Ally Financial (Auto Lending)
1.1M auto loan records exposed via compromised dealer management system integration
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
1.1M auto loan records exposed via compromised dealer management system integration
150K enterprise zero-trust configurations exposed — test environment breach spread to prod
620K Circle K loyalty customer records stolen from Canadian convenience store operator
520K alumni and donor records exposed via compromised advancement office database
4.3M individuals affected via Fortune 500 contractor — multiple state governments impacted
10M+ dating records stolen by ShinyHunters via Okta SSO social engineering
320K credit card applicant records exposed via compromised underwriting platform
2.8M customer billing records and account metadata exposed via misconfigured internal tool
4.7M customer records exposed via compromised third-party payment processing vendor
Microsoft Windows Information Disclosure Vulnerability — Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
1.9M customer records stolen from payment processing system via skimming malware at warehouses
1.8M employee benefits records from Canadian health benefits platform compromised
890K patient vaccination records exposed via misconfigured COVID-era data sharing portal
Gogs Path Traversal Vulnerability — Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
Client M&A deal documents and litigation files exposed via compromised document management system
75K employee records leaked by former staff to German newspaper — payroll, SSNs, complaints
6,215,150 records exposed — Display names, Email addresses, Geographic locations, Phone numbers and 1 more
APM and logging data from 340 enterprise customers exposed via compromised CI/CD pipeline
2.3M guest records compromised in phishing campaign targeting hotels
670K citizen records exposed
670K patient records exposed in vendor breach
2.1M patient records stolen in second cyberattack
780K banking records stolen
450K mining records compromised