Ernst & Young (EY)
Third-party IT service breach exposed client tax data (March 28 - April 12, 2026)
Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.
Third-party IT service breach exposed client tax data (March 28 - April 12, 2026)
Confidential health records exposed online and advertised for sale on Chinese website
Data breach exposing 541,000 Jira issues and customer data from major Polish retailer
Breached through Cisco vulnerability, FIRESTARTER backdoor allowed access through March
Major cyberattack exposing 19 million French citizen identity records
Ransomware attack crippled county servers, week-long restoration
Breach via Cisco vulnerability with FIRESTARTER backdoor malware allowing access through March
22 million user records exposed including emails, passwords, and banking data
Unnamed US department breached via Cisco vulnerability, FIRESTARTER backdoor allowed persistent access
ShinyHunters breach claimed 275 million records from 8,809 schools, exposing student and staff data
144,250 records exposed — Avatars, Display names, Email addresses
Citrix NetScaler Out-of-Bounds Read Vulnerability — Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability wh
339,778 records exposed — Email addresses, Passwords, Usernames
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability — F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
128,683 records exposed — Display names, Email addresses, IP addresses, Passwords and 1 more
Aquasecurity Trivy Embedded Malicious Code Vulnerability — Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, includin
292,993 records exposed — Email addresses, Names, Passwords
Langflow Code Injection Vulnerability — Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
222,762 records exposed — Email addresses, IP addresses, Passwords, Usernames
Apple Multiple Products Improper Locking Vulnerability — Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected change
Craft CMS Code Injection Vulnerability — Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
Laravel Livewire Code Injection Vulnerability — Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability — Cisco Secure Firewall Management Center (FMC) Software a
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading