Original research · Updated October 3, 2026

Washington Data Breaches by Industry, 2015 to 2026

Cyberattacks caused 74% of the data breaches reported to the Washington Attorney General from July 2023 to July 2026, and 58% of those were ransomware. The typical breach affected about 1,888 Washingtonians, not millions, and most notices reached the Attorney General more than 30 days after the organization became aware. This is Trella Commercial’s analysis of all 1,675 notices on record.

Key findings

74%

of breaches reported in the last three full reporting years (July 2023 to July 2026) were cyberattacks.

58%

of those cyberattacks were ransomware, by far the most common type.

1,888

Washingtonians affected in the median breach. 69% affected 5,000 or fewer: most reported breaches are not headline events.

17%

of notices since March 2020 reached the Attorney General within 30 days of the organization becoming aware. The median was 78 days.

71%

of notifying organizations that listed a location are based outside Washington. Your customers’ data is often breached somewhere else.

63%

of breaches exposed Social Security numbers. 37% exposed medical information.

What this means for a Washington small business

  • The main threat is a cyberattack, usually ransomware. A policy built for it pays for restoring systems, the lost income while you are down, and the extortion demand itself where the law allows. See cyber liability insurance and the complete cyber insurance guide.
  • Small breaches are the norm. 69% of reported breaches affected 5,000 or fewer Washingtonians. A breach at a dental office, a CPA firm, or an online store still triggers the same notice duties and response costs.
  • A breach at your vendor is still your problem. Under Washington law the owner of the data is responsible for notice even when its payroll, billing, or software provider was the one breached. The second-largest breach on record, the 2025 ransomware attack on Change Healthcare, reached 3,121,209 Washingtonians through a claims processor most patients never dealt with directly.
  • Response takes expertise and time. Forensics, legal review, and identifying who was affected are why most notices take longer than 30 days. Cyber policies with breach response coverage pay for that team.

What causes Washington data breaches

Share of notices by cause, July 2023 to July 2026 (705 notices).

Cyberattack74%
Unauthorized Access23%
Theft or Mistake3%

Cyberattacks by type

Share of cyberattack breaches, July 2023 to July 2026.

Ransomware58%
Other22%
Phishing8%
Malware8%
Unclear or unknown4%
Skimmers1%

Breaches by industry

Share of notices by the notifying organization’s industry, July 2023 to July 2026.

Businesses42%
Health care24%
Finance19%
Education9%
Nonprofits and charities4%
Government3%

Within businesses, which kinds report the most

All notices on record from organizations the Attorney General classifies as businesses, by business type (excluding “other”).

Retail148
Hospitality57
Professional Services57
Manufacturing49
Software42
Legal35
Consumable24
Entertainment24
Construction20
Clothing20

How big a typical breach is

Notices by number of Washington residents affected, all years (1,643 notices with a count).

501 to 1,000483
1,001 to 5,000651
5,001 to 10,000155
10,001 to 50,000225
50,001 to 100,00052
100,001+72

How long organizations take to report

Days from the date the organization became aware of the breach to the date its notice reached the Attorney General, for 1,377 breaches discovered on or after March 1, 2020, when Washington’s 30-day deadline took effect.

30 days or less17%
31 to 60 days25%
61 to 90 days13%
91 to 180 days23%
More than 180 days22%

Organizations took a median of 16 days to identify a breach after it began, and one in four took 116 days or longer. 53% were discovered while still in progress.

What information is exposed

Share of notices that included each type of personal information (1,666 notices).

Name99%
Full Date of Birth65%
Social Security Number63%
Financial & Banking Information46%
Medical Information37%
Driver's License or Washington ID Card Number33%
Health Insurance Policy or ID Number28%
Passport Number14%
Username and Password/Security Question Answers8%

Notices by reporting year

The Attorney General’s reporting year runs July 24 to July 23 (for example, 2026 is July 24, 2025 to July 23, 2026).

YearNoticesCyberattacksWashingtonians affected
202619871%3,798,885
202521272%8,567,575
202429577%12,120,062
202318163%4,581,008
202215967%4,833,519
202128686%6,510,969
20206063%1,071,799
20196574%393,283
20186359%3,515,596
20177766%2,858,566
20163949%553,912

The largest breaches affecting Washingtonians

OrganizationYearWashingtoniansCause
Equifax, Inc.20183,243,664Cyberattack
Change Healthcare Inc.20253,121,209Cyberattack (ransomware)
Comcast Cable Communications LLC20243,100,608Cyberattack
T-Mobile USA20222,079,648Cyberattack (malware)
Fred Hutchinson Cancer Center20241,694,184Cyberattack
ACTIVEOutdoors20171,449,645Unauthorized Access

Questions about Washington data breaches

How many data breaches are reported in Washington each year?

Organizations reported 235 breaches a year on average to the Washington Attorney General over the three reporting years from July 2023 to July 2026. Only breaches affecting more than 500 Washington residents must be reported, so the true number of breaches is higher.

What causes most data breaches in Washington?

Cyberattacks caused 74% of breaches reported from July 2023 to July 2026, and ransomware accounted for 58% of those cyberattacks. Unauthorized access caused 23%, and theft or mistakes 3%.

How long do organizations take to report a breach to the Washington Attorney General?

For breaches the organization became aware of on or after March 1, 2020, the median was 78 days from the date it became aware to the date its notice reached the Attorney General, and 17% of notices arrived within 30 days. Washington law (RCW 19.255.010) sets a 30-day deadline after a breach is discovered, with limited exceptions such as a law enforcement request to delay.

Do small businesses have to report data breaches in Washington?

Yes. RCW 19.255.010 applies to any person or business that owns or licenses personal information of Washington residents. Affected residents must be notified within 30 days of discovery, and the Attorney General must also be notified within 30 days when more than 500 Washington residents are affected. If a vendor holding your data is breached, it must tell you immediately, and the notice obligation stays with you as the data owner.

Does cyber insurance pay for breach notification and response?

Most cyber liability policies include breach response coverage for forensics, legal counsel, customer notification, and credit monitoring, plus extortion and business interruption coverage for ransomware. Limits, sublimits, and exclusions vary by policy, so the specific wording decides what is paid.

Methodology and sources

Source: the Washington State Attorney General’s Office, Data Breach Notifications Affecting Washington Residents and the companion personal information breakdown, published on data.wa.gov. Snapshot taken October 3, 2026: 1,675 notices submitted August 11, 2015 through September 11, 2026.

  • Washington law (RCW 19.255.010) requires notice to the Attorney General only when more than 500 Washington residents are affected, so smaller breaches are not in this data.
  • “Recent” means the three most recent full reporting years, July 2023 to July 2026. The current partial year is excluded from yearly comparisons.
  • Causes and cyberattack types are the Attorney General’s classifications. Percentages are shares of notices, not of people affected.
  • Reporting time is measured from the date the organization reported becoming aware to the date of its notice, matching the Attorney General’s own field. It does not establish that any organization missed a legal deadline: the law allows delays at law enforcement’s request, and identifying who was affected can take time.
  • Location shares use the 1,036 notices that listed a state for the notifying organization.

The summary data behind this page is available as JSON and may be reused with attribution. Suggested citation: Trella Commercial, “Washington Data Breaches by Industry, 2015 to 2026,” analysis of Washington State Attorney General data breach notices, updated October 3, 2026.

This page reports public data and is general information, not legal advice. Coverage described here depends on the actual policy wording and underwriting.

Would your policy cover a breach like these?

Send us your current policies. We will tell you what your cyber coverage pays for, what it leaves out, and what a Washington breach would cost you.