Instructure Canvas
ShinyHunters breach exposed 275 million records from 8,809 schools
The year's largest confirmed data breaches, ranked by records exposed. This list updates itself automatically as new disclosures go public.
ShinyHunters breach exposed 275 million records from 8,809 schools
62.2 million healthcare records exposed, third-largest US healthcare breach ever
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwn
A spokesperson told The Yorkshire Post that roughly 8.7 million people were impacted, although they did not provide a date range. They added that in the “vast majority” of cases, the only information accessed was an emai
Hackers stole personal, medical, and health insurance information of 3.8 million people
3.7 million patients' medical records stolen in cyberattack, one of largest healthcare breaches in US this year
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned. [...]
1.26 million patients exposed in PEAR ransomware attack on medical billing company
A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal lo
865,000 users' personal records exposed in data breach of Russian VPN provider
Tax authority breach exposed records of 678,000 people and businesses with tax, business and property information
311,000 people's personal, medical, and financial information stolen by hackers
Olivier Acuna reports: Cryptocurrency broker Bits of Gold said personal data belonging to roughly 200,000 customers was stolen by hackers, the company reported. The Tel Aviv, Israel-based company reported the security br
135,000 contact records stolen and leaked on dark web by ExfilSquad
WSFB reports: State officials say a data breach involving the Connecticut Medicaid program’s provider portal exposed payment and claims information tied to roughly 41,000 HUSKY Health members. The Connecticut Department
Ransomware breach exposed data of 21,537 individuals
Cybersecurity incident around January 11, 2026 affecting 13,300 individuals. Submitted to the HHS Office for Civil Rights Breach Portal on January 26, 2026. Third-party threat reports attributed the event to a ransomware claim. The practice is investigating and has not confirmed access or misuse of patient data.
Unauthorized access detected January 19, 2026. Ransomware encrypted files on a legacy server containing a backup of electronic medical records. Patient data exposed: names, contact information, birth dates, treatment notes, clinical histories. SSNs exposed for a limited number of individuals.
Nitrogen ransomware group claimed responsibility on the dark web in February. Data compromised includes passports, driver's licenses, and information from medical records.
Most of the incidents above began with credentials and infrastructure that were exposed long before the breach. Run a free exposure assessment to see what an attacker can already find on your organization.
Check your exposure free →