Security incidents
Incidents at named organisations, each linked to the source that reported it: material incident filings companies made to the SEC, breaches verified by Have I Been Pwned, and claims posted by ransomware groups.
- 142
- Confirmed incidents
- 112
- Unconfirmed claims
- 254
- Last 30 days
- 136
- Organisations tracked
- 2,705,731,734
- Records disclosed
This view includes organisations named on ransomware leak sites. Those are the groups’ claims, not confirmed breaches — the organisations have not confirmed them and no filing or verified record supports them.
hbpro.pt named on safepay's leak site
Established in 1994, the company has more than three decades of experience providing technology products, infrastructure, consulting, maintenance, and technical …
gsngestion.es named on safepay's leak site
The company is based in Villaviciosa de Odón, Madrid, and operates through the GSN Gestión brand. Its website states that …
cenmar-manila.com named on safepay's leak site
The company was registered with the Philippine Securities and Exchange Commission in 1997 and received authorization to operate as a …
gayafores.es named on safepay's leak site
The company is headquartered in Onda, Castellón, one of Europe's most important ceramic manufacturing regions. Established in 1949, Gayafores has …
Gellibrand Support Services named on anubis's leak site
A data breach at a company full of smiling patients.
American Contractors Insurance Group named on storm's leak site
FinTech | Richardson, Texas, United States | ACIG is a construction industry owned insurance facility based in Dallas, TX. ACIG provides workers compensation, general liability, automobile liability and subcontractor default insurance through ACIG Insurance Company and American Contractors Insurance Company Risk Retention Group. ACIG's mission is to save lives, prevent injuries and reduce the overall cost of risk and insurance for its members. The company headquarters is located in 2600 N. Central Expressway, Suite 800, Richardson, TX 75080, United States. 51-200 Employees | Deadline: 2026-08-20T20:36:09.948Z
The Cecilian Bank named on storm's leak site
FinTech | Hardin County, Kentucky, United States | The Cecilian Bank is an FDIC-insured financial institution that offers a wide range of personal and business banking services, including checking and savings accounts, loans, and online banking. Their services cater to individuals, small businesses, and large corporations, providing competitive rates and tailored financial solutions. The bank emphasizes convenience with features like online account opening and 24/7 access to banking services. With a commitment to community support, The Cecilian Bank aims to help clients achieve financial independence and business growth. The company headquarters is located in 104 East Main Street, Cecilia, KY 42724, United States.. 201-500 Employees | Deadline: 2026-08-24T12:54:01.000Z
National Salvage named on storm's leak site
Energy | Bloomington, Indiana, United States | National Salvage is a leading treated wood recycler specializing in wood recycling, rail services, and environmental services. With over 40 years of experience, they offer services such as track demolition, bridge demolition, and asbestos abatement. Their product range includes used railroad ties, recycled rail, utility poles, and railroad tie fuel. The company primarily serves clients in need of sustainable solutions for wood and rail recycling. The company headquarters is located in 6755 S Old State Road 37, Bloomington, IN 47403, United States. 201-500 Employees | Deadline: 2026-08-25T09:20:49.000Z
City of Mitchell named on storm's leak site
Consulting | Mitchell, South Dakota, United States | Mitchell is a city in and the county seat of Davison County, South Dakota, United States. Mitchell is the principal city of the Mitchell Micropolitan Statistical Area, which includes all of Davison and Hanson counties. The company headquarters is located in 612 N Main Street, Mitchell, SD 57301, United States. 51-200 Employees | Deadline: 2026-08-28T19:58:24.000Z
Jet Specialty named on qilin's leak site
Industrial Machinery & Equipment
RelyComply AML Platform named on direwolf's leak site
Zilvia.net: a data breach
In November 2025, data breached from the Zilvia.net Nissan 240SX Silvia and Z Fairlady car forum was leaked. The breach exposed 288k unique email addresses along with usernames, IP addresses and salted MD5 password hashes sourced from the vBulletin based platform. Attempts to contact Zilvia.net about the incident were unsuccessful.
ZenBusiness: a data breach
In March 2026, the hacker and extortion group "ShinyHunters" claimed to have obtained a substantial corpus of data from ZenBusiness , a business formation and compliance platform. The group claimed the data had been exfiltrated from platforms including Snowflake, Mixpanel and Salesforce, and threatened to publish it if a ransom was not paid. The following month, after claiming payment had not been made, ShinyHunters publicly released the data. The collection amounted to many terabytes across thousands of files that appeared to originate from multiple systems and business functions, including leads, support records and other CRM-related data. The data contained approximately 5M unique email addresses, often accompanied by name and phone number depending on the source file.
Zara: a data breach
In April 2026, the fashion brand Zara was among a number of organisations targeted by the ShinyHunters extortion group as part of their "pay or leak" campaign. The group claimed the breach was related to a compromise of the Anodot analytics platform and subsequently published a terabyte of data allegedly including 95M support ticket records. The data contained 197k unique email addresses alongside product SKUs, order IDs and the market the support ticket originated in. Zara's parent company Inditex advised that the incident didn't affect passwords or payment information .
Woflow: a data breach
In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group . The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of email addresses, names, phone numbers and physical addresses, with the data indicating it related to Woflow customers and, in turn, the customers of merchants using their platform.
WIRED: a data breach
In December 2025, 2.3M records of WIRED magazine users allegedly obtained from parent company Condé Nast were published online . The most recent data dated back to the previous September and exposed email addresses and display names, as well as, for a small number of users, their name, phone number, date of birth, gender, and geographic location or full physical address. The WIRED data allegedly represents a subset of Condé Nast brands the hacker also claims to have obtained.
Windows93 / Myspace93: a data breach
In January 2021, the parody site Windows93 suffered a data breach of the Myspace93 sub-site after a beta application was exploited to download server files. The compromised data was later leaked in June and included 46k Myspace93 accounts containing email and IP addresses, usernames and passwords stored in plain text.
WhiteDate: a data breach
In December 2025, the dating website "for a Europid vision" WhiteDate suffered a data breach that was subsequently leaked online , initially exposing 6.1k unique email addresses. The leaked data included extensive personal information such as physical appearance, income, education and IQ. A more comprehensive dataset was later provided to HIBP, containing usernames, IP addresses, private messages, phpBB password hashes and a total of 20k unique email addresses.
Web Hosting Talk: a data breach
In July 2016, the Web Hosting Talk forum suffered a data breach that was subsequently listed for sale . The breach of the vBulletin based forum exposed 515k user records including usernames, email addresses, IP addresses and salted MD5 password hashes.
Vultr: a data breach
In March 2023, the "AI-first global cloud platform" Vultr disclosed a security incident at a third-party vendor . Dating back to the previous year, the incident was attributed to the ActiveCampaign email marketing service provider and resulted in the exposure of 188k unique email addresses. A small number of records also included name, IP address and country of origin. No Vultr systems or additional customer data were impacted. Vultr subsequently self-submitted the impacted data to HIBP.
Vimeo: a data breach
In April 2026, the ShinyHunters extortion group listed Vimeo on their extortion portal as part of their "pay or leak" campaign . They subsequently published hundreds of gigabytes of data, predominantly consisting of video titles, technical data and metadata. The data also included 119k unique email addresses, sometimes accompanied by names. Vimeo attributed the exposure to a breach of Anodot, a third-party analytics vendor, and advised the incident does not include "Vimeo video content, valid user login credentials, or payment card information".
Vietnam Airlines: a data breach
In October 2025, data stolen from the Salesforce instances of multiple companies by a hacking group calling itself "Scattered LAPSUS$ Hunters" was publicly released . Among the affected organisations was Vietnam Airlines, which had 7.3M unique customer email addresses exposed following a breach of its Salesforce environment in June of that year. The compromised data also included names, phone numbers, dates of birth, and loyalty program membership numbers.
University of Pennsylvania: a data breach
In October 2025, the University of Pennsylvania was the victim of a data breach followed by a ransom demand , largely affecting its donor database. After the incident, the attackers sent inflammatory emails to some victims. The data was later published online in February 2026 and included 624k unique email addresses alongside names and physical addresses. For some donor records, additional personal information was exposed, including gender and date of birth. A small subset of records also contained religion, spouse name, estimated income and donation history.
Under Armour: a data breach
In November 2025, the Everest ransomware group claimed Under Armour as a victim and attempted to extort a ransom , alleging they had obtained access to 343GB of data. In January 2026, customer data from the incident was published publicly on a popular hacking forum , including 72M email addresses. Many records also contained additional personal information such as names, dates of birth, genders, geographic locations and purchase information.
Filings come from SEC EDGAR and are filtered to 8-K submissions that declare Item 1.05, not merely mention it. Breach records come from Have I Been Pwned. Ransomware claims come from RansomLook, used under CC BY 4.0; we store metadata only and never leak links.