Unauthorised access, from first foothold to leak-site listing. Every file carries a confidence grade, an artefact count, and the questions we have not answered yet.
Prescriptions, appointments and medication histories for around 19 million people were taken from MyDr, a platform used by more than 12,000 Polish medical facilities. Poland’s digital affairs minister says there is no indication of an external attack.
A dispute about volume is a dispute about the wrong axis. Ask instead which fields can be reissued.
Three compromised laptops, corporate data taken, and a filing that answers the shareholder question only.
Materiality asks whether an investor would want to know. Whether patients are harmed is a different question.
It does not mean SQL injection is rare. It means the disclosure regime records who was affected and not how.
Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.
The final count on the Conduent intrusion landed above 62 million people — third-largest in US healthcare history, at a processor most of them have never heard of.
Customer data leaked at a retailer serving 4.8 million. That figure is the customer base, not the affected count — and the distinction keeps getting lost.
6.9 million driver’s licence numbers, a field that is neither ceremonially protected nor practically replaceable.
The remedy is 24 months of monitoring. The scanned passport stays valid for ten years.
Twenty-seven thousand employees queued in person to reset a password. That is what a broken identity system looks like.
A containment shutdown that locked members out of retirement accounts, and a credit union suing its own provider over the standards it contracted for.
A compromise at a third-party ticketing platform used by EY’s IT staff. Ticket attachments hold whatever was needed to reproduce the problem.
Up to six million customers exposed in 2025; records published in 2026. Notification law assumes an incident that ends.
Three million licence holders through a vendor the state chose. The data does not know it was collected for a fishing permit.
A third-party software flaw reached email accounts across six Japanese providers. Choosing a different ISP bought no independence.
An Oracle E-Business Suite flaw exploited in August 2025, found in June 2026. The records were employees’: identity documents, bank details, health data.
The team that named the cluster was also caught by it, and published. That removes the easiest excuse for ignoring the technique.
A claimed 2.2 million records. Long-lived brands hold data collected across decades, terms and regulatory regimes nobody has reconciled.
A claimed 8.8 TB from legacy patient archives. Every property that makes a legacy system low priority makes it high value.
Extortion refused, 234 GB published, 2.6 million addresses verified. The refusal produced a record that payment never does.