Couche-Tard (Circle K Canada)
1.2M customer payment records exposed in POS breach
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
1.2M customer payment records exposed in POS breach
280K restructuring records stolen
81M citizen health records from Aadhaar-linked database exposed via API vulnerability
3.2M customer records exposed via SaaS vendor breach affecting loyalty program data
1.7M ITSM records from enterprise customers exposed via zero-day in Washington DC instance
Wiz Security claims Moltbook misconfiguration allowed full read and write access
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability — GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized exte
Sangoma FreePBX OS Command Injection Vulnerability — Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known
Sangoma FreePBX Improper Authentication Vulnerability — Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability — SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow a
2.15M customer records from connected vehicle services exposed via misconfigured cloud database
340K patient records compromised
1.4M merchant records compromised in insider incident
1.5M postal banking records exposed
3.3M employee records — background screening provider
450K resident records compromised in vendor breach
6.5M client records from BPO division exposed via compromised McCamish Systems subsidiary
290K patient records stolen
1.8M patient records exposed in supply chain attack
5,112,502 records exposed — Email addresses, Names, Phone numbers, Physical addresses
1.8M customer records exfiltrated from subsidiary Optus-linked systems via shared infrastructure
1.4M member pharmacy and benefits records accessed via compromised business associate
210K employee records and joint venture data compromised via compromised collaboration platform
2.1M citizen records from drivers license and health card renewal system compromised