LeakTrace Intelligence Desk · June 10, 2026

Weekly Breach Intelligence Briefing

Six major data breaches impacted North American organizations in 2026, ranging from educational platforms to retail and telecommunications. The attacks exploited social engineering, misconfigured systems, and third-party vulnerabilities affecting hundreds of millions of users and customers.

Critical 275M records May 01, 2026

Canvas learning platform suffers massive breach affecting 9,000 schools

Instructure

ShinyHunters exploited a vulnerability in the Free-For-Teacher program to gain initial access, exfiltrating student records, teacher messages, and enrollment data across nearly 9,000 educational institutions.

What it means: Academic institutions serving millions of students face potential phishing, identity theft, and fraud targeting students and families using exposed personal messages and enrollment information.

High 2.9M records Mar 28, 2026

Giant Tiger retail chain exposes nearly 3 million customer records

Giant Tiger

A hacker claimed to have stolen customer records from the Canadian retailer after a March attack, with the company disclosing the incident weeks later following the threat actor's public announcement.

What it means: Customers face fraud risk and identity theft from exposed email addresses, names, physical addresses, and phone numbers sold on criminal forums.

High 4.9M records Apr 01, 2026

Charter Communications Spectrum breached via voice phishing attack

Charter Communications

Attackers used a voice phishing call to trick a Charter employee into revealing Microsoft Entra credentials, then accessed Salesforce to exfiltrate customer and support ticket data.

What it means: Millions of customer records containing names, addresses, and account details enable targeted phishing, account takeover, and social engineering attacks against Spectrum subscribers.

Critical 1PB stolen records Mar 12, 2026

TELUS Digital loses 1 petabyte of sensitive data including voice recordings

TELUS Digital

Attackers leveraged stolen Google Cloud credentials from the Salesloft breach to pivot into TELUS systems, stealing customer support records, voice recordings, financial data, and FBI background checks.

What it means: The massive data theft of voice recordings and financial information exposes Canadian customers and businesses to identity fraud, blackmail, and regulatory violations under PIPEDA.

High 393.8K records Mar 05, 2026

T-Mobile insider breach exposes account credentials and government IDs

T-Mobile

An insider at T-Mobile accessed customer account information including Social Security numbers, driver's license numbers, account PINs, dates of birth, and associated phone numbers.

What it means: Customers face immediate risk of account takeover using stolen account PINs and government identifiers, and long-term identity theft risk from exposed SSNs.

High 2.35M records Jun 08, 2026

Nissan Motor data breach exposes 2.35 million customer records globally

Nissan Motor

Customer records from Nissan Motor were exposed and leaked online, compromising personal information of millions across multiple regions and sales channels.

What it means: Vehicle owners face phishing targeting automobile warranty scams, account fraud, and identity theft using exposed personal and purchasing data.