2025 Data Breaches (637 indexed)
White & Case
180K client records compromised
Cedars-Sinai Medical Center
420K patient records exposed via phishing attack on physician email accounts
Ameriprise Financial
560K client records stolen
Santander (2025)
1.1M customer records compromised in vendor breach
GitLab
560K repository metadata and pipeline records stolen
Zilvia.net
287,863 records exposed — Email addresses, IP addresses, Passwords, Usernames
OpenPLC ScadaBR
OpenPLC ScadaBR Cross-site Scripting Vulnerability — OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
China Software Developer Network
6,414,990 records exposed — Email addresses, Passwords, Usernames
ADDA
1,829,314 records exposed — Email addresses, Names, Passwords, Phone numbers
CodeStepByStep
103,077 records exposed — Email addresses, Names, Usernames
Exxon Mobil Corporation
340K employee records exposed via compromised HR onboarding system — global impact
Staples Inc.
Customer order data and employee information compromised in November cyberattack
Oracle Fusion Middleware
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability — Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attack
Beckett Collectibles
1,041,238 records exposed — Email addresses, Names, Phone numbers, Physical addresses and 1 more
International Kiteboarding Organization
340,349 records exposed — Email addresses, Geographic locations, Names, Usernames
Eurofiber
10,003 records exposed — Email addresses, Names, Phone numbers
Vultr
187,872 records exposed — Email addresses, Geographic locations, IP addresses, Names
Google Chromium V8
Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
Kaplan Education
230K+ people affected — SSNs and driver's license numbers stolen from test prep provider
Walmart (eCommerce)
3.5M marketplace seller records exposed via compromised Walmart Connect advertising platform
Fortinet FortiWeb
Fortinet FortiWeb OS Command Injection Vulnerability — Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via c
Datadog Monitoring Platform
240K customer APM configurations exposed via compromised CI/CD signing key
Denver Health
480K patient records stolen in targeted attack