Original research · Updated October 3, 2026
Washington Data Breaches by Industry, 2015 to 2026
Cyberattacks caused 74% of the data breaches reported to the Washington Attorney General from July 2023 to July 2026, and 58% of those were ransomware. The typical breach affected about 1,888 Washingtonians, not millions, and most notices reached the Attorney General more than 30 days after the organization became aware. This is Trella Commercial’s analysis of all 1,675 notices on record.
Key findings
of breaches reported in the last three full reporting years (July 2023 to July 2026) were cyberattacks.
of those cyberattacks were ransomware, by far the most common type.
Washingtonians affected in the median breach. 69% affected 5,000 or fewer: most reported breaches are not headline events.
of notices since March 2020 reached the Attorney General within 30 days of the organization becoming aware. The median was 78 days.
of notifying organizations that listed a location are based outside Washington. Your customers’ data is often breached somewhere else.
of breaches exposed Social Security numbers. 37% exposed medical information.
What this means for a Washington small business
- The main threat is a cyberattack, usually ransomware. A policy built for it pays for restoring systems, the lost income while you are down, and the extortion demand itself where the law allows. See cyber liability insurance and the complete cyber insurance guide.
- Small breaches are the norm. 69% of reported breaches affected 5,000 or fewer Washingtonians. A breach at a dental office, a CPA firm, or an online store still triggers the same notice duties and response costs.
- A breach at your vendor is still your problem. Under Washington law the owner of the data is responsible for notice even when its payroll, billing, or software provider was the one breached. The second-largest breach on record, the 2025 ransomware attack on Change Healthcare, reached 3,121,209 Washingtonians through a claims processor most patients never dealt with directly.
- Response takes expertise and time. Forensics, legal review, and identifying who was affected are why most notices take longer than 30 days. Cyber policies with breach response coverage pay for that team.
What causes Washington data breaches
Share of notices by cause, July 2023 to July 2026 (705 notices).
Cyberattacks by type
Share of cyberattack breaches, July 2023 to July 2026.
Breaches by industry
Share of notices by the notifying organization’s industry, July 2023 to July 2026.
Within businesses, which kinds report the most
All notices on record from organizations the Attorney General classifies as businesses, by business type (excluding “other”).
How big a typical breach is
Notices by number of Washington residents affected, all years (1,643 notices with a count).
How long organizations take to report
Days from the date the organization became aware of the breach to the date its notice reached the Attorney General, for 1,377 breaches discovered on or after March 1, 2020, when Washington’s 30-day deadline took effect.
Organizations took a median of 16 days to identify a breach after it began, and one in four took 116 days or longer. 53% were discovered while still in progress.
What information is exposed
Share of notices that included each type of personal information (1,666 notices).
Notices by reporting year
The Attorney General’s reporting year runs July 24 to July 23 (for example, 2026 is July 24, 2025 to July 23, 2026).
| Year | Notices | Cyberattacks | Washingtonians affected |
|---|---|---|---|
| 2026 | 198 | 71% | 3,798,885 |
| 2025 | 212 | 72% | 8,567,575 |
| 2024 | 295 | 77% | 12,120,062 |
| 2023 | 181 | 63% | 4,581,008 |
| 2022 | 159 | 67% | 4,833,519 |
| 2021 | 286 | 86% | 6,510,969 |
| 2020 | 60 | 63% | 1,071,799 |
| 2019 | 65 | 74% | 393,283 |
| 2018 | 63 | 59% | 3,515,596 |
| 2017 | 77 | 66% | 2,858,566 |
| 2016 | 39 | 49% | 553,912 |
The largest breaches affecting Washingtonians
| Organization | Year | Washingtonians | Cause |
|---|---|---|---|
| Equifax, Inc. | 2018 | 3,243,664 | Cyberattack |
| Change Healthcare Inc. | 2025 | 3,121,209 | Cyberattack (ransomware) |
| Comcast Cable Communications LLC | 2024 | 3,100,608 | Cyberattack |
| T-Mobile USA | 2022 | 2,079,648 | Cyberattack (malware) |
| Fred Hutchinson Cancer Center | 2024 | 1,694,184 | Cyberattack |
| ACTIVEOutdoors | 2017 | 1,449,645 | Unauthorized Access |
Questions about Washington data breaches
How many data breaches are reported in Washington each year?
Organizations reported 235 breaches a year on average to the Washington Attorney General over the three reporting years from July 2023 to July 2026. Only breaches affecting more than 500 Washington residents must be reported, so the true number of breaches is higher.
What causes most data breaches in Washington?
Cyberattacks caused 74% of breaches reported from July 2023 to July 2026, and ransomware accounted for 58% of those cyberattacks. Unauthorized access caused 23%, and theft or mistakes 3%.
How long do organizations take to report a breach to the Washington Attorney General?
For breaches the organization became aware of on or after March 1, 2020, the median was 78 days from the date it became aware to the date its notice reached the Attorney General, and 17% of notices arrived within 30 days. Washington law (RCW 19.255.010) sets a 30-day deadline after a breach is discovered, with limited exceptions such as a law enforcement request to delay.
Do small businesses have to report data breaches in Washington?
Yes. RCW 19.255.010 applies to any person or business that owns or licenses personal information of Washington residents. Affected residents must be notified within 30 days of discovery, and the Attorney General must also be notified within 30 days when more than 500 Washington residents are affected. If a vendor holding your data is breached, it must tell you immediately, and the notice obligation stays with you as the data owner.
Does cyber insurance pay for breach notification and response?
Most cyber liability policies include breach response coverage for forensics, legal counsel, customer notification, and credit monitoring, plus extortion and business interruption coverage for ransomware. Limits, sublimits, and exclusions vary by policy, so the specific wording decides what is paid.
Methodology and sources
Source: the Washington State Attorney General’s Office, Data Breach Notifications Affecting Washington Residents and the companion personal information breakdown, published on data.wa.gov. Snapshot taken October 3, 2026: 1,675 notices submitted August 11, 2015 through September 11, 2026.
- Washington law (RCW 19.255.010) requires notice to the Attorney General only when more than 500 Washington residents are affected, so smaller breaches are not in this data.
- “Recent” means the three most recent full reporting years, July 2023 to July 2026. The current partial year is excluded from yearly comparisons.
- Causes and cyberattack types are the Attorney General’s classifications. Percentages are shares of notices, not of people affected.
- Reporting time is measured from the date the organization reported becoming aware to the date of its notice, matching the Attorney General’s own field. It does not establish that any organization missed a legal deadline: the law allows delays at law enforcement’s request, and identifying who was affected can take time.
- Location shares use the 1,036 notices that listed a state for the notifying organization.
The summary data behind this page is available as JSON and may be reused with attribution. Suggested citation: Trella Commercial, “Washington Data Breaches by Industry, 2015 to 2026,” analysis of Washington State Attorney General data breach notices, updated October 3, 2026.
This page reports public data and is general information, not legal advice. Coverage described here depends on the actual policy wording and underwriting.
Would your policy cover a breach like these?
Send us your current policies. We will tell you what your cyber coverage pays for, what it leaves out, and what a Washington breach would cost you.