Neogen Corporation, a Michigan-based provider of food safety testing, animal health products, and genomic services, is the subject of reports of a possible cybersecurity incident. Companies that collect and store sensitive personal and employment-related information have a responsibility to protect it, and when reports of a possible breach surface, the people who may be affected deserve clear information and support.
Neogen’s Data Breach Investigation
Neogen Corporation supplies food safety testing products, animal health solutions, and genomic services to businesses across the agriculture and food industries, and in the course of its operations maintains records for its employees, customers, and business partners. Reports surfaced in late August 2026 that a cybercriminal extortion group claimed responsibility for an attack on the company’s systems, listing Neogen on a dark web data leak site.
As of this writing, Neogen has not publicly confirmed the incident, and no specific details about the scope of any breach, the number of individuals affected, or the categories of information involved have been disclosed. Reports describing the incident are based on the extortion group’s own claims rather than a confirmed statement from the company, which is common in the early stages of a suspected cyberattack before an official investigation concludes.
Companies across the food safety, agriculture, and life sciences sectors are increasingly targeted by cybercriminal extortion groups because they often maintain large volumes of employee, customer, and proprietary business data. These groups typically gain access through compromised credentials, phishing, or vulnerabilities in third-party software, then threaten to publish or sell stolen data unless a ransom is paid. When a company has not yet confirmed the scope of an alleged breach, individuals connected to that company, including current and former employees and customers, are often encouraged to stay alert for updates and any official notification that may follow.
It is common for the full picture of an alleged data breach to take time to develop, as an investigating company works to confirm whether an intrusion actually occurred, what systems were affected, and whether any personal information was accessed or exfiltrated. Regulatory notification requirements generally do not begin until a company has confirmed a breach and determined which individuals were affected, which is why public reports of a possible incident and any eventual notification letters do not always arrive at the same time.
When Did This Breach Occur?
Reports indicate the suspected incident occurred on or around August 29, 2026, based on a dark web posting by the hacker group claiming responsibility. Neogen has not publicly confirmed a breach date, and this information has not been independently verified by the company.
What Information Was Breached?
The specific categories of information potentially involved in this incident have not been publicly disclosed. Individuals affiliated with Neogen, including current and former employees and customers, who are concerned their information may have been exposed should watch for any official communication from the company and monitor their accounts for suspicious activity in the meantime.
What You Can Do
If you are affiliated with Neogen and are concerned your information may have been affected, consider the following steps:
- Watch for any official notification from Neogen and follow the guidance it provides.
- Monitor your financial accounts and credit reports for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the three major credit bureaus.
- Be cautious of unsolicited calls, texts, or emails referencing this incident, since criminals often use breach reports to run follow-up phishing scams.
- Use strong, unique passwords and enable two-factor authentication on your accounts.
File a Data Breach Lawsuit Against Neogen
If your personal information was exposed in connection with the Neogen data breach, you may have legal options available to you. Companies that collect and store sensitive personal information are expected to take reasonable steps to protect it, and when a breach occurs, affected individuals may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.