Live disclosure tracker · updated continuously

Recent Data Breach Disclosures

Every confirmed data breach we've indexed across 4488+ incidents from healthcare, finance, technology, government, retail, and education. Sourced from Verizon DBIR, public disclosure feeds, and major security news outlets. Updated automatically.

98B+
Records Exposed
4488
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026

Latest Disclosures

medium · other · Apr 9, 2026

Eurail data breach

Hackers breached Eurail in Dec 2025, stole names and passport data, and exposed over 300,000 travelers’ personal information. Threat actors breached Eurail in December 2025 and stole names and passport numbers from its n

View incident → Original disclosure Indexed 2 days, 20 hours ago
critical · healthcare · Apr 9, 2026

Weak at the seams

Before I ever held a security title, I was a software engineer implementing vertically integrated automation systems for industrial manufacturing, warehouse-scale conveyor networks, robotic material handling, physical in

View incident → Original disclosure Indexed 2 days, 20 hours ago
medium · other · Apr 9, 2026

Eurail says December data

Eurail B.V., a European travel operator that provides digital passes covering 33 national railways, says attackers stole the personal information of over 300,000 individuals in a December 2025 data breach. [...]

View incident → Original disclosure Indexed 2 days, 20 hours ago
medium · healthcare · Apr 9, 2026

Trump’s Personnel Agency Is

I posted the following article this morning over on PogoWasRight.org, but I have had so many people sending me links to stories about this news that I guess I should have posted it here, too, as a future data breach. by

View incident → Original disclosure Indexed 2 days, 20 hours ago
critical · finance · Apr 9, 2026

Lotte Card given notice

Yonhap News reports: Lotte Card has been notified by the financial watchdog that it is liable for around 5 billion won ($3.38 million) in financial penalties and a business suspension of over four months over a massive d

View incident → Original disclosure Indexed 2 days, 20 hours ago
medium · finance · Apr 9, 2026

EngageLab SDK Flaw Exposed 50M

Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency walle

View incident → Original disclosure Indexed 2 days, 20 hours ago
medium · government · Apr 9, 2026

A hacker has allegedly

Isaac Yee reports: A hacker has allegedly stolen a massive trove of sensitive data – including highly classified defense documents and missile schematics – from a state-run Chinese supercomputer in what could potentially

View incident → Original disclosure Indexed 2 days, 20 hours ago
medium · government · Apr 7, 2026

Russia Hacked Routers to Steal

Hackers linked to Russia's military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign

View incident → Original disclosure Indexed 4 days, 20 hours ago
critical · other · Apr 7, 2026

The Hidden Cost of Recurring

When talking about credential security, the focus usually lands on breach prevention. This makes sense when IBM’s 2025 Cost of a Data Breach Report puts the average cost of a breach at $4.4 million. A

View incident → Original disclosure Indexed 4 days, 20 hours ago
high · tech · Apr 6, 2026

Fortinet FortiClient EMS

Fortinet FortiClient EMS Improper Access Control Vulnerability — Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or comma

View incident → Original disclosure Indexed 5 days, 20 hours ago
critical · other · Apr 6, 2026

Germany Doxes “UNKN,” Head of

An elusive hacker who went by the handle "UNKN" and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed

View incident → Original disclosure Indexed 5 days, 20 hours ago