Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-05-20VacPartsWarehouse.com LLC (PartsWarehouse.com)VacPartsWarehouse.com LLC (PartsWarehouse.com): a data breach

VacPartsWarehouse.com LLC (PartsWarehouse.com) notified the Washington State Attorney General on May 20, 2026 of a data breach that occurred on October 31, 2025, affecting 695 Washington residents. Information involved: Name, Financial & Banking Information.

Data breach
Not disclosedWashington State Attorney General
2026-05-20Cardinal Services, Inc, Cardinal Employer Organization, andCardinal Services, Inc, Cardinal Employer Organization, and: a data breach

Cardinal Services, Inc, Cardinal Employer Organization, and notified the Washington State Attorney General on May 20, 2026 of a data breach that occurred on June 30, 2025, affecting 2,066 Washington residents. Information involved: Name, Social Security Number, Driver's License or Washington ID Card Number, Financial & Banking Information, Full Date of Birth, Passport Number, Medical Information.

Data breach
Not disclosedWashington State Attorney General
2026-05-20WEST PHARMACEUTICAL SERVICES INCWST

Surgical & Medical Instruments & Apparatus

WEST PHARMACEUTICAL SERVICES INC disclosed a material cybersecurity incident
Regulatory filing
Not disclosedSEC EDGAR
2026-05-19CTTCTT: a data breach

In April 2026, data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum . The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history of the parcel.

Data breach
468,124Have I Been Pwned
2026-05-18AddiAddi: a data breach

In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a large trove of personal data allegedly obtained from Addi. The data included 34M unique email addresses from credit scoring requests, credit bureau records, customer identity records and email validation logs. It also contained government issued IDs (Cédula de Ciudadanía), estimated income, socioeconomic levels, purchases and other credit-related data points.

Data breach
34,532,941Have I Been Pwned
2026-05-14AbrigoAbrigo: a data breach

In April 2026, the fintech software company Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group . Shortly after, data allegedly taken from the company's Salesforce instance was published publicly and contained over 700k unique email addresses belonging to both Abrigo staff and external contacts. Whilst separate from Abrigo's Salesforce compromise via the Drift application connector the previous year , the data fields described in that incident are consistent with the ShinyHunters data, namely that it was "business contact information" including "institution name, employee name, email addresses, and phone numbers".

Data breach
711,099Have I Been Pwned
2026-05-13Canada LifeCanada Life: a data breach

In April 2026, Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group . The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer support tickets. In their disclosure notice , Canada Life advised that "it is a small proportion of our customers who may have been impacted". In the wake of the incident, Canada Life also published an alert cautioning customers to be wary of phishing attacks , a pattern often seen after the public release of breached data.

Data breach
237,810Have I Been Pwned
2026-05-12Cushman & WakefieldCushman & Wakefield: a data breach

In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group . Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.

Data breach
310,431Have I Been Pwned

+1 more

2026-05-08ZaraZara: a data breach

In April 2026, the fashion brand Zara was among a number of organisations targeted by the ShinyHunters extortion group as part of their "pay or leak" campaign. The group claimed the breach was related to a compromise of the Anodot analytics platform and subsequently published a terabyte of data allegedly including 95M support ticket records. The data contained 197k unique email addresses alongside product SKUs, order IDs and the market the support ticket originated in. Zara's parent company Inditex advised that the incident didn't affect passwords or payment information .

Data breach
197,376Have I Been Pwned
2026-05-07WoflowWoflow: a data breach

In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group . The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of email addresses, names, phone numbers and physical addresses, with the data indicating it related to Woflow customers and, in turn, the customers of merchants using their platform.

Data breach
447,593Have I Been Pwned

About this tracker

435
Incidents
296
Ransomware gang claims
731
Last 30 days
401
Companies tracked
2,742,501,669
Records disclosed