Skip to content
Live · Updated every 6 hours
Track every US data breachBreached
All breaches
Exposed data archive

Phone numbers data breaches

Public breach reports where phone numbers were listed among exposed data types.

Breaches
40
Critical
8
Known affected
166,503,701
Latest report
7/28/2026

Tracked reports

table filter
H
High14d ago

Houston City College

Houston City College suffered a data breach in June 2026 when ShinyHunters extorted the college and later published data on approximately 832,000 current students and alumni.

Academic recordsCitizenship statusesDates of birth+5 more
832K
S
High21d ago

Suno, Inc.

A November 2025 Suno security incident was followed by reports of a dataset containing more than 55 million unique email addresses and a smaller set of purchase records.

Email addressesPhone numbersNames+3 more
55.3M
G
High27d ago

Goose Creek Candle Company

Goose Creek Candle Company suffered a data breach in June 2026 that exposed the personal and purchase information of approximately 6.6 million customers.

Email addressesNamesPhone numbers+2 more
6.6M
G
Critical1mo ago

Glendale Community College

Glendale Community College suffered a data breach in June 2026 affecting nearly 794,000 individuals, exposing names, email addresses, Social Security numbers, and student enrollment records.

Academic recordsDates of birthEmail addresses+6 more
794K
M
High1mo ago

Moody Bible Institute

Moody Bible Institute suffered a data breach in June 2026 in which over 2.3 million accounts had personal information including names, addresses, phone numbers, and dates of birth publicly exposed following a ShinyHunters extortion campaign.

Dates of birthEmail addressesGenders+4 more
2.3M
S
High1mo ago

Sysco

Sysco, a food distribution company, had data on approximately 2.7 million staff and customers exposed after a ShinyHunters extortion campaign resulted in the publication of corporate contact information.

Email addressesNamesPhone numbers+5 more
2.7M
A
Medium1mo ago

American Tower

American Tower had data on over 216,000 employees, contractors, customers, and leads exposed after a ShinyHunters extortion campaign in June 2026.

Email addressesNamesPhone numbers+2 more
217K
M
High1mo ago

Madison Square Garden Sports

Madison Square Garden Sports had data on nearly 10 million accounts exposed after the ShinyHunters group carried out a pay-or-leak extortion campaign and published the stolen data online.

NamesEmail addressesPhone numbers+2 more
9.8M
J
Critical1mo ago

JCPenney

JCPenney suffered a data breach in June 2026 when ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, exposing personal and HR data for approximately 368,000 current and former employees.

Dates of birthEmail addressesGovernment issued IDs+6 more
368K
R
Medium1mo ago

Ralph Lauren

Ralph Lauren had data on approximately 140,000 individuals exposed after the ShinyHunters group claimed to have extracted records from the company's Salesforce instance and published them as part of an extortion campaign.

Email addressesNamesPhone numbers+2 more
140K
C
Medium1mo ago

CFGI

CFGI, a financial consulting and advisory firm, had data on approximately 248,000 individuals exposed after the ShinyHunters group conducted an extortion campaign and subsequently published corporate contact information.

Email addressesEmployersJob titles+3 more
248K
I
Medium1mo ago

Infinite Campus

Infinite Campus, a student information system, had data on approximately 137,000 accounts stolen and published by the ShinyHunters group in March 2026 following an extortion campaign.

Email addressesEmployersJob titles+5 more
137K
B
Medium1mo ago

Berkadia

Berkadia, a commercial real estate finance company, had data from its Salesforce instance published by the ShinyHunters group in March 2026, exposing over 300,000 individuals' contact and employer information.

Email addressesEmployersNames+2 more
305K
B
Medium2mo ago

Baker Distributing Company

Baker Distributing Company had data on approximately 103,000 accounts exposed after the ShinyHunters extortion group published information allegedly taken from the company's SharePoint and Salesforce systems in May 2026.

Email addressesNamesPhone numbers+2 more
103K
B
Medium2mo ago

BCD Travel

BCD Travel, a corporate travel management company, had data on approximately 396,000 individuals exposed after ShinyHunters claimed the company as a victim of an extortion campaign and published the data publicly in early June 2026.

Email addressesNamesPhone numbers+4 more
396K
D
Critical2mo ago

DentaQuest

DentaQuest, a dental benefits administrator, had data on approximately 2.6 million individuals publicly leaked by the ShinyHunters group following an extortion campaign in May 2026.

Dates of birthEmail addressesGenders+5 more
2.6M
E
High2mo ago

Edmunds

Edmunds, the automotive research and car-shopping platform, had data on approximately 178,000 accounts exposed after the ShinyHunters hacking group claimed a breach in January 2026.

Email addressesUsernamesPasswords+3 more
178K
C
High2mo ago

Charter Communications

Charter Communications had data on approximately 4.9 million accounts exposed after the ShinyHunters group threatened extortion and subsequently published the stolen data.

Email addressesNamesPhone numbers+2 more
4.9M
K
High2mo ago

Kemper Corporation

Kemper Corporation had data on approximately 269,000 individuals exposed after the ShinyHunters ransomware group accessed its Salesforce environment via social engineering and published the stolen data in an extortion campaign.

Email addressesNamesPhone numbers+3 more
269K
M
High2mo ago

Mytheresa

Mytheresa, a luxury fashion e-commerce platform, had data on approximately 84,000 customers exposed after the ShinyHunters extortion group published it following a failed ransom demand in April 2026.

Email addressesNamesPhone numbers+3 more
84K
A
High2mo ago

Ameriprise Financial

Ameriprise Financial had data from approximately 500,000 accounts exposed after the ShinyHunters group exfiltrated over 200GB from its Salesforce and SharePoint systems and published it following failed extortion negotiations.

Email addressesEmployersFinancial transactions+4 more
503K
A
Critical2mo ago

Addi

Colombian fintech company Addi suffered a breach in March 2026 affecting over 34 million accounts, exposing financial, identity, and credit-related personal data after the ShinyHunters group claimed responsibility and published the stolen data.

Email addressesNamesPhone numbers+7 more
34.5M
7
Medium2mo ago

7-Eleven

7-Eleven suffered a data breach in April 2026 when the ShinyHunters group conducted an extortion campaign and later published data on approximately 185,000 individuals.

Dates of birthEmail addressesNames+2 more
185K
C
Medium2mo ago

CTT – Correios de Portugal

In April 2026, data allegedly taken from CTT, Portugal's national postal service, was posted to a public hacking forum, affecting approximately 468,000 accounts.

Email addressesNamesPhone numbers
468K
A
Medium2mo ago

Abrigo

Abrigo, a fintech software company, had data from its Salesforce instance published by the ShinyHunters group in April 2026, exposing business contact information for over 711,000 individuals.

Email addressesEmployersJob titles+3 more
711K
C
Medium3mo ago

Canada Life

Canada Life suffered a data breach in April 2026 when the ShinyHunters group stole and published data on over 237,000 customers, including names, email addresses, phone numbers, physical addresses, and support tickets.

Email addressesNamesPhone numbers+4 more
238K
C
Medium3mo ago

Cushman & Wakefield

In May 2026, real estate services firm Cushman & Wakefield had data on approximately 310,000 accounts exposed after the ShinyHunters group carried out an extortion campaign and published stolen corporate contact records.

Email addressesJob titlesNames+3 more
310K
W
Medium3mo ago

Woflow

Woflow, an AI-driven merchant data platform, had data on approximately 447,593 accounts exposed after the ShinyHunters extortion group published files allegedly stolen from the company in March 2026.

Email addressesNamesPhone numbers+1 more
448K
M
High3mo ago

Marcus & Millichap

Marcus & Millichap, a commercial real estate brokerage, had data on approximately 1.8 million individuals exposed after being named as an alleged victim of the ShinyHunters hacking group in April 2026.

Email addressesNamesPhone numbers+3 more
1.8M
Z
High3mo ago

ZenBusiness

ZenBusiness, a business formation platform, had data on approximately 5.1 million accounts exposed after the hacker group ShinyHunters claimed to have exfiltrated records from multiple platforms and publicly released the data following an unpaid ransom demand.

Email addressesNamesPhone numbers
5.1M
A
High3mo ago

Aman

Aman, an ultra-luxury hotel brand, suffered a data breach in April 2026 when ShinyHunters obtained customer records from their Salesforce CRM and later leaked them publicly.

Dates of birthEmail addressesGenders+7 more
216K
U
Critical3mo ago

Udemy

Udemy suffered a data breach affecting 1.4 million accounts, with customer and instructor information including email addresses, names, addresses, phone numbers, and payment methods exposed.

Email addressesNamesPhysical addresses+4 more
1.4M
S
High3mo ago

SUCCESS

SUCCESS, a personal development media brand, suffered a data breach in March 2026 exposing approximately 253,510 accounts with names, email addresses, phone numbers, and other personal information.

Device informationEmail addressesIP addresses+5 more
254K
P
Critical3mo ago

Pitney Bowes

Pitney Bowes suffered a data breach in April 2026 affecting approximately 8.2 million individuals, with ShinyHunters claiming responsibility and publicly releasing the stolen data.

Email addressesNamesPhone numbers+2 more
8.2M
M
Critical3mo ago

McGraw Hill

McGraw Hill confirmed a data breach in April 2026 affecting 13.5 million accounts, exposing email addresses, names, phone numbers, and physical addresses due to a Salesforce misconfiguration.

Email addressesNamesPhone numbers+1 more
13.5M
H
High3mo ago

Hallmark

Hallmark suffered a breach in March 2026 after attackers accessed data stored in Salesforce, exposing approximately 1.7 million customer records.

Email addressesNamesPhone numbers+2 more
1.7M
B
High3mo ago

Baydöner

Turkish restaurant chain Baydöner suffered a data breach in March 2026 exposing over 1.2 million customer records including names, email addresses, phone numbers, and plaintext passwords.

Dates of birthEmail addressesGenders+6 more
1.3M
A
High3mo ago

Aura

Aura disclosed a data breach in March 2026 affecting over 900,000 customer records, primarily from a marketing tool associated with a previously acquired company.

NamesEmail addressesPhone numbers+3 more
903K
A
Critical3mo ago

ADT

ADT confirmed a data breach affecting 5.5 million customers in April 2026, with ShinyHunters claiming responsibility and threatening to leak the data.

Dates of birthEmail addressesNames+3 more
5.5M
B
High8mo ago

Beckett Collectibles, LLC

A November 2025 breach of Beckett Collectibles reportedly exposed account and contact information associated with approximately one million email addresses.

Email addressesNamesPhone numbers+2 more
1.0M