Back to news
Cybersecurity Alert
August 2, 2026 by EmailMeNow IT Consulting

Breach Data Week of August 2, 2026: Texas, HIBP, SEC & HHS Updates

Multi-source breach data week of August 2, 2026: Texas OAG, HHS OCR, SEC Form 8-K, HIBP, and state AG trackers. Texas YTD reports +18 (352 → 370). 11 companies/entities from source roundups.

Source: EmailMeNow Breach Data Refresh

CybersecurityData BreachTexasHave I Been PwnedHHS OCRSECForm 8-K
Multi-source breach data week of August 2, 2026

This is EmailMeNow’s multi-source breach data week snapshot for August 2, 2026, covering Texas OAG, California AG, Washington AG, Have I Been Pwned, HHS OCR, and SEC Form 8-K cyber filings. Figures come from our committed datasets after the weekly refresh — not a single regulator feed.

Illustration: multi-source breach data week covering state AG, HIBP, SEC, and HHS trackers for August 2, 2026

Current YTD snapshot

SourceMetricValue
Texas OAGYTD reports370
Texas OAGTexans affected29,722,801
HHS OCR2026 submissions257
HHS OCRIndividuals (2026)24,810,594
SEC Form 8-KItem 1.05 families YTD15
SEC Form 8-KItem 1.05 raw filings YTD20
SEC Form 8-KCyber-related 8-Ks tracked34
California AGYTD notices321
Washington AGYTD reports50
Washington AGWashingtonians affected658,884
Have I Been Pwned2026 listings70
Have I Been PwnedAccounts (2026 listings)243,644,945

Week-over-week changes

Compared with the prior weekly alert baseline:

  • Texas YTD reports +18 (352 → 370)
  • Texas YTD affected +377,495 (29,345,306 → 29,722,801)
  • HHS 2026 submissions +11 (246 → 257)
  • HHS 2026 individuals +317,200 (24,493,394 → 24,810,594)
  • SEC 8-K Item 1.05 families YTD +1 (14 → 15)

Source roundups this week

SourceRoundupTracker
Have I Been PwnedAugust 1, 2026Open tracker
SEC Form 8-KJuly 31, 2026Open tracker
Texas OAGJuly 31, 2026Open tracker
California AGJuly 27, 2026Open tracker

Companies added this week

Entities newly listed in source roundups through August 2, 2026 (11 shown; 10 with a researched domain). Domain audit scores for scored filers follow in Independent Cybersecurity Audits.

OrganizationSourceDomain
SplitVPNHave I Been Pwnedsplitvpn.io
AMGEN INCSEC Form 8-Kamgen.com
SM Energy CompanyTexas OAGpeoplesenergy.co.uk
Travis County Credit UnionTexas OAGtraviscountytx.gov
Goodwin Procter LLPTexas OAGgoodwinprocter.com
TELUS International AI, Inc., d/b/a TELUS DigitalTexas OAGtelusinternational.com
MPS Enterprises, Inc. (“MPS”)Texas OAGmpsenterprises.co.uk
Sunrise CompanyTexas OAGsunrisecompany.nl
JRK Property Holdings, Inc.California AGjrk.com
Regional Center of Orange CountyCalifornia AG
SPay Inc dba Stack SportsCalifornia AGstacksports.com

Independent Cybersecurity Audits

EmailMeNow domain audits on August 2, 2026 scored 10 filer domains in this batch. 7 of 10 show 15% Transport Security or below — a recurring gap that makes spoofed breach-notification email easier to deliver. AMGEN INC (amgen.com) leads at 66% overall; SM Energy Company (peoplesenergy.co.uk) scores 23%.

Pattern: Scores below the 100% ideal on identity or transport still leave room for spoofed incident-response email — even when website headers score higher.

OrganizationDomainOverallIdentityTransportWebsiteRisk
SplitVPNsplitvpn.io48%50%15%40%Below Average
AMGEN INCamgen.com66%90%50%43%Above Average
SM Energy Companypeoplesenergy.co.uk23%0%15%37%Weakest
Travis County Credit Uniontraviscountytx.gov62%50%15%87%Above Average
Goodwin Procter LLPgoodwinprocter.com47%50%15%37%Below Average
TELUS International AI, Inc., d/b/a TELUS Digitaltelusinternational.com53%65%15%37%Average
MPS Enterprises, Inc. (“MPS”)mpsenterprises.co.uk41%35%15%37%Below Average
Sunrise Companysunrisecompany.nl38%25%45%37%Weak
JRK Property Holdings, Inc.jrk.com62%85%45%37%Above Average
SPay Inc dba Stack Sportsstacksports.com65%90%15%45%Above Average

Audit links: splitvpn.io · amgen.com · peoplesenergy.co.uk · traviscountytx.gov · goodwinprocter.com · telusinternational.com · mpsenterprises.co.uk · sunrisecompany.nl · jrk.com · stacksports.com

Website stack note

  • MPS Enterprises, Inc. (“MPS”) (mpsenterprises.co.uk): PHP outdated/unsupported (5.3.29 — no vendor security patches)
  • Sunrise Company (sunrisecompany.nl): PHP outdated/unsupported (7.4.33 — no vendor security patches); WordPress behind current (running 6.7.7; latest 7.0.4)
  • Travis County Credit Union (traviscountytx.gov): Bootstrap: Bootstrap 3/4 are past primary vendor support; upgrade to Bootstrap 5 when practical (often theme-bundled).

Sources: Texas OAG · California AG · Washington AG · Have I Been Pwned · HHS OCR · SEC EDGAR