Security incidents

Incidents at named organisations, each linked to the source that reported it: material incident filings companies made to the SEC, breaches verified by Have I Been Pwned, and claims posted by ransomware groups.

142
Confirmed incidents
112
Unconfirmed claims
254
Last 30 days
136
Organisations tracked
2,705,731,734
Records disclosed
ConfirmedData breach2026-08-22

Golf Canada: a data breach

In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). It remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.

568,972 recordsGolf CanadaHave I Been Pwned
ConfirmedData breach2026-07-11

Glendale Community College: a data breach

In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice , the college advised that "the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information".

793,925 recordsGlendale Community CollegeHave I Been Pwned
ConfirmedData breach2025-09-18

FreeOnes: a data breach

In February 2017, the forum for the adult website FreeOnes suffered a data breach that was later redistributed as part of a larger corpus of data . The data included 960k unique email addresses alongside usernames, IP addresses and salted MD5 password hashes.

960,213 recordsFreeOnesHave I Been Pwned
ConfirmedData breach2026-07-15

Fluke: a data breach

In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.

821,100 recordsFlukeHave I Been Pwned
ConfirmedData breach2026-02-18

Figure: a data breach

In February 2026, data obtained from the fintech lending platform Figure was publicly posted online . The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access.

967,178 recordsFigureHave I Been Pwned
ConfirmedData breach2026-08-19

Fanlore: a data breach

In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates . The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.

144,520 recordsFanloreHave I Been Pwned
ConfirmedData breach2026-08-07

Exact Sciences: a data breach

In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign . The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.

10,869,543 recordsExact SciencesHave I Been Pwned
ConfirmedData breach2025-11-20

Eurofiber: a data breach

In November 2025, Eurofiber France disclosed a data breach of its ticket management platform . Data containing 10k unique email addresses and a smaller number of names and phone numbers was subsequently leaked. A threat actor claiming responsibility for the breach alleges to have additional, more sensitive data including screenshots, VPN configuration files, credentials, source code, certificates, archives, and SQL backup files.

10,003 recordsEurofiberHave I Been Pwned
ConfirmedData breach2026-06-01

Edmunds: a data breach

In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached . Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone numbers and vehicle-related records.

177,860 recordsEdmundsHave I Been Pwned
ConfirmedData breach2026-05-21

Dragonica Lunaris: a data breach

In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed.

126,293 recordsDragonica LunarisHave I Been Pwned
ConfirmedData breach2026-03-15

Divine Skins: a data breach

In March 2026, the League of Legends custom skins service Divine Skins suffered a data breach . The incident was disclosed via the service's Discord server, where Divine Skins stated that an unauthorised third party accessed part of its systems, deleted all skins from the database and exposed email addresses and usernames. The data also contained a history of purchases made by users.

105,814 recordsDivine SkinsHave I Been Pwned
ConfirmedData breach2026-06-03

DentaQuest: a data breach

In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files ( ASC X12 transaction sets ) with some containing Medicaid IDs, while additional data appeared in member records and related files. DentaQuest acknowledged "a cybersecurity incident involving unauthorized access to a limited portion of our network" , and advised they had contained the attack and mitigated the threat.

2,553,599 recordsDentaQuestHave I Been Pwned
ConfirmedData breach2026-03-31

Cuties AI: a data breach

In March 2026, the NSFW AI companion platform Cuties AI suffered a data breach that was subsequently published to a public hacking forum . The incident exposed 144k unique email addresses along with display names, avatars, prompts and descriptions used to generate AI adult images, as well as URLs to the generated content. The data also included the account that created the content and a stated "preference" of either female or trans.

144,250 recordsCuties AIHave I Been Pwned
ConfirmedData breach2026-05-12

Cushman & Wakefield: a data breach

In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group . Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.

310,431 recordsCushman & WakefieldHave I Been Pwned
ConfirmedData breach2025-09-25

Cultura: a data breach

In September 2024, French retailer Cultura was the victim of a cyber attack they attributed to an external IT service provider . The resultant data breach included almost 1.5M unique email addresses along with names, phone numbers, physical addresses and orders. Cultura advised that all affected customers had been notified about the incident.

1,462,025 recordsCulturaHave I Been Pwned
ConfirmedData breach2026-05-19

CTT: a data breach

In April 2026, data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum . The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history of the parcel.

468,124 recordsCTTHave I Been Pwned
ConfirmedData breach2026-04-04

Crunchyroll: a data breach

In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users . The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the contents of the support tickets" were exposed. A subset of 1.2M email addresses from an alleged 2M record dataset being sold was later provided to HIBP.

1,195,684 recordsCrunchyrollHave I Been Pwned
ConfirmedData breach2025-11-23

CodeStepByStep: a data breach

In November 2025, the online coding practice tool CodeStepByStep suffered a data breach that exposed 17k records which were subsequently published online . The following month, a further corpus of data was released bringing the total to 103k. The impacted data included names, usernames and email addresses.

103,077 recordsCodeStepByStepHave I Been Pwned
ConfirmedData breach2026-05-28

Charter: a data breach

In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses. A subset of approximately 85k records originating from an internal employee directory also included job titles. Charter confirmed the incident, but stated that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.

4,851,517 recordsCharterHave I Been Pwned
ConfirmedData breach2026-06-18

CFGI: a data breach

In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign . The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k unique email addresses, names, phone numbers and physical addresses.

248,235 recordsCFGIHave I Been Pwned
ConfirmedData breach2026-04-24

Carnival: a data breach

In April 2026, the notorious hacking collective ShinyHunters claimed they had obtained a substantial volume of data belonging to the Carnival cruise operator and attempted to extort the organisation to prevent the data from being leaked. The following week, the group published the data publicly, which contained 8.7M records with 7.5M unique email addresses. The data contained fields indicating it related to the Mariner Society loyalty program run by Holland America, a cruise line brand under Carnival, and included names, dates of birth, genders and data relating to status within the loyalty program. Carnival acknowledged a phishing incident involving a single user account and advised they were working to better understand the scope of the unauthorised activity.

7,531,359 recordsCarnivalHave I Been Pwned
ConfirmedData breach2026-02-20

CarMax: a data breach

In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt . The data included 431k unique email addresses along with names, phone numbers and physical addresses.

431,371 recordsCarMaxHave I Been Pwned
ConfirmedData breach2026-08-25

Carhartt: a data breach

In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.

12,933,413 recordsCarharttHave I Been Pwned
ConfirmedData breach2026-02-22

CarGurus: a data breach

In February 2026, the automotive marketplace CarGurus was the target of a data breach attributed to the threat actor ShinyHunters . Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, finance pre-qualification application data and dealer account and subscription information. Impacted data also included names, phone numbers, physical and IP addresses, and auto finance application outcomes.

12,461,887 recordsCarGurusHave I Been Pwned
Page 4 of 6 · 142 incidentsPreviousNext

Filings come from SEC EDGAR and are filtered to 8-K submissions that declare Item 1.05, not merely mention it. Breach records come from Have I Been Pwned. Ransomware claims come from RansomLook, used under CC BY 4.0; we store metadata only and never leak links.