Raaga
10,225,145 records exposed — Ages, Dates of birth, Email addresses, Genders and 3 more
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
10,225,145 records exposed — Ages, Dates of birth, Email addresses, Genders and 3 more
180K employee records from automotive parts manufacturer exposed via phishing attack
680K wealth management client records exposed via misconfigured cloud storage bucket
1.2M customer records from government IT contracts exposed via compromised ProjectWEB portal
6,366,133 records exposed — Email addresses, Genders, Names, Phone numbers and 1 more
3.4M CRM records from multiple tenants exposed via privilege escalation in Data Cloud module
1.3M guest reservation records including passport and payment data compromised
1.1M tokenized card records exposed via vulnerability in token provisioning service
2.8M customer records stolen via API vulnerability in self-service portal
520K alumni and donor records exposed via compromised advancement office database
1.1M auto loan records exposed via compromised dealer management system integration
10M+ dating records stolen by ShinyHunters via Okta SSO social engineering
150K enterprise zero-trust configurations exposed — test environment breach spread to prod
4.3M individuals affected via Fortune 500 contractor — multiple state governments impacted
620K Circle K loyalty customer records stolen from Canadian convenience store operator
4.7M customer records exposed via compromised third-party payment processing vendor
2.8M customer billing records and account metadata exposed via misconfigured internal tool
320K credit card applicant records exposed via compromised underwriting platform
1.9M customer records stolen from payment processing system via skimming malware at warehouses
Microsoft Windows Information Disclosure Vulnerability — Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
1.8M employee benefits records from Canadian health benefits platform compromised
890K patient vaccination records exposed via misconfigured COVID-era data sharing portal
Gogs Path Traversal Vulnerability — Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
Client M&A deal documents and litigation files exposed via compromised document management system