Six significant data breaches in 2026 exposed millions of North American records across financial services, retail, education, and healthcare sectors. Credential theft via social engineering and voice phishing remained the primary attack vector.
Critical 750K records Jan 15, 2026
CIRO investor data exposed via phishing compromise
CIRO
Phishing attack in August 2025 led to credential compromise, exposing investor social insurance numbers and financial data.
What it means: Canadian investors face identity theft and fraud risk from financial credential exposure on the dark web.
Critical Undisclosed records Mar 12, 2026
TELUS Digital suffers cloud-based data theft
TELUS Digital
ShinyHunters stole BigQuery data from compromised Google Cloud credentials, accessing customer support records, call recordings, and internal data.
What it means: Canadian customers and employees face privacy breach with financial and background check information exposed.
Critical 13M records Apr 15, 2026
Kemper insurance data stolen in ransomware attack
Kemper Corporation
ShinyHunters ransomware attack exposed 29GB of personal information and corporate data from the major US insurance provider.
What it means: US policyholders face identity theft and fraud from exposure of personal identifiable information and financial records.
Critical 275M records May 1, 2026
Canvas learning platform breached affecting millions globally
Instructure
ShinyHunters accessed student and staff data from nearly 9,000 institutions including Canadian universities, stealing names, emails, student IDs, and private messages.
What it means: North American students and educators face phishing and privacy risks from exposure of academic records and personal communications.
Critical 4.9M records Apr 1, 2026
Charter Communications breached via voice phishing
Charter Communications
ShinyHunters used voice phishing to obtain Salesforce credentials, accessing customer records through the CRM platform.
What it means: US broadband customers face phishing and fraud from exposed personal data linked to service accounts.
High Undisclosed records Apr 22, 2026
Carnival cruise line hit by social engineering attack
Carnival Corporation
Social engineering attack on employee account opened path to IT systems, with attackers copying customer personal information.
What it means: North American cruise passengers face identity theft risk from exposure of booking and personal details.