Data Breach Tracker
Breaches, exposures, and the companies disclosing them, tracked as they surface across reporting and threat-actor activity. A standing reference for who was hit, what was exposed, and what is being claimed.
- krybit
Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's…
- shinyhunters
ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authoritie…
- rhysida
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads. The group threatens to publicly distribute exfiltrated data i…
- termite
Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers includ…
- A-Plus Software Limited
We Breached A-plus through a sql injection vulnerability and downloaded everything in there backend. We gained access to there system on 08/18/2026 The following data was stolen: 1. Website User Data (`usr.csv`) - This file contains the administrative backend infrastructure for t…
- The Liberty Group
About The Liberty Group Companys offerings include local, long distance, and international moving, lab relocation services, and logistics solutions. They cater to a diverse range of clients, providing professional and comprehensive assistance to both residential and commercial cu…
- Design-Aire Engineering, INC
About Design-Aire Engineering, INC Design-Aire Engineering specializes in mechanical, electrical, plumbing, and energy engineering services. They focus on providing innovative and sustainable solutions for their clients. The company serves a diverse range of clients, including th…
- Design-Aire Engineering, INC
Design-Aire Engineering, INC has suffered a cyberattack on its service systems, resulting in the theft of approximately 377GB of sensitive data. The breached information includes employees' personal data and detailed architectural plans of clients' buildings.
- Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen reported a data breach where threat actors stole corporate data and patient information stored in cloud systems operated by third-party service providers. The breach exposed patient health and…
- RingCentral data breach exposed info of 1.6 million accounts
…The data breach details were exposed, according to the data breach notification service Have I Been Pwned.
- UK’s state investments agency hit by data breach
The UK’s state investments agency, UK Government Investments (UKGI), experienced a data breach exposing sensitive information and contact details of 51 government officials for 40 hours. The breach also compromised high…
- Valve notifies Steam hardware customers of a data breach
Video game publisher Valve is notifying its Steam hardware customers in Europe of a data breach. Hackers stole customer data after compromising the shipping partner, CEVA Logistics.
- Zenith Bank investigates data breach
Zenith Bank is investigating a data breach and has activated its incident response protocols, intensifying cybersecurity and remediation efforts following the discovery of the incident.
- Semiconductor chip titan Analog Devices reports data breach
Analog Devices, a Massachusetts-based semiconductor chip company, reported a data breach in which intruders exfiltrated data from its networks earlier this summer. The scope of the incident remains under investigation.
- South Korea fines telco giant KT $39 million for customer data breach
South Korea's Personal Information Protection Commission (PIPC) fined telecommunications company KT Corporation $39 million (KRW 53.979 billion) for data protection violations. The penalty addresses breaches related to customer data security.
- Canadian hacker pleads guilty in Snowflake data breach case, stealing data and extorting people for millions
A Canadian man has pleaded guilty to four charges, including computer fraud, wire fraud, aggravated identity theft, and conspiracy, following a data breach at Snowflake Inc. He was involved in stealing data…
- Is a breach listed here confirmed?
- Not always. Some entries are company disclosures; others are claims made by threat actors. The Nexus surfaces them alongside reporting so you can assess corroboration yourself.
- How is this different from the ransomware tracker?
- The ransomware tracker follows extortion groups and their victims; this page covers data exposure broadly, including breaches with no ransom involved.