Multiple organizations reported or resolved matters related to cyber incidents affecting sensitive personal data. Choice Hotels International disclosed that a “skilled person” used social engineering to access (despite MFA) an application containing records for franchisees and franchise applicants, exposing data including names and Social Security numbers; the company indicated the incident involved franchise-related records rather than guest data. Separately, Wynn Resorts had not publicly responded to claims by ShinyHunters that the actor obtained roughly 800,000 records, with no proof posted and no apparent public filing or statement at the time referenced; reporting suggested the alleged exposure may involve employee data rather than guest data. In Taiwan, The Grand Hotel (Taipei) reported detecting unauthorized access and stated it could not yet rule out impact to customer/guest data.
In healthcare, a small medical practice in Northern Ireland (Grange Dental Care) reported a compromise that led to fraudulent emails being sent from the practice’s systems requesting invoice payments; the practice stated it identified the issue quickly and engaged its IT provider to contain and investigate, with initial indications the attack originated overseas. Separately, Granite Wellness Centers (California) and Pediatric Home Service (Minnesota) agreed to class action settlements tied to earlier cyberattacks exposing patient data; Granite’s matter stems from a January 2021 ransomware attack in which files containing extensive patient and identity data were confirmed accessed, and the organization agreed to a $725,000 settlement fund while denying wrongdoing and liability.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
A report stated that Wynn Resorts had not publicly responded to claims that ShinyHunters obtained 800,000 records, and that no proof or SEC material-incident filing had been identified. The claim remained unverified at the time of reporting.
The Grand Hotel in Taipei reported detecting unauthorized access to its systems and said it could not yet rule out an impact on customer data. No threat actor was publicly identified in the report.
Pediatric Home Service agreed to settle litigation arising from its November 2024 breach, offering reimbursement for documented losses, a $50 cash option, and credit monitoring services. The company denied wrongdoing and said it settled to avoid continued litigation costs and risk.
Granite Wellness Centers agreed to settle litigation tied to its 2021 ransomware incident through a $725,000 settlement fund with multiple compensation options for class members. The company denied wrongdoing and said it settled to avoid the cost and risk of continued litigation.
On a Thursday morning, Grange Dental Care's computer system was hacked, and recipients began receiving fraudulent invoice-payment emails around 9:50 a.m. The practice contacted its IT provider, stopped activity to limit damage, and began an investigation that initially suggested the attack originated overseas.
On January 14, 2026, Choice Hotels International disclosed that a social-engineering attack led to unauthorized access to an application containing franchisee and franchise applicant records, including names and Social Security numbers. The company said multifactor authentication had been required despite the compromise.
Pediatric Home Service experienced a network intrusion in November 2024 that affected tens of thousands of individuals. The breach later led to class action litigation and a proposed settlement offering reimbursement, cash payments, and credit monitoring.
Granite Wellness Centers experienced a ransomware incident in January 2021 that exposed sensitive information of up to 15,600 individuals. The incident later became the basis for a class action lawsuit and settlement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcedatabreaches.net
Open sourcehipaajournal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.