The Data Breach Brief: Week of September 23rd, 2026

4 min read time
Media image.

Injured? 

We can help.

The following data breaches have been announced this week—make sure you’re in the know.

If you received a data breach notice regarding any of the breaches listed below, act now and take Morgan & Morgan’s data breach quiz to see if you may be eligible for compensation.

Tarter Krinsky & Drogin LLP

Tarter Krinsky & Drogin LLP suffered a data breach between July 9 and September 9, 2025, when an unauthorized actor accessed certain company servers and viewed or obtained information stored within them. The compromised data may contain specific types of personal information, including:

  • Names
  • Social Security numbers
  • Driver’s license numbers
  • Dates of birth
  • Passport numbers
  • International tax identification numbers
  • Tax identification or individual tax identification numbers
  • Financial account information
  • Payment card information
  • Usernames and passwords
  • Medical information
  • Health insurance information
  • Biometric data

Graham County Hospital

Graham County Hospital suffered a data breach through third-party vendor Aesto, LLC between December 2 and 18, 2025, when an unauthorized actor accessed or acquired information stored within a portion of Aesto’s Amazon Web Services infrastructure. The compromised data may contain specific types of personal information, including:

  • Social Security numbers
  • Dates of birth

AVL Growth Partners, an Ampleo Company

AVL Growth Partners, an Ampleo Company, disclosed a data breach in September 2026 involving personal and financial information maintained by the company. The compromised data may contain specific types of personal information, including:

  • Names
  • Social Security numbers
  • Financial account codes
  • Credit and debit account information

Tessco, LLC

Tessco, LLC disclosed a data breach in September 2026 involving personal information, including information belonging to minor dependents. The compromised data may contain specific types of personal information, including:

  • Names
  • Social Security numbers
  • Financial account codes
  • Credit and debit account information

Lincoln Investment Planning, LLC

Lincoln Investment Planning, LLC disclosed a data breach in September 2026 involving sensitive personal, financial, identification, and health information. Additional details about how and when the incident occurred have not been publicly disclosed. The compromised data may contain specific types of personal information, including:

  • Names
  • Social Security numbers
  • Financial account codes
  • Credit and debit account information
  • Government-issued identification numbers
  • Health records

Gastroenterology & Hepatology of Central New York, P.C.

Gastroenterology & Hepatology of Central New York, P.C. suffered a data breach on or around March 6, 2026, when an unauthorized party accessed certain systems within its network and acquired records containing personal and protected health information. The compromised data may contain specific types of personal information, including:

  • Names
  • Dates of birth
  • Social Security numbers
  • Medical record numbers
  • Phone numbers
  • Addresses

LeMaitre Vascular, Inc.

LeMaitre Vascular, Inc. disclosed a data breach in September 2026 involving sensitive personal and health information. The company’s public notification did not specify when the incident occurred or how it happened. The compromised data may contain specific types of personal information, including:

  • Names
  • Social Security numbers
  • Government-issued identification numbers
  • Health records

If you or a loved one were affected by any of these data breaches, you may be entitled to compensation. Find out more in minutes with our online data breach quiz.

Disclaimer
This website is meant for general information and not legal advice.

Injured?

Not sure what to do next?
We'll guide you through everything you need to know.