T-Mobile
37M customer records stolen — names, billing addresses, emails, phone numbers, dates of birth
SaaS platforms, cloud providers, developer tooling, and app-layer infrastructure are concentrated attack surfaces. One tech vendor breach can expose thousands of downstream customers. Below is every tech-sector breach LeakTrace has indexed.
37M customer records stolen — names, billing addresses, emails, phone numbers, dates of birth
7.5TB of source code and creator payout data re-leaked on torrent sites from 2021 breach
6,450 customer password manager vaults potentially accessed
133 customer accounts compromised in social engineering
133 customer accounts accessed via social engineering — third breach in 12 months
290,000 customer records stolen — national IDs, IMEI numbers, contact info
211,524,284 records exposed — Email addresses, Names, Social media profiles, Usernames
200M+ email addresses and profile data compiled from API vulnerability
All customer secrets and tokens potentially compromised in platform breach
Engineer laptop malware led to customer secret theft — all secrets needed rotation
200M email-to-username mappings leaked on dark web
Employee tokens stolen, private code repositories accessed
Encrypted password vaults and customer metadata stolen via compromised developer account
15,000 email accounts compromised — business customer data accessed
925K customer password manager vaults potentially compromised
6,450 customer password vaults potentially accessed via credential-stuffing campaign
919,790 records exposed — Email addresses, IP addresses, Passwords, Usernames
2.4M smart home camera user records exposed
Hosted Exchange environment taken down by Play ransomware
Play ransomware encrypted Exchange email servers — customer hosted email disrupted
Multi-year breach — source code stolen, malware installed on hosting servers
Encrypted backups stolen, including Hamachi, Central, Pro settings
14,500 patient records leaked from major NZ IT services provider — Rhysida ransomware
Security cameras streamed to wrong users, stored unencrypted