Critical Data Breaches

22 reports

McGraw Hill

Apr 16, 2026

Critical
13,500,136 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In April 2026, education company McGraw Hill confirmed a data breach following an extortion attempt . Attributed to a Salesforce misconfiguration, the company stated the incident exposed "a limited set of data from a webpage hosted by Salesforce on its platform". More than 100GB of data was later pu...

Read Report

SongTrivia2

Apr 4, 2026

Critical
291,739 accounts exposed
Email Addresses Passwords Usernames Names

In April 2026, the music trivia platform SongTrivia2 suffered a data breach that was subsequently published to a public hacking forum . The data contained a total of 291k unique email addresses sourced from either Google OAuth logins or accounts created on the site, the latter also containing bcrypt...

Read Report

SUCCESS

Apr 1, 2026

Critical
253,510 accounts exposed
Email Addresses Passwords Names Phone Numbers +2 more

In March 2026, the personal development and achievement media brand SUCCESS suffered a data breach . The incident exposed 250k unique email addresses along with names, IP addresses, phone numbers and, for a limited number of staff members, bcrypt password hashes. The data also included orders contai...

Read Report

BreachForums Version 5

Mar 27, 2026

Critical
339,778 accounts exposed
Email Addresses Passwords Usernames Names

In March 2026, a breach of one of the many iterations of the BreachForums hacking forum known as "Version 5" was publicly disclosed . The incident exposed 340k unique email addresses along with usernames and argon2 password hashes.

Read Report

Scuf Gaming

Mar 26, 2026

Critical
128,683 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In June 2015, custom gaming controller maker Scuf Gaming suffered a data breach . The incident exposed 129k unique email addresses along with usernames, display names, IP addresses and password hashes.

Read Report

Sound Radix

Mar 26, 2026

Critical
292,993 accounts exposed
Email Addresses Passwords Names Credit Cards

In March 2026, the audio production tools company Sound Radix disclosed a data breach that they subsequently self-submitted to HIBP . The incident impacted 293k unique email addresses and names. Sound Radix advised that it is possible that additional data including hashed passwords may have been exp...

Read Report

RuneScape Boards

Mar 23, 2026

Critical
222,762 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In around 2011, the now defunct RuneScape Boards forum (also known as RSBoards) suffered a data breach that was later redistributed as part of a larger corpus of data . The vBulletin-based service exposed 223k unique email addresses along with usernames, IP addresses and salted MD5 password hashes.

Read Report

Aura

Mar 18, 2026

Critical
903,080 accounts exposed
Email Addresses Passwords Names Phone Numbers +2 more

In March 2026, the online safety service Aura disclosed a data breach that exposed 900k unique email addresses . The data was primarily associated with a marketing tool from a previously acquired company, with fewer than 20k active Aura customers affected. Exposed data included names, phone numbers,...

Read Report

Baydöner

Mar 15, 2026

Critical
1,266,822 accounts exposed
Email Addresses Passwords Names Phone Numbers

In March 2026, the Turkish restaurant chain Baydöner suffered a data breach which was subsequently published to a public hacking forum . The incident exposed over 1.2M unique email addresses along with names, phone numbers, cities of residence and plaintext passwords. A small number of records also ...

Read Report

Canadian Tire

Feb 25, 2026

Critical
38,306,562 accounts exposed
Email Addresses Passwords Names Phone Numbers +3 more

In October 2025, retailer Canadian Tire was the victim of a data breach that exposed almost 42M records. The data contained 38M unique email addresses along with names, phone numbers and physical addresses. Passwords were stored as PBKDF2 hashes and for a subset of records, dates of birth and partia...

Read Report

CarGurus

Feb 21, 2026

Critical
12,461,887 accounts exposed
Email Addresses Names Phone Numbers Ip Addresses

In February 2026, the automotive marketplace CarGurus was the target of a data breach attributed to the threat actor ShinyHunters . Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, ...

Read Report

Canada Goose

Feb 17, 2026

Critical
581,877 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +2 more

In February 2026, a data breach allegedly containing data relating to Canada Goose customers was published publicly . The data contained 920k records with 582k unique email addresses and included names, phone numbers, IP addresses, physical addresses and partial credit card data, specifically card t...

Read Report

Association Nationale des Premiers Secours

Feb 10, 2026

Critical
5,600 accounts exposed
Email Addresses Passwords Names Dates Of Birth

In January 2026, a data breach impacting the French non-profit Association Nationale des Premiers Secours (ANPS) was posted to a hacking forum . The breach exposed 5.6k unique email addresses along with names, dates of birth and places of birth. ANPS self-submitted the data to HIBP and advised the i...

Read Report

Betterment

Feb 5, 2026

Critical
1,435,174 accounts exposed
Email Addresses Passwords Names Phone Numbers +3 more

In January 2026, the automated investment platform Betterment confirmed it had suffered a data breach attributed to a social engineering attack . As part of the incident, Betterment customers received fraudulent crypto-related messages promising high returns if funds were sent to an attacker-control...

Read Report

SoundCloud

Jan 27, 2026

Critical
29,815,722 accounts exposed
Email Addresses Usernames Names

In December 2025, SoundCloud announced it had discovered unauthorised activity on its platform . The incident allowed an attacker to map publicly available SoundCloud profile data to email addresses for approximately 20% of its users. The impacted data included 30M unique email addresses, names, use...

Read Report

Under Armour

Jan 21, 2026

Critical
72,742,892 accounts exposed
Email Addresses Names Dates Of Birth Genders +1 more

In November 2025, the Everest ransomware group claimed Under Armour as a victim and attempted to extort a ransom , alleging they had obtained access to 343GB of data. In January 2026, customer data from the incident was published publicly on a popular hacking forum , including 72M email addresses. M...

Read Report

Raaga

Jan 19, 2026

Critical
10,225,145 accounts exposed
Email Addresses Passwords Names Genders

In December 2025, data allegedly breached from the Indian streaming music service 'Raaga' was posted for sale to a popular hacking forum . The data contained 10M unique email addresses along with names, genders, ages (in some cases, full date of birth), postcodes and passwords stored as unsalted MD5...

Read Report

Instagram

Jan 11, 2026

Critical
6,215,150 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In January 2026, data allegedly scraped via an Instagram API was posted to a popular hacking forum . The dataset contained 17M rows of public Instagram information, including usernames, display names, account IDs, and in some cases, geolocation data. Of these records, 6.2M included an associated ema...

Read Report

BreachForums (2025)

Jan 10, 2026

Critical
672,247 accounts exposed
Email Addresses Passwords Usernames Names

In October 2025, a reincarnation of the hacking forum BreachForums, which had previously been shut down multiple times, was taken offline by a coalition of law enforcement agencies . In the months leading up to the takedown, the site itself suffered a data breach that exposed a total of 672k unique ...

Read Report

WhiteDate

Jan 6, 2026

Critical
20,363 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In December 2025, the dating website 'for a Europid vision' WhiteDate suffered a data breach that was subsequently leaked online , initially exposing 6.1k unique email addresses. The leaked data included extensive personal information such as physical appearance, income, education and IQ. A more com...

Read Report

The Botting Network

Dec 18, 2025

Critical
96,320 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In August 2012, the forum for making money with botting 'The Botting Network' suffered a data breach that exposed 96k user records . The now defunct vBulletin forum leaked 96k email addresses, usernames, dates of birth and salted MD5 password hashes.

Read Report

Web Hosting Talk

Dec 17, 2025

Critical
515,149 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In July 2016, the Web Hosting Talk forum suffered a data breach that was subsequently listed for sale . The breach of the vBulletin based forum exposed 515k user records including usernames, email addresses, IP addresses and salted MD5 password hashes.

Read Report

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.