CPCG was listed by the Qilin ransomware group on their leak site on July 22, 2026. This indicates that the group claims to have exfiltrated internal files from CPCG. The listing on the ransomware site serves as the primary source of information, but no official confirmation from CPCG has been found.
The specific types of data exposed, the number of individuals affected, and the states impacted remain unconfirmed. It is not clear whether sensitive data such as SSNs, medical records, or financial information were involved. No official breach notification letters, company statements, or regulatory filings have been identified.
Further details regarding this incident, including official company statements or regulatory investigations, have not yet been publicly disclosed. Information about the ultimate impact is currently limited to the ransomware group's claim.