Shopify (Merchant Data)
860K merchant store records including revenue data exposed via compromised support tool
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
860K merchant store records including revenue data exposed via compromised support tool
Vite Vitejs Improper Access Control Vulnerability — Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposi
Cisco Unified Communications Products Code Injection Vulnerability — Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Comm
1.6M customer records from US and UK operations exposed via MOVEit successor vulnerability
72,742,892 records exposed — Dates of birth, Email addresses, Genders, Geographic locations and 2 more
2.3M patient records stolen from Australian private hospital operator
1.5M shipping manifests and customs records exposed via compromised logistics API
Business intelligence platform breached — ShinyHunters claimed responsibility
680K household survey response records exposed via misconfigured data sharing portal
8.7M customer records exposed via compromised customer portal at largest Korean telco
2.3M package tracking records and sender data exposed via compromised Informed Delivery API
680K wealth management client records exposed via misconfigured cloud storage bucket
10,225,145 records exposed — Ages, Dates of birth, Email addresses, Genders and 3 more
180K employee records from automotive parts manufacturer exposed via phishing attack
6,366,133 records exposed — Email addresses, Genders, Names, Phone numbers and 1 more
3.4M CRM records from multiple tenants exposed via privilege escalation in Data Cloud module
1.2M customer records from government IT contracts exposed via compromised ProjectWEB portal
1.3M guest reservation records including passport and payment data compromised
1.1M tokenized card records exposed via vulnerability in token provisioning service
2.8M customer records stolen via API vulnerability in self-service portal
150K enterprise zero-trust configurations exposed — test environment breach spread to prod
10M+ dating records stolen by ShinyHunters via Okta SSO social engineering
1.1M auto loan records exposed via compromised dealer management system integration
620K Circle K loyalty customer records stolen from Canadian convenience store operator