Incident tracker
Recent cyber attacks and data breaches
| Disclosed | Company | What happened | Type | Records | Source |
|---|---|---|---|---|---|
| 2026-06-18 | Ralph Lauren | Ralph Lauren: a data breach In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups. | Data breach | 139,903 | Have I Been Pwned ↗ |
| 2026-06-18 | Operation Endgame 4.0 | Operation Endgame 4.0: data obtained by malware On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords. The following week, a further 4M email addresses and 9M passwords relating to the StealC malware operation also targeted by Operation Endgame were provided, followed by another 131k email addresses the following month, bringing the total to more than 4.3M unique email addresses. | Data breach | 4,348,526 | Have I Been Pwned ↗ |
| 2026-06-18 | CFGI | CFGI: a data breach In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign . The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k unique email addresses, names, phone numbers and physical addresses. | Data breach | 248,235 | Have I Been Pwned ↗ |
| 2026-06-18 | Richard D. Jones, A Professional Law Corporation | Richard D. Jones, A Professional Law Corporation: a data breach Richard D. Jones, A Professional Law Corporation notified the California Attorney General of a data breach on June 18, 2026, with the breach dated August 22, 2024. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-06-17 | Alcott HR | Alcott HR: a data breach Alcott HR notified the California Attorney General of a data breach on June 17, 2026, with the breach dated February 12, 2025. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ |
| 2026-06-17 | AssuranceAmerica Managing General Agency, LLC | AssuranceAmerica Managing General Agency, LLC: a data breach AssuranceAmerica Managing General Agency, LLC notified the Washington State Attorney General on June 17, 2026 of a data breach that occurred on March 16, 2026, affecting 8,950 Washington residents. Information involved: Name, Driver's License or Washington ID Card Number, Other. | Data breach | Not disclosed | Washington State Attorney General ↗ +1 more |
| 2026-06-15 | June 2026 Stealer Logs | June 2026 Stealer Logs: credentials harvested by infostealer malware In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searchable. Individuals can view any records captured against their email address in the stealer logs section of their dashboard . Organisations can see logs affecting their domain via the stealer logs API . | Data breach | 56,278,397 | Have I Been Pwned ↗ |
| 2026-06-15 | Berkadia | Berkadia: a data breach In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as well as names, physical addresses and phone numbers, among other data. | Data breach | 305,216 | Have I Been Pwned ↗ |
| 2026-06-15 | Infinite Campus | Infinite Campus: a data breach In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus subsequently sent notifications , advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites". | Data breach | 137,123 | Have I Been Pwned ↗ |
| 2026-06-15 | Networking Technology, Inc. | Networking Technology, Inc.: a data breach Networking Technology, Inc. notified the California Attorney General of a data breach on June 15, 2026, with the breach dated March 1, 2026. The notice covers more than 500 California residents; California does not publish the exact number. | Data breach | Not disclosed | California Attorney General ↗ +1 more |
About this tracker
- 435
- Incidents
- 287
- Ransomware gang claims
- 722
- Last 30 days
- 389
- Companies tracked
- 2,742,501,669
- Records disclosed