Data breach
Hayward Holdings
- Records
- 1,697,974
- Breach date
- 31 August 2026Estimated
- Added
- 7 September 2026
What was exposed
8 types of data · 1 puts you at serious risk
- Names1,697,974
- Email addresses1,128,172
- Street addresses1,062,862
- Phone numbers685,205
- Dates of birth1,619
- Social security numbers108
- Licence plates66
- Medical diagnoses3
About this breach
A ransomware group calling itself Falcon has claimed responsibility for a cyberattack on Hayward Holdings, the North Carolina-based maker of pool and spa equipment traded on the New York Stock Exchange under the ticker HAYW. The group listed Hayward on its dark-web leak site on August 31, 2026, alleging it extracted 848 gigabytes of data, including what it described as more than one million business and customer records containing personal information. That claim has not been confirmed by the company.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
August 31, 2026: Ransomware.live recorded Falcon's leak-site post naming Hayward Holdings as a victim, at 15:22 UTC.
September 1, 2026: The law firm Migliaccio & Rathod LLP posted a breach investigation page seeking affected individuals, according to reporting compiled by Almeida Law Group.
September 2, 2026: No class action complaint related to the claim had been filed, and no SEC Form 8-K, state attorney general notification, or mainstream press confirmation had surfaced, per the same review.
What Information Was Compromised?
Our analysis found the following data types in this breach: names across roughly 1.7 million records, email addresses for about 1.13 million people, street addresses for more than 1 million, phone numbers for about 685,000, birthdates for 1,619 individuals, 108 Social Security numbers, 66 vehicle license plates, and 3 medical diagnoses.
Falcon's own posting claims the stolen material also includes Salesforce data, distributor pricing lists, margin structures, financial records, accounting ledgers, personnel files, IT infrastructure documents, privileged account credentials, and board preparation materials. These are attacker statements only and remain unverified by Hayward or any independent source.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Most of the confirmed data types are contact and identity details, which are useful for phishing, smishing, and targeted scams that impersonate Hayward or its brands. The email addresses and phone numbers in particular can support convincing messages about recalls, warranties, or account problems.
The presence of Social Security numbers, even in small numbers, is more serious because that data can enable identity theft and fraudulent credit applications. Dates of birth and street addresses make it easier for criminals to answer knowledge-based verification questions. Anyone whose plate number appears in the set should be alert to vehicle-related scams.
Because Hayward has not confirmed the incident, it is not yet known whether any of this data has been published or how it may circulate.
What Should You Do If You Were Affected?
Watch for phishing emails and texts that mention Hayward, pool equipment, orders, or warranties, and avoid clicking links in unexpected messages.
If your Social Security number was exposed, consider placing a fraud alert or credit freeze with the three major credit bureaus and reviewing your credit reports for unfamiliar activity.
Turn on multi-factor authentication for important accounts and change any password you reuse across sites.
Check Hayward's official website and communications for updates, since no consumer notification had been issued as of this writing.
In the news
- Ransomware.live victim listing for Hayward Holdingsransomware.live (opens in a new tab)
- Almeida Law Group, Hayward Holdings Data Breach Investigationalmeidalawgroup.com (opens in a new tab)
- dExpose, Falcon Ransomware Group Targets Hayward Holdingsdexpose.io (opens in a new tab)
- RecentBreaches, Hayward Holdings Ransomware Claim (2026)recentbreaches.com (opens in a new tab)
