700Credit Automotive
5.8M consumer records stolen via API compromise
Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.
5.8M consumer records stolen via API compromise
100+ orgs hit via zero-day CVE-2026-35273
Employee PII stolen via SharePoint zero-day
24B stolen credentials exposed online
62.2M records exposed in ransomware attack
Archived senior care records breached via third-party storage
Employee SSNs, banking, tax data stolen
Patient PHI and billing credentials stolen via contractor
Intel-sharing platform breached during live World Cup ops
300K traveler passports and IBANs exposed
24B stolen credentials exposed in public database
24B stolen credentials exposed from 36 sources
70GB data stolen from Canadian regional airline
SSNs, biometrics and medical records confirmed stolen
Government systems hit by INC_RANSOM ransomware
73K government accounts and 643K messages stolen
HSIN security planning network breached
108GB policyholder and financial records exfiltrated
1.8M records stolen including biometrics
Regulatory filings and credentials stolen by ShinyHunters
62.2M SSNs and health records exposed
2M business records exfiltrated by ShinyHunters
73K government accounts and 643K messages stolen
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [.