LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › HUSKY Health breach: 41,000 Connecticut members and what DSS confirmed

CRITICAL severityReportedHow we verify

HUSKY Health breach: 41,000 Connecticut members and what DSS confirmed: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 24, 2026
HUSKY Health breach: 41,000 Connecticut members and what DSS confirmed

Reported August 24, 2026.

CRITICAL
Severity
6
Data types exposed
August 24, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The HUSKY Health breach: 41,000 Connecticut members and what DSS confirmed (reported August 24, 2026) exposed Full names, Medicaid or claim identification numbers, dates of medical services and billed services details. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityReported
Exposes government-ID/financial/medical data.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In a healthcare and public-benefits landscape where payment systems and claims platforms remain frequent targets, Connecticut officials have described a limited but consequential intrusion tied to HUSKY Health. According to public confirmation from the state’s Department of Social Services (DSS), an unauthorized person gained access to a HUSKY provider payment account and obtained claims and payment information affecting about 41,000 members. The matter was reported in connection with a notice dated 2026-08-24.

DSS has stated that Social Security numbers, bank account details, and electronic health records were not taken. Official letters offering free identity monitoring began going out by mail on August 21, 2026. For members and families who rely on HUSKY coverage, the episode matters because even a bounded set of claims and payment fields can support fraud, billing confusion, or targeted scams if misused.

What is being claimed

Public detail centers on what Connecticut’s Department of Social Services has confirmed rather than on an unattributed leak-site narrative. DSS confirmed that an unauthorized person reached a HUSKY provider payment account and obtained claims and payment information for about 41,000 members. The reporting associated with this notice is dated 2026-08-24. A separate field in the same record lists people affected as unknown; the figure of about 41,000 members comes from the DSS confirmation summarized in that record.

Named data elements associated with the incident include full names, Medicaid or claim identification numbers, dates of medical services, details of billed services, payment amounts, and other health insurance policy and group numbers. DSS has also stated what was not obtained: Social Security numbers, bank accounts, and electronic health records. The method of access beyond reaching a provider payment account, the duration of unauthorized access, and any fuller technical timeline are not detailed in the available summary. Notification letters offering free identity monitoring started mailing on August 21, 2026.

How a breach like this happens

Incidents involving provider payment or claims systems typically unfold when an unauthorized party obtains credentials, session access, or another path into a portal used to view or process billing and reimbursement data. In general terms—not as a diagnosis of this event—such access can follow phishing, reused or stolen passwords, compromised vendor accounts, malware on a machine used for billing work, or weaknesses in how third-party payment tools are segmented from broader member systems.

Once inside a payment or claims environment, an intruder may be able to view or export records that exist to pay providers: who was billed, for what service dates, under which identifiers, and for what amounts. Organizations often discover the issue through account anomalies, vendor alerts, member complaints, or internal audit. Containment usually means cutting off the account path, reviewing logs, determining which records were viewed or copied, and issuing notices when health or benefits-related information may have been involved. None of this paragraph attributes a specific technique or actor to the HUSKY matter; public summary here does not name a threat group or spell out the intrusion path in technical detail.

Who is HUSKY Health breach: 41,000 Connecticut members and what DSS confirmed?

HUSKY Health is Connecticut’s Medicaid and related public health coverage program, administered in connection with the Department of Social Services. It serves low-income children, parents, pregnant people, older adults, and people with disabilities, among others, by connecting members to medical care and by paying participating providers. Programs of this kind sit at the intersection of healthcare delivery and government benefits administration.

Organizations in this sector routinely handle member identity information, Medicaid or plan identifiers, claims histories, service dates, billing codes or descriptions, payment amounts, and coordination-of-benefits details when other insurance is involved. A compromise of a provider payment account is consequential because that channel is built to move and display exactly the kinds of claims and payment records needed to reimburse care. Even when clinical charts and core identity documents such as Social Security numbers are not involved, exposure of claims-level data can still affect trust in the program and create practical risk for members who depend on continuous coverage.

What data was at risk

According to the confirmed summary, the information obtained included full names, Medicaid or claim identification numbers, dates of medical services, billed services details, payment amounts, and other health insurance policy and group numbers. DSS stated that Social Security numbers, bank accounts, and electronic health records were not taken.

That distinction is important. Claims and payment files can still reveal that someone received care, when, at a high level what was billed, and how much was paid, along with identifiers used in the Medicaid and insurance billing ecosystem. They are not the same as a full medical record or a direct key to a bank account. Exact file inventories, how the data was stored after access, and whether every affected person saw the same fields are not further itemized in the public summary beyond the categories above. Readers should treat the DSS list as the authoritative public description for this notice, not as a guess about unlisted systems.

Why it matters

For affected members, claims and payment data can be misused to attempt medical identity fraud, to submit false claims under a known Medicaid or claim number, or to craft convincing phishing and phone scams that reference real service dates or billing details. Policy and group numbers from other insurance can help someone sound legitimate when trying to change benefits information or intercept correspondence. Payment amounts and billed-service detail can also expose sensitive context about the fact and timing of care, which some people prefer to keep private even when clinical notes were not taken.

For the program and the state, the incident creates notification and support obligations, potential follow-on fraud monitoring costs, and pressure to reassure members that coverage and payments remain reliable. The confirmation that Social Security numbers, bank accounts, and electronic health records were not obtained narrows some of the worst financial and clinical-privacy scenarios, but it does not eliminate fraud or social-engineering risk tied to the fields that were obtained. Scale—about 41,000 members—means a large number of households may need to watch mail, portals, and explanation-of-benefits statements for a period of time.

If your data was involved

If you receive an official DSS or HUSKY notice, read it carefully and use only contact methods printed in that letter. Consider enrolling in any free identity monitoring offered; mailings of those offers began on August 21, 2026. Monitor Explanation of Benefits and claims histories for services you do not recognize, and report suspicious claims to HUSKY or DSS through official channels. Be wary of unsolicited calls or messages that cite your service dates, claim numbers, or payment amounts and then ask for passwords, one-time codes, or bank details—legitimate agencies will not need you to surrender credentials that way.

If you did not receive a letter but believe you may be affected, contact HUSKY or DSS support using published state contact information and ask how to verify your status. Keep records of any suspicious billing activity. As a general precaution, you can also run a free exposure scan of your email address to check whether your information has surfaced in known breach data sets unrelated to this notice, and you can place fraud alerts or credit freezes through the major credit bureaus if you are concerned about broader identity misuse. Stay conditional: act on official notice and on anomalies you actually see, rather than assuming every Connecticut resident’s full profile may have been exposed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

More recent breaches

Oz Hair and Beauty hack: was my name, email or phone number taken?August 23, 2026Oz Hair and Beauty data leak: what was taken and what to do nowAugust 23, 2026Forrestall CPAs data breach: what we know and who it may affectAugust 18, 2026resi.com Listed by Krybit Ransomware GroupAugust 24, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the HUSKY Health breach: 41,000 Connecticut members and what DSS confirmed →

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram