LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Perrigo Data Breach Notice (Indiana Attorney General)

MEDIUM severityConfirmedHow we verify

Perrigo Data Breach Notice (Indiana Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 19, 2026
Perrigo Data Breach Notice (Indiana Attorney General)

Occurred March 04, 2026 · publicly disclosed May 19, 2026. Approximately 6 people affected.

MEDIUM
Severity
6
People affected
1
Data types exposed
May 19, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Perrigo disclosed a data breach to the Indiana Attorney General on May 19, 2026, after discovering that personal information of six individuals had been exposed in an incident that occurred on March 4, 2026. If you received a notice or believe your information may have been involved, review the details provided by Perrigo and consider placing a fraud alert or credit freeze.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
6 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Organizations across healthcare and consumer goods continue to face routine pressure from opportunistic cyber incidents that expose limited sets of personal records, even when the scale is small. Against that backdrop, a formal notice filed with Indiana regulators has brought a discrete Perrigo incident into public view.

Perrigo notified Indiana residents of a data breach in a filing reported to the Indiana Attorney General on May 19, 2026. The filing places the incident itself on March 4, 2026, and states that six people were affected. The notice describes the exposed material as personal information. Public detail beyond those points remains limited, yet the disclosure matters because even narrowly scoped events can leave individuals unsure what was taken and what steps to take next.

Inside the incident

According to the Indiana Attorney General filing, Perrigo identified an incident dated March 4, 2026, and later submitted a breach notice that was reported on May 19, 2026. The filing indicates six people were affected. The data types named as exposed are described simply as personal information per the breach notification. No further public detail has been provided in the available record about how the incident was discovered, what systems were involved, whether encryption or other controls limited access, or how long unauthorized access may have lasted. Method, technical root cause, and any broader operational impact are undisclosed.

The gap between the stated incident date and the reported filing date is consistent with the time organizations often spend investigating, determining who must be notified under state law, and preparing required notices. Nothing in the public summary attributes the event to a named threat group, describes ransom demands, or confirms whether data left the environment. Readers should treat the Indiana notice as the authoritative public account of what is confirmed so far.

How a breach like this happens

Incidents that result in notices about personal information commonly begin with one of several familiar paths: stolen or guessed credentials, phishing that yields access to email or internal tools, exploitation of an unpatched remote service, misconfigured cloud storage, or malware introduced through a compromised vendor or endpoint. Once inside, an attacker or automated tool may search for files, databases, or mailboxes that contain names, contact details, identifiers, or other personal fields. In many cases the initial foothold is brief and the volume of records small; in others the same entry point is used for wider collection. Because no specific method is attributed in the Perrigo filing, these patterns are offered only as general background on how events of this type typically unfold, not as a reconstruction of this case.

Detection often comes from unusual login alerts, endpoint detections, employee reports, or later forensic review. After containment, organizations assess which individuals’ data were involved and whether state notification thresholds are met. Small affected counts, such as the six people named here, can still trigger formal notices when personal information of residents is implicated under applicable law.

Who is Perrigo?

Perrigo is a known consumer healthcare and pharmaceutical company that develops, manufactures, and distributes over-the-counter and related products. Firms in this sector routinely hold workforce records, certain customer or patient-support information, supplier data, and internal business files. They also operate regulated manufacturing and quality systems and maintain relationships with retailers, healthcare partners, and regulators. A breach involving personal information at such an organization is consequential because the data can be used for identity-related misuse, and because trust in healthcare-adjacent brands depends on careful handling of personal details—even when only a handful of people are named in a given notice.

The Indiana filing does not describe which business unit, system, or population (for example employees versus consumers) was involved. That absence leaves the precise context unconfirmed beyond the fact that Perrigo submitted a resident notification through the state’s attorney general process.

What data was at risk

The breach notification names the exposed data as personal information. It does not itemize fields such as Social Security numbers, financial account data, health details, or government IDs in the summary available here. For organizations of this kind, “personal information” in state notices can range from basic contact and identity elements to more sensitive identifiers, depending on what was actually accessed. Because the exact contents are not further detailed in the public filing summary, those specifics remain unconfirmed. No claim should be made that particular categories beyond the stated “personal information” were involved.

What's at stake

For the six people identified, the practical risk is that personal information could be misused for targeted phishing, account takeover attempts, or identity fraud if the data is detailed enough to support those activities. Even limited records can help an attacker craft convincing messages or try password resets on unrelated services. The real-world impact varies with what fields were present—something the public notice does not fully enumerate—and with whether the individuals already monitor their accounts and credit.

For Perrigo, the stakes include regulatory notification duties, potential follow-up inquiries, internal investigation and remediation costs, and reputational questions from customers, partners, and employees. A small affected count does not eliminate those obligations or the need for clear communication. Nothing in the disclosed facts establishes negligence or assigns blame; the record simply documents that a notifiable incident occurred and was reported.

What to do if you're exposed

If you believe you may be one of the individuals notified, start with the letter or email Perrigo provided: it should explain what the company knows and any support it is offering, such as credit monitoring. Place fraud alerts or freezes with the major credit bureaus if identity elements may have been involved, and watch bank, benefits, and email accounts for unexpected activity. Change passwords on important accounts, especially if you reused credentials, and treat unsolicited messages that reference the breach with caution. Keep copies of the notice for your records.

You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets, which can help you prioritize further monitoring. If you did not receive a direct notice but have a relationship with Perrigo and remain concerned, contact the company’s published privacy or support channel and ask whether your information was included. Public detail on this incident is limited to the Indiana filing’s core points—incident date March 4, 2026, report date May 19, 2026, six people affected, and personal information named as exposed—so rely on official notices rather than speculation for decisions about your own data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyPerrigo security record
60/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See Perrigo’s full breach history →
RelatedMore incidents at Perrigo

More recent breaches

PeoplesBank Data Breach Notice (Indiana Attorney General)October 8, 2026World Acceptance Corporation Data Breach Notice (Indiana Attorney General)September 30, 2026Midvale Indemnity and American Family Connect Insurance Data Breach Notice (Indiana Attorney General)September 30, 2026McKenzie Creative Brands Data Breach Notice (Indiana Attorney General)September 30, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Perrigo Data Breach Notice (Indiana Attorney General) →

Source: Indiana Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram