LeakTrace Intelligence Desk · March 19, 2026

Weekly Breach Intelligence Briefing

North American data breaches in 2026 have exposed tens of millions of records across healthcare, financial services, and government sectors. Recent disclosures reveal systematic vulnerabilities in third-party vendor management and credential-based attacks.

Critical 25M records Feb 26

Conduent ransomware attack impacts 25 million benefit recipients across 46 states

Conduent

Attackers spent three months inside Conduent's environment exfiltrating 8TB of healthcare and benefits data from Medicaid systems, SNAP programs, and health insurers.

What it means: One of the largest healthcare-related breaches on record affects millions of benefit recipients, creating identity theft and fraud exposure.

High 5.1M records Jan 31

Panera Bread customer database leaked after extortion demand rejected

Panera Bread

Attackers obtained customer contact data and published a 760MB archive containing names, emails, phone numbers, and addresses after ransom demands were refused.

What it means: Customer personal information is now available for phishing campaigns and identity fraud targeting Panera's 5 million affected accounts.

Critical 1.2M records Mar 05

University of Hawaii Cancer Center breach affects nearly 1.2 million patients

University of Hawaii

Ransomware gang breached the Cancer Center's Epidemiology Division in August 2025, stealing names, Social Security numbers, driver's license data, and voter registration information.

What it means: Compromised sensitive health and identity data puts patients at severe risk for identity theft and targeted fraud.

Critical 6.2M records Feb 07

Odido telecommunications breach affects 6.2 million customers

Odido

Attackers breached customer contact systems and downloaded names, addresses, emails, mobile numbers, dates of birth, and identification details from 6.2 million customers.

What it means: Customers face targeted phishing, SIM swap attacks, and account takeovers using verified identity and contact information.

High 4.1M records Jan 19

IBM MOVEit software vulnerability exposed Colorado patient health records

IBM/Colorado

Hackers exploited a MOVEit file transfer vulnerability to steal 4.1 million Colorado patient records including protected health information.

What it means: Healthcare providers relying on vulnerable MOVEit systems face ongoing exposure until patches are applied enterprise-wide.

High 967K records Feb 14

Figure Technology social engineering attack exposes nearly 967,000 user accounts

Figure Technology

Social engineering attack tricked an employee into providing access, allowing attackers to download user account data including names, dates of birth, addresses, and phone numbers.

What it means: Nearly one million user accounts are exposed to identity theft and phishing campaigns targeting verified personal information.