LexisNexis Legal & Professional
Customer metadata and business information accessed
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
Customer metadata and business information accessed
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability — F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
Restaurant POS system breach, customer emails exposed
750K Canadian investors' SINs and financial information
339,778 records exposed — Email addresses, Passwords, Usernames
676.8M US citizens' personal records including SSNs, names, addresses, birth dates
284,525 patient records with clinical information
192K+ student records with SSNs, birth dates, driver licenses
967K user accounts with names, birth dates, addresses, phone numbers
3.7M chat logs and 1.4M audio files exposed containing PII from AI chatbot
Aquasecurity Trivy Embedded Malicious Code Vulnerability — Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, includin
292,993 records exposed — Email addresses, Names, Passwords
128,683 records exposed — Display names, Email addresses, IP addresses, Passwords and 1 more
Langflow Code Injection Vulnerability — Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
Defense program documents and 180K employee records exposed via subcontractor email compromise
420K government contract records from Canadian IT services firm exposed in supply chain attack
A financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use Ir
340K customer records from loyalty program and online orders exposed via web app vulnerability
New Trivy Docker images 0.69.5 and 0.69.6 compromised with TeamPCP infostealer, impacting CI/CD scans
222,762 records exposed — Email addresses, IP addresses, Passwords, Usernames
1.6M enterprise customer records from S/4HANA Cloud exposed via authentication bypass
272K armed forces personnel payroll records exposed via compromised third-party payroll system
6M records from 140K+ tenants allegedly accessed via authentication bypass in legacy systems