BLOG

Major Data Breaches – April 2026

This report compiles major data breaches disclosed during April 2026 that affected approximately 1 million+ individuals, plus a small number of incidents below that threshold included for systemic significance. The selection criterion is the disclosure / notification date, not the date of the underlying breach — some incidents involved earlier intrusions but were publicly disclosed (or had their scope materially expanded) during April 2026. Each case is analyzed for victim profile, threat actor, attack methodology, Attack Vector, exposed data types, and impact volume. The Attack Vector taxonomy used in this report follows the IBM Cost of a Data Breach Report categories, with the corresponding MITRE ATT&CK technique mappings noted for each vector to support threat-modeling and detection-engineering use cases.

Executive Summary

Top Incidents by Exposure Volume (Disclosure Date)

RankIncidentScaleDisclosed
1Rockstar Games (gaming, Take-Two subsidiary)~78.6M recordsApril 14, 2026
2McGraw Hill (Big-Three educational publisher)13.5M (45M claimed)April 15, 2026
3Carnival Corporation (cruise operator)8.7MApril 18–21, 2026
4Pitney Bowes (US shipping / mailing logistics)8.2M (25M+ claimed)April 18–21, 2026
5Canada Life Assurance (Canadian insurer)5.6M+April 2026
6ADT (US home-security provider)5.5M (10M+ claimed)April 24 (SEC 8-K) / April 27, 2026 (dump)
7Citizens Bank (third-party breach)3.5MApril 2026
8Amtrak (US national passenger rail)2.1M (9.4M claimed)April 17, 2026
9Hallmark (cards / Hallmark+ streaming)1.7M (~6.2M records across 20 files)April 12–13, 2026
10Udemy (online learning marketplace)1.4MApril 24–27, 2026

Most Frequently Exposed Data Types

  1. Personally Identifiable Information (PII) — names, addresses, emails, phone numbers (in nearly every incident: McGraw Hill, Kemper, Pitney Bowes, ADT, Amtrak, Hallmark, Udemy, Carnival, Rituals, Basic-Fit, etc.)
  2. Loyalty / Membership Profile Data — preferred store, account type, gender, Mariner Society loyalty status (Carnival, Rituals, Hallmark, Hallmark+ streaming subscribers, Inditex transaction records)
  3. Customer Support Interaction Records — historical support tickets and travel/order context (Adobe, Amtrak, Hallmark, McGraw Hill)
  4. Financial / Banking Information — Basic-Fit (bank account / IBAN), Udemy (instructor payout methods: PayPal, cheque, bank transfer), Kemper (Stripe payment logs with transaction amounts), ADT (last-4 SSN/Tax ID for a subset)
  5. National ID / Government Identifiers — France Titres / ANTS (login IDs, account identifiers, place of birth), ADT (last-4 SSN/Tax ID), AFC (passport scans)
  6. Internal Corporate / Employee Data — Pitney Bowes (employee records with job titles), Adobe (alleged 15K employee records + complete HackerOne bug-bounty submissions), Vercel (API keys, NPM tokens, GitHub tokens, source code), Kemper (employee training materials), BePrime (plaintext credentials, security audit reports)
  7. Multi-domain Analytics / Game-Economy Data — Rockstar Games (in-game revenue metrics, player behavior tracking, GTA Online and Red Dead Online economy data) — competitive intelligence rather than identity-fraud material

Top Attack Vectors of April 2026

  1. Third-party vendor & Supply chain compromise — Dominant #1 of the month
    • ShinyHunters’ Salesforce extortion wave reached the majority of victims (Marcus & Millichap, McGraw Hill, Kemper, Medtronic, Pitney Bowes, Carnival, Canada Life, ADT, Amtrak, Hallmark, Udemy, Inditex).
    • Anodot (Israeli AI-analytics SaaS) compromise produced cascading Snowflake/BigQuery breaches — most notably Rockstar Games (78.6M records) and Inditex.
    • Vercel breached via Context.ai OAuth compromise; the Context.ai compromise dated back to June 2024.
    • Adobe reportedly reached through an Indian BPO contractor — a fourth-party / nth-party vendor risk.
  2. Compromised credentials (SSO Vishing-driven theft)
    • Stolen Salesforce credentials, Okta SSO sessions, and Snowflake/Anodot OAuth tokens functioned as valid, MFA-bypassing access throughout the ShinyHunters campaign.
    • ADT was breached by vishing an employee’s Okta SSO account, then pivoting into Salesforce.
    • Carnival was breached via a single phished employee account.
  3. System error / Cloud Misconfiguration (Salesforce-hosted public webpage flavor)
    • McGraw Hill’s 13.5M leak was attributed to a Salesforce-hosted public webpage misconfiguration affecting multiple Salesforce customers — no authenticated intrusion required.

Notable Attack Patterns

  • ShinyHunters’ Salesforce Extortion Wave — the threat actor of the month: A single threat actor (also tracked as UNC6040) was tied to disclosed breaches at Rockstar Games, Marcus & Millichap, Pitney Bowes, McGraw Hill, Kemper, Medtronic, Inditex, Carnival, Canada Life, ADT, Amtrak, Hallmark, and Udemy in a single month. The pattern: vishing → stolen Salesforce/Okta credentials → CRM data exfiltration → “pay-or-leak” extortion with a 3-to-7-day deadline. Encryption-based ransomware is no longer the operating model; data-theft-and-leak is.
  • GTA VI–Timed Pressure on Rockstar Games: With Grand Theft Auto VI scheduled for November 19, 2026 release, ShinyHunters’ April 14 dump of 78.6M Rockstar records (multi-domain GTA Online / Red Dead Online analytics) illustrates how threat actors increasingly time disclosures for maximum business and reputational impact rather than just financial extortion.
  • Fourth-party / nth-party Vendor Risk Crystallized at Adobe: The attacker reportedly did not breach Adobe directly — they breached an Indian BPO contractor with privileged helpdesk access, deployed a RAT via malicious email, escalated to a manager via ClickFix social engineering, then exfiltrated 13M+ tickets and Adobe’s complete HackerOne bug-bounty submission archive via the support platform’s bulk-export function.
  • French National Identity-Document Authority Hit: France Titres / ANTS — the agency that issues French passports, ID cards, and driver’s licenses — was breached on April 15, 2026, with threat actor “breach3d” claiming up to 19M records. CNIL, the Paris Public Prosecutor, and ANSSI are all involved.
  • Cybersecurity Vendor Itself Compromised: BePrime (Mexico-based cybersecurity firm) was breached on April 20 via admin accounts that lacked MFA, giving the attacker live surveillance camera access and operational control of 1,858 network devices and 2,600+ connected devices at downstream clients including Iberdrola, Whirlpool, and Alsea.

Incident-by-Incident Detailed Analysis


1. Rockstar Games — 78.6 Million Records Leaked (Largest Single Dump of April 2026)

  • Affected entity: Rockstar Games, developer of Grand Theft Auto and Red Dead Redemption franchises (subsidiary of Take-Two Interactive).
  • Why this matters: With Grand Theft Auto VI scheduled for a November 19, 2026 release, the timing of this breach is uniquely sensitive. Although Rockstar describes the leaked data as “non-material,” the dataset is alleged to contain in-game revenue metrics, player behavior tracking, and game-economy data for GTA Online and Red Dead Online — competitive intelligence of significant value to other studios and to threat actors targeting players. The attack pattern (Anodot → Snowflake token abuse) is a textbook example of SaaS-to-SaaS trust-chain compromise, with implications well beyond gaming. At 78.6 million records, this is the largest single publicly-released dataset of April 2026.
  • Threat actor: ShinyHunters
  • Attack methodology: ShinyHunters compromised Anodot, an Israeli AI-powered cloud-cost-monitoring and analytics SaaS used by Rockstar, and extracted authentication tokens that allowed the group to impersonate a legitimate internal service and silently access Rockstar’s connected Snowflake data warehouse. ShinyHunters listed Rockstar on April 11, 2026 with an April 14 deadline; after Rockstar declined to negotiate, the group published 78.6M records on April 14, 2026.
  • Attack Vector:
    • Third-party vendor / Supply chain compromise (T1195 Supply Chain Compromise / T1199 Trusted Relationship): The attack entered through Anodot’s compromised environment; Anodot’s privileged access tokens to Snowflake provided the lateral pathway into Rockstar.
    • Compromised credentials (T1078 Valid Accounts): Stolen Anodot authentication tokens were used as valid, trusted credentials against Snowflake — no Snowflake vulnerability was exploited.
  • Exposed data: Multi-domain analytics data used for GTA Online and Red Dead Online, including in-game revenue and purchase metrics, player behavior tracking, and game-economy data. No traditional consumer PII identified in the public dump.
  • Volume: ~78.6 million records publicly leaked.

2. Marcus & Millichap — 30 Million+ Salesforce Records Claimed

  • Affected entity: Marcus & Millichap, Inc. (major US commercial real estate brokerage; investment sales, financing, research, advisory services).
  • Why this matters: Real-estate transaction data combined with PII is a particularly high-value dataset for fraud, identity theft, and targeted social engineering against high-net-worth investors. The 30M-record claim places this incident among the largest single-victim disclosures of the month.
  • Threat actor: ShinyHunters
  • Attack methodology: ShinyHunters listed Marcus & Millichap on its leak site on April 11, 2026, claiming 30M+ Salesforce records compromised. A “final warning” with an April 14 deadline was issued. Part of ShinyHunters’ broader Salesforce-focused extortion campaign.
  • Attack Vector:
    • Compromised credentials (T1078 Valid Accounts): Salesforce credentials obtained earlier in 2026 through social-engineering / vishing campaigns targeting Salesforce-customer employees.
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): The attack leveraged the trust relationship between Marcus & Millichap and the Salesforce SaaS platform.
    • Phishing (T1566): Underlying credential-theft technique consistent with the broader UNC6040 vishing playbook.
  • Exposed data: PII and internal corporate data within Salesforce CRM records (specific fields not publicly itemized as of disclosure).
  • Volume: 30M+ records claimed by the threat actor.

3. Pitney Bowes — 8.2M Unique Emails Released / 25M+ Salesforce Records Claimed

  • Affected entity: Pitney Bowes Inc. (US global shipping, mailing, and ecommerce-logistics services provider).
  • Why this matters: Beyond customer PII, the breach exposed a subset of Pitney Bowes employee records with job titles — useful for crafting highly targeted business email compromise (BEC) attacks against the company’s own staff and partners. The combination of mailing/shipping customer data with detailed employee-org information creates secondary risk for invoice-fraud and supplier-impersonation campaigns across the wider logistics ecosystem.
  • Threat actor: ShinyHunters
  • Attack methodology: ShinyHunters listed Pitney Bowes on its leak site around April 18, 2026, claiming 25M+ Salesforce records compromised and demanding payment by April 21. After the deadline, the group publicly released the dataset, which Have I Been Pwned indexed at 8.2M unique email addresses. Part of ShinyHunters’ broader Salesforce-focused extortion wave.
  • Attack Vector:
    • Compromised credentials (T1078 Valid Accounts): Salesforce credentials harvested through ShinyHunters’ 2026 vishing/social-engineering campaign.
    • Phishing (T1566): Underlying credential-theft technique against Salesforce-customer employees.
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): Salesforce as the targeted SaaS data repository.
  • Exposed data: Names, email addresses, phone numbers, physical addresses; subset of Pitney Bowes employee records with job titles.
  • Volume: 8.2M unique email addresses publicly released; ShinyHunters claimed 25M+ Salesforce records.

4. France Titres / ANTS — Up to 19 Million Records Claimed at French National ID Authority

  • Affected entity: France Titres / ANTS (Agence nationale des titres sécurisés) — French national agency that manages secure identity documents, vehicle registrations, and government identity portals.
  • Why this matters: A breach at a national identity-document authority is uniquely high-impact. Even though the agency states the data does not grant direct access to portals, the combination of personal identifiers, place of birth, and account identifiers is highly weaponizable for impersonation, document fraud, phishing, and social engineering targeting French citizens. The incident has triggered involvement from CNIL (French data protection authority), the Paris Public Prosecutor, and ANSSI (French national cybersecurity agency).
  • Threat actor: A threat actor operating under the alias “breach3d”
  • Attack methodology: France Titres detected the breach on April 15, 2026 on its ants.gouv.fr portal. Threat actor “breach3d” claimed up to 19M records were stolen. ANTS notified affected individuals and engaged CNIL, prosecutorial, and ANSSI authorities.
  • Attack Vector:
    • Vulnerability exploitation (T1190 Exploit Public-Facing Application): The specific technical entry point has not been publicly disclosed, but the attack appears to have exploited weaknesses in the public-facing portal.
  • Exposed data: Login IDs, full names, email addresses, dates of birth, account identifiers; in some cases postal addresses, places of birth, and phone numbers.
  • Volume: Up to 19M records (attacker claim).

5. McGraw Hill — 13.5M Unique Emails (Salesforce-hosted Webpage Misconfiguration)

  • Affected entity: McGraw Hill (one of the world’s “Big Three” educational publishers, headquartered in Ohio).
  • Why this matters: An education publisher’s customer base spans students, educators, and institutions globally — including minors in some segments. The leaked dataset of 13.5M unique email addresses with names, phone numbers, and addresses is a goldmine for spear-phishing aimed at educators (often holders of institutional credentials) and credential-stuffing attacks against re-used passwords. The incident illustrates how a single SaaS misconfiguration can cascade into a multi-million-record exposure across multiple Salesforce customers.
  • Threat actor: ShinyHunters (UNC6040)
  • Attack methodology: ShinyHunters listed McGraw Hill in mid-April 2026 claiming up to 45M Salesforce records, with an April 14 ransom deadline. After the deadline lapsed, the group dumped 100+ GB of data containing 13.5M unique email addresses on April 15. McGraw Hill confirmed the breach as a Salesforce-hosted webpage misconfiguration affecting multiple Salesforce customers, and stated its core systems and customer databases were not breached.
  • Attack Vector:
    • System error / misconfiguration (related to T1562 Impair Defenses, indirectly): A misconfigured Salesforce-hosted public webpage exposed customer data without requiring authenticated intrusion.
    • Vulnerability exploitation (T1190 Exploit Public-Facing Application): Threat actors enumerated the misconfigured public-facing Salesforce community/site to harvest data at scale.
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): The underlying platform was a third-party SaaS environment (Salesforce) hosting McGraw Hill data.
  • Exposed data: Email addresses, names, phone numbers, physical addresses (fields appearing inconsistently across records). SSNs and financial data stated by McGraw Hill to be out of scope.
  • Volume: 13.5M unique email addresses confirmed; ShinyHunters claimed up to 45M Salesforce records.

6. Kemper Corporation — ~13M Salesforce Records (29 GB)

  • Affected entity: Kemper Corporation (Chicago-based insurance provider with ~$12 billion in assets).
  • Why this matters: A large insurance-sector breach where Salesforce records containing customer PII and Stripe payment logs were exposed. The combination of identity data with transaction amounts increases identity-fraud and pretexting risk.
  • Threat actor: ShinyHunters
  • Attack methodology: ShinyHunters posted Kemper data on its dark web leak site on April 15, 2026, claiming 29 GB of data covering 13M+ Salesforce records, consistent with the broader April Salesforce campaign.
  • Attack Vector:
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): Salesforce CRM as the targeted SaaS platform.
    • Compromised credentials (T1078 Valid Accounts): Consistent with the UNC6040 pattern of using stolen Salesforce credentials.
    • Phishing (T1566): Consistent with the broader UNC6040 vishing playbook used to obtain Salesforce credentials, although the specific entry point at Kemper has not been publicly disclosed.
  • Exposed data: Internal corporate documents, employee training materials, employee names and email addresses, and Stripe payment logs containing customer names and transaction amounts.
  • Volume: 29 GB / ~13M Salesforce records.

7. Adobe (alleged, unconfirmed by Adobe) — ~13M Support Tickets + HackerOne Archive Claim

  • Affected entity: Adobe Inc. (California-based software company).
  • Why this matters: Beyond the volume of customer support tickets, the alleged inclusion of Adobe’s complete HackerOne bug-bounty submission archive is the most consequential element. If accurate, the attacker would possess detailed, potentially-unpatched vulnerability disclosures across Adobe’s product portfolio — a roadmap for future exploitation against millions of Adobe customers. The incident also underscores fourth-party / nth-party vendor risk, as the entry point was a contracted BPO firm rather than Adobe itself.
  • Threat actor: A threat actor calling himself “Mr. Raccoon” — probabilistic links by Google Threat Intelligence Group to the UNC6783 cluster.
  • Attack methodology: Mr. Raccoon claimed in early April 2026 to have breached Adobe’s customer-support environment via an Indian BPO contractor. The attacker reportedly sent a malicious email to a BPO employee deploying a Remote Access Tool (RAT), then pivoted to a manager account using spearphishing and ClickFix techniques, ultimately exfiltrating data through the support platform’s bulk-export functionality.
  • Attack Vector:
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship / T1195 Supply Chain Compromise): The attack entered through a contracted BPO firm with privileged access to Adobe’s helpdesk environment.
    • Phishing — Spearphishing Attachment (T1566.001): Initial access via malicious email to a BPO employee delivering a RAT.
    • Phishing — Spearphishing Link / ClickFix social engineering (T1566.002): A second-stage phishing attack escalated access from the BPO employee to their manager.
    • Compromised credentials (T1078 Valid Accounts): Manager-level credentials used to access bulk customer data.
  • Exposed data (per attacker claim): ~13M customer support tickets containing PII and issue descriptions; ~15K employee records; Adobe’s complete HackerOne bug-bounty program submissions; internal documents.
  • Volume: 13M support tickets and 15K employee records (claimed; not officially confirmed by Adobe as of late April 2026).

8. Medtronic — 9M+ Records Claimed at World’s Largest Medical Device Maker

  • Affected entity: Medtronic plc (world’s largest medical device manufacturer by revenue, ~$33.5B; 90,000 employees in 150 countries).
  • Why this matters: A medical device giant of this scale handling sensitive corporate and potentially personal data is a high-value target. Although Medtronic states product, manufacturing, and patient-safety systems were segmented and unaffected, a 9M-record breach at a healthcare-adjacent vendor raises concerns about downstream phishing and identity-fraud risk, regulatory scrutiny, and reputational impact on a critical-infrastructure-tier supplier.
  • Threat actor: ShinyHunters
  • Attack methodology: ShinyHunters listed Medtronic on its Tor leak site on April 18, 2026, claiming theft of 9M+ records and terabytes of internal data, with an April 21 ransom deadline. Medtronic disclosed the breach via SEC 8-K filing on April 24. The listing was later removed from the leak site, suggesting possible negotiation or payment.
  • Attack Vector:
    • Compromised credentials (T1078 Valid Accounts): Consistent with ShinyHunters’ broader Salesforce-focused 2026 campaign — initial access typically obtained through stolen Salesforce credentials harvested via vishing/social engineering against employees of victim organizations. Medtronic has not publicly confirmed the specific entry point.
    • Phishing (T1566): Underlying credential-theft technique consistent with UNC6040 patterns.
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): Consistent with the broader April Salesforce-related campaign.
  • Exposed data: PII (per attacker claim, not officially confirmed by Medtronic) and “terabytes of internal corporate data.”
  • Volume: 9M+ records (claimed by ShinyHunters; not independently verified).

9. Carnival Corporation — 8.7M Records / 7.5M Unique Emails (Holland America Mariner Society)

  • Affected entity: Carnival Corporation (Carnival Cruise Line, Princess Cruises, Holland America, Cunard).
  • Why this matters: The leaked dataset specifically related to Holland America’s Mariner Society loyalty program, demonstrating the secondary-data risk of customer loyalty platforms. Exposure of dates of birth and gender alongside contact data significantly raises identity-theft and account-takeover risk for affected travelers. Cruise customer records are particularly attractive for impersonation and pretexting because they include travel itineraries and are tied to travel-document workflows.
  • Threat actor: ShinyHunters
  • Attack methodology: ShinyHunters listed Carnival on its leak site on April 18, 2026, claiming 8.7M+ records with an April 21 deadline. After the deadline, the group published the full dataset containing 8.7M records and 7.5M unique email addresses. Carnival confirmed the entry point was a phishing incident affecting a single user account.
  • Attack Vector:
    • Phishing — Spearphishing Link (T1566 / T1566.002): A single user account was compromised via phishing.
    • Compromised credentials (T1078 Valid Accounts): The phished account’s valid credentials enabled access to systems holding loyalty-program customer data.
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): Salesforce-hosted CRM data within the broader April wave.
  • Exposed data: Names, email addresses, dates of birth, gender, and loyalty-program (Mariner Society) status data.
  • Volume: 8.7M records / 7.5M unique email addresses.

10. Canada Life Assurance Company — 5.6M+ Records

  • Affected entity: Canada Life Assurance Company (Winnipeg-based insurance and financial services; one of the largest insurers in Canada).
  • Why this matters: A large financial-services breach in Canada with elevated regulatory exposure under PIPEDA and provincial privacy law.
  • Threat actor: ShinyHunters
  • Attack methodology: Part of the same April 2026 ShinyHunters extortion wave; specific intrusion details have not been publicly disclosed.
  • Attack Vector:
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): Salesforce CRM.
    • Compromised credentials (T1078 Valid Accounts): Consistent with UNC6040 patterns.
    • Phishing (T1566): Consistent with UNC6040 entry tactics.
  • Exposed data: PII (specific field-level disclosure pending).
  • Volume: 5.6M+ records.

11. ADT — 5.5M Individuals Confirmed (Okta SSO Vishing → Salesforce)

  • Affected entity: ADT Inc. (oldest and largest US home-security provider, founded 1874; 6M+ residential and small-business monitoring customers).
  • Why this matters: A home-security breach is uniquely sensitive because the threat actor obtains addresses of homes that explicitly chose to install alarm monitoring — a population with a higher concentration of valuables. The combination of names, addresses, phone numbers, dates of birth, and partial SSN/Tax IDs is high-value for both identity fraud and physical-security targeting (phishing impersonating ADT support, social-engineering scams about “alarm system upgrades”). Critically, no payment information or customer security system data was accessed.
  • Threat actor: ShinyHunters
  • Attack methodology: ADT detected unauthorized access to its cloud environments on April 20, 2026 and disclosed the incident via SEC 8-K filing on April 24, 2026. ShinyHunters listed ADT on its leak site on April 23 claiming 10M+ records, with an April 27 deadline. ADT did not pay; ShinyHunters publicly released an 11 GB archive on April 27. Have I Been Pwned indexed the breach with 5.5M unique email addresses confirmed exposed. ShinyHunters told BleepingComputer they breached ADT by compromising an employee’s Okta SSO account through a vishing attack, then pivoted into ADT’s Salesforce instance.
  • Attack Vector:
    • Phishing — Vishing (T1566): Voice-phishing call against an ADT employee to harvest Okta SSO credentials.
    • Compromised credentials (T1078 Valid Accounts): The stolen Okta SSO session enabled authenticated access to ADT’s cloud and Salesforce environments, bypassing technical controls because the access looked legitimate.
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): The Okta-to-Salesforce trust chain was exploited; Salesforce was the actual data repository accessed.
  • Exposed data: Names, phone numbers, physical addresses, email addresses; in a smaller percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs. No payment information; home security systems were not affected per ADT.
  • Volume: 5.5M individuals confirmed via Have I Been Pwned; ShinyHunters claimed 10M+ records.

12. Citizens Bank — 3.5 Million Customers (Third-Party Breach)

  • Affected entity: Citizens Financial Group (Rhode Island-based bank holding company, founded 1828).
  • Why this matters: A retail-banking breach affecting account-level information for millions of customers, with elevated risk of account takeover and targeted financial fraud.
  • Threat actor: Not publicly attributed at time of writing.
  • Attack methodology: Citizens Bank was breached via a cyberattack on a third-party company; specifics of the intermediary have not been disclosed.
  • Attack Vector:
    • Third-party vendor / Supply chain compromise (T1195 Supply Chain Compromise / T1199 Trusted Relationship): Citizens Bank itself was not directly breached; the attackers reached customer data through an external party that processed or stored Citizens Bank data.
  • Exposed data: Customer names, addresses, and account numbers.
  • Volume: 3.5 million customers.

13. Amtrak — 2.1M Unique Emails Confirmed (9.4M Records Claimed)

  • Affected entity: Amtrak (National Railroad Passenger Corporation, the US national passenger rail operator).
  • Why this matters: As critical national transportation infrastructure, Amtrak’s customer base and travel patterns are valuable for both criminal phishing and potentially intelligence-collection use cases. The breach revealed 2.1M+ unique accounts with exposed data including names, emails, addresses, and customer support records. Customer support records and travel histories enable highly contextual social-engineering attacks because attackers can reference real prior interactions in phishing messages. Amtrak’s customer base includes frequent business and government travelers, making this dataset particularly attractive for follow-on targeting.
  • Threat actor: ShinyHunters
  • Attack methodology: ShinyHunters claimed in April 2026 that 9.4M Salesforce records had been obtained from Amtrak. After ransom negotiations failed, the group published the dataset, which Have I Been Pwned indexed on April 17, 2026 with 2.1M unique email addresses. The intrusion is attributed to ShinyHunters’ broader 2026 Salesforce social-engineering campaign.
  • Attack Vector:
    • Compromised credentials (T1078 Valid Accounts): Salesforce credentials harvested earlier in 2026 from Amtrak employees via social engineering.
    • Phishing — Vishing (T1566): The initial credential-theft phase relied on phishing/vishing of employees.
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): Salesforce CRM as the targeted SaaS platform.
  • Exposed data: Email addresses, full names, physical addresses, and customer support records / support ticket history.
  • Volume: 2.1M unique email addresses confirmed via Have I Been Pwned; ShinyHunters claimed 9.4M records.

14. Hallmark — 1.7M Unique Emails / ~6.2M Records Across 20 Files

  • Affected entity: Hallmark Cards, Inc. and the Hallmark+ streaming service.
  • Why this matters: Hallmark customer data, including support-ticket histories, enables highly personalized scams targeting customers around occasions (birthdays, anniversaries, condolences) that the threat actor can infer from purchase records. The dataset includes both legacy Hallmark customers and Hallmark+ streaming subscribers.
  • Threat actor: ShinyHunters
  • Attack methodology: Hallmark was allegedly breached on March 9, 2026 with attackers accessing the company’s Salesforce environment. After ransom demands were not met, ShinyHunters dumped the 9.59 GB dataset on April 12, 2026. Have I Been Pwned indexed it on April 13, 2026.
  • Attack Vector:
    • Compromised credentials (T1078 Valid Accounts): Salesforce credentials obtained via ShinyHunters’ broader 2026 Salesforce social-engineering campaign.
    • Phishing (T1566): Underlying credential-theft technique.
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): Salesforce CRM as the targeted SaaS platform.
  • Exposed data: Full names, email addresses, phone numbers, physical addresses, and historical customer support tickets.
  • Volume: 1.7M unique email addresses (~6.2M total records across 20 files).

15. Udemy — 1.4M Unique Emails Leaked (Includes Instructor Payout Methods)

  • Affected entity: Udemy, Inc. (one of the world’s largest online learning marketplaces).
  • Why this matters: The leaked dataset is unusually rich for a Salesforce-derived breach: in addition to standard customer PII, it includes instructor payout method details (PayPal, bank transfers, cheques) and employer information. This combination provides attackers with everything needed to run targeted invoice-fraud, fake-payment-update, and tax-fraud scams against Udemy instructors — a particularly vulnerable population because instructors transact with Udemy financially.
  • Threat actor: ShinyHunters
  • Attack methodology: ShinyHunters listed Udemy on its leak site on April 24, 2026 with a “Pay or Leak” warning and a final deadline of April 27, 2026. After the deadline, the group released a 2.3 GB dataset containing 1.4M+ records from Udemy’s Salesforce environment. Have I Been Pwned indexed the dataset on April 26, 2026.
  • Attack Vector:
    • Compromised credentials (T1078 Valid Accounts): Salesforce credentials harvested via ShinyHunters’ 2026 vishing/social-engineering campaign against Salesforce-customer employees.
    • Phishing (T1566): Underlying credential-theft technique.
    • Third-party vendor / Supply chain compromise (T1199 Trusted Relationship): Salesforce CRM as the targeted SaaS platform.
  • Exposed data: 1.4M unique email addresses (customers and instructors), names, physical addresses, phone numbers, employer information, and instructor payout methods (PayPal, cheque, bank transfer).
  • Volume: 1.4M unique email addresses publicly leaked.

16. Basic-Fit — ~1M Members Across Six Countries (Including Bank Account Details)

  • Affected entity: Basic-Fit (Europe’s largest gym chain, 5.8M+ registered members and 2,150+ clubs across 12 countries — Netherlands, Belgium, France, Spain, Germany, Luxembourg, etc.).
  • Why this matters: Unlike most April 2026 incidents, the Basic-Fit breach exposed bank account details — directly enabling SEPA direct-debit fraud and account-takeover risk for affected European members. The combination of names, addresses, dates of birth, and banking information is one of the most directly fraud-enabling datasets disclosed this month.
  • Threat actor: Not publicly attributed; no group has claimed responsibility.
  • Attack methodology: Basic-Fit detected unauthorized access to the system that records members’ visits to its clubs. Although the access was blocked within minutes of detection by system-monitoring processes, an external forensic investigation found that data on roughly 1M members across six countries had been downloaded by the attacker. Disclosed April 13, 2026; affected members and the relevant data-protection authority were notified.
  • Attack Vector:
    • Others (technical entry point not publicly disclosed): Basic-Fit has not disclosed the attack technique. The brief intrusion-to-detection window plus high data volume is consistent with either compromised credentials (T1078) against an internal application or a vulnerability exploitation event (T1190) against the visit-tracking system, but neither has been publicly confirmed.
  • Exposed data: Names, home addresses, email addresses, phone numbers, dates of birth, and bank account details. No identification documents (Basic-Fit does not store these) and no passwords accessed.
  • Volume: ~1M members affected (200,000 in the Netherlands plus members across Belgium, Luxembourg, France, Spain, and Germany).

17. Rituals — Undisclosed Subset of 41M+ “My Rituals” Loyalty Database

  • Affected entity: Rituals (Netherlands-based luxury cosmetics and home-fragrance brand, 1,400+ retail boutiques and 4,800 luxury perfumeries across 33 countries; €2.4B revenue in 2025).
  • Why this matters: The “My Rituals” loyalty database has 41M+ members across Europe, the UK, and the United States. Although Rituals has not disclosed the exact affected count, the upper bound is one of the largest single-victim data exposures of the month. Loyalty-program data of this scale is highly weaponizable for phishing campaigns built around occasion-based purchasing patterns (gifts, birthdays, beauty subscriptions). The breach also fits a broader pattern of European retail loyalty-database breaches in 2026 (Co-op, Marks & Spencer), suggesting a coordinated targeting campaign or shared tooling.
  • Threat actor: Not publicly attributed; no group has claimed responsibility as of disclosure.
  • Attack methodology: Rituals identified an “unauthorized download” of My Rituals member data in April 2026 and disclosed the breach on April 22, 2026 via website notice and direct email to affected customers. Rituals stated that access was contained immediately upon discovery; relevant authorities (including the Dutch Data Protection Authority / Autoriteit Persoonsgegevens) were notified, and an external forensic investigation is underway. The company has not disclosed the technical entry point.
  • Attack Vector:
    • Others (technical entry point not publicly disclosed): Rituals has declined to comment on attribution or attack vector for security reasons. The pattern (large-scale unauthorized data download from a customer database) is consistent with either compromised credentials (T1078) or an exposed application interface (T1190), but neither has been publicly confirmed.
  • Exposed data: Full name, date of birth, gender, postal address, email address, phone number, preferred Rituals store, and account type. No passwords or payment information accessed (per Rituals).
  • Volume: Exact affected count not disclosed; the My Rituals database contains 41M+ members worldwide.

18. Inditex (Zara, Bershka, Stradivarius) — Tied to the Anodot/Snowflake Wave

  • Affected entity: Inditex (world’s largest clothing retailer; parent of Zara, Bershka, Stradivarius, Pull&Bear, Oysho, etc.; 7,200+ stores in 93 markets).
  • Why this matters: Inditex itself reports that no customer names, contact information, passwords, or payment data were exposed — only commercial transaction records. However, the breach is significant because it is part of a multi-victim event tied to a “former technology provider” and overlaps with ShinyHunters’ Snowflake/Anodot attack wave (the same path used in the Rockstar Games breach), illustrating the cascading risk of shared SaaS and AI-analytics infrastructure across retail giants.
  • Threat actor: ShinyHunters (claimed via the Anodot/Snowflake compromise)
  • Attack methodology: Inditex publicly disclosed unauthorized access on April 15, 2026 (detected April 16) involving customer transaction databases hosted by a third-party (former) technology provider. ShinyHunters separately claimed to have compromised Zara’s BigQuery instances via the prior compromise of Israeli AI-analytics firm Anodot — the same access path used in the Rockstar Games Snowflake breach.
  • Attack Vector:
    • Third-party vendor / Supply chain compromise (T1195 / T1199): The breach originated at a former technology / AI-analytics provider (Anodot) that had access to Inditex BigQuery / Snowflake environments.
    • Compromised credentials (T1078 Valid Accounts): Cloud-data-warehouse credentials obtained through the upstream Anodot compromise.
  • Exposed data: Commercial transaction records (per Inditex). No customer names, addresses, passwords, or payment data per Inditex’s statement.
  • Volume: Inditex did not publish a record count. ShinyHunters’ broader Snowflake-wave campaign affects multiple multinational retailers; volume specific to Inditex is undisclosed but is grouped within multi-million-record claims for the wave.

19. Vercel — Cloud Platform Breached via June 2024 Context.ai OAuth Compromise

  • Affected entity: Vercel (San Francisco-based cloud application platform widely used for hosting JavaScript / Next.js applications).
  • Why this matters: The Vercel incident is the clearest example in April of how a single compromised AI-tool OAuth grant can give attackers long-lived, password-independent access to a major cloud infrastructure provider, with downstream supply-chain implications for everyone deploying on Vercel. Multiple employee accounts with access to internal deployments, API keys, NPM tokens, GitHub tokens, source code, and database data were claimed to be in the dataset; NPM token theft in particular raises supply-chain risk for any package maintained from Vercel.
  • Threat actor: A threat actor claiming affiliation with ShinyHunters posted the data on BreachForums on April 19, 2026; ShinyHunters itself denied involvement.
  • Attack methodology: By compromising a single AI tool, the attacker bypassed traditional perimeter defenses and gained long-lived, password-independent access to a major cloud infrastructure provider. Specifically, the attacker leveraged a compromised OAuth integration with Context.ai, a third-party AI tool authorized to access Vercel’s environment. The initial compromise of the Context.ai OAuth application occurred around June 2024 — meaning the attacker had persistent access for an extended dwell time before exploitation became visible.
  • Attack Vector:
    • Third-party vendor / Supply chain compromise (T1199 / T1195): The trust boundary between Vercel and Context.ai was the entry point. The attacker did not breach Vercel directly; they breached an AI tool that had been granted broad OAuth scopes into Vercel’s systems.
    • Compromised credentials (T1078 Valid Accounts): The stolen OAuth tokens functioned as valid, MFA-independent credentials, enabling persistent access.
  • Exposed data: Multiple Vercel employee accounts with access to internal deployments, API keys, NPM tokens, GitHub tokens, source code, and database data (claimed by the attacker).
  • Volume: ~580 records of employee information claimed by the attacker; broader infrastructure access also claimed but not fully verified at time of writing.

20. BePrime — Cybersecurity Vendor Hit, Live Surveillance Camera Access at Downstream Clients

  • Affected entity: BePrime (Mexico-based cybersecurity company serving large Latin American enterprises including Iberdrola, Whirlpool, and Alsea — operator of Domino’s, Starbucks, and Vips outlets).
  • Why this matters: A breach at a cybersecurity vendor that managed network and surveillance devices for major industrial clients. The data exposed included plaintext credentials, security audit reports, and live surveillance camera access — meaning the breach gave attackers operational access to physical-security infrastructure at downstream clients, not just data.
  • Threat actor: Not publicly attributed at time of writing.
  • Attack methodology: On April 20, 2026, an attacker infiltrated BePrime admin accounts that lacked MFA, harvested API keys, and took control of 1,858 network devices and 2,600+ connected devices belonging to BePrime clients. Data was posted on a data breach forum.
  • Attack Vector:
    • Compromised credentials (T1078 Valid Accounts / T1110 Brute Force): Admin accounts lacking MFA were the initial entry point.
    • Third-party vendor / Supply chain compromise (T1195 / T1199): Once inside BePrime, the attacker used BePrime’s privileged position as a security vendor to reach 4,000+ devices at downstream clients including Iberdrola and Whirlpool.
  • Exposed data: 12.6 GB including plaintext credentials, transaction records, security audit reports, and live surveillance camera access; affected downstream clients include Iberdrola, Whirlpool, and Alsea.
  • Volume: 12.6 GB; 1,858 network devices and 2,600+ connected devices under attacker control.

21. KelpDAO — $292M DeFi Loss

  • Affected entity: KelpDAO (decentralized cryptocurrency staking platform; rsETH protocol).
  • Why this matters: A high-impact crypto incident with $292M in financial loss across multiple platforms that depend on KelpDAO. Included for systemic significance to the broader DeFi ecosystem despite the absence of a traditional PII record count.
  • Threat actor: Not publicly attributed at time of writing.
  • Attack methodology: On April 18, 2026, KelpDAO detected suspicious activity that forced it to pause operations and rsETH contracts. Investigation is ongoing.
  • Attack Vector:
    • Vulnerability exploitation (T1190 Exploit Public-Facing Application): Consistent with typical DeFi exploits where smart contract or protocol-level vulnerabilities are abused for unauthorized fund movement; specific technical root cause has not been publicly confirmed.
  • Exposed data: Financial assets (no traditional PII disclosure reported).
  • Volume: $292M in loss; record count not applicable.

22. Asian Football Confederation (AFC) — ~150K Members Including Cristiano Ronaldo, Passport Scans

  • Affected entity: The Asian Football Confederation (supreme governing body of football, futsal, and beach soccer across most of Asia).
  • Why this matters: Although the absolute number of affected individuals (~150,000) is below the 1M threshold, this incident is included for systemic significance: it is described as one of the largest data breaches in football history, and the dataset includes high-profile individuals (including Cristiano Ronaldo) along with passport scans, which carry an unusually elevated identity-fraud and impersonation risk.
  • Threat actor: Not publicly attributed at time of writing.
  • Attack methodology: Attackers exfiltrated AFC’s member database and posted highly sensitive personal details on a dark web forum.
  • Attack Vector:
    • Others: Insufficient public information to attribute a definitive vector.
  • Exposed data: Passport scans, emails, contract details, and AFC registration files for players, coaches, and other members.
  • Volume: ~150,000 members. > ※ Included for systemic significance despite being below the 1M threshold.

References

  1. SharkStriker — April 2026 Data Breaches: 15+ Major Incidents & Latest Updates
  2. TechCrunch — Cosmetics giant Rituals confirms data breach of customer membership records
  3. BleepingComputer — Cosmetics giant Rituals discloses data breach affecting customers
  4. BleepingComputer — Data breach at edtech giant McGraw Hill affects 13.5 million accounts
  5. The Register — McGraw Hill linked to 13.5M-record data leak
  6. CyberInsider — McGraw Hill data breach incident exposed 13.5 million accounts
  7. Rescana — McGraw-Hill Salesforce Data Breach 2026: Analysis of ShinyHunters Extortion and Cloud Misconfiguration Risks
  8. Rescana — ADT Salesforce Data Breach 2026: ShinyHunters Compromise Okta SSO via Vishing Attack
  9. Have I Been Pwned — Amtrak Data Breach
  10. UpGuard — Amtrak data breach exposes over 2 million customer records
  11. Cybernews — Hackers threaten to leak over 9M Amtrak records, including personal info
  12. SC Media — Amtrak allegedly breached by ShinyHunters, massive data leak threatened
  13. Cyber News Centre — 23rd April 2026 Cyber Update: Vercel Breach Exposes Critical Flaw in AI Tool OAuth Permissions
  14. Strobes — Vercel Security Breach 2026: How One AI Tool Did It
  15. MINE2 — Anodot SaaS Breach: ShinyHunters Stole OAuth Tokens to Hit Dozens of Companies
  16. State of Surveillance — Rockstar Games Breached Through a Tool It Probably Forgot It Had
  17. centrexIT — The Attack Surface Most Companies Aren’t Watching: Their CRM
  18. Security Boulevard — Cisco CRM “Salesforce Data Breach” Claims Tied to ShinyHunters
  19. Security Boulevard — Amtrak Data Breach Exposes Millions of Customer Records
  20. ComplianceHub.Wiki — Rituals Cosmetics Confirms Membership Database Breach: GDPR Notification, Dutch AP, and the Loyalty Program Risk Pattern
  21. Privacy Guides — Data Breach Roundup (Apr 17 – 23, 2026)
  22. CM-Alliance — Major Cyber Attacks, Data Breaches, Ransomware Attacks in April 2026
  23. ShieldWorkz — Incident report: The McGraw Hill Salesforce breach
  24. The420.in — McGraw Hill Data Breach Exposes 1.35 Million Users After Salesforce Flaw
  25. National CIO Review — 13.5 Million Accounts Affected in Latest ShinyHunters Campaign
🔒

Coming Soon

We're building this product right now. Be the first to know when it launches.