Live breach-disclosure news pulled straight from the public primary sources: confirmed breaches from the Have I Been Pwned catalog, public-company incident disclosures from SEC Form 8-K Item 1.05 filings, breach notices filed with the California Attorney General, healthcare breach reports published by HHS Office for Civil Rights, and — kept separate, because confirmation takes weeks — what the security press is reporting right now.
Every entry here is third-party disclosure data quoted from the named primary source. It is presented as a reference: Senserva cannot validate third-party data. Verify against the linked source before acting on anything on this page.
The most recently published entries in the Have I Been Pwned breach catalog: what was breached, when, and what kinds of data leaked.
United States public companies are required to disclose material cybersecurity incidents on Form 8-K. These are the latest filings carrying the Item 1.05 heading, from SEC EDGAR full-text search.
California law requires an organisation to notify affected residents, and to send the Attorney General a sample of any notice reaching more than 500 Californians. These are the latest of those filings — confirmed, self-disclosed, and frequently the first confirmed record anywhere. One caveat, in the registry's own words: the organisation that sent a notice is not always the one that experienced the breach — a bank may notify about card numbers taken at a merchant. Each row links to its entry in the registry.
US law requires a breach of protected health information affecting 500 or more people to be reported to the Department of Health and Human Services, which publishes them. Confirmed and self-reported, like the sections above. Two things to read them correctly: these are submission dates, and the portal runs a few weeks behind — and the portal has no per-record web address, so each row links to the HHS breach portal rather than to its own entry.
The four sections above are confirmed, and confirmation takes time: Have I Been Pwned lists a breach once it is verified, and an 8-K arrives when the company is ready to file. This section is what the security press is reporting now — often weeks earlier, and sometimes about incidents the named companies dispute or deny. Treat every item as an allegation until one of the sections above carries it. Headlines and links from The Register; read the original before you act on it.
Generated from the confirmed breaches and SEC incident filings above, refreshed once a day. Copy it into Claude, ChatGPT, or Copilot for a team briefing in your own words. Free, no sign-in.
Breaches are the outcome; the way in is usually an exploited CVE or a configuration mistake. See what is being exploited right now on Senserva Live, this week's KEV additions, and the hottest patches and CVEs.
Patch Tuesday | Microsoft patch tracker | Exploited this week | Non-Microsoft CVE tracker | What's Hot | Open source patch tracker | End of life tracker