Optus (Australia 2026)
2.8M customer records stolen via API vulnerability in self-service portal
SaaS platforms, cloud providers, developer tooling, and app-layer infrastructure are concentrated attack surfaces. One tech vendor breach can expose thousands of downstream customers. Below is every tech-sector breach LeakTrace has indexed.
2.8M customer records stolen via API vulnerability in self-service portal
10M+ dating records stolen by ShinyHunters via Okta SSO social engineering
150K enterprise zero-trust configurations exposed — test environment breach spread to prod
2.8M customer billing records and account metadata exposed via misconfigured internal tool
Microsoft Windows Information Disclosure Vulnerability — Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
Gogs Path Traversal Vulnerability — Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
6,215,150 records exposed — Display names, Email addresses, Geographic locations, Phone numbers and 1 more
75K employee records leaked by former staff to German newspaper — payroll, SSNs, complaints
APM and logging data from 340 enterprise customers exposed via compromised CI/CD pipeline
560K automation records exposed
560K corporate client records stolen
450K customer records exposed in targeted attack
17.5M account records posted to BreachForums
2.3M guest records compromised in phishing campaign targeting hotels
672,247 records exposed — Email addresses, Forum posts, Passwords, Private messages and 1 more
560K manufacturing and IoT device records exposed
120K workspace records exposed via OAuth misconfiguration
Microsoft Office PowerPoint Code Injection Vulnerability — Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineT
Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability — Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code ex
340K gaming records exposed in ransomware
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability — MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol head
2,364,431 records exposed — Dates of birth, Display names, Email addresses, Genders and 4 more
Digiever DS-2105 Pro Missing Authorization Vulnerability — Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.
2.3M subscriber records leaked on hacking forum