Live disclosure tracker · updated continuously

Finance & Banking Data Breaches

Banks, payment processors, fintechs, and crypto exchanges sit at the top of every threat actor target list. Below is every finance-sector breach LeakTrace has indexed.

98B+
Records Exposed
10649
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Finance & Banking Data Breaches (10649 indexed)

critical · healthcare · Aug 29, 2026

McKesson is

Lawrence Abrams reports: Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters ex

critical · government · Aug 29, 2026

Berlin's state government has

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The

critical · healthcare · Aug 29, 2026

PEAR

SuspectFile reports: A cyberattack against a Texas healthcare organization allegedly resulted in the exfiltration of approximately 1.4 TB of data, according to claims made by the ransomware group PEAR. The alleged victim

critical · healthcare · Aug 28, 2026

McKesson

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it

medium · healthcare · Aug 28, 2026

Matt Trewern

Matt Trewern reports on another charity hit by the Beacon CRM data breach that affected more than 1,000 charities and non-profits: People using an HIV charity have been told their “sensitive and personal” hea

critical · finance · Aug 28, 2026

Winona County

WXOW in Minnesota reports: Winona County paid more than $128,000 following a January ransomware attack, according to a county news release. The county said it negotiated and paid $128,539.57 with assistance from its insu

medium · other · Aug 28, 2026

Love Electric Breach

Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A seller on an English-language data-breach forum claimed on Au

critical · other · Aug 27, 2026

A spokesperson

A spokesperson told The Yorkshire Post that roughly 8.7 million people were impacted, although they did not provide a date range. They added that in the “vast majority” of cases, the only information accessed was an emai

medium · tech · Aug 27, 2026

ThreatsDay

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command tra

medium · government · Aug 27, 2026

Brian Krebs

Brian Krebs reports: Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply c

high · tech · Aug 27, 2026

ownCloud ownCloud

ownCloud Improper Authentication Vulnerability — ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim

medium · other · Aug 27, 2026

Manchester Airports Group

Gabriel Higgins reports: Manchester Airports Group (MAG) has confirmed that it has been the target of a cybersecurity incident carried out by an unauthorised third party, resulting in the exposure of a quantity of custom