LeakTrace Intelligence Desk · April 4, 2026

Weekly Breach Intelligence Briefing — April 4, 2026

North American threat activity surged with significant credential harvesting campaigns and third-party vendor compromises. <cite index="11-1,22-1">Major extortion groups targeted automotive and retail sectors through supply chain attacks and social engineering</cite>, while benefits administrators emerged as high-value targets for sustained data exfiltration.

Significant 910GB records Apr 02

Nissan Hit by Everest Ransomware via Vendor Compromise

Nissan Motor Corporation

Everest ransomware group claimed to have stolen 910GB of customer, dealership, and loan data from a third-party file transfer system serving North American Nissan and Infiniti dealerships. Nissan confirmed the breach was isolated to a vendor with no indication of direct system compromise.

What it means: The stolen data spans 13 years of records and demonstrates how supply chain compromises can expose massive automotive sector datasets.

High 5.1M records Feb 03

ShinyHunters Breach Exposes 5.1M Panera Customer Records

Panera Bread

ShinyHunters compromised Panera through a Microsoft Entra single-sign-on attack and published 760GB of customer data after failed extortion. The archive contained 5.1 million unique email addresses plus names, addresses and phone numbers.

What it means: The attack demonstrates the continuing success of voice phishing tactics against SSO credentials, enabling access to entire cloud environments.

High 2.7M records Mar 18

Benefits Administrator Navia Loses 2.7M Member Records

Navia Benefit Solutions

Hackers maintained access to Navia's systems for 24 days from December 22, 2025 to January 15, 2026, exfiltrating personal and health information of 2.7 million benefit plan participants. Exposed data included names, Social Security numbers, dates of birth, and health plan information.

What it means: Benefits administrators aggregate sensitive data from thousands of employers in one location, making them prime targets for mass data theft.

Significant 447K records Mar 12

Lloyds Banking Glitch Exposes 447K UK Customer Transactions

Lloyds Banking Group

A software defect during an overnight system update caused Lloyds mobile banking apps to display other customers' transactions, account numbers, and National Insurance numbers to unintended users. The exposure lasted approximately 5 hours with no unauthorized transactions or financial losses.

What it means: The incident highlights the fragility of digital banking platforms where single deployment failures can compromise years of customer trust in hours.