Baylor Genetics disclosed a data security incident affecting nearly 250,000 individuals after detecting unauthorized activity in parts of its internal network. The company said an unauthorized third party accessed portions of its network and stored data between June 11 and June 17, 2026, with the intrusion discovered on June 15 during that window. Baylor Genetics reported 248,430 affected individuals to Texas regulators and notified law enforcement as it investigated the breach.
The exposed information included sensitive personal, medical, insurance, and Social Security data, while some current and former employees also had government identification and financial account information compromised. Baylor Genetics said it has secured affected systems and strengthened security controls following the incident, and reported that it had not identified misuse of the stolen information at the time of disclosure. No threat actor had publicly claimed responsibility.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Baylor Genetics said it completed a detailed review of the data and individuals potentially affected by the incident on July 30, 2026. The review followed the June network intrusion investigation conducted with outside cybersecurity and digital forensics specialists.
Baylor Genetics said its investigation determined the unauthorized third party's access to parts of its network and stored data continued until June 17, 2026.
On June 15, 2026, Baylor Genetics identified unauthorized activity within portions of its internal network. The company then launched an investigation with external cybersecurity experts, took containment steps, and notified law enforcement.
Baylor Genetics said an unauthorized third party accessed portions of its network and data stored on it beginning on June 11, 2026. The intrusion window later identified by the company ran from June 11 through June 17, 2026.
Baylor Genetics disclosed a data security incident affecting at least 248,430 individuals and reported it to Texas regulators. The company said exposed data included personal, medical, insurance, and Social Security information, with some employee records also including government ID and financial account data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceteiss.co.uk
Open sourcebaylorgenetics.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.