Back to news
Cybersecurity Alert
September 6, 2026 by EmailMeNow IT Consulting

Breach Data Week of September 6, 2026: Texas, HIBP, SEC & HHS Updates

Multi-source breach data week of September 6, 2026: Texas OAG, HHS OCR, SEC Form 8-K, HIBP, and state AG trackers. Texas YTD reports +17 (426 → 443). 13 companies/entities from source roundups.

Source: EmailMeNow Breach Data Refresh

CybersecurityData BreachTexasHave I Been PwnedHHS OCRSECForm 8-K
Multi-source breach data week of September 6, 2026

This is EmailMeNow’s multi-source breach data week snapshot for September 6, 2026, covering Texas OAG, California AG, Washington AG, Have I Been Pwned, HHS OCR, and SEC Form 8-K cyber filings. Figures come from our committed datasets after the weekly refresh — not a single regulator feed.

Illustration: multi-source breach data week covering state AG, HIBP, SEC, and HHS trackers for September 6, 2026

Current YTD snapshot

SourceMetricValue
Texas OAGYTD reports443
Texas OAGTexans affected31,641,884
HHS OCR2026 submissions320
HHS OCRIndividuals (2026)61,171,138
SEC Form 8-KItem 1.05 families YTD19
SEC Form 8-KItem 1.05 raw filings YTD24
SEC Form 8-KCyber-related 8-Ks tracked43
California AGYTD notices381
Washington AGYTD reports50
Washington AGWashingtonians affected570,121
Have I Been Pwned2026 listings81
Have I Been PwnedAccounts (2026 listings)283,048,751

Week-over-week changes

Compared with the prior weekly alert baseline:

  • Texas YTD reports +17 (426 → 443)
  • Texas YTD affected +169,301 (31,472,583 → 31,641,884)
  • HHS 2026 submissions +26 (294 → 320)
  • HHS 2026 individuals +12,654,912 (48,516,226 → 61,171,138)
  • SEC 8-K Item 1.05 families YTD +2 (17 → 19)

Source roundups this week

Source-specific detail pages for this week’s new listings. This digest is the multi-source hub (YTD totals + companies); open a roundup below for that source’s table and audits.

Companies added this week

Entities newly listed in source roundups through September 6, 2026 (13 shown; 13 with a researched domain). Domain audit scores for scored filers follow in Independent Cybersecurity Audits.

OrganizationSourceDomain
LHC Group, IncTexas OAGlhcgroup.com
Bimbo Bakeries USATexas OAGbimbobakeriesusa.com
Brown, Jake & McDaniel, P.C.Texas OAGbrown.com
Virta Health Corp. and Virta Medical, PCTexas OAGvirtamedical.com
Fiesta Insurance Franchise CorporationCalifornia AGfiesta.com
Fishbrain ABCalifornia AGfishbrain.com
HumanEdge, Inc.California AGhumanedge.com
Knowledge Research CenterCalifornia AGknowledgeresearchgroup.com
See’s Candies, Inc.California AGsees.com
YouLend US LLCCalifornia AGyoulend.com
Manchester Airports GroupHave I Been Pwnedmagairports.com
Park Dental Partners, Inc.SEC Form 8-Kpark56dental.com
NovoCure LtdSEC Form 8-Koteis.fr

Independent Cybersecurity Audits

EmailMeNow domain audits on September 6, 2026 scored 13 filer domains in this batch. 11 of 13 show 15% Transport Security or below — a recurring gap that makes spoofed breach-notification email easier to deliver. YouLend US LLC (youlend.com) leads at 78% overall; Fiesta Insurance Franchise Corporation (fiesta.com) scores 23%.

Pattern: Scores below the 100% ideal on identity or transport still leave room for spoofed incident-response email — even when website headers score higher.

OrganizationDomainOverallIdentityTransportWebsiteRisk
LHC Group, Inclhcgroup.com49%55%15%37%Below Average
Bimbo Bakeries USAbimbobakeriesusa.com43%0%15%90%Below Average
Brown, Jake & McDaniel, P.C.brown.com37%25%15%37%Weak
Virta Health Corp. and Virta Medical, PCvirtamedical.com23%0%15%37%Weakest
Fiesta Insurance Franchise Corporationfiesta.com23%0%15%37%Weakest
Fishbrain ABfishbrain.com69%95%70%43%Above Average
HumanEdge, Inc.humanedge.com63%90%15%37%Above Average
Knowledge Research Centerknowledgeresearchgroup.com37%25%15%37%Weak
See’s Candies, Inc.sees.com54%65%15%40%Average
YouLend US LLCyoulend.com78%90%40%84%Good
Manchester Airports Groupmagairports.com63%90%15%37%Above Average
Park Dental Partners, Inc.park56dental.com64%90%15%40%Above Average
NovoCure Ltdoteis.fr47%50%15%37%Below Average

Audit links: lhcgroup.com · bimbobakeriesusa.com · brown.com · virtamedical.com · fiesta.com · fishbrain.com · humanedge.com · knowledgeresearchgroup.com · sees.com · youlend.com · magairports.com · park56dental.com · oteis.fr

Website stack note

  • Bimbo Bakeries USA (bimbobakeriesusa.com): Drupal behind current (running 11; latest 11.4.6)
  • Fiesta Insurance Franchise Corporation (fiesta.com): Bootstrap: Bootstrap 3/4 are past primary vendor support; upgrade to Bootstrap 5 when practical (often theme-bundled).
  • Knowledge Research Center (knowledgeresearchgroup.com): PHP outdated/unsupported (7.1.33 — no vendor security patches); WordPress behind current (running 4.2.38; latest 7.1); WordPress: WordPress core older than 6.4 has multiple known security fixes in later releases; upgrade promptly.; Contact Form 7: Contact Form 7 versions before 5.9 include fixed XSS and related issues.
  • NovoCure Ltd (oteis.fr): WordPress behind current (running 6.7.7; latest 7.1)
  • Park Dental Partners, Inc. (park56dental.com): Drupal major version behind (reports 10; current major is 11.4.6)

Sources: Texas OAG · California AG · Washington AG · Have I Been Pwned · HHS OCR · SEC EDGAR