Houston City College
Houston City College suffered a data breach in June 2026 when ShinyHunters extorted the college and later published data on approximately 832,000 current students and alumni.
Houston City College suffered a data breach in June 2026 when ShinyHunters extorted the college and later published data on approximately 832,000 current students and alumni.
Hackers obtained and publicly released data from gig economy platform Paidwork in March 2026, exposing over 23 million accounts including banking information, passwords, and broad personal profile data.
A November 2025 Suno security incident was followed by reports of a dataset containing more than 55 million unique email addresses and a smaller set of purchase records.
Fluke Corporation had data on over 821,000 accounts exposed after the ShinyHunters group published more than 100GB of allegedly stolen data in July 2026.
Goose Creek Candle Company suffered a data breach in June 2026 that exposed the personal and purchase information of approximately 6.6 million customers.
Glendale Community College suffered a data breach in June 2026 affecting nearly 794,000 individuals, exposing names, email addresses, Social Security numbers, and student enrollment records.
Moody Bible Institute suffered a data breach in June 2026 in which over 2.3 million accounts had personal information including names, addresses, phone numbers, and dates of birth publicly exposed following a ShinyHunters extortion campaign.
Sysco, a food distribution company, had data on approximately 2.7 million staff and customers exposed after a ShinyHunters extortion campaign resulted in the publication of corporate contact information.
American Tower had data on over 216,000 employees, contractors, customers, and leads exposed after a ShinyHunters extortion campaign in June 2026.
Mercor reported that compromised LiteLLM versions enabled unauthorized access to some Mercor systems between March 24 and March 30, 2026.
Madison Square Garden Sports had data on nearly 10 million accounts exposed after the ShinyHunters group carried out a pay-or-leak extortion campaign and published the stolen data online.
JCPenney suffered a data breach in June 2026 when ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, exposing personal and HR data for approximately 368,000 current and former employees.
Ralph Lauren had data on approximately 140,000 individuals exposed after the ShinyHunters group claimed to have extracted records from the company's Salesforce instance and published them as part of an extortion campaign.
International law enforcement, coordinated through Europol and Eurojust, disrupted the SocGholish malware network on 18 June 2026, providing HIBP with approximately 154,000 affected email addresses and over 500,000 previously unseen passwords.
CFGI, a financial consulting and advisory firm, had data on approximately 248,000 individuals exposed after the ShinyHunters group conducted an extortion campaign and subsequently published corporate contact information.
One Medical reported unauthorized access to a third-party file storage system used for archived Iora Health information.
Infinite Campus, a student information system, had data on approximately 137,000 accounts stolen and published by the ShinyHunters group in March 2026 following an extortion campaign.
Berkadia, a commercial real estate finance company, had data from its Salesforce instance published by the ShinyHunters group in March 2026, exposing over 300,000 individuals' contact and employer information.
Baker Distributing Company had data on approximately 103,000 accounts exposed after the ShinyHunters extortion group published information allegedly taken from the company's SharePoint and Salesforce systems in May 2026.
BCD Travel, a corporate travel management company, had data on approximately 396,000 individuals exposed after ShinyHunters claimed the company as a victim of an extortion campaign and published the data publicly in early June 2026.
DentaQuest, a dental benefits administrator, had data on approximately 2.6 million individuals publicly leaked by the ShinyHunters group following an extortion campaign in May 2026.
Edmunds, the automotive research and car-shopping platform, had data on approximately 178,000 accounts exposed after the ShinyHunters hacking group claimed a breach in January 2026.
Atlas Menu, a GTA V and CS2 cheat service, had its database published to a public GitHub repository in May 2026, exposing data for approximately 64,000 accounts.
Charter Communications had data on approximately 4.9 million accounts exposed after the ShinyHunters group threatened extortion and subsequently published the stolen data.
Kemper Corporation had data on approximately 269,000 individuals exposed after the ShinyHunters ransomware group accessed its Salesforce environment via social engineering and published the stolen data in an extortion campaign.
Mytheresa, a luxury fashion e-commerce platform, had data on approximately 84,000 customers exposed after the ShinyHunters extortion group published it following a failed ransom demand in April 2026.
Ameriprise Financial had data from approximately 500,000 accounts exposed after the ShinyHunters group exfiltrated over 200GB from its Salesforce and SharePoint systems and published it following failed extortion negotiations.
Colombian fintech company Addi suffered a breach in March 2026 affecting over 34 million accounts, exposing financial, identity, and credit-related personal data after the ShinyHunters group claimed responsibility and published the stolen data.
7-Eleven suffered a data breach in April 2026 when the ShinyHunters group conducted an extortion campaign and later published data on approximately 185,000 individuals.
In January 2021, the Windows93 parody site's Myspace93 sub-site was breached via an exploited beta application, exposing data from approximately 46,000 accounts.