Commonwealth Bank (Australia)
1.9M customer records from wealth management division exposed via partner API vulnerability
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
1.9M customer records from wealth management division exposed via partner API vulnerability
1.2M bank accounts potentially compromised in national registry breach
1.9M veteran health records exposed via compromised community care referral system
290K student and research records exposed via compromised research data portal
1.7M customer records exposed via compromised partner API in mobile services platform
480K frequent flyer records including passport numbers accessed via loyalty program vulnerability
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability — Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious a
2.4M patient records stolen from 65 hospitals in coordinated supply chain attack
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability — Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that l
Vite Vitejs Improper Access Control Vulnerability — Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposi
380K customer utility records and pipeline operations data exposed via compromised SCADA vendor
Versa Concerto Improper Authentication Vulnerability — Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to ac
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craf
42K student records exposed via zero-day in student information system — grades and SSNs
860K merchant store records including revenue data exposed via compromised support tool
1.6M customer records from US and UK operations exposed via MOVEit successor vulnerability
2.3M patient records stolen from Australian private hospital operator
72,742,892 records exposed — Dates of birth, Email addresses, Genders, Geographic locations and 2 more
Cisco Unified Communications Products Code Injection Vulnerability — Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Comm
680K household survey response records exposed via misconfigured data sharing portal
8.7M customer records exposed via compromised customer portal at largest Korean telco
Business intelligence platform breached — ShinyHunters claimed responsibility
1.5M shipping manifests and customs records exposed via compromised logistics API
2.3M package tracking records and sender data exposed via compromised Informed Delivery API