Six major data breaches across North America in 2026 exposed over 400 million records, with educational platforms, telecommunications, and financial institutions bearing the brunt of attacks. Critical infrastructure vulnerabilities and third-party compromises remained the primary entry points for threat actors.
Critical 275M records May 07, 2026
Canvas learning platform suffers massive cyberattack affecting 275M users across 9000 institutions globally
Instructure
Educational platform Canvas was breached allowing attackers to steal student and teacher data including names, emails, student IDs, and private messages across universities worldwide.
What it means: Schools had to extend assignment deadlines and cancel finals as attackers defaced login pages with ransom demands, forcing Instructure to pay undisclosed settlement to recover systems.
Critical 1M records Jan 05, 2026
Brightspeed internet provider's 1M customer accounts compromised in January breach
Brightspeed
Fiber broadband provider's customer database was accessed containing names, billing addresses, email addresses, phone numbers, and account details across 20 US states.
What it means: Attack on critical infrastructure provider triggered four separate class-action lawsuits and exposed millions of residential and business customers to identity theft risk.
High 70K records Apr 20, 2026
Canada Life data breach exposes 70000 customers through employee account compromise
Canada Life
Major Canadian insurance firm's employee account was compromised allowing attackers to access customer names, dates of birth, mailing addresses, gender, and income information.
What it means: Breach affected less than 0.5 percent of clients but compromised personal data used for determining workplace benefits and retirement plans across the country.
Critical 750K records Jan 14, 2026
CIRO investment regulator breach exposes 750000 Canadian investors' financial data from phishing attack
CIRO
Investment industry regulator's systems were compromised via phishing allowing attackers to access investor Social Insurance Numbers, account numbers, and annual income data.
What it means: Organization mandated to protect investors failed to prevent breach, triggering multiple class actions and widespread loss of confidence in Canada's financial regulatory framework.
High 6.8M records Mar 24, 2026
Crunchyroll anime streaming breach exposes 6.8M users through third-party vendor compromise
Crunchyroll
Anime streaming service's support system was breached when attackers phished employee at Telus outsourcing partner, obtaining 8 million support tickets with customer names, emails, IP addresses, and payment card details.
What it means: 100GB of personal data was exfiltrated within 24 hours showing third-party vendor risks remain critical vulnerability for companies handling customer support operations.
High 10M records Jan 31, 2026
Match Group dating platforms suffer multiple breaches exposing millions of user accounts in January incident
Match Group
Dating app parent company behind Tinder, Hinge, and OkCupid was breached through third-party marketing analytics platform AppsFlyer allowing access to user profiles and account data.
What it means: Millions of dating app users faced privacy exposure and targeted phishing risk as attackers claimed access to credentials and platform data from multiple dating services.