CSIDB logo
Incident

American Addiction Centers

Incident posture

Attack window
May 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 09:45

Linked entities

Victim
American Addiction Centers
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

American Addiction Centers detected unauthorized access to its Salesforce environment on May 12, 2026, leading to exfiltration of names, contact information, Social Security numbers, health insurance data, and patient health descriptions; the breach was discovered June 5, 2026 and confirmed June 12, 2026.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

American Addiction Centers, a Brentwood, Tennessee-based provider of addiction treatment services operating more than 30 facilities across the United States, disclosed a security incident involving a third-party vendor's Salesforce environment. Suspicious activity was identified within the Salesforce instance on June 5, 2026. A forensic investigation was launched, and on June 12, 2026, investigators determined that there had been unauthorized access to the Salesforce environment on May 12, 2026, and that data had been exfiltrated from that system. The forensic review confirmed that the incident was contained to the Salesforce environment and did not affect any other systems operated by American Addiction Centers. The organization notified the California Attorney General about the incident.

The data review confirmed that the information acquired by the unauthorized party included names, contact information, Social Security numbers, health insurance information, and brief descriptions that patients had provided related to their health. The affected data pertained to individuals who had initial outreach contact with American Addiction Centers. The organization stated that security measures had already been implemented prior to the breach and indicated that it would continue to review its security measures to further protect and monitor the Salesforce environment. Complimentary credit monitoring and identity theft protection services were made available to affected individuals. At the time of the disclosure, the total number of individuals affected had not been announced.

Sources

Sources available to members: 1 source.

CSIDB