LeakTrace Intelligence Desk · March 28, 2026

Weekly Breach Intelligence Briefing — March 28, 2026

This week witnessed significant identity broker exposures and healthcare ransomware disruptions across North America. Data broker vulnerabilities dominated the landscape, with massive credential databases exposed while healthcare infrastructure faced continued ransomware pressure.

Critical 677M records Mar 03

Infutor Data Broker Exposes 677M Americans' SSNs

Infutor/ActiveProspect

An Elasticsearch database containing full names, addresses, phone numbers, dates of birth, and Social Security numbers was exposed on the internet without authentication. SOCRadar discovered the misconfigured database linked to data broker Infutor.

What it means: This represents wholesale compromise of identity infrastructure, providing criminals everything needed for large-scale fraud across financial services and healthcare sectors.

High 2.7M records Mar 19

Navia Benefits Breach Compromises 2.7M Employee Records

Navia Benefit Solutions

Threat actors exploited Broken Object Level Authorization vulnerability between December 2025-January 2026, accessing Social Security numbers, names, addresses, and health plan information. Multiple major employers' benefits data was compromised.

What it means: Employee benefits systems represent a goldmine for identity thieves, affecting workers across multiple Fortune 500 companies through a single vendor compromise.

High 400K records Mar 03

LexisNexis Legal Suffers Government Data Breach

LexisNexis Legal & Professional

FulcrumSec exploited React2Shell vulnerability to access AWS infrastructure, stealing 2GB of data including federal judges, DOJ attorneys, and court clerk information. The attack leveraged over-privileged container access to Redshift databases.

What it means: Compromise of legal sector infrastructure threatens attorney-client privilege and exposes government legal operations to criminal-targeting sources.

Significant 6.8M records Mar 19

Crunchyroll Customer Support Tickets Stolen

Crunchyroll

Hackers compromised Okta SSO account of support agent and planted malware, stealing over 8 million support tickets containing email addresses, names, login information, and geographic data.

What it means: Customer service infrastructure provides extensive personal data for social engineering attacks and account takeover campaigns against younger demographics.

High 192K records Feb 21

Kaplan Education Provider Exposes Driver's Licenses

Kaplan North America

Unauthorized party accessed networks containing names, Social Security numbers, dates of birth, and driver's license numbers. The education and training provider began notifications in mid-March after discovering the breach in February.

What it means: Educational services hold complete identity packages needed for financial fraud, affecting students and professionals seeking career advancement.

Critical Unknown records Mar 10

Telus Digital Hit by ShinyHunters Mega-Breach

Telus Digital

ShinyHunters exploited stolen Google Cloud credentials to access nearly 1 petabyte of data including customer support logs, voice recordings, FBI background checks, source code, and financial information from 28+ clients. Attackers demanded $65M Bitcoin ransom.

What it means: Supply chain compromise of major BPO provider exposes sensitive data across multiple industries, demonstrating risks of third-party vendor concentration.