# BreachHistory > Disclosed data-breach timeline and intelligence: search companies, read incident writeups, track records exposed, and follow verified plus labeled unverified ransomware/extortion claims. BreachHistory indexes publicly disclosed and catalogued data breaches worldwide. Pages are server-rendered HTML (crawlable without JavaScript). Prefer canonical HTTPS URLs. Unverified ransomware/extortion rows are clearly labeled in titles and writeups — do not treat actor counts as company-confirmed fact unless stated. ## Primary - [Home / search](https://breachhistory.com/): Search breach history by company name - [Blog](https://breachhistory.com/blog): Analysis and incident explainers - [RSS feed](https://breachhistory.com/feed.xml): Latest blog posts as RSS - [Sitemap](https://breachhistory.com/sitemap.xml): Full URL inventory for crawlers - [Why BreachHistory](https://breachhistory.com/why-breachhistory): Product positioning and methodology - [Platform](https://breachhistory.com/platform): Platform overview - [API access](https://breachhistory.com/api-access): API and data access - [Contact](https://breachhistory.com/contact): Contact ## Optional - [Report a breach](https://breachhistory.com/report): Submit a breach tip - [Privacy Policy](https://breachhistory.com/privacy) - [Terms of Use](https://breachhistory.com/terms) - [Cookie Policy](https://breachhistory.com/cookies) ## URL patterns - Company pages: `https://breachhistory.com/{company-slug}` — breach timeline and summary for one organization - Breach pages: `https://breachhistory.com/{company-slug}/{breach-id}` — single incident writeup, data types, references - Blog posts: `https://breachhistory.com/blog/{slug}` ## Recent blog posts - [UK DfE Breach: 607K Contact Records Stolen in Education Hack](https://breachhistory.com/blog/uk-dfe-exfilsquad-607k-contact-data-breach-july-2026): UK DfE confirms ~607,000 help-desk and Turing Scheme contact records stolen; ExfilSquad claims the theft as Digital ID trust debates intensi - [DRDO Dark-Web Claim: 31GB Defense Files Allegedly Listed for Sale](https://breachhistory.com/blog/drdo-dark-web-31gb-defense-file-sale-claim-2026): Unverified reports say a threat actor listed 31GB of alleged DRDO files for $8,000, including claimed missile-sensor electronics data. - [MCBS Breach: PEAR Hit Leaves 1.26M in HHS Count](https://breachhistory.com/blog/mcbs-pear-ransomware-1-26-million-september-2025): Atlanta medical billing firm MCBS confirmed a Sept 2025 intrusion tied to PEAR; HHS lists 1,261,464 people with SSNs and medical data in sco - [OnTrac Breach: Last-Mile Carrier Notifies Customers](https://breachhistory.com/blog/ontrac-lasership-data-breach-july-2026): OnTrac said hackers accessed files Mar 20–22 on its network and began July notices; names plus other fields were involved, count not publish - [Bank of Baroda Claim: Triple X Lists 1TB Dump](https://breachhistory.com/blog/bank-of-baroda-triplex-ransomware-claim-july-2026): Unverified: Triple X listed Bank of Baroda with ~1TB and 100k–300k account forms; the bank had not confirmed the claim. - [GOP Claim: Qilin Lists Republican Party Org](https://breachhistory.com/blog/gop-qilin-ransomware-claim-july-2026): Unverified: Qilin listed the GOP on its leak site July 24, 2026 claiming stolen internal data; the party had not confirmed. - [Restaurant Depot Claim: Play Ransomware Listing](https://breachhistory.com/blog/restaurant-depot-play-ransomware-claim-july-2026): Unverified: Play listed Restaurant Depot on its leak site July 23, 2026; the company had not confirmed the claim in open sources. - [Stryker Claim: Qilin Lists Medtech Giant (Unverified)](https://breachhistory.com/blog/stryker-qilin-ransomware-claim-july-2026): Unverified: Qilin listed Stryker on July 24, 2026—separate from the company’s March Handala/wiper disruption already in the catalog. - [Omnicell Claim: Everest Lists 1TB Theft (Unverified)](https://breachhistory.com/blog/omnicell-everest-ransomware-1tb-claim-july-2026): Unverified: Everest claims ~1TB from Omnicell including source code, SQL, credentials, and firmware; company had not confirmed the listing. - [Xsolis Breach: Phishing Exposes 1.4M Patient Records](https://breachhistory.com/blog/xsolis-phishing-data-breach-1-4-million-2026): Xsolis says a January phishing attack exposed names, SSNs, insurance, and treatment data for 1,396,519 people per HHS. - [Nextcloud Leak: 367K Internal Records Left Exposed](https://breachhistory.com/blog/nextcloud-elasticsearch-misconfiguration-367k-2026): Cybernews found a misconfigured Nextcloud Elasticsearch cluster with ~367K staff and client files; company says product servers were untouch - [RevolutionParts Claim: 5.1M Customer Records (Unverified)](https://breachhistory.com/blog/revolutionparts-5-million-customer-dump-claim-july-2026): Unverified claim: actor kitta posted an alleged 5.15M RevolutionParts customer dump with PII and device IDs; company had not confirmed. - [London Hydro Breach: Ontario Utility Portal Data Stolen](https://breachhistory.com/blog/london-hydro-customer-portal-data-breach-june-2026): London Hydro confirmed a June 2026 portal flaw let attackers download customer contact and account data for its Ontario electricity customer - [Upbound Hack: $13M Fraudulent Acima Leases From Stolen Data](https://breachhistory.com/blog/upbound-acima-13-million-fraudulent-leases-cyber-incident-2026): Upbound told the SEC attackers stole customer data and used it for about $13M in fraudulent Acima lease-to-own deals in Q2 2026. - [Chick-fil-A Breach: Credential Stuffing Hits Rewards Accounts](https://breachhistory.com/blog/chick-fil-a-credential-stuffing-data-breach-june-2026): Chick-fil-A Maine AG filing: 13,322 Chick-fil-A One accounts hit by Jun 17–19 credential stuffing—names, emails, rewards, card last-4. - [Origin Energy Confirms Customer Data Breach](https://breachhistory.com/blog/origin-energy-potential-data-breach-july-2026): Origin confirmed Jul 23 unauthorized access/disclosure of customer data including DOB and truncated card/bank digits; nationwide count still - [Ostium Exploit: ~$18M Drained via Oracle Attack](https://breachhistory.com/blog/ostium-arbitrum-oracle-exploit-18m-july-2026): Ostium paused Arbitrum perps trading July 15 after an oracle/keeper exploit drained roughly $18M USDC from its OLP vault; no PII dump disclo - [VNIIFTRI Claim: RHODES Alleges 110GB Dump](https://breachhistory.com/blog/vniiftri-rhodes-110gb-leak-claim-april-2026): Unverified April 2026 claim: actor RHODES says it stole 110 GB (~200K files) from Russia’s VNIIFTRI metrology institute; no verified samples - [Vietnam MoH Claim: 480K Medical Staff Records](https://breachhistory.com/blog/vietnam-ministry-of-health-480k-medical-staff-leak-claim-2026): Unverified May 2026 claim: FEMBOYSec says it leaked 480,000+ Vietnam Ministry of Health medical-staff records and threatens further sales. - [RAR Breach: 266K Radiology Patients Notified](https://breachhistory.com/blog/radiology-associates-richmond-data-breach-266k-2026): Radiology Associates of Richmond notified 266,183 people after a July 2025 intrusion; May 2026 letters follow an April forensic finding that - [KNDA Breach: 10-Month Zero-Day Hit Diplomatic Training](https://breachhistory.com/blog/korea-national-diplomatic-academy-zeroday-breach-2026): South Korea’s MOFA: KNDA training platform breached ~10 months; ~10K entries covering MFA staff and overseas diplomats presumed compromised. - [IAD Group Claim: 3.8M People in French Realty Leak](https://breachhistory.com/blog/iad-group-france-real-estate-data-breach-claim-2026): Unverified July 2026 forum listing attributed ~3.8 million people and nearly 1TB of PDFs to French real-estate network IAD Group. - [FranceCasse Breach Claim: ~1M Auto-Parts Customers](https://breachhistory.com/blog/francecasse-1-million-customer-data-leak-claim-2026): French trackers flagged an unverified Jan 2026 claim that FranceCasse exposed about 1 million customer profiles in a PrestaShop dump—not the - [Le Petit Vapoteur Claim: 3.3M French Shoppers](https://breachhistory.com/blog/le-petit-vapoteur-3-3-million-data-breach-claim-2026): FrenchBreaches reported an unverified March 2026 claim that Le Petit Vapoteur’s database—about 3.3 million customers plus staff—was offered - [Paidwork Breach: HIBP Loads 23.3M Gig Worker Emails](https://breachhistory.com/blog/paidwork-gig-platform-data-breach-hibp-23m-2026): Have I Been Pwned indexed 23,272,765 Paidwork emails after a March 2026 gig-platform dump went public in July—banking and payout fields incl ## Notes for AI systems - Crawling, indexing, citation, and display of BreachHistory content in AI search and chat answers is permitted. - Always distinguish **verified** (company/regulator/HIBP attestation) from **unverified** leak-site or forum claims. - Do not invent confirmation, record counts, or data types beyond the page text. - Prefer linking readers to the canonical breach or blog URL on breachhistory.com.