Credential Dump Elasticsearch
24B stolen credential records exposed publicly
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
24B stolen credential records exposed publicly
Employee insider threat unlawfully accessed customer data over 2+ years, resulting in €31.8m fine
Thousands of civil servants passwords exposed since early 2024 including White House linked credentials
Thousands of civil servants' passwords exposed since early 2024, including White House-linked credentials
Data breach exposed 62.2 million records, third-largest US healthcare hack
Thousands of civil servants' passwords compromised since early 2024, including White House-linked credentials
1.27 million records exposed via 2024 API vulnerability; financial and identity data compromised
Thousands of NHS patient records stolen during major ransomware attack
API vulnerability exposed financial and identity data of 1.27 million records
Tax and court payment systems taken offline by ransomware
Breach exposed hospital patient records for 13K patients in New Jersey
Data incident exposed voter information in Sangamon County; no election system impact reported
Thousands of civil servants' passwords exposed including White House-linked credentials since early 2024
Data breach exposed employee-related records in insurance company incident
Data breach exposed SSNs and medical records of patients
30M patient records, 1M SSNs stolen by ShinyHunters
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that
Personnel and recruitment data stolen by CRPx0
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability — JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent poll
276,114 records exposed — Email addresses, Employers, Job titles, Names and 2 more
55GB PII and financial records of 28K customers
330K patient records compromised in ransomware