Stripe Inc. (Merchant Data)
1.5M merchant processing records exposed via compromised internal dashboard access
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
1.5M merchant processing records exposed via compromised internal dashboard access
105,814 records exposed — Email addresses, Purchases, Usernames
1.4M insurance policyholder records exposed via compromised claims processing system
85K client records from Canadian offices exposed via supply chain compromise
820K patient lab results exposed via misconfigured API following Quest Diagnostics merger
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability — Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerabil
430K employee and business partner records stolen in DarkAngels ransomware attack
Google Skia Out-of-Bounds Write Vulnerability — Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerabil
1.8M Creative Cloud subscriber records exposed via compromised customer success platform
2.3M student records from 23 campuses exposed via compromised PeopleSoft instance
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability — n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for
1.3M customer records stolen via compromised third-party data analytics platform
3.8M customer records exposed in cross-border data breach affecting Canadian and US operations
1.2M clinical trial participant records exposed via compromised research data platform
Over 250 legitimate websites, including news outlets and a US Senate candidate’s official webpage, been compromised to infect visitors with infostealers, warn Rapid7 researchers
French small and medium businesses remained the organizations most targeted by ransomware in 2025
Contractor laptop with cached Gotham deployment configs and access tokens compromised
Ericsson data breach affects 15k employees/customers after third-party service provider compromise
620K policyholder records from cyber insurance division exposed in targeted attack
Prolific ShinyHunters group claims to have stolen data from nearly 400 websites in Experience Cloud attacks
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability — SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on t
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability — Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticat
1.5M patient records from Singapore public healthcare system breached for second time
2.8M PC Optimum loyalty member records stolen including purchase history and contact data