Live disclosure tracker · updated continuously

2026 Data Breaches Year-to-Date

2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.

98B+
Records Exposed
848
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026

2026 Data Breaches Year-to-Date (848 indexed)

critical · government · May 18, 2026

CISA Admin Leaked AWS GovCloud

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts a

View incident → Original disclosure Indexed 1 week, 1 day ago
medium · finance · May 18, 2026

⚡ Weekly Recap: Exchange 0-Day,

Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: t

View incident → Original disclosure Indexed 1 week, 1 day ago
critical · retail · May 18, 2026

Public Amazon bucket

A hotel check-in system exposed over 1 million passports, IDs, and selfies online due to a misconfigured cloud storage bucket. A security lapse in the Reqrea’s Tabiq hotel check-in system exposed over 1 million pas

View incident → Original disclosure Indexed 1 week, 1 day ago
medium · other · May 17, 2026

Grafana GitHub Token Breach Led

Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its codebase. "Our investigation has determined that no custom

View incident → Original disclosure Indexed 1 week, 2 days ago
critical · education · May 16, 2026

Illuminate wins another round in

The Supreme Court of California has ruled in J.M. v. Illuminate Education, Inc., a case closely watched by those concerned about holding edtech vendors liable in the event of a data breach. As background on the case: In

View incident → Original disclosure Indexed 1 week, 3 days ago
medium · other · May 16, 2026

OpenAI

OpenAI said the TanStack supply chain attack compromised two employee devices and exposed credentials from code repositories. OpenAI confirmed that the recent TanStack supply chain attack compromised two employee devices

View incident → Original disclosure Indexed 1 week, 3 days ago
medium · other · May 16, 2026

Welcome to BlackFile

Google’s Threat Intelligence Group writes: Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the “BlackFile” brand

View incident → Original disclosure Indexed 1 week, 3 days ago
high · tech · May 15, 2026

Microsoft Microsoft

Microsoft Exchange Server Cross-Site Scripting Vulnerability — Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditi

View incident → Original disclosure Indexed 1 week, 4 days ago
medium · other · May 15, 2026

TanStack Supply Chain Attack Hits

OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data, production systems, or intellectual p

View incident → Original disclosure Indexed 1 week, 4 days ago
medium · tech · May 15, 2026

Expired domain leads to supply

A popular npm package called node-ipc has been compromised, with hackers publishing malicious versions that bundle credential stealing malware. The root cause of the compromise was an expired domain name that attackers m

View incident → Original disclosure Indexed 1 week, 4 days ago
medium · government · May 15, 2026

In Other News

Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters hacks Canvas. The post In Other News: Big Tech vs Canada Enc

View incident → Original disclosure Indexed 1 week, 4 days ago
high · tech · May 14, 2026

Cisco Catalyst SD-WAN

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability — Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass a

View incident → Original disclosure Indexed 1 week, 5 days ago