LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › American Addiction Centers Data Breach Notice (California Attorney General)

MEDIUM severityConfirmedHow we verify

American Addiction Centers Data Breach Notice (California Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 7, 2026
American Addiction Centers Data Breach Notice (California Attorney General)

Reported August 7, 2026.

MEDIUM
Severity
1
Data types exposed
August 7, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

American Addiction Centers disclosed a data breach on August 07, 2026, exposing personal information of an undisclosed number of individuals. If you have received services from the organization, review the official notice and consider placing a fraud alert or credit freeze.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

American Addiction Centers has notified California residents that a data breach occurred, according to a filing reported to the California Attorney General. The notice places the incident on May 12, 2026, and the filing itself was reported on August 07, 2026. How many people were affected remains unknown, and the notice describes the exposed material only as personal information.

For anyone who has sought treatment, contacted the organization, or shared identifying details in connection with addiction care, that combination of limited public detail and sensitive context is the practical stake: personal information tied to a behavioral-health provider can heighten risks of identity misuse, targeted scams, or unwanted contact even when the full scope of the breach is not yet clear.

Inside the incident

Public detail comes from the California Attorney General filing associated with American Addiction Centers’ data breach notice. That filing reports the incident date as May 12, 2026, and the notification to California residents as reported on August 07, 2026. The organization is identified as American Addiction Centers. The number of people affected is unknown. The data types named as exposed are described as personal information per the breach notification. Method of intrusion, systems involved, duration of unauthorized access, and whether data were exfiltrated in bulk or selectively are not disclosed in the available facts. No threat actor is attributed.

The gap between the stated incident date and the reported filing date is part of the public record; the reasons for that interval, any internal investigation findings, and remediation steps taken are not detailed in the facts provided. Readers should treat only the dates, the organization name, the California notice, and the high-level description of personal information as confirmed from the disclosure.

How a breach like this happens

Incidents described in regulatory breach notices often follow familiar patterns, though none of the following should be read as a finding about this specific event. Attackers commonly gain an initial foothold through phishing messages that harvest credentials, through exploitation of unpatched remote-access or web-facing software, or through compromised accounts belonging to employees, contractors, or vendors. Once inside a network, they may move laterally, search file shares and databases, and copy records that contain names, contact details, identifiers, or other personal fields.

In healthcare and behavioral-health environments, systems that support admissions, billing, patient portals, electronic health records, or customer-relationship tools can hold concentrated personal data. Misconfigured cloud storage, weak multi-factor authentication, or overly broad access privileges can enlarge the blast radius. Detection sometimes occurs weeks or months later, when unusual outbound traffic, ransomware notes, or third-party alerts surface. Organizations then investigate, determine notification obligations under state law—including California’s requirements—and send notices that may describe affected data only in general terms while investigations continue. No specific group or technique is named in the facts for this incident, and none should be assumed.

About American Addiction Centers

American Addiction Centers operates in the substance-use and behavioral-health treatment sector in the United States. Organizations of this kind typically provide or coordinate residential and outpatient care, assessments, admissions support, and related services for people seeking help with addiction. In the ordinary course of that work they collect and maintain personal information needed to identify patients and contacts, schedule care, communicate with individuals and families, verify insurance or payment arrangements, and meet clinical and regulatory record-keeping duties.

A breach involving such an organization is consequential because the relationship is inherently sensitive. People often share not only standard identifiers but also information about health status, treatment history, and personal circumstances they would not disclose lightly. Even when a notice lists only “personal information” without further breakdown, the sector context means affected individuals may face elevated concern about privacy, stigma, and secondary misuse of any data that did leave the organization’s control.

What data was at risk

The breach notification, as reflected in the facts, names exposed data types as personal information. It does not itemize fields such as Social Security numbers, financial account numbers, medical record details, or specific contact elements. The exact contents are therefore unconfirmed beyond that general label.

Organizations in addiction treatment and related care typically hold, in ordinary operations, data such as names, addresses, phone numbers, email addresses, dates of birth, insurance or billing identifiers, and clinical or treatment-related information. Whether any of those categories were involved in this incident is not established by the public facts. Readers should not assume a particular data element was exposed solely because it is common in the sector; equally, they should not assume the exposure was trivial because the notice uses a broad phrase.

The real-world impact

For affected people, the concrete risks depend on what was actually taken and how it might be reused. Personal information can support identity theft, account takeover attempts, or convincing phishing and vishing that reference a real treatment relationship. Even limited contact details can enable harassment or social-engineering calls that pressure someone for money, credentials, or further private facts. Because addiction care is stigmatized in many communities, any leak that could reveal or imply treatment involvement may also carry personal and professional consequences beyond pure financial fraud.

For the organization, a notified breach typically brings regulatory scrutiny, notification and support costs, potential civil claims, and reputational strain among patients, families, and referral partners. The facts do not state the number of California residents notified, any nationwide scope, or financial impact; those points remain unknown. Impact assessment for any individual therefore starts from the personal information description in the notice and from whether that person had a relationship with American Addiction Centers around the relevant period.

If your data was in this breach

If you received a notice from American Addiction Centers, or if you believe your information may have been involved, keep the notice and any reference numbers. Consider placing a fraud alert or credit freeze with the major credit bureaus if you are concerned about identity theft, and monitor bank, credit card, and insurance statements for unfamiliar activity. Be cautious of unsolicited calls, texts, or emails that claim to relate to this incident or to your treatment—legitimate follow-up should not demand passwords, payment by gift card, or urgent wire transfers. Review account passwords and enable multi-factor authentication where you can. You can also run a free exposure scan of your email to check whether your information has surfaced in known breach data, which may help you prioritize further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyAmerican Addiction Centers security record
56/100
DoxxScan™ · Elevated doxx risk
D- 44Very poor record

2 reported incidents on record.

See American Addiction Centers’s full breach history →
RelatedMore incidents at American Addiction Centers

More recent breaches

ASOS US Sales LLC Data Breach Notice (California Attorney General)August 21, 2026Kern Psychiatric Health and Wellness Center, Inc Data Breach Notice (California Attorney General)August 21, 2026Southern Illinois University Data Breach Notice (California Attorney General)August 20, 2026Northern Inyo Healthcare District d/b/a Northern Inyo Hospital Data Breach Notice (California Attorney General)August 20, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the American Addiction Centers Data Breach Notice (California Attorney General) →

Source: California Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram