[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3omnyzgrsd5nx":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":38,"seoTitle":39,"seoDescription":40,"logoUrl":41,"isVerified":4,"isSensitive":4,"isSpamList":42,"isMalware":42,"company":43},"6a4cecd57eb7c38c58ce5f47","Community Connections 2026","Community Connections 2026 Data Breach","community-connections-2026","communityconnectionsdc.org","2026-03-18T00:00:00.000Z","2026-07-07T12:11:01.077Z",null,"2026-09-17T16:22:34.100Z","2026-07-18T23:21:45.101Z","Manual reviewed breach record","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report_hip.jsf",[17,19],"https:\u002F\u002Fwww.hipaajournal.com\u002Fcommunity-connections-data-breach\u002F",18943,"known","unknown","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"Medium",[31,32,33,34,35,36,37],"Names","Physical addresses","Dates of birth","Social security numbers","Personal health data","Health insurance information","Financial transactions","\u003Cp>The Community Connections 2026 data breach involves unauthorized access to the computer systems of a Washington, DC-based organization that provides mental health, addiction support, housing support and community-based health coordination services. The organization announced that it noticed suspicious activity in its systems on March 20, 2026, and then initiated a forensic investigation to understand the scope of the incident. As a result of the investigation, it was stated that the unauthorized activity took place between March 18, 2026 and March 20, 2026, and personal information held in some systems may be subject to unauthorized access. This registration is classified as a high-risk event, where the identity, contact, health and financial information of individuals who use health and social support services must be evaluated together.\u003C\u002Fp>\u003Cp>Behavioral health and support service providers such as Community Connections collect not only basic identification information, but also sensitive health, insurance, care and social information due to the nature of the service relationship. It can also process support information. Therefore, the impact of the incident is broader than an ordinary contact information leak. Identity fields such as name, address, date of birth, and social security number; medical information, combined with health insurance information and general financial information, increases the risk of identity theft, fraudulent healthcare claims, insurance abuse, social engineering and targeted fraud. Although the organization's own announcement states that there is no evidence of misuse, the risk with such data combinations may persist for a long time.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>Supported data types for this event include names, physical addresses, dates of birth, social security numbers, personal health information, health insurance information, and general financial transaction or account relationship information. These areas may not be available to the same extent for every affected person; Incident announcements indicate that the information that may be subject to access may vary from person to person. However, including a person's social security number along with their name, address, and date of birth creates a strong basis for identity-based attacks, such as opening a new account, applying for credit, or tax or utility fraud.\u003C\u002Fp>\u003Cp>Health information and health insurance information pose privacy risks beyond financial losses. Revealing data related to mental health support, addiction services, housing support, care coordination or insurance relationships can have sensitive consequences on a person's social environment, work life or access to public services. Due to the general expression of the financial information category, narrower classes such as bank or card numbers are not used in this record; The risk assessment was made based on the possibility that financial information may be misused in the context of account transactions, payment relationships or financial authentication.\u003C\u002Fp>\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\u003Cp>The basic timeline of the incident is supported by the official announcement: suspicious activity was noticed on March 20, 2026, with the intrusion window being announced as March 18, 2026 to March 20, 2026. The number of people affected in the healthcare sector breach notification is listed as 18,943. Some state and legal notices show the broader notification list as 20,879 people. Because of this difference, the register holds 18,943 people as the main number, but it is noted that there is a larger list of notifications surrounding the event. This approach both preserves the number in the official health record and prevents the higher reporting from appearing as the exact number of unique victims.\u003C\u002Fp>\u003Cp>The accuracy limit in this record is deliberately kept narrow. The organization's announcement supports the existence of the incident, date of detection, access range, and that some information held in the systems may be subject to unauthorized access. The domain list is consistent with the categories mentioned in public notices and independent review notices; However, it should not be taken for granted that the same data classes are affected for every individual. For this reason, the record verification status is left at a conservative level rather than full certainty. The goal is to keep the actual event visible while not overstating the number or area coverage.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk groups are current and former patients served by Community Connections, clients, care coordination recipients, individuals with health insurance relationships, and individuals who have a relationship with the organization through social or housing support. It's not just about financial identity risk, as the organization's service area includes areas such as mental health, addiction support, housing support, field work for the homeless, primary care coordination and trauma-sensitive care. Even understanding the sensitive service relationship may pose a privacy, security, and discrimination risk for some individuals.\u003C\u002Fp>\u003Cp>People with fields such as address, date of birth, and social security number are at higher risk of identity theft. For people with health insurance or medical information fields, risks such as fraudulent healthcare claims, incorrect insurance use, inaccurate billing, unexplained health record changes, and bypassing identity verification questions come to the fore. People who are associated with financial information should be more careful about bank movements, payment warnings, credit report changes and collection notifications they do not recognize. The risk level should be considered critical, especially if the identity, health and financial data of the same person are affected together.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>People who receive a Community Connections notification should first evaluate the identity protection service provided in the letter without missing the application deadline. Credit reports should be examined at regular intervals, and if any unrecognized accounts, inquiries or address changes are observed, an objection should be made to the relevant institutions immediately. Individuals whose social security numbers may have been affected should consider the options of a credit freeze or fraud alert. These steps make it more difficult to open new credit or accounts and help prevent attackers from turning credentials into financial gain.\u003C\u002Fp>\u003Cp>On the healthcare side, insurance disclosures, billing records, and healthcare transcripts should be checked for unrecognized transactions or services. If an unrecognized examination, prescription, claim, insurance expense or incorrect health record is observed, the health insurance provider and the relevant institution should be contacted by creating a written record. Unusual movements in financial accounts, small test payments, unknown direct debit orders or address change attempts should be monitored. One should be careful about authentication requests received via e-mail, phone and text messages, and should not enter information through links.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In this case, the risk is not limited to the short-term reporting period. Since social security number, date of birth, and health information are fields that cannot be changed or are difficult to change, attackers can still use this data months or years later. Affected individuals should perform regular annual credit report checks, be wary of fraudulent refund applications ahead of tax season, and periodically review health insurance records. In particular, it may be a stronger measure for people who do not apply for new loans to keep the credit freezing option for a long time.\u003C\u002Fp>\u003Cp>To reduce the impact of similar events on the corporate side, centralized monitoring of network access records, strict auditing of privileged accounts, regular testing of backup and incident response processes, multi-stage authentication, personnel awareness training and sensitive health data. Narrower access permissions are important for In behavioral health and social service organizations, data inventory also becomes critical; Knowing which patient, insurance, financial and identity fields are kept in which system allows post-event notifications to be made faster and more clearly.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>Users checking the Community Connections 2026 record on Leakdata should consider this record as a possible high-sensitivity health and identity data impact if the result appears. Individuals who are unsure whether they have received a notification should check their relationship with Community Connections, any letters that may have been sent to their old address, their insurance accounts, and their credit reports. Since the data classes in this record may not be the same for each person, the fields included in the individual notification letter should be considered priority. However, individuals who may have a social security number or health insurance information should not act with the assumption of low risk.\u003C\u002Fp>\u003Cp>This record is maintained as a separate event with a March 2026 timeline and not as a duplicate legacy Community Connections event. The year is stated in the title to avoid confusion with previous notifications from different years. Users should refer to the date, institution name, and field list when evaluating their own results. If any signs of abuse are detected, the bank, insurance provider, credit bureaus and relevant public authorities should be contacted quickly; Applications, objections and documents related to the incident should be kept.\u003C\u002Fp>","Community Connections 2026 Data Breach (18.9 Thousand Reported Records)","Community Connections 2026 Data Breach. 18.9 Thousand reported records are reported. Reported data: Names, Physical addresses, Dates of birth. Review the…","\u002Fuploads\u002Flogo\u002Fcommunity-connections-2026.png",false,{"name":44,"sector":45,"country":46,"website":10,"websiteArchiveUrl":47,"websiteStatus":47,"websiteCheckedAt":13},"Community Connections","Healthcare \u002F Behavioral Health and Support Services","United States",""]