Data Breach Alerts
Track significant data breach incidents as they are disclosed. Understand what happened, what data was exposed, and what your team should watch for.

A data breach exposes sensitive information — credentials, financial records, health data, or intellectual property — to parties who should never have access to it. Every incident on this page represents leaked or stolen data that is now circulating on the open internet, in dark web marketplaces, or in the hands of extortion groups. For the organisations named, the fallout ranges from regulatory penalties and legal exposure to fraud against their customers and long-term erosion of trust.
This feed tracks significant breaches as they are publicly disclosed, summarising what happened, which data types were exposed, the sector affected, and the severity of the incident. Use it to understand attacker behaviour, benchmark risk in your own industry, and spot the credential leaks and supply-chain exposures that most often precede a targeted attack. Many breaches begin quietly: an exposed database, a set of stolen credentials sold on a forum, or a compromised third-party vendor — signals that surface on the dark web weeks before an incident becomes public.
ScruteX monitors these sources continuously — dark web forums, paste sites, breach databases, and Telegram channels — and alerts your team the moment your organisation, domains, employees, or customers appear in exposed data. Early detection turns a would-be headline into a contained incident. Browse the latest alerts below, or run a free exposure scan to see what is already circulating about your organisation.
Notice
Data breach alerts are compiled from publicly available breach notification records and security reporting. Inclusion on this page does not imply fault or negligence by the affected organisation. If you represent an organisation listed here and believe any information requires correction, please contact hello@scrutex.ai.
Cheyenne and Arapaho Tribes
Government / Tribal Administration · January 2026
The Cheyenne and Arapaho Tribes of Oklahoma suffered a data security incident resulting in unauthorised access to tribal member and employee personal information.
ESOP (Employee Stock Ownership Plan Provider)
Financial Services · January 2026
A financial services firm administering employee stock ownership plans reported a breach affecting plan participant personal and financial data.
Sundher Group
Professional Services · December 2025
Professional services firm Sundher Group reported unauthorised access to client and employee records following a network intrusion.
Wilson Workflow Solutions
Technology · December 2025
Workflow automation provider Wilson Workflow Solutions experienced a ransomware attack resulting in data exfiltration and service disruption.
Aura
Identity Protection / Cybersecurity · March 2026
Aura, an identity protection and digital privacy company, confirmed a data breach exposing approximately 900,000 marketing contacts. The breach is notable given the company’s core business of protecting customers from identity theft and privacy violations.
Marquis
Financial Services · March 2026
Financial services firm Marquis disclosed that a ransomware attack led to the theft of personal data for approximately 672,000 individuals.
Washington State Benefits Administrator
Healthcare / Employee Benefits · March 2026
A Washington-state based employee benefits administrator is notifying nearly 2.7 million individuals that their personal and health plan information, including Social Security numbers, was potentially stolen in a hacking incident discovered in January 2026.
Olympique de Marseille
Sports / Entertainment · March 2026
French football club Olympique de Marseille confirmed a cyberattack after data appeared online. The club initially described the incident as an attempted attack but subsequently acknowledged that data was leaked.
Frequently asked questions
Where does the data in breach alerts come from?+
Publicly available breach notifications, regulatory disclosures, dark web leak sites, threat actor forums, and the ScruteX threat intelligence feed. Every entry is time-stamped and sourced.
How quickly are alerts published?+
Significant incidents are typically published within 24–72 hours of public disclosure or credible dark web posting. Customers with active monitoring receive private alerts earlier.
Can I monitor my organisation privately?+
Yes. ScruteX Data Exposure Insights continuously monitors your domain, brand, and executives for leaks on the dark web and surfaces alerts before they are public.