People search SAP data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 2 SAP-linked incidents, with headline counts up to 7K+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why SAP breach history matters
SAP operates in Software (Germany). Across indexed rows, recurring themes include cloud and database misconfiguration, third-party and supply-chain exposure. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2026 — CAP npm packages compromised (TeamPCP-style; infostealer preinstall; Apr)
Cataloged incident. On April 29, 2026, BleepingComputer, Aikido, and Socket reported that several official SAP npm packages supporting the Cloud Application Programming Model (CAP) and Cloud MTA Build Tool—@cap-js/sqlite v2.2.2, @cap-js/postgres v2.2.2, @cap-js/db-service v2.10.1, and mbt v1.2.48—were trojanized with malicious preinstall scripts launching Bun-based loaders and obfuscated JavaScript stealers. The malware harvested npm and GitHub tokens, SSH keys, and cloud/CI secrets (including memory scraping on GitHub Actions workers Exposed categories include Developer and CI/CD secrets exfiltrated from machines that installed poisoned packages—no centralized consumer row count. No attested victim count is published for this row yet. See the sap-cap-npm-supply-chain 2026 record and canonical BreachHistory entry.
2023 — 6,900 employee and partner emails
Cataloged incident. Approximately 6,900 names and email addresses from SAP employees, partners, and customers were exposed through an unsecured server without requiring hacking. About 6,630 were @sap.com addresses, while roughly 270 were private data from customer and partner employees. Exposed categories include Names, email addresses. BreachHistory cites approximately 7K+ affected records in this row. See the sap2023 and canonical BreachHistory entry.
Patterns and analysis
- Cloud and database misconfiguration — appears across multiple SAP catalog entries; prioritize controls that address this class of failure.
- Third-party and supply-chain exposure — appears across multiple SAP catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Bookmark the SAP company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/sap · Latest: sap-cap-npm-supply-chain2026.
Sources: BreachHistory catalog (2 rows for SAP), company and regulator disclosures cited in individual breach records.