Tracker

Data breaches 2026: the running list

Notable data breaches and data-extortion attacks disclosed in 2026 — each with our own sourced report. Updated as new disclosures land.

39 entries37 confirmedLatest 26 Sep 2026India only
DisclosedOrganisationSectorCountryRecordsCause / actorStatus
Keio CorporationJapanese railway operator confirmed ransomware on group servers that disrupted some group business systems, not trains; data access still under investigation.Read our reportOtherJapanUnknownRansomwareConfirmed
Times Car (Park24)Park24 confirmed a third party took data from about 6.6M Times Car accounts, including licence images and unrecoverable passwords; card data not leaked.Read our reportOtherJapan6.6M accountsUnknownConfirmed
RevolutRevolut handed customer data, including ID documents and statements, to a third party that sent fraudulent requests from a real government email domain.Read our reportFinanceUnited KingdomUnknownSocial engineeringConfirmed
IDScan.netID-verification firm said an unauthorised party may have copied customer names and licence numbers; Krebs tied it to a service selling 153M+ licences.Read our reportTechnologyUnited StatesUnknownUnknownConfirmed
Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)ATF confirmed a breach of a standalone CALEA-related system, designated a major incident; Qilin claimed it and posted ~6.3GB of unverified files.Read our reportGovernmentUnited StatesUnknownUnknownQilinConfirmed
Boston ScientificGlobal disruption from late August; CrowdStrike's findings (22 Sep) say entry was via an external network device, with no evidence data was accessed or taken.Read our reportHealthcareUnited StatesUnknownUnknownConfirmed
Dodo PaymentsBengaluru payments firm said attackers used a Metabase flaw to reach an internal analytics system holding some merchant data; a dark-web listing claims more.Read our reportFinanceIndiaUnknownVulnerabilityConfirmed
Aesto HealthHealth-data archiving vendor reported 9,540,683 people to HHS after unauthorised access to its AWS environment in December 2025.Read our reportHealthcareUnited States9.5MUnknownConfirmed
CEVA LogisticsIntrusion from 29 July halted eight European warehouses and exposed shipping data held for clients incl. Bol, De Bijenkorf, ING and Valve.Read our reportLogisticsFranceUnknownUnknownConfirmed
Bank of BarodaBank disclosed a cyber incident linked to a possible business email compromise after an anonymous claim of data access; ~1TB leak claims are unverified.Read our reportFinanceIndiaUnknownSocial engineeringConfirmed
DentaQuestDental benefits firm began notifying at least 15M people of May network access exposing SSNs, Medicaid/Medicare IDs and dental data.Read our reportHealthcareUnited States15MData theftShinyHuntersConfirmed
Abbott (Exact Sciences)Abbott confirmed unauthorised access to legacy Exact Sciences cancer-diagnostics systems; ShinyHunters claims 30M customer rows.Read our reportHealthcareUnited States10.9M emails (HIBP)Data theftShinyHuntersConfirmed
Reliance Infrastructure (Kudankulam project data)Reliance confirmed a 'partial breach' of a Yotta-hosted server after files tied to Kudankulam nuclear plant work appeared on a leak site.Read our reportOtherIndiaUnknownData theftWorld LeaksConfirmed
UMANG (MeitY government services app)Researchers found flaws exposing EPFO UANs, LPG bookings and plaintext Aadhaar numbers via linked services; MeitY said data in affected APIs is now encrypted.Read our reportGovernmentIndiaUnknownVulnerabilityConfirmed
National Testing Agency (CUET-UG 2026 candidate data)MediaNama found about 15.5 lakh CUET-UG 2026 candidate records offered for sale; NTA says it shares data only via DigiLocker and authorised APIs. Origin unclear.Read our reportEducationIndia1.6M (seller's claim)UnknownClaimed
AdaptHealthHome medical equipment provider disclosed June data theft via a contractor's session; later reported 4,115,802 people affected to HHS.Read our reportHealthcareUnited States4.1MSocial engineeringShinyHuntersConfirmed
IDRBT (.bank.in domain registry)Unauthenticated APIs in the RBI-mandated .bank.in registrar exposed data on 5,576 bank staff for 13+ months; CERT-In said the issue was fixed.Read our reportFinanceIndia5.6KVulnerabilityConfirmed
LastPassPassword manager said support-case data with names and contact details was stolen via the Klue breach; vaults and its own systems unaffected.Read our reportTechnologyUnited StatesUnknownData theftIcarusConfirmed
Bajaj AutoAutomaker told stock exchanges ransomware hit its systems and tech subsidiary; operations continued and it did not say if data was taken.Read our reportManufacturingIndiaUnknownRansomwareConfirmed
Tata ElectronicsApple and Tesla supplier confirmed a cyber incident after ~630GB (204,000+ files) of alleged company data was posted online.Read our reportManufacturingIndiaUnknownData theftWorld LeaksConfirmed
KlueCompetitive-intel vendor said a 2022 pilot credential was reused to reach customer Salesforce data, hitting LastPass, Jamf and others.Read our reportTechnologyCanadaUnknownData theftIcarusConfirmed
UltrahumanWearables maker told users in June that credentials stolen from an employee laptop gave read-only access to contact, purchase and fitness data on 27 March.Read our reportTechnologyIndiaUnknownData theftConfirmed
Pay Tel CommunicationsUpGuard found an open cloud server with 300,000+ callers' IDs at the prison payphone firm; Pay Tel says it closed it by 14 May and only researchers accessed it.Read our reportTelecomUnited StatesUnknownMisconfigurationConfirmed
Carnival CorporationCruise operator told Maine's AG that just under 6M people had names, contact details, birth dates and state ID numbers exposed after an April attack.Read our reportTravelUnited States~6MSocial engineeringShinyHuntersConfirmed
UK Visa Portal (third-party visa service)A private visa-help site exposed at least 100,000 documents incl. passports and selfies via a cloud storage flaw, TechCrunch found.Read our reportOtherUnited KingdomUnknownMisconfigurationClaimed
Charter CommunicationsCharter confirmed a breach; ShinyHunters claims vishing and Salesforce access and 40M records. Charter says no sensitive personal data or CPNI was taken.Read our reportTelecomUnited States4.9M emails (HIBP)Social engineeringShinyHuntersConfirmed
CBSE (On-Screen Marking portal)Student researchers showed admin access to CBSE's marking portal; CBSE said on 26 May it was a test site, then on 1 June that the vulnerabilities were contained.Read our reportEducationIndiaUnknownVulnerabilityConfirmed
HDFC Asset Management CompanyFund house reported a cyber incident found 16 May; Bombay HC barred use of data the Morpheus group claims to hold. HDFC AMC has not confirmed data loss.Read our reportFinanceIndiaUnknownUnknownMorpheus (claimed)Confirmed
Reqrea (Tabiq hotel check-in)A public cloud bucket held over 1M passports, licences and selfies from a hotel check-in system; the firm secured it and is reviewing exposure.Read our reportTechnologyJapan1M+MisconfigurationConfirmed
Instructure (Canvas)Canvas maker confirmed two intrusions exposing usernames, emails, enrolments and messages; it later said it reached an agreement with the attacker.Read our reportEducationUnited StatesUnknownVulnerabilityShinyHuntersConfirmed
VercelVercel said an attacker took over an employee's Google account via a compromised Context.ai OAuth app and read non-sensitive environment variables.Read our reportTechnologyUnited StatesUnknownData theftConfirmed
Duales (Duc app)Toronto money-transfer app left an Amazon storage server of customer licences and passports public; files locked after TechCrunch alert.Read our reportFinanceCanada360,000+ filesMisconfigurationConfirmed
European CommissionThe Commission disclosed a breach on 27 March; CERT-EU later said a stolen AWS key from the Trivy supply-chain compromise led to theft of ~92GB of data.Read our reportGovernmentEuropean UnionUnknownData theftTeamPCP / ShinyHuntersConfirmed
CareCloudHealth IT firm disclosed a March intrusion into an EHR environment; in August it reported about 3.7M patients' records stolen to HHS.Read our reportHealthcareUnited States3.7MData theftConfirmed
StrykerStryker confirmed a global disruption of its Microsoft environment; pro-Iran group Handala claimed it wiped devices and took 50TB of data.Read our reportHealthcareUnited StatesUnknownUnknownHandalaConfirmed
Bhavnagar District Co-operative BankPolice say the accused changed mobile numbers linked to four accounts and pushed ~1,170 NEFT transfers, siphoning ₹7.34 crore; ₹2.04 crore frozen.Read our reportFinanceIndiaUnknownVulnerabilityConfirmed
FBI (surveillance data system)FBI confirmed intrusion into an unclassified system holding pen-register surveillance returns, exposing targets' phone numbers; later a major incident.Read our reportGovernmentUnited StatesUnknownUnknownConfirmed
DavaIndia Pharmacy (Zota Healthcare)Insecure admin APIs exposed ~17,000 online orders and control of 883 stores, a researcher disclosed in February; the flaw was fixed in 2025 after a CERT-In report.Read our reportHealthcareIndiaUnknownVulnerabilityConfirmed
CrunchbaseCrunchbase confirmed documents were exfiltrated from its corporate network; ShinyHunters claims 2M+ records and says it used social engineering.Read our reportTechnologyUnited StatesUnknownUnknownShinyHuntersConfirmed