Metro Inc. (Canada)
740K customer records from Jean Coutu pharmacy division exposed in ransomware attack
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
740K customer records from Jean Coutu pharmacy division exposed in ransomware attack
Dutch telco Odido has revealed a major data breach impacting over six million customers
623,750 records exposed — Charitable donations, Dates of birth, Email addresses, Genders and 7 more
780K international health insurance member records exposed via insider data theft
1.8M taxpayer records exposed via compromised e-filing software vendor
900K patient research records exposed via compromised genomics analysis platform
1.2M SNKRS app user records exposed — sneaker purchase history and payment data stolen
740K enterprise customer metadata and colocation records exposed in Netscaler vulnerability exploit
780K enterprise meeting recordings and transcripts accessed via compromised admin portal
1.4M citizen records from provincial health and education systems compromised
780K customer records from wealth management division exposed via insider threat
480K investor records from Canadian asset manager exposed via compromised fund admin portal
Defense subcontractor breach exposes classified program metadata and personnel clearance records
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Suc
6.2M customer records including passport and bank account numbers leaked by ShinyHunters
Hundreds of thousands of users have downloaded malicious AI extensions masquerading as ChatGPT, Gemini, Grok and others, warn cybersecurity researchers at LayerX
Microsoft Configuration Manager SQL Injection Vulnerability — Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially cra
SolarWinds Web Help Desk Security Control Bypass Vulnerability — SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted
Accenture Cybersecurity warns over difficult to detect, “sophisticated toolset” being deployed as part of extortion campaigns
Apple Multiple Buffer Overflow Vulnerability — Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker w
Notepad++ Download of Code Without Integrity Check Vulnerability — Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or r
290K driver and rider records exposed via compromised third-party background check vendor
5.9M patient records exposed after legacy Cerner migration database left unsecured on Oracle Cloud
870K SkyMiles member records and passport data exposed via compromised CrowdStrike integration