Australian Medical Clinics (Partnered)
Cyberattack exposed Medicare numbers, treatment details, and pathology results
Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.
Cyberattack exposed Medicare numbers, treatment details, and pathology results
Ransomware attack resulted in data breach; apparent payment made to threat actors
Unauthorized third party gained access to systems storing franchisee documents
Ransomware attack forced systems offline globally, disrupting operations
Massive data breach affecting schools and colleges nationwide, with data extortion attack
Patient personal information exposed through at-home diagnostic tests
15 million patients affected; largest 2026 US health breach exposed SSNs and dental/vision health info
Ransomware attack shut down education platform used by universities and K-12 schools across US, impacting thousands of students during finals week
Tens of thousands of students and teachers affected in education technology data breach
Third-party vendor breach exposed tax client data; 81-day notification delay
Second-largest dental benefits administrator breached; 15M patients impacted in largest 2026 healthcare breach
Data breach after ransomware attack; appears payment was made to threat actors
Tens of thousands of Queensland students and teachers affected in significant global education technology breach
Australian travel agency; threat actor alleged customer records breach on underground hacking forums
Patient data potentially exposed through third-party vendor breach detected by Kroll administrator
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability — WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerabil
Microsoft Windows Protection Mechanism Failure Vulnerability — Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
ConnectWise ScreenConnect Path Traversal Vulnerability — ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and cri
5,488,888 records exposed — Dates of birth, Email addresses, Names, Partial government issued IDs and 2 more
8,243,989 records exposed — Email addresses, Job titles, Names, Phone numbers and 1 more
1,401,259 records exposed — Email addresses, Employers, Job titles, Names and 3 more
SimpleHelp Missing Authorization Vulnerability — SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be
7,531,359 records exposed — Dates of birth, Email addresses, Genders, Geographic locations and 3 more
D-Link DIR-823X Command Injection Vulnerability — D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to