Live disclosure tracker · updated continuously

Finance & Banking Data Breaches

Banks, payment processors, fintechs, and crypto exchanges sit at the top of every threat actor target list. Below is every finance-sector breach LeakTrace has indexed.

98B+
Records Exposed
11620
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Finance & Banking Data Breaches (11620 indexed)

high · tech · Jul 27, 2026

Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability — Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged intern

high · tech · Jul 27, 2026

Fortinet FortiOS

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability — Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote u

medium · other · Jul 25, 2026

ShinyHunters data

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]

View incident → Original disclosure Indexed 1 month, 1 week ago
high · tech · Jul 25, 2026

Jessica Lyons

Jessica Lyons reports on today’s entry in the “No Need to Hack When It’s Leaking” files: Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked

View incident → Original disclosure Indexed 1 month, 1 week ago
medium · tech · Jul 24, 2026

Chick-fil-A has

Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]

View incident → Original disclosure Indexed 1 month, 1 week ago
medium · finance · Jul 24, 2026

Roxanne Libatique

Roxanne Libatique reports: Origin Energy has declined to comment on a public claim that it privately resolved a cyber extortion threat – a posture that, as of July 24, leaves the company managing simultaneous obligations

View incident → Original disclosure Indexed 1 month, 1 week ago