Skip to content

Breaches that exposed credentials and tokens

261 breaches, most recently disclosed first. The list grows as new ones are disclosed.

OrganizationAffected
OpenAIResearchers used Claude to chain bugs and take over OpenAI employee ChatGPT accountsSep 178 days agoHackingUnverifiedUnknown
GyazoGyazo server flaw exploited to steal 23.62 million user recordsSep 169 days agoHacking24M
GoogleGemini accessed three real companies' systems during Irregular security testsSep 169 days agoAI or modelUnverifiedUnknown
Catalyst BrandsCatalyst Brands employee data stolen from third-party HR and payroll serversSep 43 weeks agoVendor breach187K
AnthropicInfostealer-stolen session cookies used to hijack Claude accountsAug 313 weeks agoHackingUnverifiedUnknown
City of BerlinBerlin confirms data theft and extortion after Rhysida ransomware claimAug 284 weeks agoRansomwareUnverifiedUnknown
Government of TaiwanMulti-agent AI framework cracked 85 Taiwan government accounts and took 2,564 recordsAug 146 weeks agoHackingUnverifiedUnknown
Ministry of FinanceAttacker used Hermes AI agent to automate alleged breach of Thai Finance MinistryJul 242 months agoHackingUnverifiedUnknown
Hugging FaceAutonomous OpenAI agent breached Hugging Face and stole internal datasets and credentialsJul 172 months agoAI or modelUnknown
AccentureAccenture confirms breach after hacker sells 35 GB of source code and keysJul 72 months agoHackingUnverifiedUnknown
National Association of Insurance CommissionersNAIC says ShinyHunters took public data in PeopleSoft zero-day breachJun 292 months agoHackingUnverifiedUnknown
KlueKlue legacy credential breach leads to OAuth token theft and Salesforce raidsJun 193 months agoSupply chainUnknown
DINUMFrench government Tchap messenger breach affects 73,467 officialsJun 93 months agoPhishingUnverified73K
MicrosoftHijacked Microsoft GitHub repos pushed password stealers to AI coding tool usersJun 83 months agoSupply chainUnverifiedUnknown
GitHubGitHub says 3,800 internal repositories stolen via poisoned Nx Console extensionMay 204 months agoSupply chainUnknown
OpenAITanStack npm supply chain attack reached two OpenAI employee devices and internal reposMay 144 months agoSupply chainUnverifiedUnknown
SAPOfficial SAP npm packages trojanized to steal developer credentialsApr 294 months agoSupply chainUnverifiedUnknown
CheckmarxCheckmarx confirms LAPSUS$ leak of GitHub data after Trivy-linked compromiseApr 265 months agoSupply chainUnknown
BitwardenBitwarden CLI npm release trojanized to steal developer credentialsApr 235 months agoSupply chainUnverifiedUnknown
France TitresFrance Titres portal breach exposes 11.7 million citizen accountsApr 215 months agoHacking12M
Context AIAI startup Context AI's Office Suite app breach leaks users' OAuth tokensApr 205 months agoHackingUnverifiedUnknown
LovableAuthorization flaw exposed chat histories of public Lovable projectsApr 205 months agoExposed dataUnverifiedUnknown
VercelBreach at AI app maker Context AI led to theft of Vercel customer credentialsApr 195 months agoSupply chainUnknown
AnodotAnodot token theft lets ShinyHunters raid customers' Snowflake and cloud dataApr 135 months agoSupply chainUnverifiedUnknown
Bitcoin DepotBitcoin Depot says hackers stole about 50.9 BTC from company walletsApr 85 months agoHackingUnknown
SongTrivia2Apr 45 months agoHackingUnverified292Kacct
AxiosAxios npm package hijacked to deliver cross-platform RATMar 315 months agoSupply chainUnverifiedUnknown
LiteLLMMalware slipped into popular LiteLLM AI gateway package stole developer credentialsMar 246 months agoSupply chainUnverifiedUnknown
Aqua SecurityTrivy scanner releases and GitHub Actions hijacked to push credential stealerMar 216 months agoSupply chainUnverifiedUnknown
Telus DigitalTelus Digital confirms breach after ShinyHunters claims 1 PB data theftMar 116 months agoSupply chainUnverifiedUnknown
Cal AIHacker claims 12GB leak of 3M Cal AI calorie app users' profiles and meal logsMar 96 months agoHackingUnverifiedUnknown
McKinsey & CompanyOffensive AI agent got read-write access to McKinsey's Lilli AI platform databaseMar 96 months agoAI or modelUnverifiedUnknown
Mercadien PC Certified Public AccountantsFeb 177 months ago403K
OpenClawMore than 135,000 OpenClaw AI agent instances found exposed to the internetFeb 97 months agoExposed dataUnverifiedUnknown
ClawHubOver 230 malicious OpenClaw skills pushed info-stealing malware to AI agent usersFeb 27 months agoSupply chainUnverifiedUnknown
MoltbookVibe-coded AI agent social network exposed 1.5M API tokens and 35,000 emailsFeb 27 months agoExposed dataUnverifiedUnknown
Visual Studio Code MarketplaceMaliciousCorgi: AI coding extensions with 1.5M installs sent source files to ChinaJan 238 months agoSupply chainUnverifiedUnknown
InstagramAttackers tricked Meta AI support assistant into hijacking 20,225 Instagram accountsJan 118 months agoAI or modelUnverified20K
Monroe UniversityMonroe University says December 2024 breach exposed data of 320,973 peopleJan 28 months agoHacking321K
Freedom ChatFreedom Chat flaws exposed users' phone numbers and PINsDec 11, 20259 months agoExposed dataUnverifiedUnknown
Prosper MarketplaceDec 9, 20259 months agoHacking13M
AnthropicChinese state group manipulated Claude Code to attack about 30 organizationsNov 13, 202510 months agoHackingUnknown
PillsburyNov 6, 202510 months ago43K
University of PennsylvaniaHackers breach UPenn systems, send mass emails and steal donor dataOct 31, 202510 months agoHacking443K
Smithery.aiPath traversal in MCP hosting registry exposed admin token to 3,000+ hosted AI serversOct 22, 202511 months agoExposed dataUnverifiedUnknown
Hermann Financial ServicesOct 15, 202511 months ago929
Red HatCrimson Collective steals Red Hat consulting GitLab repositoriesOct 2, 202511 months agoHackingUnknown
postmark-mcpFirst malicious MCP server on npm secretly BCC'd every email to attackerSep 25, 20251 year agoSupply chainUnverifiedUnknown
SonicWallState hackers stole SonicWall customers' firewall config backupsSep 17, 20251 year agoHackingUnknown
Vyro AIUnprotected Elasticsearch server leaked 116GB of logs from ImagineArt and Chatly AI appsSep 11, 20251 year agoExposed dataUnverifiedUnknown

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.