Skip to main content

§Answers

How do I find out about recent data breaches?

Use Have I Been Pwned to check whether your own accounts appear in known breaches. For organisational disclosures, read United States state attorney general breach notification portals, SEC Form 8-K Item 1.05 filings for listed companies, and your national data protection regulator’s register. News outlets are fastest; official registers are authoritative and slower.

Timing is the thing most people get wrong. Disclosure lags discovery by weeks or months, and the first public report of a breach is frequently not a disclosure at all but a claim on a ransomware gang’s leak site — an assertion by an attacker with an incentive to exaggerate. Treat the first report as a lead, and wait for the organisation, a regulator or a filing before treating scope or numbers as real.

For personal exposure, Have I Been Pwned is the standard tool: search any address free, and it aggregates credentials from known breach corpora. Password managers and browsers now run equivalent checks. Neither tells you about a breach that has not been published, which is most of them.

For organisational disclosure the registers are the authoritative layer. Several United States state attorneys general — California, Maine, Washington and others — publish searchable notification databases with the affected count and dates. Publicly listed United States companies must file a Form 8-K under Item 1.05 for material cybersecurity incidents, though many file voluntarily under Item 8.01 instead, so both are worth watching. In the European Union, GDPR obliges notification to a supervisory authority within 72 hours, and NIS2 adds sector reporting; national regulators publish enforcement decisions that often reveal incidents never covered as news.

News aggregation is what closes the speed gap between an incident and its paperwork. As of September 2026, breach coverage in the sec-news.ai archive clusters heavily in a few source publications — thehackernews.com, securityweek.com, cybersecuritynews.com and bleepingcomputer.com supply about 80% of everything the pipeline gathers from 29 configured sources — which reflects the feeds we run rather than where stories break. The live data breach topic feed on this site collects them as they arrive, which is the appropriate place for anything that changes week to week.

Related coverage

Data Breachesdispatches →

Major data breaches, exposure incidents, credential leaks, and regulatory disclosures from the past week.