Vanderbilt University
190K student and medical center records exposed via ransomware on administrative systems
2025 marked a continued acceleration in confirmed-breach disclosures. Below is every 2025 incident LeakTrace has indexed.
190K student and medical center records exposed via ransomware on administrative systems
520K card holder records exposed via vulnerability in mobile banking application
D-Link Routers Buffer Overflow Vulnerability — D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (E
Array Networks ArrayOS AG OS Command Injection Vulnerability — Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.
817,808 records exposed — Email addresses, IP addresses, Names, Passwords and 1 more
280K antitrust investigation records exposed via phishing attack on senior associates
780K customer and pipeline operational records exposed
340K customer records stolen
Meta React Server Components Remote Code Execution Vulnerability — Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw i
450K merchant records exposed via third-party integration
340K resident records stolen
180K enterprise streaming configurations exposed via SSRF vulnerability in management API
340K patient records exposed
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability — OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload a
Android Framework Privilege Escalation Vulnerability — Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Android Framework Information Disclosure Vulnerability — Android Framework contains an unspecified vulnerability that allows for information disclosure.
2.8M smart home device user records exposed via misconfigured internal analytics pipeline
340K patent application records exposed
420K patient records exposed via phishing attack on physician email accounts
1.8M registered health platform users — 126K patients directly affected
340K client records stolen in ransomware
Law firm cyberattacks nearly doubled in 2025 — average breach cost $5.08M
180K student records compromised
560K client records stolen