-exposure</link>
      <description>Everyone who depends on tech assumes its risks. The justice system is no exception. See how detailed arrest records for South Carolina were exposed online.

// Severity: info // Records (est.): 0 // Source: upguard // Original: https://www.upguard.com/breaches/spartan-south-carolina-arrest-records-data-exposure</description>
      <guid isPermaLink="false">obsidian-lake:breach:b701edd194b48ee3</guid>
      <category>info</category>
      <category>upguard</category>
      <pubDate>Sat, 26 Jul 2025 03:27:49 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Out of Pocket: How an ISP Exposed Administrative System Credentials | UpGuard</title>
      <link>https://www.upguard.com/breaches/out-of-pocket-how-an-isp-exposed-administrative-system-credentials</link>
      <description>ISPs do more than provide internet service for individual customers-- they can also act as part of US critical infrastructure. See how one ISP exposed their administrative and root passwords to the public.

// Severity: info // Records (est.): 0 // Source: upguard // Original: https://www.upguard.com/breaches/out-of-pocket-how-an-isp-exposed-administrative-system-credentials</description>
      <guid isPermaLink="false">obsidian-lake:breach:9c2b7b1bd50a2733</guid>
      <category>info</category>
      <category>upguard</category>
      <pubDate>Sat, 26 Jul 2025 03:27:49 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Spy Games: How Booz Allen Hamilton Exposed Pentagon Access Keys | UpGuard</title>
      <link>https://www.upguard.com/breaches/spy-games-booz-allen-hamilton-pentagon</link>
      <description>While this blog post provides a description of a data exposure discovery involving Booz Allen Hamilton and the US National Geospatial-Intelligence Agency (NGA), this is no longer an active data breach.

// Severity: info // Records (est.): 0 // Source: upguard // Original: https://www.upguard.com/breaches/spy-games-booz-allen-hamilton-pentagon</description>
      <guid isPermaLink="false">obsidian-lake:breach:502a5e86a571c948</guid>
      <category>info</category>
      <category>upguard</category>
      <pubDate>Sat, 26 Jul 2025 03:27:49 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Double Indemnity: How An Insurer Exposed Its Customers | UpGuard</title>
      <link>https://www.upguard.com/breaches/nas-leak-mdjia</link>
      <description>A shared-risk property insurance provider in Maryland left exposed data revealing the personal details of thousands of customers.

// Severity: info // Records (est.): 0 // Source: upguard // Original: https://www.upguard.com/breaches/nas-leak-mdjia</description>
      <guid isPermaLink="false">obsidian-lake:breach:2912e6157297f1f3</guid>
      <category>info</category>
      <category>upguard</category>
      <pubDate>Sat, 26 Jul 2025 03:27:49 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Out of Commission: How the Oklahoma Department of Securities Leaked Millions of Files | UpGuard</title>
      <link>https://www.upguard.com/breaches/rsync-oklahoma-securities-commission</link>
      <description>A storage server configured for public access exposed millions of files belonging to the Oklahoma Securities Commission.

// Severity: info // Records (est.): 0 // Source: upguard // Original: https://www.upguard.com/breaches/rsync-oklahoma-securities-commission</description>
      <guid isPermaLink="false">obsidian-lake:breach:df52e9278ec2c7ee</guid>
      <category>info</category>
      <category>upguard</category>
      <pubDate>Thu, 10 Jul 2025 08:09:36 +0000</pubDate>
    </item>
    <item>
      <title>[CRITICAL] The RNC Files: Inside the Largest US Voter Data Leak | UpGuard</title>
      <link>https://www.upguard.com/breaches/the-rnc-files</link>
      <description>UpGuard has discovered an open database containing information on what appear to be approximately 198 million American voters left misconfigured by a GOP analytics firm.

// Severity: critical // Records (est.): 198,000,000 // Source: upguard // Original: https://www.upguard.com/breaches/the-rnc-files</description>
      <guid isPermaLink="false">obsidian-lake:breach:f096f9f0b67fdeb9</guid>
      <category>critical</category>
      <category>upguard</category>
      <pubDate>Thu, 10 Jul 2025 08:09:36 +0000</pubDate>
    </item>
    <item>
      <title>[CRITICAL] Home Economics: How Life in 123 Million American Households Was Exposed Online | UpGuard</title>
      <link>https://www.upguard.com/breaches/cloud-leak-alteryx</link>
      <description>This cloud leak reveals the personal details of 123 million US households, revealing in-depth analysis of their finances sold by credit reporting agency Experian.

// Severity: critical // Records (est.): 123,000,000 // Source: upguard // Original: https://www.upguard.com/breaches/cloud-leak-alteryx</description>
      <guid isPermaLink="false">obsidian-lake:breach:5d77144505da7eae</guid>
      <category>critical</category>
      <category>upguard</category>
      <pubDate>Thu, 10 Jul 2025 08:09:36 +0000</pubDate>
    </item>
    <item>
      <title>[INFO] Florida County Database Mistake: Election Officials’ Logins Among Exposed Data | UpGuard</title>
      <link>https://www.upguard.com/breaches/martin-county-florida-election-officials-passwords</link>
      <description>UpGuard can now disclose that an Amazon S3 storage bucket containing publicly exposed backups of systems representing the intranet and web presence for Martin County, Florida has been secured.

// Severity: info // Records (est.): 0 // Source: upguard // Original: https://www.upguard.com/breaches/martin-county-florida-election-officials-passwords</description>
      <guid isPermaLink="false">obsidian-lake:breach:51bd0c6b752f0bdd</guid>
      <category>info</category>
      <category>upguard</category>
      <pubDate>Wed, 20 Nov 2024 06:36:57 +0000</pubDate>
    </item>
  </channel>
</rss>
