Live disclosure tracker · updated continuously

2026 Data Breaches Year-to-Date

2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.

98B+
Records Exposed
644
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026

2026 Data Breaches Year-to-Date (644 indexed)

high · tech · Apr 13, 2026

Microsoft Windows

Microsoft Windows Out-of-Bounds Read Vulnerability — Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation

View incident → Original disclosure Indexed 2 weeks, 5 days ago
high · tech · Apr 13, 2026

Microsoft Exchange Server

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability — Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

View incident → Original disclosure Indexed 2 weeks, 5 days ago
medium · tech · Apr 13, 2026

GTA-maker Rockstar Games

Joe Tidy reports: Grand Theft Auto developer Rockstar Games has been targeted for a second time in three years by hackers. The data breach affecting the gaming giant was reported by cybersecurity news outlets on Saturday

View incident → Original disclosure Indexed 2 weeks, 5 days ago
critical · other · Apr 13, 2026

MN: Spring Lake Park Schools

Spring Lake Park Today reports: Spring Lake Park Schools in Minnesota were forced to close on Monday due to a suspected ransomware attack that disrupted the district’s computer systems. Local authorities are invest

View incident → Original disclosure Indexed 2 weeks, 5 days ago
critical · healthcare · Apr 11, 2026

Brockton Hospital still dealing

Yesterday, Bryan Lambert reported:  Health care providers at Brockton Hospital are preparing to work off paper, not computers, for the next two weeks as the health care hub deals with an ongoing cybersecurity incident. T

medium · finance · Apr 10, 2026

EngageLab SDK flaw opens door

A flaw in EngageLab SDK exposed up to 50M Android users, including 30M crypto wallets, letting apps bypass security and access private data. Microsoft researchers found a critical flaw in EngageSDK that lets apps bypass

View incident → Original disclosure Indexed 3 weeks, 1 day ago
medium · legal · Apr 10, 2026

Silent Ransom Group

Jones Day wasn’t the only big law firm to recently fall prey to threat actors variously known as Silent Ransom Group, Luna Moth, Chatty Spider, or UNC3753. DataBreaches will refer to them as the Silent Ransom Group

View incident → Original disclosure Indexed 3 weeks, 1 day ago
medium · government · Apr 10, 2026

UK says it

A Russian attack submarine and vessels from the country’s Main Directorate of Deep Sea Research (GUGI) were involved in what the UK Ministry of Defence called “nefarious activity over critical undersea infrastructure els

View incident → Original disclosure Indexed 3 weeks, 1 day ago