DataBreaches.net
databreaches-net · C · active
Long-running independent breach tracker run by Dissent Doe; primary aggregator for breach disclosures (often the first to publish state AG breach-notification filings, hospital/clinic disclosures, education-sector incidents). WebFetch returns HTTP 403 (re-confirmed 2026-05-08; RSS at /feed/ also 403's). REQUIRED FETCH METHOD: `python3 tools/fetch_source.py url https://databreaches.net/` (host added to bridge allowlist 2026-05-08). NB: the bridge ALSO returns 403 from some egress IPs (the publisher's WAF appears to have IP-reputation rules in addition to UA filtering). If the bridge fails, surface as a coverage gap rather than retrying. Discovery layer: trace each breach back to the victim's own statement or regulator filing before citing. |. Sustained 403 = transport block, no demote; needs alternate-URL strategy or replacement. | 2026-06-20 full audit (v2.62): RECOVERED via the Chrome-138 UA + Sec-CH-UA client hints. FETCH → `feed https://databreaches.net/feed/` returns 200 with dated breach disclosures (the HTML homepage is still 403, skip it). Discovery: trace each breach to the victim statement / regulator filing before citing. fetch_method bridge→rss; +ransomware. | 2026-06-20 v2.64 fetch-waste review: KEPT; the /feed/ RSS carries ~1.4 KB article bodies per item (readable without drilling). Confirmed full-content feed. | 2026-07-05 admiralty audit: C (was HIGH), discovery/aggregation layer with some original reporting; trace each breach to victim statement/regulator filing before citing. Live via /feed/, no change (active). | 2026-08-13: RECIPE: individual article URLs 403 on raw WebFetch; use `fetch_source.py feed` for the listing and `fetch_source.py url` for article bodies (auto-falls back to the reader, which succeeded on every article this run).
Cited in 6 entries
Citation cadence
Citation days per ISO week (10 weeks of coverage span, total 6).
- Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain2026-09-13
- CNIL fines Hôpital privé de la Loire EUR 500,000 over a 727,000-record breach traced to a single unprotected external physician account2026-09-04
- MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion, and because it is a processor, not a controller, the people affected cannot be told directly2026-08-13
- Metabase: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances, exploited since 3 August, and no CVE was ever assigned2026-08-09
- A Flemish Government agency confirms a DPRK compromise reached it through a contractor's workstation, one of 1,640 organisations a researcher counted from inside the actors' own servers2026-08-08
- Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records, claim unverified and contradicted by the filing2026-07-09