Breach List Database

A meta-database collecting resources that compile lists of (security) incidents.

When Your AI Becomes a Target: AI Security Incidents and Best Practices

Academic survey mapping AI-specific attacks and defensive best practices.

OWASP Top 10 for Agentic Apps — ASI Agentic Exploits & Incidents

Community-curated list of real-world exploits against agentic AI systems.

JESTR AI Incidents

SEC-disclosed incidents tagged with an AI breach taxonomy and business-impact context.

GenAI Incidents

13,000+ filterable entries tracking GenAI and agentic AI security incidents by severity.

Security Incidents From Caching

Curated collection of breaches caused by misconfigured or exploited caching layers.

breaches.cloud

Public-cloud customer breach write-ups with root-cause analysis and timeline reconstruction.

CloudVulnDB

Open database of cloud-provider vulnerabilities and security issues across major platforms.

AWS Customer Security Incidents

Open-source index of publicly documented AWS customer security incidents.

s3-leaks

Chronological catalog of publicly exposed S3 buckets and resulting data leaks.

Blockchain Graveyard

Memorial for cryptocurrencies and exchanges killed by hacks, thefts, and security failures.

blocksec-incidents

Community-maintained tracker of blockchain and smart-contract security incidents.

Defi Llama

Running tally of DeFi hacks with amounts stolen, vectors, and protocol post-mortems.

Destroyed by Breach

Spreadsheet tracking companies that shut down following a security incident.

Identity Attacks in the Wild

Catalog of real-world identity-based attacks against SaaS and cloud environments.

RansomLook

Aggregator of ransomware gang activity, leak sites, and victim announcements.

Ransomware.live

Live tracker of ransomware incidents with timeline and threat-actor attribution.

steg-in-the-wild

Documented cases of steganography used in malware delivery and covert communication.

CNCF Supply Chain Security Compromises

CNCF-curated catalog of open-source supply chain attacks and compromises.

OpenSSF Catalog of Supply Chain Compromises

Spreadsheet dataset of supply chain security incidents with structured metadata.

OSS Supply Chain Attack Compendium

Research compendium mapping open-source software supply chain attack patterns.

MITRE Adversarial ML Threat Matrix Case Studies

Adversarial machine learning threat matrix with documented real-world case studies.

Repository of Industrial Security Incidents

Database of industrial control system and critical infrastructure security incidents.

Web Hacking Incident Database

Early web application security incident archive predating modern breach disclosure.

VSec.dk / Incidents

~37 incidents since 2012. High threshold—national impact or critical infrastructure.

RecentBreaches.com / US

14,119+ incidents. Separates confirmed filings from ransomware claims. Very low threshold.

AusDataBreach.org

Hundreds of incidents. Three-tier severity. Very low threshold—includes 3-record breaches.

FrenchBreaches.com

Labels incidents Confirmée vs Revendiquée. Lists exposed data types. Includes attempted attacks.

IndianBreaches.com

Indexes publicly visible threat-actor posts. Does not acquire or host stolen data.

CanadaBreaches.ca

JS-rendered; details could not be retrieved.

EURepoC.eu / Database

Research-grade. Tracks EU Cyber Diplomacy Toolbox. High selectivity. Static dataset versions.

Wikipedia List of Data Breaches

Crowdsourced chronological list of major data breaches with impact figures.

Wikipedia List of Security Hacking Incidents

Broad historical index of notable security hacking incidents.

Have I Been Pwned's Pwned Websites

Searchable index of breached sites with user count and data classes exposed.

Foobarsec

Airtable-based gallery and grid of security incidents, breaches, and vulnerability disclosures.

Data Breach DB

Academic research dataset of data breaches with structured metadata and analysis.

Privacy Right Clearinghouse

Long-running consumer advocacy database of U.S. data breaches, downloadable in multiple formats.

CSIS's Significant Cyber Incidents

Policy-focused tracker of geopolitically significant cyber incidents.

CSIDB

Dashboard of 600+ cyber incidents with victim, threat actor, and country breakdowns.

Board Cybersecurity Incident Tracker (8-Ks)

Tracker of cybersecurity incidents from SEC filings, state AGs, and news sources.

Breach HQ

Weekly-updated open database of reported breaches with organization and threat actor details.

Analysis of Every CA Breach Notification in 2017

Deep-dive analysis of California breach notifications from a single reporting year.

Collection of Breach Blog Posts

Curated anthology of write-ups and post-mortems from notable security incidents.

h/t Shellsharks, which I’ve aggregated in