Amtrak
2,147,679 records exposed — Email addresses, Names, Physical addresses, Support tickets
SaaS platforms, cloud providers, developer tooling, and app-layer infrastructure are concentrated attack surfaces. One tech vendor breach can expose thousands of downstream customers. Below is every tech-sector breach LeakTrace has indexed.
2,147,679 records exposed — Email addresses, Names, Physical addresses, Support tickets
13,500,136 records exposed — Email addresses, Names, Phone numbers, Physical addresses
Apache ActiveMQ Improper Input Validation Vulnerability — Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
Microsoft Office Remote Code Execution — Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially craft
Microsoft SharePoint Server Improper Input Validation Vulnerability — Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a networ
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability — Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability — Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. —
Fortinet FortiClient EMS SQL Injection Vulnerability — Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically
Adobe Acrobat and Reader Prototype Pollution Vulnerability — Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
Adobe Acrobat Use-After-Free Vulnerability — Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
1,736,520 records exposed — Email addresses, Names, Phone numbers, Physical addresses and 1 more
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability — Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code executi
106,271 records exposed — Email addresses, Social media profiles
291,739 records exposed — Auth tokens, Avatars, Email addresses, Names and 2 more
TrueConf Client Download of Code Without Integrity Check Vulnerability — TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path ca
Employee unlawfully accessed customer data over two years; €31.8m fine for breach transparency failure
Cybercriminals breached systems and stole limited set of customer and prospective customer data
Breach exposed legal emails, flight data, and banking details; data claimed on hacker forums
Cyberattack exposed 19 million personal identity records including government data
Alleged data breach involving sensitive banking and corporate information
Data breach via compromise of third-party vendor file-transfer system
165 organizations breached via compromised Snowflake credentials; ShinyHunters exploited Anodot access
Cyberattack exposed 19 million records containing personal data linked to national identity