Six critical data breaches hit North America in 2026, spanning education, healthcare, and retail. Instructure's Canvas suffered the largest education-sector breach affecting 275 million users globally, while NYC Health and Hospitals exposed 1.8 million patients' data including biometrics.
Critical 275M records May 1, 2026
Instructure Canvas platform breached twice in May
Instructure
Canvas was compromised twice within two weeks via exploited Free-For-Teacher accounts, affecting over 8,800 institutions with student records and messages.
What it means: The largest education-sector breach on record disrupted exam periods and revealed the sector's vulnerability to social engineering and weak institutional verification controls.
Critical 1.8M records Feb 11, 2026
NYC Health and Hospitals data compromised through vendor
NYC Health + Hospitals
An unnamed third-party vendor was breached, exposing patient medical records, financial data, and biometric fingerprints from November 2025 through February 2026.
What it means: The largest U.S. public health system breach demonstrated that healthcare organizations cannot protect data when vendors have unrestricted access.
Critical 3M records March 15, 2026
Giant Tiger exposes nearly 3 million Canadian customer records
Giant Tiger
The Canadian retailer's systems were breached in March, exposing names, email addresses, physical addresses, and phone numbers of nearly 3 million customers.
What it means: A major Canadian retailer's delayed disclosure of a major breach raised concerns about Canadian retailers' incident detection and response capabilities.
High 1.3K records Jan 25, 2026
Canada Computers confirms payment card and personal data exposure
Canada Computers
Unauthorized access to the retailer's website systems exposed personal details and payment card data for 1,284 Canadian customers.
What it means: The incident highlighted vulnerability in e-commerce infrastructure and exposed the risks of inadequate access controls in retail technology platforms.
High 4.9M records Apr 1, 2026
Charter Communications social engineering leads to customer data leak
Charter Communications
A vishing attack compromised an employee's Microsoft Entra account, granting attackers access to Salesforce data of approximately 4.9 million customer accounts.
What it means: Social engineering bypassed technical controls at a major U.S. broadband provider, exposing customer names, addresses, phone numbers, and email addresses.
High 7.5M records Apr 22, 2026
Carnival cruise line breached via employee account compromise
Carnival Corporation
Social engineering against a single employee account provided attackers access to personal information and loyalty program data for millions of cruise customers.
What it means: The world's largest cruise operator's breach confirmed that single employee accounts can expose millions of sensitive travel and financial records.