Live disclosure tracker · updated continuously

2026 Data Breaches Year-to-Date

2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.

98B+
Records Exposed
653
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026

2026 Data Breaches Year-to-Date (653 indexed)

high · tech · Apr 20, 2026

Kentico Kentico Xperience

Kentico Xperience Path Traversal Vulnerability — Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

critical · healthcare · Apr 19, 2026

Qilin’s 2024 attack on NHS

Long-term follow-ups are important, and DataBreaches is glad that Alexander Martin points out that at least one NHS Trust is still impacted by the Qilin ransomware attack on Synnovis in 2024. From his reporting: At South

View incident → Original disclosure Indexed 2 weeks, 1 day ago
medium · tech · Apr 19, 2026

Vercel

Cloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems and are attempting to sell stolen data. [...]

View incident → Original disclosure Indexed 2 weeks, 1 day ago
critical · other · Apr 17, 2026

Operation PowerOFF

Operation PowerOFF shut down 53 DDoS-for-hire domains, arrested four suspects, and exposed data on over 3 million criminal user accounts. Operation PowerOFF is an international law enforcement action that dismantled 53 d

View incident → Original disclosure Indexed 2 weeks, 3 days ago
medium · government · Apr 17, 2026

Oklahoma State Tax Commission Fails

DataBreaches missed this one, but The Daily Hodl didn’t. They reported on March 31: A US state tax agency has placed taxpayers’ personal info at risk by missing an extended data breach that lasted 18 months. The Ok

View incident → Original disclosure Indexed 2 weeks, 3 days ago
high · education · Apr 17, 2026

Teen arrested in Northern Ireland

Alexander Martin reports: A 16-year-old boy has been arrested in Northern Ireland after a cyberattack disrupted access to educational systems used by potentially hundreds of thousands of students. The boy, who has not be

View incident → Original disclosure Indexed 2 weeks, 3 days ago
medium · healthcare · Apr 17, 2026

Flawed Cisco update threatens to

Cisco admins are scrambling to patch a critical flash memory overflow vulnerability in over 200 Cisco Systems IOS XE-based models of wireless access points (APs), caused by a recent flawed software update. If the issu

View incident → Original disclosure Indexed 2 weeks, 3 days ago
medium · other · Apr 17, 2026

Recently

Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. [...]

View incident → Original disclosure Indexed 2 weeks, 3 days ago
high · tech · Apr 16, 2026

Apache ActiveMQ

Apache ActiveMQ Improper Input Validation Vulnerability — Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

View incident → Original disclosure Indexed 2 weeks, 4 days ago
medium · other · Apr 16, 2026

Sweden

Sweden says a pro-Russian group attacked a heating plant in 2025. The failed cyberattack highlights growing threats to Europe’s energy infrastructure. Sweden has blamed a pro-Russian group linked to Russian intelligence

View incident → Original disclosure Indexed 2 weeks, 4 days ago