Skip to content
Live · Updated every 6 hours
Track every US data breachBreached
All breaches

Every breach we track

53 total
30 / 53
A
Medium1d ago

American Tower

American Tower had data on over 216,000 employees, contractors, customers, and leads exposed after a ShinyHunters extortion campaign in June 2026.

Email addressesNamesPhone numbers+2 more
217K
M
High3d ago

Madison Square Garden Sports

Madison Square Garden Sports had data on nearly 10 million accounts exposed after the ShinyHunters group carried out a pay-or-leak extortion campaign and published the stolen data online.

NamesEmail addressesPhone numbers+2 more
9.8M
J
Critical7d ago

JCPenney

JCPenney suffered a data breach in June 2026 when ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, exposing personal and HR data for approximately 368,000 current and former employees.

Dates of birthEmail addressesGovernment issued IDs+6 more
368K
R
Medium8d ago

Ralph Lauren

Ralph Lauren had data on approximately 140,000 individuals exposed after the ShinyHunters group claimed to have extracted records from the company's Salesforce instance and published them as part of an extortion campaign.

Email addressesNamesPhone numbers+2 more
140K
O
Medium8d ago

Operation Endgame 4.0 (SocGholish Malware Operation)

International law enforcement, coordinated through Europol and Eurojust, disrupted the SocGholish malware network on 18 June 2026, providing HIBP with approximately 154,000 affected email addresses and over 500,000 previously unseen passwords.

Email addressesPasswords
154K
C
Medium9d ago

CFGI

CFGI, a financial consulting and advisory firm, had data on approximately 248,000 individuals exposed after the ShinyHunters group conducted an extortion campaign and subsequently published corporate contact information.

Email addressesEmployersJob titles+3 more
248K
I
Medium12d ago

Infinite Campus

Infinite Campus, a student information system, had data on approximately 137,000 accounts stolen and published by the ShinyHunters group in March 2026 following an extortion campaign.

Email addressesEmployersJob titles+5 more
137K
B
Medium12d ago

Berkadia

Berkadia, a commercial real estate finance company, had data from its Salesforce instance published by the ShinyHunters group in March 2026, exposing over 300,000 individuals' contact and employer information.

Email addressesEmployersNames+2 more
305K
B
Medium20d ago

Baker Distributing Company

Baker Distributing Company had data on approximately 103,000 accounts exposed after the ShinyHunters extortion group published information allegedly taken from the company's SharePoint and Salesforce systems in May 2026.

Email addressesNamesPhone numbers+2 more
103K
B
Medium22d ago

BCD Travel

BCD Travel, a corporate travel management company, had data on approximately 396,000 individuals exposed after ShinyHunters claimed the company as a victim of an extortion campaign and published the data publicly in early June 2026.

Email addressesNamesPhone numbers+4 more
396K
D
Critical23d ago

DentaQuest

DentaQuest, a dental benefits administrator, had data on approximately 2.6 million individuals publicly leaked by the ShinyHunters group following an extortion campaign in May 2026.

Dates of birthEmail addressesGenders+5 more
2.6M
E
High26d ago

Edmunds

Edmunds, the automotive research and car-shopping platform, had data on approximately 178,000 accounts exposed after the ShinyHunters hacking group claimed a breach in January 2026.

Email addressesUsernamesPasswords+3 more
178K
A
Medium27d ago

Atlas Menu

Atlas Menu, a GTA V and CS2 cheat service, had its database published to a public GitHub repository in May 2026, exposing data for approximately 64,000 accounts.

Email addressesIP addressesPasswords (hashed)+2 more
64K
C
High29d ago

Charter Communications

Charter Communications had data on approximately 4.9 million accounts exposed after the ShinyHunters group threatened extortion and subsequently published the stolen data.

Email addressesNamesPhone numbers+2 more
4.9M
K
High1mo ago

Kemper Corporation

Kemper Corporation had data on approximately 269,000 individuals exposed after the ShinyHunters ransomware group accessed its Salesforce environment via social engineering and published the stolen data in an extortion campaign.

Email addressesNamesPhone numbers+3 more
269K
M
High1mo ago

Mytheresa

Mytheresa, a luxury fashion e-commerce platform, had data on approximately 84,000 customers exposed after the ShinyHunters extortion group published it following a failed ransom demand in April 2026.

Email addressesNamesPhone numbers+3 more
84K
A
High1mo ago

Ameriprise Financial

Ameriprise Financial had data from approximately 500,000 accounts exposed after the ShinyHunters group exfiltrated over 200GB from its Salesforce and SharePoint systems and published it following failed extortion negotiations.

Email addressesEmployersFinancial transactions+4 more
503K
A
Critical1mo ago

Addi

Colombian fintech company Addi suffered a breach in March 2026 affecting over 34 million accounts, exposing financial, identity, and credit-related personal data after the ShinyHunters group claimed responsibility and published the stolen data.

Email addressesNamesPhone numbers+7 more
34.5M
7
Medium1mo ago

7-Eleven

7-Eleven suffered a data breach in April 2026 when the ShinyHunters group conducted an extortion campaign and later published data on approximately 185,000 individuals.

Dates of birthEmail addressesNames+2 more
185K
W
Medium1mo ago

Windows93 / Myspace93

In January 2021, the Windows93 parody site's Myspace93 sub-site was breached via an exploited beta application, exposing data from approximately 46,000 accounts.

Email addressesIP addressesPasswords+1 more
46K
D
Medium1mo ago

Dragonica Lunaris

Dragonica Lunaris, a European private game server, suffered a data breach in December 2025 that exposed account data for approximately 126,000 users.

Email addressesUsernamesDates of birth+3 more
126K
C
Medium1mo ago

CTT – Correios de Portugal

In April 2026, data allegedly taken from CTT, Portugal's national postal service, was posted to a public hacking forum, affecting approximately 468,000 accounts.

Email addressesNamesPhone numbers
468K
A
Medium1mo ago

Abrigo

Abrigo, a fintech software company, had data from its Salesforce instance published by the ShinyHunters group in April 2026, exposing business contact information for over 711,000 individuals.

Email addressesEmployersJob titles+3 more
711K
C
Medium1mo ago

Canada Life

Canada Life suffered a data breach in April 2026 when the ShinyHunters group stole and published data on over 237,000 customers, including names, email addresses, phone numbers, physical addresses, and support tickets.

Email addressesNamesPhone numbers+4 more
238K
C
Medium1mo ago

Cushman & Wakefield

In May 2026, real estate services firm Cushman & Wakefield had data on approximately 310,000 accounts exposed after the ShinyHunters group carried out an extortion campaign and published stolen corporate contact records.

Email addressesJob titlesNames+3 more
310K
Z
Medium1mo ago

Zara

In April 2026, Zara was targeted by the ShinyHunters extortion group, exposing approximately 197,000 unique email addresses along with purchase and support ticket data linked to a compromise of the Anodot analytics platform.

Email addressesGeographic locationsPurchases+1 more
197K
W
Medium1mo ago

Woflow

Woflow, an AI-driven merchant data platform, had data on approximately 447,593 accounts exposed after the ShinyHunters extortion group published files allegedly stolen from the company in March 2026.

Email addressesNamesPhone numbers+1 more
448K
I
Critical1mo ago

Instructure (Canvas)

TechCrunch reported that hackers stole student data during a breach at education technology company Instructure, which is widely known for its Canvas platform.

student data
L
Medium1mo ago

LegionProxy

LegionProxy, a commercial residential and ISP proxy network, suffered a data breach in April 2026 that exposed approximately 10,000 accounts including email addresses, names, bcrypt password hashes, and purchase records.

Email addressesNamesPasswords (hashed)+1 more
10K
V
Medium1mo ago

Vimeo

In April 2026, the ShinyHunters extortion group published data from a third-party analytics vendor breach affecting approximately 119,000 Vimeo user email addresses and names.

Email addressesNames
119K