State of Ohio Unemployment System
890K unemployment claimant records exposed via compromised benefits administration portal
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
890K unemployment claimant records exposed via compromised benefits administration portal
2.1M pharmacy patient records exposed via compromised health services vendor
Campaign combines stolen Telegram accounts, fake Zoom calls and ClickFix attacks to deploy infostealer malware
680K European cardholder records exposed via compromised transaction processing node
Microsoft Windows Improper Privilege Management Vulnerability — Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privile
210K client records compromised via vendor
340K employee and supply records exposed
Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability — Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized
Microsoft Windows Type Confusion Vulnerability — Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
Microsoft Windows Shell Protection Mechanism Failure Vulnerability — Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature ov
Microsoft Windows NULL Pointer Dereference Vulnerability — Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability — Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feat
280K patient records exposed
450K customer records exposed in credential harvesting
670K mining operational records exposed in targeted espionage
450K patient records exposed in POS breach
190K student records exposed
5,600 records exposed — Dates of birth, Email addresses, Names, Places of birth and 1 more
Picus Security warns of the increasingly sophisticated ways malicious activity is staying hidden
1,017 records exposed — Chat logs, Email addresses, IP addresses, Usernames
3.1M customer records accessed via compromised customer service platform
340K customer utility records exposed via compromised billing system vendor
340K defense and aerospace employee records exposed via LockBit 3.0 ransomware
SecurityScorecard has identified over 40,000 OpenClaw deployments exposed to potential attack