Security incidents

Incidents at named organisations, each linked to the source that reported it: material incident filings companies made to the SEC, breaches verified by Have I Been Pwned, and claims posted by ransomware groups.

142
Confirmed incidents
112
Unconfirmed claims
254
Last 30 days
136
Organisations tracked
2,705,731,734
Records disclosed
ConfirmedData breach2026-03-18

Aura: a data breach

In March 2026, the online safety service Aura disclosed a data breach that exposed 900k unique email addresses . The data was primarily associated with a marketing tool from a previously acquired company, with fewer than 20k active Aura customers affected. Exposed data included names, phone numbers, physical and IP addresses, and customer service notes. Aura advised that no Social Security numbers, passwords or financial information were compromised.

903,080 recordsAuraHave I Been Pwned
ConfirmedData breach2026-05-30

Atlas Menu: a data breach

In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.

63,926 recordsAtlas MenuHave I Been Pwned
ConfirmedData breach2025-10-04

Artists&Clients: a data breach

In August 2025, the "marketplace that connects artists to prospective clients" Artists&Clients, suffered a data breach and subsequent ransom demand of US$50k . The data was subsequently leaked publicly and included 95k unique email addresses alongside usernames, IP addresses and bcrypt password hashes.

95,351 recordsArtists&ClientsHave I Been Pwned
ConfirmedData breach2025-09-21

Animeify: a data breach

In October 2021, the now defunct Arabic language Anime website Animeify suffered a data breach that was later redistributed as part of a larger corpus of data . The data included 808k unique email addresses along with names, usernames, genders and plain text passwords.

808,034 recordsAnimeifyHave I Been Pwned
ConfirmedData breach2026-04-17

Amtrak: a data breach

In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak . The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. They subsequently published the alleged data which contained over 2M unique email addresses along with names, physical addresses and customer support records.

2,147,679 recordsAmtrakHave I Been Pwned
ConfirmedData breach2026-05-26

Ameriprise: a data breach

In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general , Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".

502,597 recordsAmeripriseHave I Been Pwned
ConfirmedData breach2026-06-26

American Tower: a data breach

In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.

216,601 recordsAmerican TowerHave I Been Pwned
ConfirmedData breach2026-05-01

Aman: a data breach

In April 2026, the ultra-luxury hotel brand Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign , with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. Whilst not present on all records, the data also included genders, physical addresses, phone numbers, nationalities, dates of birth, spouse names and VIP status codes.

215,563 recordsAmanHave I Been Pwned
ConfirmedData breach2026-08-09

Alcon: a data breach

In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.

218,395 recordsAlconHave I Been Pwned
ConfirmedData breach2026-04-27

ADT: a data breach

In April 2026, home security firm ADT confirmed a data breach by ShinyHunters , which listed the company on its website as part of a "pay or leak" extortion attempt. The breach impacted 5.5M unique email addresses along with names, phone numbers and physical addresses. ADT also advised that "in a small percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were included" and that it had contacted all affected people.

5,488,888 recordsADTHave I Been Pwned
ConfirmedData breach2025-10-07

Adpost: a data breach

In February 2025, data obtained from an earlier Adpost breach surfaced. The dataset contained 3.3M records including email addresses, usernames, and display names. Adpost later published a disclosure notice and advised they'd forced a credential refresh, among other actions.

3,339,512 recordsAdpostHave I Been Pwned
ConfirmedData breach2026-05-18

Addi: a data breach

In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a large trove of personal data allegedly obtained from Addi. The data included 34M unique email addresses from credit scoring requests, credit bureau records, customer identity records and email validation logs. It also contained government issued IDs (Cédula de Ciudadanía), estimated income, socioeconomic levels, purchases and other credit-related data points.

34,532,941 recordsAddiHave I Been Pwned
ConfirmedData breach2025-11-23

ADDA: a data breach

In March 2025, data allegedly breached from the ADDA housing societies service was posted to a public hacking forum . The data contained over 1.8M unique email addresses along with names, phone numbers and MD5 password hashes.

1,829,314 recordsADDAHave I Been Pwned
ConfirmedData breach2026-05-14

Abrigo: a data breach

In April 2026, the fintech software company Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group . Shortly after, data allegedly taken from the company's Salesforce instance was published publicly and contained over 700k unique email addresses belonging to both Abrigo staff and external contacts. Whilst separate from Abrigo's Salesforce compromise via the Drift application connector the previous year , the data fields described in that incident are consistent with the ShinyHunters data, namely that it was "business contact information" including "institution name, employee name, email addresses, and phone numbers".

711,099 recordsAbrigoHave I Been Pwned
ConfirmedData breach2026-05-24

7-Eleven: a data breach

In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters , with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers. A small number of records also contained additional exposed data fields. The company later advised the breach was limited to "certain 7-Eleven systems used to store franchisee documents", a statement consistent with the exposed data.

185,256 records7-ElevenHave I Been Pwned
Page 5 of 5 · 115 incidentsPrevious

Filings come from SEC EDGAR and are filtered to 8-K submissions that declare Item 1.05, not merely mention it. Breach records come from Have I Been Pwned. Ransomware claims come from RansomLook, used under CC BY 4.0; we store metadata only and never leak links.