California’s Attorney General added 6 new data breach notices to its public list on September 2, 2026, according to the California AG Data Breach List.
Unlike Texas and Washington, California’s public list does not publish a residents-affected count — so this roundup tracks incident visibility and reporting dates, not population impact. For affected-resident totals, see our Texas OAG breach tracker.
September month-to-date now totals 10 notices on the California list through September 2, 2026.
Notices Reported September 2, 2026
| Organization | Breach Date(s) (if known) | Reported |
|---|---|---|
| Fiesta Insurance Franchise Corporation | 05/25/2026 | 09/02/2026 |
| Fishbrain AB | 07/30/2026 | 09/02/2026 |
| HumanEdge, Inc. | 03/17/2026, 03/18/2026 | 09/02/2026 |
| Knowledge Research Center | 07/08/2026 | 09/02/2026 |
| See’s Candies, Inc. | 04/11/2026, 04/13/2026 | 09/02/2026 |
| YouLend US LLC | 06/05/2026, 06/09/2026 | 09/02/2026 |
Independent Cybersecurity Audits
EmailMeNow domain audits on September 2, 2026 scored 6 filer domains in this batch.
4 of 6 show 15% Transport Security or below — a recurring gap that makes spoofed breach-notification email easier to deliver.
YouLend US LLC (youlend.com) leads at 78% overall; Fiesta Insurance Franchise Corporation (fiesta.com) scores 23%.
Pattern: Scores below the 100% ideal on identity or transport still leave room for spoofed incident-response email — even when website headers score higher.
| Organization | Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|---|
| Fiesta Insurance Franchise Corporation | fiesta.com | 23% | 0% | 15% | 37% | Weakest |
| Fishbrain AB | fishbrain.com | 69% | 95% | 70% | 43% | Above Average |
| HumanEdge, Inc. | humanedge.com | 63% | 90% | 15% | 37% | Above Average |
| Knowledge Research Center | knowledgeresearchgroup.com | 37% | 25% | 15% | 37% | Weak |
| See’s Candies, Inc. | sees.com | 54% | 65% | 15% | 40% | Average |
| YouLend US LLC | youlend.com | 78% | 90% | 40% | 84% | Good |
Audit links: fiesta.com · fishbrain.com · humanedge.com · knowledgeresearchgroup.com · sees.com · youlend.com
Website stack note
- Fiesta Insurance Franchise Corporation (
fiesta.com): Bootstrap: Bootstrap 3/4 are past primary vendor support; upgrade to Bootstrap 5 when practical (often theme-bundled). - Knowledge Research Center (
knowledgeresearchgroup.com): PHP outdated/unsupported (7.1.33 — no vendor security patches); WordPress behind current (running 4.2.38; latest 7.1); WordPress: WordPress core older than 6.4 has multiple known security fixes in later releases; upgrade promptly.; Contact Form 7: Contact Form 7 versions before 5.9 include fixed XSS and related issues.
Related trackers
- All state AG trackers
- Texas OAG YTD dashboard
- California AG breach list
- Washington AG tracker
- Healthcare AG breach tracker
- Washington healthcare breaches (2026)
- Washington law firm breaches (2026)
- CA September roundup
- TX September roundup
- WA August roundup
- TX Parks breach
- Have I Been Pwned
- HIBP September roundup
- Breach data week (September)
- HHS OCR August roundup
- SEC 8-K September roundup
- Monitoring guide
Source: California AG — Data Breach List