| Keio CorporationJapanese railway operator confirmed ransomware on group servers that disrupted some group business systems, not trains; data access still under investigation.Read our report | Other | Japan | Unknown | Ransomware | Confirmed |
| Times Car (Park24)Park24 confirmed a third party took data from about 6.6M Times Car accounts, including licence images and unrecoverable passwords; card data not leaked.Read our report | Other | Japan | 6.6M accounts | Unknown | Confirmed |
| RevolutRevolut handed customer data, including ID documents and statements, to a third party that sent fraudulent requests from a real government email domain.Read our report | Finance | United Kingdom | Unknown | Social engineering | Confirmed |
| IDScan.netID-verification firm said an unauthorised party may have copied customer names and licence numbers; Krebs tied it to a service selling 153M+ licences.Read our report | Technology | United States | Unknown | Unknown | Confirmed |
| Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)ATF confirmed a breach of a standalone CALEA-related system, designated a major incident; Qilin claimed it and posted ~6.3GB of unverified files.Read our report | Government | United States | Unknown | UnknownQilin | Confirmed |
| Boston ScientificGlobal disruption from late August; CrowdStrike's findings (22 Sep) say entry was via an external network device, with no evidence data was accessed or taken.Read our report | Healthcare | United States | Unknown | Unknown | Confirmed |
| Dodo PaymentsBengaluru payments firm said attackers used a Metabase flaw to reach an internal analytics system holding some merchant data; a dark-web listing claims more.Read our report | Finance | India | Unknown | Vulnerability | Confirmed |
| Aesto HealthHealth-data archiving vendor reported 9,540,683 people to HHS after unauthorised access to its AWS environment in December 2025.Read our report | Healthcare | United States | 9.5M | Unknown | Confirmed |
| CEVA LogisticsIntrusion from 29 July halted eight European warehouses and exposed shipping data held for clients incl. Bol, De Bijenkorf, ING and Valve.Read our report | Logistics | France | Unknown | Unknown | Confirmed |
| Bank of BarodaBank disclosed a cyber incident linked to a possible business email compromise after an anonymous claim of data access; ~1TB leak claims are unverified.Read our report | Finance | India | Unknown | Social engineering | Confirmed |
| DentaQuestDental benefits firm began notifying at least 15M people of May network access exposing SSNs, Medicaid/Medicare IDs and dental data.Read our report | Healthcare | United States | 15M | Data theftShinyHunters | Confirmed |
| Abbott (Exact Sciences)Abbott confirmed unauthorised access to legacy Exact Sciences cancer-diagnostics systems; ShinyHunters claims 30M customer rows.Read our report | Healthcare | United States | 10.9M emails (HIBP) | Data theftShinyHunters | Confirmed |
| Reliance Infrastructure (Kudankulam project data)Reliance confirmed a 'partial breach' of a Yotta-hosted server after files tied to Kudankulam nuclear plant work appeared on a leak site.Read our report | Other | India | Unknown | Data theftWorld Leaks | Confirmed |
| UMANG (MeitY government services app)Researchers found flaws exposing EPFO UANs, LPG bookings and plaintext Aadhaar numbers via linked services; MeitY said data in affected APIs is now encrypted.Read our report | Government | India | Unknown | Vulnerability | Confirmed |
| National Testing Agency (CUET-UG 2026 candidate data)MediaNama found about 15.5 lakh CUET-UG 2026 candidate records offered for sale; NTA says it shares data only via DigiLocker and authorised APIs. Origin unclear.Read our report | Education | India | 1.6M (seller's claim) | Unknown | Claimed |
| AdaptHealthHome medical equipment provider disclosed June data theft via a contractor's session; later reported 4,115,802 people affected to HHS.Read our report | Healthcare | United States | 4.1M | Social engineeringShinyHunters | Confirmed |
| IDRBT (.bank.in domain registry)Unauthenticated APIs in the RBI-mandated .bank.in registrar exposed data on 5,576 bank staff for 13+ months; CERT-In said the issue was fixed.Read our report | Finance | India | 5.6K | Vulnerability | Confirmed |
| LastPassPassword manager said support-case data with names and contact details was stolen via the Klue breach; vaults and its own systems unaffected.Read our report | Technology | United States | Unknown | Data theftIcarus | Confirmed |
| Bajaj AutoAutomaker told stock exchanges ransomware hit its systems and tech subsidiary; operations continued and it did not say if data was taken.Read our report | Manufacturing | India | Unknown | Ransomware | Confirmed |
| Tata ElectronicsApple and Tesla supplier confirmed a cyber incident after ~630GB (204,000+ files) of alleged company data was posted online.Read our report | Manufacturing | India | Unknown | Data theftWorld Leaks | Confirmed |
| KlueCompetitive-intel vendor said a 2022 pilot credential was reused to reach customer Salesforce data, hitting LastPass, Jamf and others.Read our report | Technology | Canada | Unknown | Data theftIcarus | Confirmed |
| UltrahumanWearables maker told users in June that credentials stolen from an employee laptop gave read-only access to contact, purchase and fitness data on 27 March.Read our report | Technology | India | Unknown | Data theft | Confirmed |
| Pay Tel CommunicationsUpGuard found an open cloud server with 300,000+ callers' IDs at the prison payphone firm; Pay Tel says it closed it by 14 May and only researchers accessed it.Read our report | Telecom | United States | Unknown | Misconfiguration | Confirmed |
| Carnival CorporationCruise operator told Maine's AG that just under 6M people had names, contact details, birth dates and state ID numbers exposed after an April attack.Read our report | Travel | United States | ~6M | Social engineeringShinyHunters | Confirmed |
| UK Visa Portal (third-party visa service)A private visa-help site exposed at least 100,000 documents incl. passports and selfies via a cloud storage flaw, TechCrunch found.Read our report | Other | United Kingdom | Unknown | Misconfiguration | Claimed |
| Charter CommunicationsCharter confirmed a breach; ShinyHunters claims vishing and Salesforce access and 40M records. Charter says no sensitive personal data or CPNI was taken.Read our report | Telecom | United States | 4.9M emails (HIBP) | Social engineeringShinyHunters | Confirmed |
| CBSE (On-Screen Marking portal)Student researchers showed admin access to CBSE's marking portal; CBSE said on 26 May it was a test site, then on 1 June that the vulnerabilities were contained.Read our report | Education | India | Unknown | Vulnerability | Confirmed |
| HDFC Asset Management CompanyFund house reported a cyber incident found 16 May; Bombay HC barred use of data the Morpheus group claims to hold. HDFC AMC has not confirmed data loss.Read our report | Finance | India | Unknown | UnknownMorpheus (claimed) | Confirmed |
| Reqrea (Tabiq hotel check-in)A public cloud bucket held over 1M passports, licences and selfies from a hotel check-in system; the firm secured it and is reviewing exposure.Read our report | Technology | Japan | 1M+ | Misconfiguration | Confirmed |
| Instructure (Canvas)Canvas maker confirmed two intrusions exposing usernames, emails, enrolments and messages; it later said it reached an agreement with the attacker.Read our report | Education | United States | Unknown | VulnerabilityShinyHunters | Confirmed |
| VercelVercel said an attacker took over an employee's Google account via a compromised Context.ai OAuth app and read non-sensitive environment variables.Read our report | Technology | United States | Unknown | Data theft | Confirmed |
| Duales (Duc app)Toronto money-transfer app left an Amazon storage server of customer licences and passports public; files locked after TechCrunch alert.Read our report | Finance | Canada | 360,000+ files | Misconfiguration | Confirmed |
| European CommissionThe Commission disclosed a breach on 27 March; CERT-EU later said a stolen AWS key from the Trivy supply-chain compromise led to theft of ~92GB of data.Read our report | Government | European Union | Unknown | Data theftTeamPCP / ShinyHunters | Confirmed |
| CareCloudHealth IT firm disclosed a March intrusion into an EHR environment; in August it reported about 3.7M patients' records stolen to HHS.Read our report | Healthcare | United States | 3.7M | Data theft | Confirmed |
| StrykerStryker confirmed a global disruption of its Microsoft environment; pro-Iran group Handala claimed it wiped devices and took 50TB of data.Read our report | Healthcare | United States | Unknown | UnknownHandala | Confirmed |
| Bhavnagar District Co-operative BankPolice say the accused changed mobile numbers linked to four accounts and pushed ~1,170 NEFT transfers, siphoning ₹7.34 crore; ₹2.04 crore frozen.Read our report | Finance | India | Unknown | Vulnerability | Confirmed |
| FBI (surveillance data system)FBI confirmed intrusion into an unclassified system holding pen-register surveillance returns, exposing targets' phone numbers; later a major incident.Read our report | Government | United States | Unknown | Unknown | Confirmed |
| DavaIndia Pharmacy (Zota Healthcare)Insecure admin APIs exposed ~17,000 online orders and control of 883 stores, a researcher disclosed in February; the flaw was fixed in 2025 after a CERT-In report.Read our report | Healthcare | India | Unknown | Vulnerability | Confirmed |
| CrunchbaseCrunchbase confirmed documents were exfiltrated from its corporate network; ShinyHunters claims 2M+ records and says it used social engineering.Read our report | Technology | United States | Unknown | UnknownShinyHunters | Confirmed |