CIBC (Canada)
1.2M customer records compromised via third-party mortgage processing vendor
Banks, payment processors, fintechs, and crypto exchanges sit at the top of every threat actor target list. Below is every finance-sector breach LeakTrace has indexed.
1.2M customer records compromised via third-party mortgage processing vendor
967,178 records exposed — Dates of birth, Email addresses, Names, Phone numbers and 1 more
780K customer records from wealth management division exposed via insider threat
480K investor records from Canadian asset manager exposed via compromised fund admin portal
Campaign combines stolen Telegram accounts, fake Zoom calls and ClickFix attacks to deploy infostealer malware
680K European cardholder records exposed via compromised transaction processing node
450K customer records exposed in credential harvesting
2.8M customer trading records and SSNs exposed via social engineering attack on support staff
Payment gateway ransomware attack causes widespread merchant and municipal outages
180K client portfolio records accessed by compromised contractor with elevated privileges
890K insurance records stolen in targeted attack
3.2M credit card applicant records exposed via new cloud misconfiguration — second incident
780K advisor and client records exposed
1,435,174 records exposed — Dates of birth, Device information, Email addresses, Employers and 5 more
340K reinsurance policyholder records from global operations exposed in targeted attack
1.4M merchant records compromised in insider incident
1.5M postal banking records exposed
1.8M customer records from private banking division exposed via compromised document management
920K brokerage account records exposed via compromised data analytics vendor
1.2M bank accounts potentially compromised in national registry breach
1.9M customer records from wealth management division exposed via partner API vulnerability
1.6M customer records from US and UK operations exposed via MOVEit successor vulnerability
680K wealth management client records exposed via misconfigured cloud storage bucket
1.1M tokenized card records exposed via vulnerability in token provisioning service