2026-05-08
// Education · K-12 + HE //
Critical
Instructure Canvas — 275M records claimed
Records275,000,000
ActorShinyHunters
VectorUnder investigation
ShinyHunters claimed exfiltration of student and educator records from the learning-management platform that serves the majority of US universities and a large slice of K-12. Names, emails, student IDs, course enrolment. Risk is downstream — every school district in the affected set has been told to assume their roster is on the market.
2026-05-02
// Retail · QSR //
Critical
McDonald's — 64M applicants via AI chatbot
Records64,000,000
ActorResearchers (whitehat)
VectorDefault credentials
Two researchers walked into the chain's hiring chatbot using the password 123456 and walked out with the personal records of every applicant the AI had ever spoken to. The flaw was reported privately. The credential was — and this is in the disclosure — never rotated.
2026-04-28
// Tech · Cloud Infra //
High
Vercel — OAuth supply-chain compromise
RecordsUnder investigation
ActorLumma Stealer operator
Vector3rd-party OAuth (Context.ai)
An employee had authorised a third-party AI tool with broad Workspace scopes; the tool itself was compromised. Two-month dwell time. Stolen: access keys, source, API tokens, internal deployment credentials. Vercel didn't catch it — the attacker monetising it publicly is how they found out.
2026-04-24
// Tech · Creative SaaS //
High
Adobe — 13M support tickets, 15K HR records
Records13,000,000+
ActorMr. Racoon
Vector3rd-party BPO · phishing
Threat actor claims responsibility for siphoning 13M customer-support tickets, 15K employee records, internal corporate docs, and the company's bug-bounty submissions. Entry was reportedly through a contracted support BPO. Your vendor's posture is your posture.
2026-04-19
// Healthcare · Hospital Network //
Critical
PIH Health — 3M patients, care disrupted
Records3,000,000+
ActorUndisclosed ransomware group
VectorRansomware
Ransomware attack against PIH Health Hospitals took critical systems offline; over 3M California patients were unable to access care while systems were recovered. The incident reads as a textbook target: regional hospital network, soft underbelly, downtime costs lives.
2026-04-15
// Finance · Insurance //
High
Allianz Life — majority of customer base
Records1,100,000+
ActorUnattributed
Vector3rd-party CRM
The insurer confirmed an unauthorised actor accessed a third-party CRM and exfiltrated sensitive data on the majority of US customers. Specific data types remain partially undisclosed; the population includes policy holders, beneficiaries, and applicants.
2026-04-11
// Telecom · Broadband //
High
Brightspeed — 1M+ customers, ransom
Records1,000,000+
ActorCrimson Collective
VectorRansomware + exfil
New extortion crew Crimson Collective claimed theft of data on more than a million broadband customers. Subscriber records, account details, and internal documentation. Threat actor is new — operators should treat their TTPs as not yet fully characterised.
2026-04-04
// Retail · Sport/Apparel //
High
Nike — 1.4 TB internal data claimed
Volume1.4 TB
ActorUnattributed
VectorPrivilege misuse (susp.)
Attackers claimed exfiltration of 1.4 TB of internal Nike data. Investigation pending. Patterns at this scale almost always come back to insufficient internal monitoring or compromised privileged credentials — not a perimeter exploit.
2026-03-22
// Gov · State //
Medium
Rhode Island — RIBridges benefits system
Records650,000+
ActorInternational ransomware crew
VectorVendor compromise
Personal and banking information of hundreds of thousands of Rhode Island residents exposed through the state's benefits and Medicaid eligibility platform. State has paused enrolment and engaged federal partners. The vendor model means the state was the patient, not the surgeon.
2026-03-18
// MedTech · Manufacturer //
High
Stryker — wiper attack, offices offline
RecordsTbd · ops impact severe
ActorIran-aligned hacktivists
VectorDestructive malware (wiper)
Employees reportedly watched as company endpoints were wiped in real time. Offices shuttered while teams forensicated. Geopolitical pattern — defence-adjacent and medical manufacturers are now soft targets in state-aligned hacktivist campaigns.
2026-02-26
// Tech · Marketplace //
Medium
CarGurus — 12M user accounts
Records12,000,000+
ActorUnattributed
VectorAccount-store compromise
Marketplace confirmed unauthorised access to the systems holding customer account information. Payment cards not confirmed exposed; credentials are. Treat the population as high-risk for credential reuse and targeted phishing.
2026-02-19
// Healthcare · Specialty Care //
High
Anne Arundel Dermatology — 1.9M patients
Records1,900,000
ActorUndisclosed
VectorUnauthorised network access
Specialty-care provider disclosed unauthorised access exposing the personal and health information of 1.9 million patients. Names, SSNs, treatment information potentially exposed. Notice has begun; OCR posting expected.
2026-02-12
// Education · University Health //
Medium
Texas Tech Health Sci. Center — 800K+
Records800,000+
ActorUndisclosed
VectorCyberattack · investigating
Oregon DOJ disclosure notes the September 2024 incident at the Texas university's health sciences arm now confirmed at 800,000+ affected. The pattern is familiar: university hospital networks remain a soft target with valuable PHI.
2026-02-05
// Finance · Community Bank //
Medium
Heritage Bank — 182,793 individuals
Records182,793
ActorUndisclosed
VectorUnder investigation
The financial-services firm confirmed an intrusion between March and April 2026 affecting just under 183K individuals. Specific data exposed not yet itemised in the public notice; affected customers are being mailed.
2026-01-22
// Tech · Dating //
High
Match Group — Tinder, Hinge, OkCupid
RecordsMillions (claimed)
ActorShinyHunters
VectorAppsFlyer (3rd party)
ShinyHunters claimed access via the marketing-analytics provider AppsFlyer. Match has acknowledged a "security incident" still under investigation. Dating-app data is unusually high-leverage — sexual orientation, location patterns, private message metadata.
2026-01-10
// Telecom · Legal //
Settled
AT&T — $177M class settlement
Settlement$177,000,000
Origin2024 breaches
StatusNotice phase
The carrier reached a $177M settlement covering two 2024 incidents that exposed CDR-style call/text metadata and customer account data. Class members should expect a postcard. If you were a US AT&T subscriber in 2022–2024, assume your metadata is on the market.
2025-11-04
// Healthcare · SaaS //
Info
PracticeSuite — 13K records, server illegally accessed
Records~13,000
ActorUndisclosed
VectorStorage server access
Practice-management vendor disclosed unauthorised access on a storage server, affecting an estimated 13,000 individuals. Small in count, but a useful pattern: medical SaaS vendors aggregate PHI across many tiny practices.