Incident tracker
Recent cyber attacks and data breaches
| Disclosed | Company | What happened | Type | Records | Source |
|---|---|---|---|---|---|
| 2026-03-02 | Lovora | Lovora: a data breach In February 2026, the couples and relationship app Lovora allegedly suffered a data breach that exposed 496k unique email addresses. The data also included users’ display names and profile photos, along with other personal information collected through use of the app. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident. | Data breach | 495,556 | Have I Been Pwned ↗ |
| 2026-03-02 | Quitbro | Quitbro: a data breach In February 2026, the porn addiction app Quitbro allegedly suffered a data breach that exposed 23k unique email addresses. The data also included users’ years of birth, responses to questions within the app and their last recorded relapse time. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident. | Data breach | 22,874 | Have I Been Pwned ↗ |
| 2026-03-02 | KomikoAI | KomikoAI: a data breach In February, the AI-powered comic generation platform KomikoAI suffered a data breach . The incident exposed 1M unique email addresses along with names, user posts and the AI prompts used to generate content. The exposed data enables the mapping of individual AI prompts to specific email addresses. | Data breach | 1,060,191 | Have I Been Pwned ↗ |
| 2026-02-26 | Odido | Odido: a data breach In February 2026, Dutch telco Odido was the victim of a data breach and subsequent extortion attempt . Shortly after, a total of 6M unique email addresses were published across four separate data releases over consecutive days. The exposed data includes names, physical addresses, phone numbers, bank account numbers, dates of birth, customer service notes and passport, driver’s licence and European national ID numbers. Odido has published a disclosure notice including an FAQ to support affected customers. | Data breach | 6,077,025 | Have I Been Pwned ↗ |
| 2026-02-25 | Canadian Tire | Canadian Tire: a data breach In October 2025, retailer Canadian Tire was the victim of a data breach that exposed almost 42M records. The data contained 38M unique email addresses along with names, phone numbers and physical addresses. Passwords were stored as PBKDF2 hashes and for a subset of records, dates of birth and partial credit card data were also included (card type, expiry and masked card number). In its disclosure notice , Canadian Tire advised that the incident did not impact bank account information or loyalty program data. | Data breach | 38,306,562 | Have I Been Pwned ↗ |
| 2026-02-22 | CarGurus | CarGurus: a data breach In February 2026, the automotive marketplace CarGurus was the target of a data breach attributed to the threat actor ShinyHunters . Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, finance pre-qualification application data and dealer account and subscription information. Impacted data also included names, phone numbers, physical and IP addresses, and auto finance application outcomes. | Data breach | 12,461,887 | Have I Been Pwned ↗ |
| 2026-02-20 | CarMax | CarMax: a data breach In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt . The data included 431k unique email addresses along with names, phone numbers and physical addresses. | Data breach | 431,371 | Have I Been Pwned ↗ |
| 2026-02-18 | Figure | Figure: a data breach In February 2026, data obtained from the fintech lending platform Figure was publicly posted online . The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access. | Data breach | 967,178 | Have I Been Pwned ↗ |
| 2026-02-17 | Canada Goose | Canada Goose: a data breach In February 2026, a data breach allegedly containing data relating to Canada Goose customers was published publicly . The data contained 920k records with 582k unique email addresses and included names, phone numbers, IP addresses, physical addresses and partial credit card data, specifically card type and last 4 digits. Canada Goose advised that the data "appears to relate to past customer transactions" and stated that it originated from a breach at a third party in August 2025. The most recent transaction date in the data is July 2025. | Data breach | 581,877 | Have I Been Pwned ↗ |
| 2026-02-16 | University of Pennsylvania | University of Pennsylvania: a data breach In October 2025, the University of Pennsylvania was the victim of a data breach followed by a ransom demand , largely affecting its donor database. After the incident, the attackers sent inflammatory emails to some victims. The data was later published online in February 2026 and included 624k unique email addresses alongside names and physical addresses. For some donor records, additional personal information was exposed, including gender and date of birth. A small subset of records also contained religion, spouse name, estimated income and donation history. | Data breach | 623,750 | Have I Been Pwned ↗ |
About this tracker
- 435
- Incidents
- 295
- Ransomware gang claims
- 730
- Last 30 days
- 395
- Companies tracked
- 2,742,501,669
- Records disclosed