Live disclosure tracker · updated continuously

2026 Data Breaches Year-to-Date

2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.

98B+
Records Exposed
461
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026

2026 Data Breaches Year-to-Date (461 indexed)

high · tech · Mar 20, 2026

Apple Multiple Products

Apple Multiple Products Improper Locking Vulnerability — Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected change

View incident → Original disclosure Indexed 3 weeks, 2 days ago
high · tech · Mar 20, 2026

Apple Multiple Products

Apple Multiple Products Classic Buffer Overflow Vulnerability — Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause une

View incident → Original disclosure Indexed 3 weeks, 2 days ago
high · tech · Mar 20, 2026

Apple Multiple Products

Apple Multiple Products Buffer Overflow Vulnerability — Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web con

View incident → Original disclosure Indexed 3 weeks, 2 days ago
critical · other · Mar 20, 2026

Feds Disrupt IoT Botnets Behind

The U.S. Justice Department joined authorities in Canada and Germany in dismantling the online infrastructure behind four highly disruptive botnets that compromised more than three million hacked Internet of Things (IoT)

View incident → Original disclosure Indexed 3 weeks, 2 days ago
high · tech · Mar 20, 2026

Laravel Livewire

Laravel Livewire Code Injection Vulnerability — Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

View incident → Original disclosure Indexed 3 weeks, 2 days ago
high · tech · Mar 18, 2026

Microsoft SharePoint

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability — Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

View incident → Original disclosure Indexed 3 weeks, 4 days ago