Live disclosure tracker · updated continuously

Healthcare Data Breaches

Hospitals, clinics, insurers, and medical-IT vendors are the highest-value targets in cybercrime. Below is every healthcare-sector breach LeakTrace has indexed — patient records, HIPAA disclosures, ransomware victims, and supply-chain compromises.

98B+
Records Exposed
11600
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Healthcare Data Breaches (11600 indexed)

high · tech · Jun 29, 2026

SimpleHelp SimpleHelp

SimpleHelp Authentication Bypass Vulnerability — SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login

high · retail · Jun 28, 2026

Sysco

2,691,852 records exposed — Customer feedback, Email addresses, Employers, Job titles and 4 more

View incident → Indexed 2 months ago
medium · tech · Jun 26, 2026

American Tower

216,601 records exposed — Email addresses, Job titles, Names, Phone numbers and 1 more

View incident → Indexed 2 months, 1 week ago
high · tech · Jun 25, 2026

PTC Windchill and FlexPLM

PTC Windchill and FlexPLM Improper Input Validation Vulnerability — PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by

View incident → Original disclosure Indexed 2 months, 1 week ago
high · tech · Jun 23, 2026

Ubiquiti UniFi OS

Ubiquiti UniFi OS Path Traversal Vulnerability — Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that coul

View incident → Original disclosure Indexed 2 months, 1 week ago
high · tech · Jun 23, 2026

Ubiquiti UniFi OS

Ubiquiti UniFi OS Improper Access Control Vulnerability — Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to

View incident → Original disclosure Indexed 2 months, 1 week ago
high · tech · Jun 23, 2026

Ubiquiti UniFi OS

Ubiquiti UniFi OS Improper Input Validation Vulnerability — Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injectio

View incident → Original disclosure Indexed 2 months, 1 week ago
high · tech · Jun 23, 2026

Lantronix EDS5000

Lantronix EDS5000 Code Injection Vulnerability — Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are exe

View incident → Original disclosure Indexed 2 months, 1 week ago
medium · education · Jun 20, 2026

JCPenney

368,418 records exposed — Dates of birth, Email addresses, Government issued IDs, Job titles and 4 more

View incident → Indexed 2 months, 1 week ago
high · tech · Jun 18, 2026

Splunk Enterprise

Splunk Enterprise Missing Authentication for Critical Function Vulnerability — Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create o

View incident → Original disclosure Indexed 2 months, 2 weeks ago
medium · retail · Jun 18, 2026

Ralph Lauren

139,903 records exposed — Age groups, Email addresses, Genders, Names and 1 more

View incident → Indexed 2 months, 2 weeks ago
medium · finance · Jun 18, 2026

CFGI

248,235 records exposed — Email addresses, Employers, Job titles, Names and 2 more

View incident → Indexed 2 months, 2 weeks ago