Looking for a complete SAP data breaches list? This page answers common searches like "SAP hacked," "SAP breach history," and "list of SAP data breaches" with a verified timeline, record counts, root causes, and step-by-step guidance if you may have been affected.
SAP data breach history: Misconfigured servers and npm supply-chain pivots on SAP’s CAP stack show ERP vendors face modern cloud-era risk. BreachHistory indexes 2 verified or attested incidents tied to SAP, spanning 2023–2026. This page is a complete, searchable timeline—not a single event—linking every catalog row with context on scale, root cause, and what users should do when a new SAP notice drops.
Why SAP stays on breach trackers
Global tech brands combine massive user bases, high-value intellectual property, and complex supply chains. Attackers target SAP for credentials, source code, CRM exports, and employee directories. When you read headlines about "SAP hacked," the incident may be a consumer PII leak, a developer artifact exposure, or a third-party SaaS tenant breach—each with different remediation steps.
Data breaches list — SAP
Below are the major incidents in our catalog, newest first. Record counts use company, regulator, or Have I Been Pwned attestation where available; actor-only marketing shows as "Unverified / not disclosed."
- 2026 — SAP — CAP npm packages compromised (TeamPCP-style; infostealer preinstall; Apr) (Unverified / not disclosed records)
- 2023 — Unsecured server — 6,900 employee and partner emails (7K+ records)
Biggest and most consequential incidents
2023 Unsecured server — 6,900 employee and partner emails
Approximately 6,900 names and email addresses from SAP employees, partners, and customers were exposed through an unsecured server without requiring hacking. About 6,630 were @sap.com addresses, while roughly 270 were private data from customer and partner employees. Full incident record →
2026 SAP — CAP npm packages compromised (TeamPCP-style; infostealer preinstall; Apr)
On April 29, 2026, BleepingComputer, Aikido, and Socket reported that several official SAP npm packages supporting the Cloud Application Programming Model (CAP) and Cloud MTA Build Tool—@cap-js/sqlite v2.2.2, @cap-js/postgres v2.2.2, @cap-js/db-service v2.10.1, and mbt v1.2.48—were trojanized with malicious preinstall scripts launching Bun-based loaders and obfuscated JavaScript stealers. The malware harvested npm and GitHub tokens, SSH keys, and cloud/CI secrets (including memory scraping on GitHub Actions workers… Full incident record →
By the numbers (catalog snapshot)
- 2 incidents indexed under SAP on BreachHistory
- 7K+ combined attested records across rows with disclosed numerators (many incidents overlap or count emails—not unique people)
- 2023 — year of the largest attested row in our catalog
Patterns in SAP's breach history
- Credential and session theft — Phishing, stuffing, and OAuth token abuse recur across tech platforms.
- Cloud misconfiguration — S3 buckets, misconfigured APIs, and file shares expose data without a traditional "hack."
- Extortion without precise counts — Ransomware and leak-site actors often publish before victims confirm scope.
- Supply-chain spillover — npm, SDK, and CRM tenant breaches affect SAP customers even when corporate HQ databases stay intact.
What to do if you used SAP
- Enable multi-factor authentication on every SAP account and linked SSO identity.
- Check Have I Been Pwned when new SAP headlines appear.
- Rotate passwords that were reused on email, banking, or work SSO.
- Watch for phishing that cites real breach details (order numbers, usernames) to appear legitimate.
- Follow official SAP security communications—not SMS links from unknown numbers.
Related searches
- SAP data breach list
- Has SAP been hacked?
- SAP hack history
- SAP data leak timeline
- How many times has SAP been breached?
- SAP breach records on BreachHistory
FAQ
How many data breaches has SAP had?
BreachHistory indexes 2 verified or attested SAP data breaches spanning 2023–2026. Counts vary when researchers merge scraping, misconfiguration, and ransomware as separate events.
What is the biggest SAP data breach?
The largest attested incident in our catalog is 7K+ records (Unsecured server — 6,900 employee and partner emails). See the full timeline for sources and remediation details.
Has SAP been hacked?
Yes — SAP appears on breach trackers with 2 indexed incidents including Unsecured server — 6,900 employee and partner emails. This page links every catalog row with primary sources and what users should do if affected.
Does SAP send data breach notifications?
Regulated markets require consumer notices for many PII events. Not every source-code or scraping story triggers email alerts—read each incident row for notification status.
Explore every SAP incident on BreachHistory
Browse the full catalog: SAP breach records
Compiled from BreachHistory data/breaches.json and primary sources linked on each incident page. Updated 2026-06-15.