Skip to content
Unlisted Report logoUnlisted ReportSubscribe

Breach tracker

The latest confirmed and reported data breaches

OrganisationRecordsData exposedDateStatus
Global retailer89MNames, addresses, partial cardsOct 1Confirmed
Health insurer4.2MClaims, policy numbersSep 30Notifying
Telecom carrier12MSIM & call recordsSep 29Investigating
Fintech app1.1MTransaction historiesSep 28Patched
Hotel chain640KPassport scansSep 25Confirmed
University38KPayroll, research filesSep 29Contained

12,400+

Vulnerabilities disclosed this year

$4.9M

Average cost of a data breach

204 days

Average time to identify a breach

68%

Breaches involving human error

Vulnerability watch

Critical flaws security teams should patch this week

CVE-2026-4411CVSS 9.8

Remote code execution in enterprise VPN gateways

Actively exploited. Patch or disable the web portal now.

CVE-2026-3907CVSS 9.1

Authentication bypass in a popular file-transfer server

Exploit code is public; data theft reported.

CVE-2026-3650CVSS 8.8

Browser extension autofill flaw exposes saved passwords

Fixed in the latest release — update automatically.

CVE-2026-3312CVSS 8.1

Privilege escalation in widely used router firmware

Vendor firmware update available for most models.

Watch & listen

The Unlisted Report podcast and video briefings

▶

Podcast · Ep. 42

Inside the 89-million-record retail breach

38 min

▶

Video · Ep. 41

How ransomware gangs pick their victims

12 min

▶

Podcast · Ep. 40

Passkeys, explained without the jargon

27 min

Browse by topic

Have a tip?

Seen a breach, leak or exposed database? Our newsroom reviews every confidential tip.

Contact the newsroom →