Slack (Salesforce)
2.1M workspace messages and uploaded files exfiltrated from compromised enterprise workspace
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
2.1M workspace messages and uploaded files exfiltrated from compromised enterprise workspace
340K patient records compromised
280K customer and pipeline records exposed
420K immigration applicant records accessed via compromised case management portal
210K luxury retail customer records exposed
340K transaction records compromised
Employee and partner data exposed in warehouse management system breach
450K employee and operations records compromised
780K customer records compromised in supply chain attack
3.1M Medicaid and Medicare patient records exfiltrated via compromised claims portal
International law enforcement operation led by Europol targets network of teenagers and young adults involved in ransomware attacks, extortion and other crimes
560K insurance policyholder records compromised via ransomware attack on claims system
920K customer records and server configurations exposed via compromised management portal
6,077,025 records exposed — Bank account numbers, Customer service comments, Dates of birth, Driver's licenses and 7 more
Legal transcription vendor breach — sensitive court proceedings compromised via subcontractor
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability — Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authenti
2.4M drivers license records exposed via compromised address verification contractor
1.1M customer loyalty records exposed in platform breach
Cisco SD-WAN Path Traversal Vulnerability — Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands w
2.2M customer records exposed via compromised residential internet provisioning system
Soliton Systems K.K FileZen OS Command Injection Vulnerability — Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP
430K defense contractor employee records and clearance data compromised via vendor
Advantest, a Japanese specialist in testing computer chips for major semiconductor manufacturers, has deployed incident response protocols following a cybersecurity incident
University of Mississippi Medical Center is still scrambling to respond to a ransomware attack last Thursday