Instructure
Supply chain breach of Canvas platform generated 58% of all breach notices in 2026
Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.
Supply chain breach of Canvas platform generated 58% of all breach notices in 2026
1 million social security numbers exposed via cybersecurity loophole in mapping service
Inadvertent exposure of personal information for over 700,000 state residents
300,000 people's digital health information records were accessed and sold from health records networks to law firms
Cyberattack forced shift to manual operations, systems being restored
Threat actor claims 5.5 million customer, employee, and corporate records exposed for sale
Data breach resulting in €42 million fine for cybersecurity vulnerabilities and GDPR violations
Microsoft SharePoint breach compromised 200 government accounts
Patient health information compromised through third-party vendor breach
Inadvertent exposure of personal information of 700,000 state residents
Inadvertent exposure of personal data belonging to over 700,000 state residents
Years-long data breach of residents' private health-related information
Data regulator fined subsidiaries €42 million for cybersecurity vulnerabilities contributing to 2024 breach
1.26 million patients exposed in PEAR ransomware attack on medical billing/practice-management system
Hardware wallet data breach resulting in theft of over $100M worth of bitcoin
Hacker group claimed access to employee data; company stated data may be years-old
Yearslong breach exposed residents' private health-related information
Inadvertently exposed personal information of 700,000 state residents
Sensitive personal health information exposed from at-home diagnostic tests
Data breach impacting personal, treatment, and health insurance information of 145,381 patients
Data breach with inadequate security controls resulted in €42M GDPR fines from French data regulator
Yearslong breach of residents' private health-related information
Corporate data stolen through social engineering attack on employees
Fined €42 million for cybersecurity vulnerabilities contributing to 2024 breach; three major GDPR violations