Resources

Breach Advisories

In-depth analysis of significant data breaches and cyber incidents. Understand what happened, who was affected, and what your organisation can learn from each event.

Disclaimer

These advisories summarise publicly reported cybersecurity incidents for educational purposes. All information is sourced from publicly available reports and may include claims that are unverified or disputed. See individual advisories for full source citations and disclaimers.

Showing 58 of 58 advisories

IDMerit

Identity Verification / Fintech - Global - February 2026

Misconfiguration

Analysis of the IDMerit KYC data exposure affecting approximately 1 billion identity verification records across 26 countries due to a misconfigured MongoDB database.

GlobalApproximately 1 billion records

Under Armour

Retail / Consumer - United States - January 2026

Ransomware

Analysis of the Under Armour data breach with 72 million customer records allegedly leaked by the Everest ransomware group after a failed extortion attempt.

United States72 million email addresses; 191 million total records

Conduent Business Solutions

Government IT Services / Healthcare - United States - February 2026

Ransomware

Analysis of the Conduent ransomware breach affecting over 25 million individuals including government benefits recipients. SafePay group claimed to have exfiltrated 8TB of data.

United StatesOver 25 million individuals (and growing)

Instagram / Meta Platforms

Social Media - Global - January 2026

Unauthorised Access

Analysis of the alleged Instagram data leak of 17.5 million accounts. Meta denies the breach occurred and the claims remain unverified.

Global17.5 million accounts (claimed, unconfirmed)

CarGurus

Automotive / E-commerce - United States - February 2026

Data Breach

Analysis of the CarGurus data breach reportedly exposing 12.4 million user records including hashed passwords.

United States12.4 million users

Match Group (Hinge, Match, OkCupid)

Dating / Social Media - Global - January 2026

Social Engineering

Analysis of the alleged Match Group breach reportedly exposing 10 million records from Hinge, Match.com, and OkCupid via claimed compromise of marketing analytics partner.

Global10 million records

Odido

Telecommunications - Netherlands - March 2026

Social Engineering

Analysis of the Odido data breach affecting over 6 million individuals in the Netherlands. Social engineering attack bypassed MFA and exposed customer data including IBANs and identity document metadata.

NetherlandsOver 6.5 million individuals and approximately 600,000 businesses

Panera Bread

Food Service / Retail - United States - February 2026

Data Breach

Analysis of the Panera Bread data breach with 5.1 million customer accounts leaked by ShinyHunters after failed extortion attempt.

United States5.1 million unique accounts

TriZetto Provider Solutions

Healthcare IT / Revenue Management - United States - March 2026

Unauthorised Access

Analysis of the TriZetto Provider Solutions data breach affecting over 3.4 million patients. An 11-month unauthorised access to healthcare claims processing systems exposed SSNs and health data.

United StatesOver 3.4 million individuals (and growing)

Crunchbase

Technology / Business Intelligence - United States - January 2026

Data Breach

Analysis of the Crunchbase data breach exposing 2 million records including internal documents and contracts.

United States2 million records

MexiTravels (reservations.mexitravels.com)

Travel / Hospitality - Mexico - March 2026

Data Leak

Analysis of the MexiTravels data leak exposing approximately 1.98 million travel reservation records. SQL database dump published on dark web forums.

MexicoApproximately 1.98 million records

Den kulturelle skolesekken (DKS)

Education / Government / Arts - Norway - March 2026

Data Breach

Analysis of the Den kulturelle skolesekken (DKS) data breach in Norway exposing approximately 1.3 million records from the national cultural education programme.

NorwayApproximately 1.3 million records (claimed)

University of Hawai'i Cancer Center

Healthcare / Academic Research - United States - March 2026

Ransomware

Analysis of the University of Hawai'i Cancer Center ransomware attack affecting up to 1.24 million individuals. Legacy research data from the 1990s exposed including SSNs.

United StatesUp to approximately 1.24 million individuals

FICOBA (French National Bank Account Registry)

Financial Services / Government - France - February 2026

Data Breach

Analysis of the FICOBA breach exposing 1.2 million French bank account records from the national registry.

France1.2 million bank account records

Brightspeed

Telecommunications - United States - January 2026

Data Breach

Analysis of the Brightspeed data breach affecting over 1 million customers with partial payment card information exposed.

United StatesOver 1 million customers

Figure Technology Solutions

Fintech / Blockchain - United States - February 2026

Social Engineering

Analysis of the Figure Technology breach affecting 967,000 users via social engineering by the ShinyHunters group.

United StatesNearly 967,000 users

Adidas Licensing Partner

Retail / Apparel - Global - February 2026

Data Breach

Analysis of the Adidas licensing partner breach exposing 815,000 rows of data including plaintext passwords.

Global815,000 rows (approximately 130 unique accounts)

CIRO (Canadian Investment Regulatory Organization)

Financial Services / Regulatory - Canada - January 2026

Phishing

Analysis of the CIRO breach affecting 750,000 people at Canada's investment regulatory organisation via phishing attack.

CanadaApproximately 750,000 people

Illinois Department of Human Services

Government / Social Services - United States - January 2026

Misconfiguration

Analysis of the Illinois DHS data exposure affecting 705,017 individuals due to a system misconfiguration exposing public assistance data.

United States705,017 individuals

Roku

Technology / Entertainment - United States - March 2026

Data Breach

Analysis of Roku's second data breach in two years affecting 576,000 customer accounts.

United States576,000 customers

youX

Fintech - Australia - February 2026

Data Breach

Analysis of the youX breach exposing 444,538 Australian borrowers' government IDs and driver's licences.

Australia444,538 borrowers

Minnesota Department of Human Services

Government / Social Services - United States - January 2026

Insider Threat

Analysis of the Minnesota DHS insider threat incident affecting 303,965 individuals' personal and protected information.

United States303,965 individuals

Clinic Service Corporation

Healthcare - United States - January 2026

Hacking

Analysis of the Clinic Service Corporation breach affecting 82,331 individuals' health data.

United States82,331 individuals

LifeLong Medical Care

Healthcare - United States - January 2026

Hacking

Analysis of the LifeLong Medical Care breach affecting 70,000 individuals via hacking at a business associate.

United States70,000 individuals

Bryan Texas Utilities

Utilities - United States - February 2026

Ransomware

Analysis of the Bryan Texas Utilities ransomware attack disrupting billing services for 70,000 customers.

United States70,000 customers

Avosina Healthcare Solutions

Healthcare - United States - January 2026

Ransomware

Analysis of the Avosina Healthcare ransomware attack by Qilin group affecting 44,425 individuals.

United States44,425 individuals

PayPal

Fintech / Payments - United States - February 2026

Credential Stuffing

Analysis of the PayPal credential-stuffing attack affecting 34,942 users with SSN exposure over a 5-month period.

United States34,942 users

Vida Y Salud-Health Systems

Healthcare - United States - January 2026

Data Breach

Analysis of the Vida Y Salud breach affecting 34,504 individuals with SSNs and medical data exposed.

United States34,504 individuals

Wakefield & Associates

Financial Services - United States - January 2026

Ransomware

Analysis of the Wakefield & Associates ransomware attack by Akira group affecting 31,751 individuals.

United States31,751 individuals

Jefferson-Blount-St. Clair Mental Health Authority

Healthcare / Mental Health - United States - January 2026

Ransomware

Analysis of the Jefferson-Blount Mental Health Authority ransomware attack by Medusa group affecting 30,434 individuals.

United States30,434 individuals

Japan Airlines

Aviation / Travel - Japan - February 2026

Unauthorised Access

Analysis of the Japan Airlines breach affecting 28,000 customers via unauthorised access to luggage delivery reservation system.

Japan28,000 customers

Mid Michigan Medical Billing Service

Healthcare - United States - January 2026

Ransomware

Analysis of the Mid Michigan Medical Billing ransomware attack by Qilin group affecting 28,185 individuals.

United States28,185 individuals

RTL Group

Media / Entertainment - Luxembourg - February 2026

Data Breach

Analysis of the RTL Group breach exposing 27,000 employees' contact and job details.

Luxembourg27,000 employees

Volvo Group North America

Automotive / Manufacturing - United States - February 2026

Ransomware

Analysis of the Volvo Group breach affecting 17,000 employees via the Conduent/SafePay ransomware supply chain attack.

United States17,000 employees

Pecan Tree Dental

Healthcare / Dental - United States - January 2026

Ransomware

Analysis of the Pecan Tree Dental ransomware attack by Sinobi group affecting 13,300 individuals.

United States13,300 individuals

Central Ozarks Medical Center

Healthcare - United States - January 2026

Hacking

Analysis of the Central Ozarks Medical Center breach affecting 11,818 individuals' health data.

United States11,818 individuals

360 Dental PC

Healthcare / Dental - United States - January 2026

Ransomware

Analysis of the 360 Dental PC ransomware attack affecting 11,273 individuals.

United States11,273 individuals

US Immigration and Customs Enforcement / Customs and Border Protection

Government / Law Enforcement - United States - January 2026

Insider Threat

Analysis of the ICE and Border Patrol insider leak exposing 4,500 law enforcement workers' details.

United States4,500 individuals

Microsoft

Technology - Global - February 2026

Phishing

Analysis of the Microsoft Outlook add-in credential theft affecting 4,000 user accounts.

Global4,000 user accounts

Coinbase

Fintech / Cryptocurrency - Global - February 2026

Insider Threat

Analysis of the Coinbase insider threat exposing 30 individuals' KYC data and crypto wallet balances.

Global30 individuals (initial); up to 70,000 customers in broader incident

Nike

Retail / Apparel - United States - January 2026

Data Breach

Analysis of the Nike data breach with 1.4TB of internal design and manufacturing data claimed stolen by WorldLeaks.

United StatesUnknown (1.4TB of data)

LexisNexis

Legal / Information Services - United States - March 2026

Data Breach

Analysis of the LexisNexis cloud breach exposing 2GB of legal and government client data.

United StatesUnknown (2GB structured data)

Wynn Resorts

Hospitality / Gaming - United States - February 2026

Ransomware

Analysis of the Wynn Resorts ransomware attack exposing customer and corporate data.

United StatesUnknown

Substack

Media / Technology - United States - February 2026

Data Breach

Analysis of the Substack breach exposing subscriber email addresses and phone numbers.

United StatesUnknown

Flickr

Technology / Social Media - Global - February 2026

Third-party Exposure

Analysis of the Flickr data exposure via third-party breach including user IP addresses and locations.

GlobalUnknown

Eurail

Travel / Transportation - Europe - January 2026

Data Breach

Analysis of the Eurail breach with passport and customer data allegedly offered for sale on the dark web.

EuropeUnknown (1.3TB claimed for sale)

European Commission

Government / International - European Union - February 2026

Hacking

Analysis of the European Commission staff data exposure via exploited Ivanti Endpoint Manager Mobile vulnerability.

European UnionUnknown

Directorate of File Automation (DAF), Senegal

Government - Senegal - February 2026

Data Breach

Analysis of the claimed Senegal government biometric database breach by Green Blood Group with 139TB of identity data.

SenegalUnknown (139TB claimed)

Terry Reilly Health Services

Healthcare - United States - February 2026

Third-party Exposure

Analysis of the Terry Reilly Health Services breach via TriZetto supply chain cascade exposing SSNs and health data.

United StatesUnknown

San Diego Eye Bank

Healthcare - United States - February 2026

Ransomware

Analysis of the San Diego Eye Bank ransomware attack exposing patient and donor data.

United StatesUnknown

Dutch Data Protection Authority (Autoriteit Persoonsgegevens)

Government / Regulatory - Netherlands - February 2026

Hacking

Analysis of the Dutch Data Protection Authority breach via Ivanti vulnerability - the data privacy regulator itself compromised.

NetherlandsUnknown

Iron Mountain

Information Management - United States - February 2026

Extortion

Analysis of the Iron Mountain extortion attempt claiming 1.4TB of data from the records management company.

United StatesUnknown (1.4TB claimed)

Ledger / Global-e

Fintech / Cryptocurrency - Global - January 2026

Third-party Exposure

Analysis of the Ledger/Global-e breach exposing crypto wallet customer data including physical addresses and order details.

GlobalUnknown (potentially millions)

Stryker Corporation

Healthcare / Medical Devices - United States - March 2026

Hacking

Analysis of the Handala group’s destructive wiper attack on Stryker Corporation, which reportedly wiped up to 200,000 devices across 79 countries using the company’s own Microsoft Intune platform.

United States80,000 to 200,000 devices reportedly wiped across 79 countries

TELUS Digital

Business Process Outsourcing / Technology Services - Canada - March 2026

Data Breach

Analysis of the TELUS Digital breach where ShinyHunters allegedly stole close to 1 petabyte of data, reportedly including BPO customer data for 28 companies, using credentials from the Salesloft Drift breach.

CanadaClose to 1 petabyte of data allegedly stolen; BPO customer data for reportedly 28 major companies

Infutor

Data Brokerage / Identity Verification - United States - March 2026

Misconfiguration

Analysis of the Infutor data exposure affecting approximately 677 million records of US consumer data, including Social Security Numbers, reportedly caused by a misconfigured Elasticsearch database.

United StatesApproximately 676,798,866 unique records

Loblaw Companies

Retail / Grocery - Canada - March 2026

Unauthorised Access

Analysis of the Loblaw Companies data breach where hackers accessed customer contact information from Canada’s largest food and pharmacy retailer, which operates 2,400+ stores.

CanadaUndisclosed; Loblaw operates 2,400+ stores and has 18 million loyalty programme members

AkzoNobel

Manufacturing / Chemicals - Netherlands - March 2026

Ransomware

Analysis of the Anubis ransomware attack on AkzoNobel where the group claims to have stolen 170GB of data including passport scans and confidential agreements from the global paints and coatings manufacturer.

Netherlands170GB of data allegedly stolen