PostHole
Compose Login
You are browsing us.zone2 in read-only mode. Log in to participate.
rss-bridge 2026-01-29T11:10:31+00:00

Mega Breaches in 2026

Here’s a collection of the main mega breaches (that is data breaches with more than one million records compromised and possibly leaked) during 2026. The information is derived from the cyber attacks timelines that I published, normally, on a bi-weekly basis.


  • Post published:January 29, 2026
  • Reading time:1 min read

Views: 7,198

Last modified: February 27, 2026

[View Paolo Passeri's LinkedIn profile]

Connect on Linkedin

Follow me on X

Follow me on Bluesky

[View Paolo Passeri's Mastdon profile]

Connect on Mastodon

Here’s a collection of the main mega breaches (that is data breaches with more than one million records compromised and possibly leaked) during 2026. The information is derived from the cyber attacks timelines that I published, normally, on a bi-weekly basis.

The timeline will be updated as new mega breaches are discovered.

Mega Breaches 2026 **

No Data Found

Top 20 Breaches (Millions Records) **

No Data Found

Top Sectors (Number of Records) **

No Data Found

Top Sectors (Number of Breaches) **

No Data Found

Enjoy the data, and thanks for sharing it, and supporting my work in spreading the risk awareness across the community. Also, don’t forget to connect on Linkedin, or even follow @paulsparrows on X (formerly Twitter), psparrows.bsky.social on Bluesky, or @ppasseri@Infosec.exchange on Mastodon for the latest updates.

**BE NOTIFIED OF NEW BLOG POSTS: SUSCRIBE!

SUPPORT MY WORK!
MAKE A DONATION

Creating the timelines is a very time-consuming task.

Any little helps!

POPULAR POSTS

With this new project I am going to track the biggest data breaches of 2021 extracted from my cyber attack timelines.

In the first half of February 2026 I collected 96 events (6.4 events/day) with a threat landscape dominated by malware with 33%, (it was 38% in the second half of last month, once again ahead of ransomware (up to 20% from 14%), and account takeovers ...

In the second timeline of November 2024 I collected 117 events (7.8 events/day) with a threat landscape dominated by malware

It's time to publish the statistics related to the main cyber attacks occurred in June and derived from the two corresponding timelines (Part I and Part II). The summer is here and apparently crooks are partially taking a break, since I collected 96 events (vs ...

It's time to publish the first timeline of October, covering the main cyber attacks occurred between 1 and 15 October 2016. So the good news is that the decreasing trend is confirmed since these first two weeks have shown the lowest number of cyber attacks ...

[The Biggest Data Breaches of 2022

[Leaky Buckets: a List of Cloud Misconfigurations

Click Here](https://www.hackmageddon.com/2021/02/01/leaky-buckets-a-list-of-cloud-misconfigurations/)

[Cloud-Native Threats in 2021

Date ReportedDate OccurredDate DiscoveredAuthorTargetDescriptionAttackTarget ClassAttack ClassCountryLinkInitial AccessRecords RawRecords
04/01/2026Late 2025 / Early 2026-Crimson CollectiveBrightspeedCrimson Collective claims to have breached US fiber provider Brightspeed, allegedly exfiltrating personal data for over one million customers. The stolen data includes names, addresses, emails, and payment details. Brightspeed is investigating the claims, though the hackers shared proof of the breach with dark web monitoring experts.RansomwareInformation/CommunicationCyber CrimeUSUnknown1,001.000.000,00
09/01/2026As early as August 202409/01/2026dk0mArmenian GovernmentArmenian authorities are investigating the alleged sale of 8 million government records on a hacker forum for $2,500. The dataset reportedly includes official notifications from police and judicial bodies. While officials deny a direct email infrastructure breach, they suggest data may have originated from a civil litigation platform.UnknownPublic AdministrationCyber CrimeAMUnknown8,008.000.000,00
09/01/202609/01/202609/01/2026UnknownBettermentFintech firm Betterment confirms a data breach after attackers exploited a third-party marketing platform to send fraudulent "triple your crypto" scam emails. While the attackers accessed customer contact details—including names and birthdates—Betterment maintains that core systems, login credentials, and investment accounts remain secure and were not directly compromised.Account TakeoverFintechCyber CrimeUSSupply Chain Compromise1,441.435.174,00
11/01/2026Early January 2026Early January 2026UnknownEndesaSpanish energy giant Endesa suffers a major data breach after a threat actor gained unauthorized access to its commercial platform. The attacker exfiltrated roughly 1.05 terabytes of sensitive data, including customer identification, contact details, DNI numbers, and payment information (IBANs), impacting millions of electricity and gas customers in Spain.UnknownElectricity/GasCyber CrimeESUnknown20,0020.000.000,00
11/01/2026During 2022?07/01/2026UnknownInstagramMeta (Instagram) denies claims of a data breach after a threat actor alleged the theft of 17.5 million user records. The company maintains its systems are secure, suggesting the "leak" is likely aggregated public data or recycled information from historical third-party breaches rather than a fresh hack of its infrastructure. According to several security researchers the breach comes from an alleged 2022 API leak.UnknownInformation/CommunicationCyber CrimeUSMisconfiguration?17,0217.017.213,00
21/01/2026During November 202521/01/2026EverestUnder ArmourUnder Armour investigates claims of a data breach after a threat actor leaked a database allegedly containing millions of customer email addresses. While the company confirmed it is looking into the matter, it has not yet verified the authenticity of the leaked data or the specific source.RansomwareWholesale/RetailCyber CrimeUSUnknown72,0072.000.000,00
26/01/2026During December 2025During December 2025ShinyHunters (a.k.a. UNC6040, SLSH, Scattered LAPSUS$ Hunters)SoundCloudThreat actors have stolen the personal and contact information belonging to over 29.8 million SoundCloud user accounts after breaching the audio streaming platform's systems.UnknownArts/EntertainmentCyber CrimeDEUnknown29,8029.800.000,00

[...]


Original source

Reply