LeakTrace Intelligence Desk · April 22, 2026

Weekly Breach Intelligence Briefing

Six major data breaches hit North American and global targets in 2026, compromising over 26 million records across financial services, healthcare, and government sectors. Phishing attacks and third-party vendor compromises dominated the incident landscape, with several breaches involving months-long disclosure delays.

Critical 750K records Jan 14, 2026

CIRO investment watchdog phishing attack exposes 750,000 investor records

Canadian Investment Regulatory Organization

Sophisticated phishing attack in August 2025 led to unauthorized access of Canadian investor personal and financial information, confirmed in January 2026 forensic investigation.

What it means: Affected investors face elevated identity theft and fraud risk despite no evidence of dark web activity as of investigation date.

Critical 2.7M records Jan 23, 2026

Navia benefits administrator hit by API flaw exposing 2.7 million Americans

Navia Benefit Solutions

Unauthorized actor exploited read-only API vulnerability gaining undetected access from December 22, 2025 through January 15, 2026, exfiltrating health plan and personal data.

What it means: Millions of U.S. employees face phishing and medical identity theft risks from exposed Social Security numbers and health enrollment information.

Critical 15.8M records Mar 3, 2026

Cegedim Santé France medical breach exposes 15.8 million patient records including sensitive health notes

Cegedim Santé

Late 2025 cyberattack compromised MonLogicielMedical platform used by 1,500 French doctors, stealing administrative files and 165,000 files containing doctors' free-text notes with HIV status and mental health details.

What it means: Patients face severe privacy violation and targeted extortion risks from exposure of highly sensitive medical and personal information.

High 70K records Apr 20, 2026

Canada Life insurance breach compromises 70,000 customer workplace benefits records

Canada Life

Cybercriminal accessed employee account at major Canadian insurer, stealing personal information from benefits database including names, dates of birth, addresses, and annual income data.

What it means: Affected group benefits participants face targeted fraud and social engineering risks from exposure of income and employment details.

High 6.8M records Mar 12, 2026

Crunchyroll anime streaming service loses 6.8 million customer support records via vendor compromise

Crunchyroll

Attacker compromised Telus International employee account via phishing malware, gaining Okta SSO access to download 8 million support tickets containing customer names, emails, and support interaction details.

What it means: Millions of anime subscribers face sophisticated phishing attacks leveraging detailed support ticket information to impersonate legitimate company communications.

Critical 350GB records Mar 27, 2026

European Commission cloud infrastructure breach leaks 350GB of government data from AWS account

European Commission

Attackers accessed cloud infrastructure hosting Europa.eu website on March 24, 2026, exfiltrating databases, mail server contents, and confidential contracts before access was revoked.

What it means: EU institutional data exposure creates diplomatic and security risks affecting multiple government operations and sensitive policy information.