Rumpke Waste & Recycling agreed to a $750,000 class-action settlement tied to a cyberattack that resulted in the theft of over 3TB of data and impacted nearly 17,000 current and former employees, according to multiple reports. The incident was publicly disclosed on January 13, 2026, and is described as having been detected around October 2024; no threat actor attribution was provided in the reporting. Exposed data is described as including highly sensitive personal identifiers such as Social Security numbers, and the settlement includes reimbursement and credit monitoring for affected individuals, while the company denies wrongdoing.
The other items in the set describe separate security stories and should not be conflated with the Rumpke matter. PcComponentes denied that attackers breached its internal systems or stole a 16M-record customer database, but acknowledged evidence of a credential stuffing campaign against customer accounts. Separately, Microsoft’s January security update addressed 114 vulnerabilities including three reported zero-days—CVE-2026-20805, CVE-2026-21265, and CVE-2023-31096—with CVE-2026-20805 described as actively exploited; this is a patch/vulnerability disclosure topic rather than a confirmed Microsoft “data breach.”

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
By 2026-01-21, reporting said Rumpke had agreed to a preliminary $750,000 settlement related to the breach. The settlement includes cash payments or reimbursements and credit monitoring for affected individuals, while the company denied wrongdoing.
On 2026-01-13, Rumpke Waste & Recycling publicly disclosed a data breach tied to the earlier cyberattack. The company said the incident affected nearly 17,000 current and former employees.
Around October 2024, attackers reportedly gained unauthorized access to Rumpke Waste & Recycling systems and stole more than 3 terabytes of data. The compromised data included sensitive employee information, including Social Security numbers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
upguard.com
Open sourceupguard.com
Open sourceupguard.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.