Six critical 2026 breaches spanning North America exposed millions of records through employee credential theft, ransomware, and third-party vulnerabilities. Canadian financial institutions and U.S. educational platforms faced significant incidents while global platforms like Canvas impacted institutions worldwide.
High 70K records Apr 20, 2026
Canada Life credential theft compromises 70000 customer records
Canada Life
Attackers accessed Canada Life employee account and extracted names, dates of birth, addresses, and income data from workplace benefits division.
What it means: Employees and retirees face identity theft risk with personal income and benefit information now in criminal hands.
Critical 3M records May 26, 2026
Giant Tiger retailer discloses 3M customer records stolen in March
Giant Tiger
Canadian retailer disclosed attack from March containing customer email addresses, names, physical addresses, and phone numbers.
What it means: Millions of Canadian shoppers face phishing and fraud risk from exposed contact information now in breach databases.
Critical Unknown records May 1, 2026
Canvas LMS outage hits 9000 schools across North America and globally
Instructure Canvas
Unauthorized actors accessed Canvas systems on April 25 extracting student names, email addresses, IDs, and messages affecting educational institutions in US, Canada, and worldwide.
What it means: Students and staff across North America had personal academic information stolen during exam periods with ransom demands forcing system shutdown.
Critical 1.2M records Feb 27, 2026
UH Cancer Center breach exposes 1.2M patient records with SSNs
University of Hawaii Cancer Center
Ransomware gang accessed epidemiology division extracting names, Social Security numbers, driver license data, and voter registration information from 1993-2007 studies.
What it means: Medical research patients face decades of identity theft risk with government-issued IDs and SSNs compromised from legacy research files.
Critical 2.5M records May 20, 2026
Norton Healthcare ransomware attack impacts 2.5M patients and employees
Norton Healthcare
Attackers gained unauthorized access to systems containing patient medical records and employee data from major Kentucky healthcare provider with 40+ clinics.
What it means: Patients across Kentucky face medical identity theft with healthcare records sold on dark web markets affecting treatment history and billing data.
Critical 11.7M records Apr 20, 2026
France government identity portal breaches 11.7M citizen accounts
France Titres ANTS
Attackers accessed individual and professional accounts on government portal extracting names, emails, dates of birth, addresses, phone numbers, and login credentials after teen suspect was detained.
What it means: Millions of French citizens have government identity data exposed enabling credential fraud and financial impersonation across Europe.