WA Data Breach Notifications - Security Intelligence
Pricing
$2.00 / 1,000 wa data breach notification records
WA Data Breach Notifications - Security Intelligence
Washington data-breach notifications (1,653, WA AG, 2017-present): breached organization, industry, cause (cyberattack / unauthorized access), attack type (ransomware / phishing), Washingtonians affected. Filter by industry, attack type, date or minimum affected; screen vendors and suppliers.
Pricing
$2.00 / 1,000 wa data breach notification records
Rating
0.0
(0)
Developer
Wenhao Yang
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
a day ago
Last modified
Categories
Share
WA Data Breach Notifications (wa-data-breach)
Pull Washington data-breach notifications - ~1,670 breaches filed with the WA Attorney General (2015-present, free public open data). Every time a business, healthcare organization or government body discovers a breach affecting 500+ Washington residents, state law requires them to file one of these.
This is a security-intelligence feed: who got breached in WA, in what industry, by what kind of attack, and how many Washingtonians were exposed.
Built for security researchers, auditors, vendor-screening and supply-chain teams, insurance underwriters, journalists and market-intelligence users - the question "has this organization / this industry / this vendor ever had a WA data breach?" answered in one query.
What this data is
Each record is one breach notification:
| Field | Meaning |
|---|---|
name | The breached organization |
industryType | Business / Health / Finance / Education / Government / Non-Profit/Charity |
businessType | Finer business category (e.g. Software, Medical) |
breachCause | Cyberattack / Unauthorized Access / Theft or Mistake |
cyberAttackType | Ransomware / Malware / Phishing / Skimmers... |
washingtoniansAffected | WA residents exposed (source also carries a range) |
year / dateSubmitted | When the notification was filed |
daysToContain | Days from discovery to containment (where known) |
Note on scope: notifications are required at ~500+ WA residents affected, so this is the reportable tail of breaches, not every incident. It still shows the industry and attack-vector mix clearly (ransomware dominates; Health is the top non-Business industry).
Typical questions it answers
- Ransomware victims in WA - filter
cyberAttackType=Ransomware; every row carrieswashingtoniansAffected, so you can rank the biggest hits downstream. - Healthcare breaches - filter
industryType=Health(+ ayearFrom). ~330 Health notifications on file. - Has this company ever reported a breach here? - filter
name=...(e.g. "Premera", "Delta"). - Large-impact incidents -
minAffected=10000. - Newest activity - leave everything blank; you get the latest notifications first.
Inputs (all optional)
| Input | What it does |
|---|---|
name | Breached organization (substring) |
keywords | Match across org name / industry / business type |
industryType | Industry (Business / Health / Finance / Education / Government) |
breachCause | Cyberattack / Unauthorized Access / Theft or Mistake |
cyberAttackType | Attack type (substring: Ransomware, Phishing, ...) |
minAffected | At least N Washingtonians affected |
yearFrom / yearTo | Notification-year range |
maxResults | Cap records (default 50) |
Example inputs
Ransomware victims in WA - cyberAttackType is a substring.
{ "cyberAttackType": "Ransomware", "maxResults": 10 }
Healthcare breaches in recent years - combine the industry with a notification-year floor.
{ "industryType": "Health", "yearFrom": "2024", "maxResults": 10 }
Has this company ever reported a breach? - name is a case-insensitive substring.
{ "name": "Premera", "maxResults": 10 }
Large-impact incidents - minAffected is a floor on Washingtonians exposed.
{ "minAffected": 10000, "maxResults": 10 }
Low cost & full coverage
$0.002 per record returned, and each record is metered individually.
Every breach notification on file is in the dataset - the full ~1,670 reportable breaches (2015-present). Runs scan the whole set and return exactly what matches your filters. One source quirk handled for you: the dataset's own year field is the state fiscal year of reporting, which runs ahead of the real filing date (a breach filed in Aug 2026 can be stamped 2027), so all date filtering here runs off the actual submission date rather than the label that would silently mislead a naive pull.
Example output
One breach notification - cyberAttackType="Ransomware" returns records like this one:
{"platform": "wa-data-breach","source": "wa-ag-breach-notifications","name": "Quatrro Business Support Services, Inc.","industryType": "Business","businessType": "Professional Services","breachCause": "Cyberattack","cyberAttackType": "Ransomware","washingtoniansAffected": 10008,"affectedRange": "10,000-49,999","year": "2026","dateSubmitted": "2026-09-09","dateAware": "2025-12-07","daysToContain": 0}
Data source & freshness
- Source: data.wa.gov - WA AG Data Breach Notifications (
sb4j-ca4h, Socrata SODA API, free public, no login). - Update cadence: the AG publishes notifications as they're filed - through the present.