The Data Breach Brief: Week of July 20th, 2026
Injured?
The following data breaches have been announced this week—make sure you’re in the know.
If you received a data breach notice regarding any of the breaches listed below, act now and take Morgan & Morgan’s data breach quiz to see if you may be eligible for compensation.
Fiesta Insurance Franchise Corporation
Fiesta Insurance Franchise Corporation disclosed a data breach after experiencing a data security incident on or around June 9, 2025. Following an extensive forensic investigation and data review, Fiesta Insurance determined on June 26, 2026, that certain files containing personal information may have been accessed or acquired without authorization.
The compromised data included specific types of personal information, including:
- Names
- Addresses
- Social Security numbers
- Dates of birth
- Driver’s license numbers
- Passport numbers
- Financial account information
- Health-related financial information
Lake Region Healthcare
Lake Region Healthcare disclosed a data breach after detecting unauthorized access to its network on or around May 19, 2025. The organization secured its network and launched an investigation with external cybersecurity professionals. The investigation and review of the affected data concluded on June 5, 2026.
The compromised data included specific types of personal information, including:
- Names
- Dates of birth
- Social Security numbers
- Medical record numbers
- Patient account numbers
- Health insurance information
- Contact information
- Medical and treatment information
- Government-issued identification
- Financial information
Markel Insurance
Markel Insurance disclosed a data breach after an unauthorized actor used social engineering to deceive two employees and gain access to a limited portion of the company’s systems between March 17 and March 18, 2026. Markel detected and blocked the unauthorized activity and subsequently determined that certain personal information had been obtained without authorization.
The compromised data included specific types of personal information, including:
- Names
- Social Security numbers
- Driver’s license numbers
- Medical information
Global Special Operations Forces Foundation
Global Special Operations Forces Foundation disclosed a data breach after learning on or around October 14, 2025, that an unauthorized individual may have accessed one of its email accounts. Following a forensic investigation and manual document review, the organization determined on or around July 9, 2026, that files containing personal information may have been accessed and acquired without authorization.
The compromised data included specific types of personal information, including:
- Names
- Social Security numbers
- Driver’s license numbers
- Government-issued identification numbers
- Non-U.S. national identification numbers
- Dates of birth
- Medical information
Pinnacle Financial Partners, Inc.
Pinnacle Financial Partners, Inc. disclosed a data breach involving Mercadien, P.C., CPAs, a third-party accounting firm that provided advisory services to Pinnacle. Mercadien determined that an unauthorized party accessed and acquired certain data from its network between September 17 and October 9, 2025. Pinnacle subsequently determined on June 16, 2026, that information belonging to some of its clients was included in the affected data.
The compromised data included specific types of personal information, including:
- Names
- Addresses
- Other personal information maintained by Mercadien on Pinnacle’s behalf
If you or a loved one were affected by any of these data breaches, you may be entitled to compensation. Find out more in minutes with our online data breach quiz.

We've got your back
Injured?
Not sure what to do next?
We'll guide you through everything you need to know.