Back to news
Cybersecurity Alert
September 4, 2026 by EmailMeNow IT Consulting

3 New California AG Breach Notices Published September 4, 2026

California's data breach list added 3 notices on September 4, 2026. California does not publish residents-affected counts — this roundup tracks reporting visibility.

Source: California Attorney General - Data Breach List

CybersecurityData BreachCaliforniaState AG
California Attorney General data breach notices for September 4, 2026

California’s Attorney General added 3 new data breach notices to its public list on September 4, 2026, according to the California AG Data Breach List.

Unlike Texas and Washington, California’s public list does not publish a residents-affected count — so this roundup tracks incident visibility and reporting dates, not population impact. For affected-resident totals, see our Texas OAG breach tracker.

September month-to-date now totals 14 notices on the California list through September 4, 2026.

Notices Reported September 4, 2026

OrganizationBreach Date(s) (if known)Reported
Bimbo Bakeries USA08/09/202509/04/2026
Catalyst Brands LLC05/20/202609/04/2026
Elixir Medical Corporation07/20/2026, 07/21/202609/04/2026

Independent Cybersecurity Audits

EmailMeNow domain audits on September 4, 2026 scored 3 filer domains in this batch. 3 of 3 show 15% Transport Security or below — a recurring gap that makes spoofed breach-notification email easier to deliver. Elixir Medical Corporation (elixirmedical.com) leads at 54% overall; Catalyst Brands LLC (catalystbrandstrategy.com) scores 37%.

Pattern: Scores below the 100% ideal on identity or transport still leave room for spoofed incident-response email — even when website headers score higher.

OrganizationDomainOverallIdentityTransportWebsiteRisk
Bimbo Bakeries USAbimbobakeriesusa.com43%0%15%90%Below Average
Catalyst Brands LLCcatalystbrandstrategy.com37%25%15%37%Weak
Elixir Medical Corporationelixirmedical.com54%50%15%62%Average

Audit links: bimbobakeriesusa.com · catalystbrandstrategy.com · elixirmedical.com

Website stack note

  • Bimbo Bakeries USA (bimbobakeriesusa.com): Drupal behind current (running 11; latest 11.4.8)
  • Elixir Medical Corporation (elixirmedical.com): WordPress behind current (running 3.7.1; latest 7.1.2); WordPress: WordPress core older than 6.4 has multiple known security fixes in later releases; upgrade promptly.

Source: California AG — Data Breach List