January 2026 proved to be one of the most consequential months in recent cybersecurity history. From high-profile retail and tech giants to dating apps and fitness platforms, a staggering number of organizations saw sensitive data exposed, stolen, or sold on underground forums. In this comprehensive overview, we trace every major breach we track from January 2026—drawing on our BreachHistory database and public reporting—and explain what happened, why it happened, and what it means for affected users.
Executive summary
Our database records 11 separate breach incidents tied to January 2026, impacting more than 100 million records across 10+ organizations. The month was dominated by:
- ShinyHunters — The prolific threat group struck Match Group (Tinder/Hinge) and Panera Bread, exploiting API weaknesses and stolen credentials.
- Ransomware and extortion — Nike (WorldLeaks), Under Armour/MyFitnessPal (Everest), and others faced data theft and extortion demands.
- Misconfiguration and credential theft — Target suffered a dual blow: exposed source code and infostealer-compromised employee workstations.
- Legacy data resurfacing — Instagram’s BreachForums leak was tied to older API harvesting, while 2024 data resurfaced Jan 2026.
Major incidents by date
January 29 — Nike: 1.4 TB internal data breach
The sportswear giant confirmed it was investigating a potential breach after the WorldLeaks extortion group claimed to have stolen and published approximately 1.4 TB of internal data. The leak, posted to WorldLeaks’ site in late January, reportedly included ~188,000 files: design schematics (including Jordan SP27 materials), bills of materials, R&D documents, factory audits, manufacturing resources, and strategic presentations.
Root cause: Unauthorized access to internal systems; no confirmed exposure of customer financial data at the time of reporting. WorldLeaks operates as a pure data-extortion group rather than traditional ransomware.
Data compromised: Employee records, business data, internal files, intellectual property.
Reference: Nike 2026 breach on BreachHistory
January 26 — Match Group (Tinder, Hinge, OkCupid): ShinyHunters API scrape
ShinyHunters published claims on BreachForums that they exfiltrated Match Group data from Tinder, Hinge, OkCupid, and Match. The initial dump was reported at ~1.7 GB (~10 million records in some accounts; our database records ~85,000 records for the API scrape specifically). Reporting suggested attackers abused an Okta SSO compromise and accessed Match’s AppsFlyer marketing analytics instance and cloud storage.
Root cause: API vulnerability exploited by ShinyHunters; alternative reporting cites Okta SSO and marketing analytics platform access.
Data compromised: User preferences, dating app data; samples also showed user IDs, IPs, advertising/mobile analytics data, profile/match logs, subscription payer IDs, and internal documents.
Match Group confirmed a security incident and stated a “limited amount” of user data was stolen, with no evidence that credentials, financial info, or private messages were accessed.
Reference: Match Group 2026 breach on BreachHistory
January 25 — Panera Bread: 9.1M administrative credential compromise
Panera Bread was hit by a breach that exposed millions of customer records. ShinyHunters claimed access via Microsoft Entra (SSO); independent analyses pointed to weak authentication and insecure API endpoints. Have I Been Pwned and SecurityAffairs confirmed approximately 5.1 million affected accounts; other reports and the threat actor claimed up to 14 million records (760 MB compressed). Our database records the administrative credential compromise at 9.1 million records.
Root cause: Compromised administrative credentials; unauthorized cloud access; insecure API and weak auth also cited.
Data compromised: Names, emails, phone numbers, addresses, loyalty rewards, partial payment info; 5.1M customer emails plus PII for ~26,000 employees in some reports.
Reference: Panera Bread 2026 breach on BreachHistory
January 19 — Target: Employee workstation infostealer compromise
Infostealer logs from a compromised Target employee workstation were discovered. Malware had captured session cookies and credentials for Confluence, Jira, and IAM portals, potentially enabling further lateral movement. This incident was separate from but temporally close to the source code leak.
Root cause: Infostealer malware on employee workstation; credential and session cookie theft.
Data compromised: Session cookies, credentials, Confluence/Jira/IAM access.
Reference: Target 2026 infostealer breach on BreachHistory
January 12 — Target: Proprietary source code & documentation leak
A threat actor posted samples of Target’s internal repositories on a public Gitea instance, claiming to sell the full archive (~860 GB). Multiple current and former Target employees confirmed the leaked code matched real internal systems, referencing “BigRED,” “TAP [Provisioning],” proprietary codenames, Hadoop datasets, and Vela-based CI/CD tooling. The exposure was attributed to misconfigured access controls that allowed internal Git repositories to be exposed to the public internet.
Root cause: Misconfigured access controls; internal Git repositories exposed to public internet.
Data compromised: Source code, architectural blueprints, API metadata, tens of thousands of files.
Target restricted access to its enterprise Git server (git.target.com) after disclosure.
Reference: Target 2026 source code breach on BreachHistory
January 9 — Instagram: BreachForums leak (17.5M records)
A dataset titled “INSTAGRAM.COM 17M GLOBAL USERS — 2024 API LEAK” was posted to BreachForums in early January (actor “Solonik”), claiming ~17–17.5 million records. The data reportedly included usernames, display names, user IDs, email addresses (~6.2M unique), international phone numbers, and partial geo data. Researchers concluded the data was harvested via an Instagram API exposure in 2024 and resurfaced in January 2026. A spike in unsolicited password-reset emails followed; Meta fixed an issue allowing external triggering of reset emails and denied a systems breach.
Root cause: BreachForums leak; data originally harvested via API exposure in 2024.
Data compromised: Email, phone, username, profile data.
Reference: Instagram 2026 BreachForums leak on BreachHistory
January 2026: Additional tracked incidents
The following breaches are also recorded in our database with January 2026 dates. Many were reported to Have I Been Pwned or similar sources; technical details vary in completeness. Note: Incidents that occurred in late 2025 (SoundCloud, Raaga, Pass'Sport, Substack, BreachForums, WhiteDate) or February 2026 (Toy Battles) have been excluded from this January roundup and appear under their actual breach dates in our database.
Company Records Breach link Under Armour (MyFitnessPal)72.7MView breach Panera Bread (additional)5.1MView breach Instagram (additional)6.2MView breach Betterment1.4MView breach Association Nationale des Premiers Secours5.6KView breachNotable context: Under Armour, Betterment
Under Armour / MyFitnessPal — The Everest ransomware group claimed responsibility for a breach exposing ~72.7 million MyFitnessPal customer records (breach Nov 2025; 72M sample posted Jan 22, 2026). Data included names, emails, dates of birth, genders, locations, and purchase/loyalty info. Under Armour stated it was “aware” of the claims and investigating; the breach was added to Have I Been Pwned.
Betterment — A social engineering attack in January 2026 gave attackers access to internal messaging systems; they used it to send fraudulent “crypto” scam messages. ~1.4 million customer records (names, emails, and in subsets: phone numbers, addresses, DOB, job/employer info) were exposed.
Root causes: What went wrong?
- API and credential misuse — ShinyHunters repeatedly exploited API vulnerabilities and stolen/compromised credentials (Okta, Microsoft Entra) to access marketing analytics, cloud storage, and customer databases.
- Misconfiguration — Target’s internal Git repositories were exposed to the public internet due to access control failures.
- Infostealer malware — Employee workstations infected with infostealers led to session cookie and credential theft (Target).
- Data extortion — Groups like WorldLeaks and Everest shifted from traditional ransomware to pure data theft and extortion.
- Legacy exposure — Instagram’s data came from an older API leak.
- Social engineering — Betterment’s incident showed human compromise as a vector.
Recommendations for affected users
- Change passwords, especially for accounts that may have been reused across breached services.
- Enable multi-factor authentication (MFA) wherever possible.
- Monitor for phishing and targeted scams using exposed contact details.
- Use a password manager to avoid credential reuse.
- Check Have I Been Pwned to see if your email appears in known breaches.
Conclusion
January 2026 underscored the continued convergence of extortion, API abuse, credential theft, and misconfiguration as primary drivers of large-scale breaches. Our BreachHistory database tracks these incidents to help defenders, researchers, and users understand patterns, timelines, and recurrence. For detailed breach timelines, records exposed, and technical writeups, search any company on BreachHistory or browse the links above.