High Data Breaches

27 reports

Canada Life

May 13, 2026

High
237,810 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In April 2026, Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group . The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer support tickets. In ...

Read Report

Cushman & Wakefield

May 12, 2026

High
310,431 accounts exposed
Email Addresses Names Phone Numbers Job Titles

In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group . Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with te...

Read Report

Woflow

May 7, 2026

High
447,593 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group . The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of e...

Read Report

Reborn Gaming

May 4, 2026

High
126 accounts exposed
Email Addresses Ip Addresses

In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM) . The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.

Read Report

Marcus & Millichap

May 3, 2026

High
1,837,078 accounts exposed
Email Addresses Names Phone Numbers Employers +1 more

In April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group . Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, ...

Read Report

ZenBusiness

May 2, 2026

High
5,118,184 accounts exposed
Email Addresses Names Phone Numbers

In March 2026, the hacker and extortion group "ShinyHunters" claimed to have obtained a substantial corpus of data from ZenBusiness , a business formation and compliance platform. The group claimed the data had been exfiltrated from platforms including Snowflake, Mixpanel and Salesforce, and threate...

Read Report

Aman

May 1, 2026

High
215,563 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +2 more

In April 2026, the ultra-luxury hotel brand Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign , with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. Whilst not present on...

Read Report

Pitney Bowes

Apr 27, 2026

High
8,243,989 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +1 more

In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses...

Read Report

Udemy

Apr 26, 2026

High
1,401,259 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +1 more

In April 2026, online training company Udemy was the victim of a “pay or leak” extortion attempt perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also included names, physical a...

Read Report

Carnival

Apr 24, 2026

High
7,531,359 accounts exposed
Email Addresses Names Dates Of Birth Genders

In April 2026, the notorious hacking collective ShinyHunters claimed they had obtained a substantial volume of data belonging to the Carnival cruise operator and attempted to extort the organisation to prevent the data from being leaked. The following week, the group published the data publicly, whi...

Read Report

Amtrak

Apr 17, 2026

High
2,147,679 accounts exposed
Email Addresses Names Physical Addresses

In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak . The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. They subsequently published the alleged data which contained over 2M uniqu...

Read Report

Hallmark

Apr 12, 2026

High
1,736,520 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In March 2026, Hallmark suffered an alleged breach and subsequent extortion after attackers gained access to data stored within Salesforce. The data was later published after the extortion deadline passed, exposing 1.7M unique email addresses across both Hallmark and the Hallmark+ streaming service,...

Read Report

Crunchyroll

Apr 4, 2026

High
1,195,684 accounts exposed
Email Addresses Names Ip Addresses Geographic Locations

In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users . The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the conten...

Read Report

KomikoAI

Mar 2, 2026

High
1,060,191 accounts exposed
Email Addresses Names

In February, the AI-powered comic generation platform KomikoAI suffered a data breach . The incident exposed 1M unique email addresses along with names, user posts and the AI prompts used to generate content. The exposed data enables the mapping of individual AI prompts to specific email addresses.

Read Report

Odido

Feb 26, 2026

High
688,102 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +1 more

In February 2026, Dutch telco Odido was the victim of a data breach and subsequent extortion attempt . Following the incident, 1M records containing 317k unique email addresses were published, with the attackers threatening to leak additional data in the following days. That threat was subsequently ...

Read Report

CarMax

Feb 20, 2026

High
431,371 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt . The data included 431k unique email addresses along with names, phone numbers and physical addresses.

Read Report

Figure

Feb 18, 2026

High
967,178 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +1 more

In February 2026, data obtained from the fintech lending platform Figure was publicly posted online . The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and at...

Read Report

APOIA.se

Feb 16, 2026

High
450,764 accounts exposed
Email Addresses Names Physical Addresses

In December 2025, a database of the Brazilian crowdfunding platform APOIA.se was posted to an online forum . In January 2026, the company confirmed it had suffered a data breach. The incident exposed 451k unique email addresses along with names and physical addresses.

Read Report

University of Pennsylvania

Feb 16, 2026

High
623,750 accounts exposed
Email Addresses Names Physical Addresses Genders

In October 2025, the University of Pennsylvania was the victim of a data breach followed by a ransom demand , largely affecting its donor database. After the incident, the attackers sent inflammatory emails to some victims. The data was later published online in February 2026 and included 624k uniqu...

Read Report

Toy Battles

Feb 10, 2026

High
1,017 accounts exposed
Email Addresses Usernames Names Ip Addresses

In February 2026, the online gaming community Toy Battles suffered a data breach. The incident exposed 1k unique email addresses alongside usernames, IP addresses and chat logs. Following the breach, Toy Battles self-submitted the data to Have I Been Pwned.

Read Report

Substack

Feb 6, 2026

High
663,121 accounts exposed
Email Addresses Names Phone Numbers

In October 2025, the publishing platform Substack suffered a data breach that was subsequently circulated more widely in February 2026. The breach exposed 663k account holder records containing email addresses along with publicly visible profile information from Substack accounts, such as publicatio...

Read Report

Panera Bread

Jan 31, 2026

High
5,112,502 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In January 2026, Panera Bread suffered a data breach that exposed 14M records . After an attempted extortion failed, the attackers published the data publicly, which included 5.1M unique email addresses along with associated account information such as names, phone numbers and physical addresses. Pa...

Read Report

Pass'Sport

Jan 18, 2026

High
6,366,133 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +1 more

In December 2025, data from France's Pass'Sport program was posted to a popular hacking forum . Initially misattributed to CAF (the French family allowance fund), the data contained 6.5M unique email addresses affecting 3.5M households. The data also included names, phone numbers, genders and physic...

Read Report

WIRED

Dec 27, 2025

High
2,364,431 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +2 more

In December 2025, 2.3M records of WIRED magazine users allegedly obtained from parent company Condé Nast were published online . The most recent data dated back to the previous September and exposed email addresses and display names, as well as, for a small number of users, their name, phone number,...

Read Report

Utair

Dec 26, 2025

High
401,400 accounts exposed
Email Addresses Names Physical Addresses Dates Of Birth

In August 2020, news broke of a data breach of Russian airline Utair that dated back to the previous year . The breach contained over 400k unique email addresses along with extensive personal information including names, physical addresses, dates of birth, passport numbers and loyalty program detail...

Read Report

Медицинская лаборатория Гемотест (Gemotest)

Dec 24, 2025

High
6,341,495 accounts exposed
Email Addresses Names Physical Addresses Dates Of Birth

In April 2022, Russian pharmaceutical company Gemotest suffered a data breach that exposed 31 million patients . The data contained 6.3 million unique email addresses along with names, physical addresses, dates of birth, passport and insurance numbers. Gemotest was later fined for the breach.

Read Report

AUTOSUR

Dec 18, 2025

High
487,226 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In March 2025, the French vehicle inspection company AUTOSUR suffered a data breach exposing over 10M customer records, though only 487k unique email addresses were present. The compromised data included names, phone numbers, physical addresses, and vehicle details such as make and model, VIN, and r...

Read Report

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.