{
  "title": "CyberShitty.com data breach tracker",
  "url": "https://cybershitty.com/breaches",
  "updated": "2026-09-26",
  "note": "Confirmed = the organisation or a regulator confirmed it. Claimed = reported claim, not yet confirmed. Free to cite with a link back.",
  "entries": [
    {
      "date": "2026-09-26",
      "org": "Keio Corporation",
      "sector": "Other",
      "country": "Japan",
      "records": "Unknown",
      "cause": "Ransomware",
      "actor": "",
      "status": "Confirmed",
      "summary": "Japanese railway operator confirmed ransomware on group servers that disrupted some group business systems, not trains; data access still under investigation.",
      "source_label": "Keio Corporation — Notice and apology concerning system failure due to ransomware attack (26 Sep 2026)",
      "source_url": "https://www.keio.co.jp/news/update/announce/nr260926v13404/",
      "report_url": "https://cybershitty.com/breaches/keio-2026"
    },
    {
      "date": "2026-09-25",
      "org": "Renfe (via Adif systems)",
      "sector": "Other",
      "country": "Spain",
      "records": "Unknown",
      "cause": "Unknown",
      "actor": "",
      "status": "Confirmed",
      "summary": "Spanish rail operator confirmed an attack via compromised Adif servers; names and emails, later ID numbers and encrypted passwords, possibly affected.",
      "source_label": "Railin — Renfe amplía el alcance del ciberataque vinculado a Adif (28 Sep 2026)",
      "source_url": "https://www.railin.net/es/noticias/renfe-amplia-el-alcance-del-ciberataque/",
      "report_url": "https://cybershitty.com/breaches/renfe-2026"
    },
    {
      "date": "2026-09-25",
      "org": "Times Car (Park24)",
      "sector": "Other",
      "country": "Japan",
      "records": "6.6M accounts",
      "cause": "Unknown",
      "actor": "",
      "status": "Confirmed",
      "summary": "Park24 confirmed a third party took data from about 6.6M Times Car accounts, including licence images and unrecoverable passwords; card data not leaked.",
      "source_label": "Park24 — Times Car web system unauthorised access: investigation results (2nd report) (28 Sep 2026)",
      "source_url": "https://www.park24.co.jp/news/2026/09/20260928-1.html",
      "report_url": "https://cybershitty.com/breaches/times-car-2026"
    },
    {
      "date": "2026-09-24",
      "org": "US Department of Defense (Defense Manpower Data Center)",
      "sector": "Government",
      "country": "United States",
      "records": "3.05M",
      "cause": "Vulnerability",
      "actor": "",
      "status": "Confirmed",
      "summary": "Unauthorised users reached a DMDC file-sharing server; unencrypted SSNs and service data of 2.76M living and 294,000 deceased people exposed.",
      "source_label": "Stars and Stripes — Breach at Pentagon personnel database exposed data of millions (29 Sep 2026)",
      "source_url": "https://www.stripes.com/theaters/us/2026-09-29/data-breach-pentagon-personnel-records-23001764.html",
      "report_url": "https://cybershitty.com/breaches/pentagon-dmdc-2026"
    },
    {
      "date": "2026-09-22",
      "org": "FBI (FBIJobs.gov portal)",
      "sector": "Government",
      "country": "United States",
      "records": "Unknown",
      "cause": "Vulnerability",
      "actor": "ShinyHunters (claimed)",
      "status": "Claimed",
      "summary": "ShinyHunters claims staff data theft via a PeopleSoft flaw; FBI confirms only that it is investigating, and its job portals are offline.",
      "source_label": "Help Net Security — FBI job portals remain offline after ShinyHunters claims breach (28 Sep 2026)",
      "source_url": "https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/",
      "report_url": "https://cybershitty.com/breaches/fbi-jobs-portal-2026"
    },
    {
      "date": "2026-09-12",
      "org": "Revolut",
      "sector": "Finance",
      "country": "United Kingdom",
      "records": "Unknown",
      "cause": "Social engineering",
      "actor": "",
      "status": "Confirmed",
      "summary": "Revolut handed customer data, including ID documents and statements, to a third party that sent fraudulent requests from a real government email domain.",
      "source_label": "TechCrunch — Revolut confirms customer data breach through fake government requests (12 Sep 2026)",
      "source_url": "https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/",
      "report_url": "https://cybershitty.com/breaches/revolut-2026"
    },
    {
      "date": "2026-09-01",
      "org": "IDScan.net",
      "sector": "Technology",
      "country": "United States",
      "records": "Unknown",
      "cause": "Unknown",
      "actor": "",
      "status": "Confirmed",
      "summary": "ID-verification firm said an unauthorised party may have copied customer names and licence numbers; Krebs tied it to a service selling 153M+ licences.",
      "source_label": "KrebsOnSecurity — FBI probes service selling 153M drivers licenses (Sep 2026)",
      "source_url": "https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/",
      "report_url": "https://cybershitty.com/breaches/idscan-net-2026"
    },
    {
      "date": "2026-08-27",
      "org": "Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)",
      "sector": "Government",
      "country": "United States",
      "records": "Unknown",
      "cause": "Unknown",
      "actor": "Qilin",
      "status": "Confirmed",
      "summary": "ATF confirmed a breach of a standalone CALEA-related system, designated a major incident; Qilin claimed it and posted ~6.3GB of unverified files.",
      "source_label": "BleepingComputer — ATF confirms 'major incident' after recent Qilin breach claims (27 Aug 2026)",
      "source_url": "https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/",
      "report_url": "https://cybershitty.com/post/atf-major-incident-qilin-calea"
    },
    {
      "date": "2026-08-26",
      "org": "Boston Scientific",
      "sector": "Healthcare",
      "country": "United States",
      "records": "Unknown",
      "cause": "Unknown",
      "actor": "",
      "status": "Confirmed",
      "summary": "Global disruption from late August; CrowdStrike's findings (22 Sep) say entry was via an external network device, with no evidence data was accessed or taken.",
      "source_label": "Boston Scientific — Form 8-K, Item 1.05 (filed 8 Sep 2026)",
      "source_url": "https://www.sec.gov/Archives/edgar/data/0000885725/000088572526000059/bsx-20260907.htm",
      "report_url": "https://cybershitty.com/post/boston-scientific-cyberattack-guidance"
    },
    {
      "date": "2026-08-17",
      "org": "Dodo Payments",
      "sector": "Finance",
      "country": "India",
      "records": "Unknown",
      "cause": "Vulnerability",
      "actor": "",
      "status": "Confirmed",
      "summary": "Bengaluru payments firm said attackers used a Metabase flaw to reach an internal analytics system holding some merchant data; a dark-web listing claims more.",
      "source_label": "Dodo Payments — Security incident involving an internal analytics system (17 Aug 2026)",
      "source_url": "https://dodopayments.com/blogs/security-incident-internal-analytics-system",
      "report_url": "https://cybershitty.com/breaches/dodo-payments-2026"
    },
    {
      "date": "2026-08-14",
      "org": "Aesto Health",
      "sector": "Healthcare",
      "country": "United States",
      "records": "9.5M",
      "cause": "Unknown",
      "actor": "",
      "status": "Confirmed",
      "summary": "Health-data archiving vendor reported 9,540,683 people to HHS after unauthorised access to its AWS environment in December 2025.",
      "source_label": "HIPAA Journal — Aesto Health data breach (Aug/Sep 2026)",
      "source_url": "https://www.hipaajournal.com/aesto-health-data-breach/",
      "report_url": "https://cybershitty.com/breaches/aesto-health-2026"
    },
    {
      "date": "2026-08-10",
      "org": "CEVA Logistics",
      "sector": "Logistics",
      "country": "France",
      "records": "Unknown",
      "cause": "Unknown",
      "actor": "",
      "status": "Confirmed",
      "summary": "Intrusion from 29 July halted eight European warehouses and exposed shipping data held for clients incl. Bol, De Bijenkorf, ING and Valve.",
      "source_label": "TechCrunch — A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers (10 Aug 2026)",
      "source_url": "https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/",
      "report_url": "https://cybershitty.com/post/ceva-logistics-cyberattack-european-warehouses"
    },
    {
      "date": "2026-07-28",
      "org": "Bank of Baroda",
      "sector": "Finance",
      "country": "India",
      "records": "Unknown",
      "cause": "Social engineering",
      "actor": "",
      "status": "Confirmed",
      "summary": "Bank disclosed a cyber incident linked to a possible business email compromise after an anonymous claim of data access; ~1TB leak claims are unverified.",
      "source_label": "The Record — India's Bank of Baroda confirms cyber incident after hackers claim data theft (28 Jul 2026)",
      "source_url": "https://therecord.media/india-bank-of-baroda-reports-cybersecurity-incident",
      "report_url": "https://cybershitty.com/post/bank-of-baroda-cyber-incident-data-leak-claims"
    },
    {
      "date": "2026-07-17",
      "org": "DentaQuest",
      "sector": "Healthcare",
      "country": "United States",
      "records": "15M",
      "cause": "Data theft",
      "actor": "ShinyHunters",
      "status": "Confirmed",
      "summary": "Dental benefits firm began notifying at least 15M people of May network access exposing SSNs, Medicaid/Medicare IDs and dental data.",
      "source_label": "HIPAA Journal — DentaQuest data breach (Jul 2026)",
      "source_url": "https://www.hipaajournal.com/dentaquest-data-breach/",
      "report_url": "https://cybershitty.com/breaches/dentaquest-2026"
    },
    {
      "date": "2026-07-16",
      "org": "Abbott (Exact Sciences)",
      "sector": "Healthcare",
      "country": "United States",
      "records": "10.9M emails (HIBP)",
      "cause": "Data theft",
      "actor": "ShinyHunters",
      "status": "Confirmed",
      "summary": "Abbott confirmed unauthorised access to legacy Exact Sciences cancer-diagnostics systems; ShinyHunters claims 30M customer rows.",
      "source_label": "HIPAA Journal — Abbott investigating cyberattack claims from two threat actors (20 Jul 2026)",
      "source_url": "https://www.hipaajournal.com/abbott-investigating-cyberattack-claims/",
      "report_url": "https://cybershitty.com/breaches/abbott-2026"
    },
    {
      "date": "2026-07-16",
      "org": "Reliance Infrastructure (Kudankulam project data)",
      "sector": "Other",
      "country": "India",
      "records": "Unknown",
      "cause": "Data theft",
      "actor": "World Leaks",
      "status": "Confirmed",
      "summary": "Reliance confirmed a 'partial breach' of a Yotta-hosted server after files tied to Kudankulam nuclear plant work appeared on a leak site.",
      "source_label": "MediaNama — Reliance and Kudankulam Nuclear Power Plant data breach (16 Jul 2026)",
      "source_url": "https://www.medianama.com/2026/07/223-reliance-data-breach-kudankulam-files-dark-web/",
      "report_url": "https://cybershitty.com/post/reliance-infrastructure-kudankulam-data-breach"
    },
    {
      "date": "2026-07-14",
      "org": "UMANG (MeitY government services app)",
      "sector": "Government",
      "country": "India",
      "records": "Unknown",
      "cause": "Vulnerability",
      "actor": "",
      "status": "Confirmed",
      "summary": "Researchers found flaws exposing EPFO UANs, LPG bookings and plaintext Aadhaar numbers via linked services; MeitY said data in affected APIs is now encrypted.",
      "source_label": "MediaNama — Researchers find security flaws in UMANG that exposed user data across government services (14 Jul 2026)",
      "source_url": "https://www.medianama.com/2026/07/223-researchers-find-security-flaws-umang-exposed-user-data-across-government-services/",
      "report_url": "https://cybershitty.com/breaches/umang-2026"
    },
    {
      "date": "2026-07-08",
      "org": "National Testing Agency (CUET-UG 2026 candidate data)",
      "sector": "Education",
      "country": "India",
      "records": "1.6M (seller's claim)",
      "cause": "Unknown",
      "actor": "",
      "status": "Claimed",
      "summary": "MediaNama found about 15.5 lakh CUET-UG 2026 candidate records offered for sale; NTA says it shares data only via DigiLocker and authorised APIs. Origin unclear.",
      "source_label": "MediaNama — Leaked data of Indian students from government exams and private coaching institutes is sold online (8 Jul 2026)",
      "source_url": "https://www.medianama.com/2026/07/223-leaked-data-indian-students-government-exams-private-coaching-institutes-sold-online/",
      "report_url": "https://cybershitty.com/breaches/national-testing-agency-2026"
    },
    {
      "date": "2026-07-02",
      "org": "AdaptHealth",
      "sector": "Healthcare",
      "country": "United States",
      "records": "4.1M",
      "cause": "Social engineering",
      "actor": "ShinyHunters",
      "status": "Confirmed",
      "summary": "Home medical equipment provider disclosed June data theft via a contractor's session; later reported 4,115,802 people affected to HHS.",
      "source_label": "BleepingComputer — AdaptHealth confirms 4.1 million people exposed in July cyberattack (9 Sep 2026)",
      "source_url": "https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/",
      "report_url": "https://cybershitty.com/post/adapthealth-breach-4-1-million-patients"
    },
    {
      "date": "2026-06-29",
      "org": "IDRBT (.bank.in domain registry)",
      "sector": "Finance",
      "country": "India",
      "records": "5.6K",
      "cause": "Vulnerability",
      "actor": "",
      "status": "Confirmed",
      "summary": "Unauthenticated APIs in the RBI-mandated .bank.in registrar exposed data on 5,576 bank staff for 13+ months; CERT-In said the issue was fixed.",
      "source_label": "MediaNama — How vulnerabilities in RBI's bank.in registry exposed sensitive data for 13 months (29 Jun 2026)",
      "source_url": "https://www.medianama.com/2026/06/223-security-vulnerabilities-rbi-bank-in-registry-sensitive-data/",
      "report_url": "https://cybershitty.com/breaches/idrbt-2026"
    },
    {
      "date": "2026-06-23",
      "org": "LastPass",
      "sector": "Technology",
      "country": "United States",
      "records": "Unknown",
      "cause": "Data theft",
      "actor": "Icarus",
      "status": "Confirmed",
      "summary": "Password manager said support-case data with names and contact details was stolen via the Klue breach; vaults and its own systems unaffected.",
      "source_label": "TechCrunch — LastPass says hackers stole customer support case data during Klue breach (23 Jun 2026)",
      "source_url": "https://techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/",
      "report_url": "https://cybershitty.com/breaches/lastpass-2026"
    },
    {
      "date": "2026-06-23",
      "org": "Bajaj Auto",
      "sector": "Manufacturing",
      "country": "India",
      "records": "Unknown",
      "cause": "Ransomware",
      "actor": "",
      "status": "Confirmed",
      "summary": "Automaker told stock exchanges ransomware hit its systems and tech subsidiary; operations continued and it did not say if data was taken.",
      "source_label": "The Record — Indian auto giant Bajaj Auto hit by ransomware incident (24 Jun 2026)",
      "source_url": "https://therecord.media/indian-auto-giant-bajaj-auto-hit-by-ransomware",
      "report_url": "https://cybershitty.com/post/bajaj-auto-ransomware-attack"
    },
    {
      "date": "2026-06-22",
      "org": "Tata Electronics",
      "sector": "Manufacturing",
      "country": "India",
      "records": "Unknown",
      "cause": "Data theft",
      "actor": "World Leaks",
      "status": "Confirmed",
      "summary": "Apple and Tesla supplier confirmed a cyber incident after ~630GB (204,000+ files) of alleged company data was posted online.",
      "source_label": "TechCrunch — Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach (22 Jun 2026)",
      "source_url": "https://techcrunch.com/2026/06/22/tata-electronics-a-major-tech-supplier-to-apple-and-tesla-confirms-data-breach/",
      "report_url": "https://cybershitty.com/post/tata-electronics-cyber-incident-world-leaks-claims"
    },
    {
      "date": "2026-06-19",
      "org": "Klue",
      "sector": "Technology",
      "country": "Canada",
      "records": "Unknown",
      "cause": "Data theft",
      "actor": "Icarus",
      "status": "Confirmed",
      "summary": "Competitive-intel vendor said a 2022 pilot credential was reused to reach customer Salesforce data, hitting LastPass, Jamf and others.",
      "source_label": "TechCrunch — Klue says hackers stole credential from 2022 that led to customer data breaches (23 Jun 2026)",
      "source_url": "https://techcrunch.com/2026/06/23/klue-says-hackers-stole-credential-from-2022-that-led-to-customer-data-breaches/",
      "report_url": "https://cybershitty.com/breaches/klue-2026"
    },
    {
      "date": "2026-06-02",
      "org": "Ultrahuman",
      "sector": "Technology",
      "country": "India",
      "records": "Unknown",
      "cause": "Data theft",
      "actor": "",
      "status": "Confirmed",
      "summary": "Wearables maker told users in June that credentials stolen from an employee laptop gave read-only access to contact, purchase and fitness data on 27 March.",
      "source_label": "MediaNama — Ultrahuman suffers a major security breach, exposing users' wellness data (4 Jun 2026)",
      "source_url": "https://www.medianama.com/2026/06/223-ultrahuman-suffers-security-breach-exposing-users-wellness-data/",
      "report_url": "https://cybershitty.com/breaches/ultrahuman-2026"
    },
    {
      "date": "2026-05-28",
      "org": "Pay Tel Communications",
      "sector": "Telecom",
      "country": "United States",
      "records": "Unknown",
      "cause": "Misconfiguration",
      "actor": "",
      "status": "Confirmed",
      "summary": "UpGuard found an open cloud server with 300,000+ callers' IDs at the prison payphone firm; Pay Tel says it closed it by 14 May and only researchers accessed it.",
      "source_label": "TechCrunch — Security lapse at prison payphone service Pay-Tel exposed 300,000+ callers' licences (28 May 2026)",
      "source_url": "https://techcrunch.com/2026/05/28/a-security-lapse-at-prison-payphone-service-pay-tel-publicly-exposed-over-300000-callers-drivers-licenses/",
      "report_url": "https://cybershitty.com/breaches/pay-tel-communications-2026"
    },
    {
      "date": "2026-05-27",
      "org": "Carnival Corporation",
      "sector": "Travel",
      "country": "United States",
      "records": "~6M",
      "cause": "Social engineering",
      "actor": "ShinyHunters",
      "status": "Confirmed",
      "summary": "Cruise operator told Maine's AG that just under 6M people had names, contact details, birth dates and state ID numbers exposed after an April attack.",
      "source_label": "The Register — Carnival confirms ShinyHunters cruised off with 6M customer records (28 May 2026)",
      "source_url": "https://www.theregister.com/cyber-crime/2026/05/28/carnival-shinyhunters-cruised-off-with-6m-customer-records/5247808",
      "report_url": "https://cybershitty.com/breaches/carnival-corporation-2026"
    },
    {
      "date": "2026-05-27",
      "org": "UK Visa Portal (third-party visa service)",
      "sector": "Other",
      "country": "United Kingdom",
      "records": "Unknown",
      "cause": "Misconfiguration",
      "actor": "",
      "status": "Claimed",
      "summary": "A private visa-help site exposed at least 100,000 documents incl. passports and selfies via a cloud storage flaw, TechCrunch found.",
      "source_label": "TechCrunch — UK visa portal spilled applicants' passports and selfies online (27 May 2026)",
      "source_url": "https://techcrunch.com/2026/05/27/uk-visa-portal-spilled-thousands-of-applicants-passports-and-selfies-online-and-hasnt-fixed-the-leak/",
      "report_url": "https://cybershitty.com/breaches/uk-visa-portal-2026"
    },
    {
      "date": "2026-05-26",
      "org": "Charter Communications",
      "sector": "Telecom",
      "country": "United States",
      "records": "4.9M emails (HIBP)",
      "cause": "Social engineering",
      "actor": "ShinyHunters",
      "status": "Confirmed",
      "summary": "Charter confirmed a breach; ShinyHunters claims vishing and Salesforce access and 40M records. Charter says no sensitive personal data or CPNI was taken.",
      "source_label": "BleepingComputer — Charter confirms data breach after ShinyHunters extortion threat (26 May 2026)",
      "source_url": "https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/",
      "report_url": "https://cybershitty.com/breaches/charter-communications-2026"
    },
    {
      "date": "2026-05-22",
      "org": "CBSE (On-Screen Marking portal)",
      "sector": "Education",
      "country": "India",
      "records": "Unknown",
      "cause": "Vulnerability",
      "actor": "",
      "status": "Confirmed",
      "summary": "Student researchers showed admin access to CBSE's marking portal; CBSE said on 26 May it was a test site, then on 1 June that the vulnerabilities were contained.",
      "source_label": "MediaNama — CBSE hacked: Cybersecurity researcher demonstrates access after official denials (30 May 2026)",
      "source_url": "https://www.medianama.com/2026/05/223-cbse-hacked-cybersecurity-researcher-demonstrates-access-official-denials/",
      "report_url": "https://cybershitty.com/breaches/cbse-2026"
    },
    {
      "date": "2026-05-18",
      "org": "HDFC Asset Management Company",
      "sector": "Finance",
      "country": "India",
      "records": "Unknown",
      "cause": "Unknown",
      "actor": "Morpheus (claimed)",
      "status": "Confirmed",
      "summary": "Fund house reported a cyber incident found 16 May; Bombay HC barred use of data the Morpheus group claims to hold. HDFC AMC has not confirmed data loss.",
      "source_label": "ETV Bharat — HDFC AMC gets HC relief in cyber theft case; injunction granted against hackers (1 Jun 2026)",
      "source_url": "https://www.etvbharat.com/en/state/hdfc-asset-management-company-gets-hc-relief-in-cyber-theft-case-injunction-granted-against-hackers-enn26060102919",
      "report_url": "https://cybershitty.com/breaches/hdfc-asset-management-company-2026"
    },
    {
      "date": "2026-05-15",
      "org": "Reqrea (Tabiq hotel check-in)",
      "sector": "Technology",
      "country": "Japan",
      "records": "1M+",
      "cause": "Misconfiguration",
      "actor": "",
      "status": "Confirmed",
      "summary": "A public cloud bucket held over 1M passports, licences and selfies from a hotel check-in system; the firm secured it and is reviewing exposure.",
      "source_label": "TechCrunch — A hotel check-in system left a million passports and driver's licenses open (15 May 2026)",
      "source_url": "https://techcrunch.com/2026/05/15/a-hotel-check-in-system-left-a-million-passports-and-drivers-licenses-open-for-anyone-to-see/",
      "report_url": "https://cybershitty.com/breaches/reqrea-2026"
    },
    {
      "date": "2026-05-01",
      "org": "Instructure (Canvas)",
      "sector": "Education",
      "country": "United States",
      "records": "Unknown",
      "cause": "Vulnerability",
      "actor": "ShinyHunters",
      "status": "Confirmed",
      "summary": "Canvas maker confirmed two intrusions exposing usernames, emails, enrolments and messages; it later said it reached an agreement with the attacker.",
      "source_label": "Instructure — Security incident update (May–Jul 2026)",
      "source_url": "https://www.instructure.com/incident_update",
      "report_url": "https://cybershitty.com/breaches/instructure-2026"
    },
    {
      "date": "2026-04-19",
      "org": "Vercel",
      "sector": "Technology",
      "country": "United States",
      "records": "Unknown",
      "cause": "Data theft",
      "actor": "",
      "status": "Confirmed",
      "summary": "Vercel said an attacker took over an employee's Google account via a compromised Context.ai OAuth app and read non-sensitive environment variables.",
      "source_label": "TechCrunch — Vercel says some of its customers' data was stolen prior to its recent hack (23 Apr 2026)",
      "source_url": "https://techcrunch.com/2026/04/23/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack/",
      "report_url": "https://cybershitty.com/breaches/vercel-2026"
    },
    {
      "date": "2026-04-02",
      "org": "Duales (Duc app)",
      "sector": "Finance",
      "country": "Canada",
      "records": "360,000+ files",
      "cause": "Misconfiguration",
      "actor": "",
      "status": "Confirmed",
      "summary": "Toronto money-transfer app left an Amazon storage server of customer licences and passports public; files locked after TechCrunch alert.",
      "source_label": "TechCrunch — Canadian money-transfer app Duc exposed driver's licenses and passports (2 Apr 2026)",
      "source_url": "https://techcrunch.com/2026/04/02/canadian-money-transfer-app-duc-expose-drivers-licenses-passports-amazon-server/",
      "report_url": "https://cybershitty.com/breaches/duales-2026"
    },
    {
      "date": "2026-03-27",
      "org": "European Commission",
      "sector": "Government",
      "country": "European Union",
      "records": "Unknown",
      "cause": "Data theft",
      "actor": "TeamPCP / ShinyHunters",
      "status": "Confirmed",
      "summary": "The Commission disclosed a breach on 27 March; CERT-EU later said a stolen AWS key from the Trivy supply-chain compromise led to theft of ~92GB of data.",
      "source_label": "TechCrunch — Europe's cyber agency blames hacking gangs for massive data breach and leak (3 Apr 2026)",
      "source_url": "https://techcrunch.com/2026/04/03/europes-cyber-agency-blames-hacking-gangs-for-massive-data-breach-and-leak/",
      "report_url": "https://cybershitty.com/breaches/european-commission-2026"
    },
    {
      "date": "2026-03-24",
      "org": "CareCloud",
      "sector": "Healthcare",
      "country": "United States",
      "records": "3.7M",
      "cause": "Data theft",
      "actor": "",
      "status": "Confirmed",
      "summary": "Health IT firm disclosed a March intrusion into an EHR environment; in August it reported about 3.7M patients' records stolen to HHS.",
      "source_label": "TechCrunch — CareCloud confirms 3.7M patients had their medical records stolen (19 Aug 2026)",
      "source_url": "https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/",
      "report_url": "https://cybershitty.com/breaches/carecloud-2026"
    },
    {
      "date": "2026-03-11",
      "org": "Stryker",
      "sector": "Healthcare",
      "country": "United States",
      "records": "Unknown",
      "cause": "Unknown",
      "actor": "Handala",
      "status": "Confirmed",
      "summary": "Stryker confirmed a global disruption of its Microsoft environment; pro-Iran group Handala claimed it wiped devices and took 50TB of data.",
      "source_label": "TechCrunch — Stryker hack: pro-Iran hacktivist group Handala says it is behind attack (11 Mar 2026)",
      "source_url": "https://techcrunch.com/2026/03/11/stryker-hack-pro-iran-hacktivist-group-handala-says-it-is-behind-attack/",
      "report_url": "https://cybershitty.com/breaches/stryker-2026"
    },
    {
      "date": "2026-03-11",
      "org": "Bhavnagar District Co-operative Bank",
      "sector": "Finance",
      "country": "India",
      "records": "Unknown",
      "cause": "Vulnerability",
      "actor": "",
      "status": "Confirmed",
      "summary": "Police say the accused changed mobile numbers linked to four accounts and pushed ~1,170 NEFT transfers, siphoning ₹7.34 crore; ₹2.04 crore frozen.",
      "source_label": "DeshGujarat — Bhavnagar District Cooperative Bank suspends operations after Rs 7 crore cyber fraud (11 Mar 2026)",
      "source_url": "https://deshgujarat.com/2026/03/11/bhavnagar-district-cooperative-bank-suspends-operations-after-rs-7-crore-cyber-fraud/",
      "report_url": "https://cybershitty.com/breaches/bhavnagar-district-co-operative-bank-2026"
    },
    {
      "date": "2026-03-06",
      "org": "FBI (surveillance data system)",
      "sector": "Government",
      "country": "United States",
      "records": "Unknown",
      "cause": "Unknown",
      "actor": "",
      "status": "Confirmed",
      "summary": "FBI confirmed intrusion into an unclassified system holding pen-register surveillance returns, exposing targets' phone numbers; later a major incident.",
      "source_label": "Nextgov/FCW — Suspected Chinese breach of FBI system exposed surveillance targets' phone numbers (3 Apr 2026)",
      "source_url": "https://www.nextgov.com/cybersecurity/2026/04/suspected-chinese-breach-fbi-system-exposed-surveillance-targets-phone-numbers/412612/",
      "report_url": "https://cybershitty.com/breaches/fbi-2026"
    },
    {
      "date": "2026-02-13",
      "org": "DavaIndia Pharmacy (Zota Healthcare)",
      "sector": "Healthcare",
      "country": "India",
      "records": "Unknown",
      "cause": "Vulnerability",
      "actor": "",
      "status": "Confirmed",
      "summary": "Insecure admin APIs exposed ~17,000 online orders and control of 883 stores, a researcher disclosed in February; the flaw was fixed in 2025 after a CERT-In report.",
      "source_label": "TechCrunch — Indian pharmacy chain giant exposed customer data and internal systems (13 Feb 2026)",
      "source_url": "https://techcrunch.com/2026/02/13/indias-major-pharmacy-chain-exposed-customer-data-and-internal-systems/",
      "report_url": "https://cybershitty.com/breaches/davaindia-pharmacy-2026"
    },
    {
      "date": "2026-01-26",
      "org": "Crunchbase",
      "sector": "Technology",
      "country": "United States",
      "records": "Unknown",
      "cause": "Unknown",
      "actor": "ShinyHunters",
      "status": "Confirmed",
      "summary": "Crunchbase confirmed documents were exfiltrated from its corporate network; ShinyHunters claims 2M+ records and says it used social engineering.",
      "source_label": "SecurityWeek — Crunchbase confirms data breach after hacking claims (26 Jan 2026)",
      "source_url": "https://www.securityweek.com/crunchbase-confirms-data-breach-after-hacking-claims/",
      "report_url": "https://cybershitty.com/breaches/crunchbase-2026"
    }
  ]
}