LeakTrace Intelligence Desk · June 24, 2026

Weekly Breach Intelligence Briefing

Six critical data breaches hit North America in 2026, spanning education, healthcare, and retail. Instructure's Canvas suffered the largest education-sector breach affecting 275 million users globally, while NYC Health and Hospitals exposed 1.8 million patients' data including biometrics.

Critical 275M records May 1, 2026

Instructure Canvas platform breached twice in May

Instructure

Canvas was compromised twice within two weeks via exploited Free-For-Teacher accounts, affecting over 8,800 institutions with student records and messages.

What it means: The largest education-sector breach on record disrupted exam periods and revealed the sector's vulnerability to social engineering and weak institutional verification controls.

Critical 1.8M records Feb 11, 2026

NYC Health and Hospitals data compromised through vendor

NYC Health + Hospitals

An unnamed third-party vendor was breached, exposing patient medical records, financial data, and biometric fingerprints from November 2025 through February 2026.

What it means: The largest U.S. public health system breach demonstrated that healthcare organizations cannot protect data when vendors have unrestricted access.

Critical 3M records March 15, 2026

Giant Tiger exposes nearly 3 million Canadian customer records

Giant Tiger

The Canadian retailer's systems were breached in March, exposing names, email addresses, physical addresses, and phone numbers of nearly 3 million customers.

What it means: A major Canadian retailer's delayed disclosure of a major breach raised concerns about Canadian retailers' incident detection and response capabilities.

High 1.3K records Jan 25, 2026

Canada Computers confirms payment card and personal data exposure

Canada Computers

Unauthorized access to the retailer's website systems exposed personal details and payment card data for 1,284 Canadian customers.

What it means: The incident highlighted vulnerability in e-commerce infrastructure and exposed the risks of inadequate access controls in retail technology platforms.

High 4.9M records Apr 1, 2026

Charter Communications social engineering leads to customer data leak

Charter Communications

A vishing attack compromised an employee's Microsoft Entra account, granting attackers access to Salesforce data of approximately 4.9 million customer accounts.

What it means: Social engineering bypassed technical controls at a major U.S. broadband provider, exposing customer names, addresses, phone numbers, and email addresses.

High 7.5M records Apr 22, 2026

Carnival cruise line breached via employee account compromise

Carnival Corporation

Social engineering against a single employee account provided attackers access to personal information and loyalty program data for millions of cruise customers.

What it means: The world's largest cruise operator's breach confirmed that single employee accounts can expose millions of sensitive travel and financial records.