In August 2026, the Alcon eye care company was named in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data allegedly…
Tag: Have I Been Pwned latest breaches
Brinks Home – 732,162 breached accounts
In July 2026, Brinks Home was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data they alleged was taken…
Exact Sciences – 10,869,543 breached accounts
In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters “pay or leak” extortion campaign . The group claimed to…
Inter-Con Security – 276,114 breached accounts
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was…
SplitVPN – 865,336 breached accounts
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records,…
Houston City College – 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters “pay or leak” extortion campaign . Data allegedly obtained from the college was later…
Houston City College – 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic…
Suno – 55,282,226 breached accounts
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used…
Paidwork – 23,272,765 breached accounts
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M…
Fluke – 821,100 breached accounts
In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact…
Goose Creek – 6,574,121 breached accounts
In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company’s customers, claiming the company had a security vulnerability and suffered a data breach. The data was…
Glendale Community College – 793,925 breached accounts
In June 2026, Glendale Community College was the target of a ShinyHunters “pay or leak” extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including…
Moody Bible Institute – 2,303,416 breached accounts
In June 2026, Moody Bible Institute was targeted by a ShinyHunters “pay or leak” extortion campaign. Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other…
Sysco – 2,691,852 breached accounts
In June 2026, the food distribution company Sysco was targeted by a ShinyHunters “pay or leak” extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information…
American Tower – 216,601 breached accounts
In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees,…
Madison Square Garden Sports – 9,796,738 breached accounts
In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters “pay or leak” extortion campaign. The group later published the alleged data, which included almost 10M unique email addresses spanning staff and…
JCPenney – 368,418 breached accounts
In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters “pay or leak” extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed…
Ralph Lauren – 139,903 breached accounts
In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation’s Salesforce instance, including 140k unique email addresses…
Operation Endgame 4.0 – 153,527 breached accounts
On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust,…
CFGI – 248,235 breached accounts
In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters “pay-or-leak” extortion campaign. The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k unique email addresses, names, phone numbers…