On May 27, 2026, the ransomware group Qilin publicly claimed responsibility for a cyberattack against Shocco Springs, a U.S. hospitality organization. The group posted an extortion notice stating sensitive data would be leaked unless negotiations began. As of now, Shocco Springs has not released an official breach statement.
No official confirmation exists regarding the number of affected individuals or the types of data exposed, including whether medical, financial, or SSN data were involved. No state Attorney General filings or class action lawsuits have been reported. The incident is still under initial investigation, and details about affected individuals and data types remain unverified.
Details about data breaches can emerge over time, and official notices may be delayed.