LeakTrace Intelligence Desk · March 19, 2026

Weekly Breach Intelligence Briefing

Six major 2026 breaches across North America exposed tens of millions of records through healthcare system compromises, retail attacks, and ransomware incidents. Patient data, customer information, and sensitive government records remain the primary targets as attackers exploit third-party vulnerabilities and credential theft.

Critical 25M+ records Jan 15, 2026

Conduent Ransomware Exposes Government Benefits Data Across States

Conduent

A ransomware gang breached the business services provider handling Medicaid, SNAP, and benefits processing for over 30 states, exfiltrating approximately 8 TB of sensitive data including names, Social Security numbers, medical records, and health insurance details.

What it means: Millions of Americans receiving government benefits had their personal and health information exposed, requiring notifications across multiple states and triggering at least 10 class action lawsuits.

Critical 4.1M records Jan 08, 2026

Colorado Hospital Breach Via MOVEit Exploits Affects Patients

IBM MOVEit (Colorado)

Attackers exploited a MOVEit file transfer vulnerability to access a healthcare system's database, stealing sensitive patient health records from Colorado residents.

What it means: Millions of patients' confidential medical information became accessible to criminals, increasing risk of identity theft and fraudulent insurance claims.

High 5.1M records Jan 24, 2026

Panera Bread Customer Database Stolen and Published Online

Panera Bread

A criminal group compromised Panera's systems through a Microsoft security weakness and published a stolen archive containing customer names, emails, phone numbers, and addresses after the company refused their ransom demand.

What it means: Millions of frequent Panera customers face heightened phishing and identity fraud risks from widely available contact information.

High 1M records Feb 15, 2026

Canada Goose Luxury Brand Exposed Nearly One Million Customer Records

Canada Goose

A third-party breach from August 2025 exposed customer transaction records containing names, addresses, phone numbers, and email addresses for the Canadian apparel company.

What it means: The luxury retailer's customer base became vulnerable to targeted phishing and fraud campaigns using verified purchase and personal contact information.

Critical 750K records Jan 15, 2026

CIRO Investment Regulator Breach Exposes Investor Finances

CIRO

A phishing attack in August 2025 led to the theft of investor Social Insurance Numbers and financial data, with the breach remaining undetected for months until mid-January notification.

What it means: Thousands of Canadian investors face significant identity theft and financial fraud risk from compromised regulatory records.

High Undisclosed records Feb 28, 2026

VIQ Solutions Legal Records Breached By Contractor Access

VIQ Solutions

An Indian subcontractor improperly accessed sensitive legal records and court transcripts despite prior warnings about vendor risk in August 2025, exposing confidential litigation documents.

What it means: Legal discovery materials containing privileged information and protected client communications became compromised, threatening ongoing litigation and client confidentiality.