// FEED · BREACH-INTEL · US //

US Data
Breach Feed.

see what surfaced this week.

A curated, weekly rolling feed of significant US data breaches — pulled from regulatory filings, public disclosures, and the cypherpunk press. Calm signal, not vendor FUD. Subscribe via RSS, or read it here.

// $ Lost (rolling 12mo) // $1.8B
// PII records leaked (12mo) // 142M
// Records exposed (12mo) // 377M+
// Last poll // 06:14 UTC
// Next poll // 14m

// The Feed //

17 entries
Severity
Sector
Search

Instructure Canvas 275M records claimed

Records275,000,000
ActorShinyHunters
VectorUnder investigation

ShinyHunters claimed exfiltration of student and educator records from the learning-management platform that serves the majority of US universities and a large slice of K-12. Names, emails, student IDs, course enrolment. Risk is downstream — every school district in the affected set has been told to assume their roster is on the market.

McDonald's 64M applicants via AI chatbot

Records64,000,000
ActorResearchers (whitehat)
VectorDefault credentials

Two researchers walked into the chain's hiring chatbot using the password 123456 and walked out with the personal records of every applicant the AI had ever spoken to. The flaw was reported privately. The credential was — and this is in the disclosure — never rotated.

Vercel OAuth supply-chain compromise

RecordsUnder investigation
ActorLumma Stealer operator
Vector3rd-party OAuth (Context.ai)

An employee had authorised a third-party AI tool with broad Workspace scopes; the tool itself was compromised. Two-month dwell time. Stolen: access keys, source, API tokens, internal deployment credentials. Vercel didn't catch it — the attacker monetising it publicly is how they found out.

Adobe 13M support tickets, 15K HR records

Records13,000,000+
ActorMr. Racoon
Vector3rd-party BPO · phishing

Threat actor claims responsibility for siphoning 13M customer-support tickets, 15K employee records, internal corporate docs, and the company's bug-bounty submissions. Entry was reportedly through a contracted support BPO. Your vendor's posture is your posture.

PIH Health 3M patients, care disrupted

Records3,000,000+
ActorUndisclosed ransomware group
VectorRansomware

Ransomware attack against PIH Health Hospitals took critical systems offline; over 3M California patients were unable to access care while systems were recovered. The incident reads as a textbook target: regional hospital network, soft underbelly, downtime costs lives.

Allianz Life majority of customer base

Records1,100,000+
ActorUnattributed
Vector3rd-party CRM

The insurer confirmed an unauthorised actor accessed a third-party CRM and exfiltrated sensitive data on the majority of US customers. Specific data types remain partially undisclosed; the population includes policy holders, beneficiaries, and applicants.

Brightspeed 1M+ customers, ransom

Records1,000,000+
ActorCrimson Collective
VectorRansomware + exfil

New extortion crew Crimson Collective claimed theft of data on more than a million broadband customers. Subscriber records, account details, and internal documentation. Threat actor is new — operators should treat their TTPs as not yet fully characterised.

Nike 1.4 TB internal data claimed

Volume1.4 TB
ActorUnattributed
VectorPrivilege misuse (susp.)

Attackers claimed exfiltration of 1.4 TB of internal Nike data. Investigation pending. Patterns at this scale almost always come back to insufficient internal monitoring or compromised privileged credentials — not a perimeter exploit.

Rhode Island RIBridges benefits system

Records650,000+
ActorInternational ransomware crew
VectorVendor compromise

Personal and banking information of hundreds of thousands of Rhode Island residents exposed through the state's benefits and Medicaid eligibility platform. State has paused enrolment and engaged federal partners. The vendor model means the state was the patient, not the surgeon.

Stryker wiper attack, offices offline

RecordsTbd · ops impact severe
ActorIran-aligned hacktivists
VectorDestructive malware (wiper)

Employees reportedly watched as company endpoints were wiped in real time. Offices shuttered while teams forensicated. Geopolitical pattern — defence-adjacent and medical manufacturers are now soft targets in state-aligned hacktivist campaigns.

CarGurus 12M user accounts

Records12,000,000+
ActorUnattributed
VectorAccount-store compromise

Marketplace confirmed unauthorised access to the systems holding customer account information. Payment cards not confirmed exposed; credentials are. Treat the population as high-risk for credential reuse and targeted phishing.

Anne Arundel Dermatology 1.9M patients

Records1,900,000
ActorUndisclosed
VectorUnauthorised network access

Specialty-care provider disclosed unauthorised access exposing the personal and health information of 1.9 million patients. Names, SSNs, treatment information potentially exposed. Notice has begun; OCR posting expected.

Texas Tech Health Sci. Center 800K+

Records800,000+
ActorUndisclosed
VectorCyberattack · investigating

Oregon DOJ disclosure notes the September 2024 incident at the Texas university's health sciences arm now confirmed at 800,000+ affected. The pattern is familiar: university hospital networks remain a soft target with valuable PHI.

Heritage Bank 182,793 individuals

Records182,793
ActorUndisclosed
VectorUnder investigation

The financial-services firm confirmed an intrusion between March and April 2026 affecting just under 183K individuals. Specific data exposed not yet itemised in the public notice; affected customers are being mailed.

Match Group Tinder, Hinge, OkCupid

RecordsMillions (claimed)
ActorShinyHunters
VectorAppsFlyer (3rd party)

ShinyHunters claimed access via the marketing-analytics provider AppsFlyer. Match has acknowledged a "security incident" still under investigation. Dating-app data is unusually high-leverage — sexual orientation, location patterns, private message metadata.

AT&T $177M class settlement

Settlement$177,000,000
Origin2024 breaches
StatusNotice phase

The carrier reached a $177M settlement covering two 2024 incidents that exposed CDR-style call/text metadata and customer account data. Class members should expect a postcard. If you were a US AT&T subscriber in 2022–2024, assume your metadata is on the market.

PracticeSuite 13K records, server illegally accessed

Records~13,000
ActorUndisclosed
VectorStorage server access

Practice-management vendor disclosed unauthorised access on a storage server, affecting an estimated 13,000 individuals. Small in count, but a useful pattern: medical SaaS vendors aggregate PHI across many tiny practices.

// no entries match the current filter //
FEED · LIVE | 9 sources polled | last update 2026-05-19 06:14 UTC | next poll in 14m | uplink: tor + clearnet | v0.1 · build 2026.05.19