A rapidly expanding Cyber Incident Registry is emerging as a detailed snapshot of how cyber threats are rippling through U.S. organizations and critical services. As of late August, the registry lists 171 incidents affecting 210 organizations across 474 locations, with updates logged within the past seven days. Rather than a static database, it functions as a living record of digital disruptions, attacks, and suspected incidents spanning everything from healthcare and emergency services to retail and government operations.
The registry organizes incidents by sector, geography, status, and technical characteristics, making it possible to see not only what has gone wrong but where and for whom. Categories range from 911 and public safety answering points to banks, telecom carriers, public utilities, and both nonprofit and for-profit healthcare providers. Filters for critical infrastructure sectors, threat actors, confidence levels, and campaign tags allow observers to trace patterns such as which attacks hit emergency services or which groups repeatedly appear in healthcare-related incidents.
Recent additions underscore how cyber incidents are increasingly intertwined with essential services. One case involves McKesson Corporation, which discovered unauthorized access to third-party applications on August 25, 2026, in business units serving oncology, multispecialty practices and medical-surgical customers. The company confirmed data exfiltration affecting a subset of customers and reported intermittent service degradation, though systems and services remained available and its orders, distribution centers and shipping operations continued functioning.
The McKesson entry also illustrates the blurring lines between data theft and classic ransomware. The threat group ShinyHunters claimed responsibility and alleged a large data-extortion demand, but McKesson has not publicly attributed the incident or confirmed that ransomware was deployed. In the registry, the event is tagged as resolved and confirmed under the Healthcare and Public Health critical infrastructure category, capturing both the technical and sectoral dimensions without overstating what is known about the attack's mechanics.
Another incident highlights the sensitivity of law enforcement data in the cyber arena. The Bureau of Alcohol, Tobacco, Firearms and Explosives shut down a breached standalone system that contained information about targets of ATF investigations, resulting in the loss of a specific internal investigative resource while the agency maintained its broader mission capability. The threat group Qilin later began publishing files that outside observers said appeared to contain ATF investigative material, though the agency has not authenticated the files or attributed the incident, and there is no public evidence of ransomware encryption.
Cyber disruption is not limited to digital records and data; it can manifest in very physical ways. Refrigeration failures at Defense Commissary Agency stores, affecting at least a dozen locations across nine states beginning August 26, 2026, restricted chilled and frozen food sales. While full details are not laid out in the registry excerpt, the listing sits alongside other entries in sectors such as Emergency Services, Government Services and Facilities, and Retail, underscoring how operational technology and supply chains are increasingly part of the cyber risk landscape.
Why this matters
The Cyber Incident Registry offers a granular, cross-sector view of cyber risk that goes beyond headline breaches to show how incidents translate into real-world impacts, from healthcare data exposure to impaired law enforcement tools and spoiled food inventories. By tracking threat actors like ShinyHunters and Qilin, flagging whether ransomware is confirmed, suspected or absent, and distinguishing between active and resolved cases, it gives defenders and policymakers a more nuanced picture of the threat environment. This kind of structured transparency can inform everything from sector-specific resilience planning to broader debates on disclosure standards and the handling of sensitive investigative or medical information.
Looking ahead, the expanding scope of the registry suggests that cyber incidents touching critical infrastructure, public services and key commercial operations will continue to be documented in greater detail. As more organizations and agencies appear in the database, patterns around threat groups, affected sectors and failure modes may become clearer, potentially guiding investment and policy decisions. For now, the registry stands as an evolving record of how attacks on systems and data are increasingly inseparable from the continuity of essential services, hinting at a future where monitoring and sharing incident information is as important as traditional technical defenses.