Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2026-02-22CarGurusCarGurus: a data breach

In February 2026, the automotive marketplace CarGurus was the target of a data breach attributed to the threat actor ShinyHunters . Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, finance pre-qualification application data and dealer account and subscription information. Impacted data also included names, phone numbers, physical and IP addresses, and auto finance application outcomes.

Data breach
12,461,887Have I Been Pwned
2026-02-20CarMaxCarMax: a data breach

In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt . The data included 431k unique email addresses along with names, phone numbers and physical addresses.

Data breach
431,371Have I Been Pwned
2026-02-18FigureFigure: a data breach

In February 2026, data obtained from the fintech lending platform Figure was publicly posted online . The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access.

Data breach
967,178Have I Been Pwned
2026-02-17Canada GooseCanada Goose: a data breach

In February 2026, a data breach allegedly containing data relating to Canada Goose customers was published publicly . The data contained 920k records with 582k unique email addresses and included names, phone numbers, IP addresses, physical addresses and partial credit card data, specifically card type and last 4 digits. Canada Goose advised that the data "appears to relate to past customer transactions" and stated that it originated from a breach at a third party in August 2025. The most recent transaction date in the data is July 2025.

Data breach
581,877Have I Been Pwned
2026-02-16University of PennsylvaniaUniversity of Pennsylvania: a data breach

In October 2025, the University of Pennsylvania was the victim of a data breach followed by a ransom demand , largely affecting its donor database. After the incident, the attackers sent inflammatory emails to some victims. The data was later published online in February 2026 and included 624k unique email addresses alongside names and physical addresses. For some donor records, additional personal information was exposed, including gender and date of birth. A small subset of records also contained religion, spouse name, estimated income and donation history.

Data breach
623,750Have I Been Pwned
2026-02-16APOIA.seAPOIA.se: a data breach

In December 2025, a database of the Brazilian crowdfunding platform APOIA.se was posted to an online forum . In January 2026, the company confirmed it had suffered a data breach. The incident exposed 451k unique email addresses along with names and physical addresses.

Data breach
450,764Have I Been Pwned
2026-02-10Toy BattlesToy Battles: a data breach

In February 2026, the online gaming community Toy Battles suffered a data breach. The incident exposed 1k unique email addresses alongside usernames, IP addresses and chat logs. Following the breach, Toy Battles self-submitted the data to Have I Been Pwned.

Data breach
1,017Have I Been Pwned
2026-02-10Association Nationale des Premiers SecoursAssociation Nationale des Premiers Secours: a data breach

In January 2026, a data breach impacting the French non-profit Association Nationale des Premiers Secours (ANPS) was posted to a hacking forum . The breach exposed 5.6k unique email addresses along with names, dates of birth and places of birth. ANPS self-submitted the data to HIBP and advised the incident was traced back to a legacy system and did not impact health data, financial information or passwords.

Data breach
5,600Have I Been Pwned
2026-02-06SubstackSubstack: a data breach

In October 2025, the publishing platform Substack suffered a data breach that was subsequently circulated more widely in February 2026. The breach exposed 663k account holder records containing email addresses along with publicly visible profile information from Substack accounts, such as publication names and bios. A subset of records also included phone numbers.

Data breach
663,121Have I Been Pwned
2026-02-05BettermentBetterment: a data breach

In January 2026, the automated investment platform Betterment confirmed it had suffered a data breach attributed to a social engineering attack . As part of the incident, Betterment customers received fraudulent crypto-related messages promising high returns if funds were sent to an attacker-controlled cryptocurrency wallet. The breach exposed 1.4M unique email addresses, along with names and geographic location data. A subset of records also included dates of birth, phone numbers, and physical addresses. In its disclosure notice , Betterment stated that the incident did not provide attackers with access to customer accounts and did not expose passwords or other login credentials.

Data breach
1,435,174Have I Been Pwned

About this tracker

435
Incidents
295
Ransomware gang claims
730
Last 30 days
395
Companies tracked
2,742,501,669
Records disclosed