Six major 2026 data breaches impacted millions of North Americans, including Canadian financial regulators and educators, U.S. healthcare systems, and global pharmaceutical suppliers. Attacks exploited phishing, third-party vendors, and social engineering to exfiltrate sensitive personal data ranging from medical records to investment details.
Critical 750K records Jan 14, 2026
CIRO phishing breach exposes 750K Canadian investor records
CIRO
A sophisticated phishing attack targeting Canada's investment regulator compromised sensitive financial data on 750,000 investors including social insurance numbers and account details.
What it means: Investors face elevated risk of identity theft and fraud as criminals hold master financial profiles linking names, income, and investment holdings.
High 70K records Apr 22, 2026
Canada Life employee account breach exposes 70K customer records
Canada Life
Criminals exploited an employee account at Canada's largest life insurer to access customer personal data including names, dates of birth, and income information.
What it means: Corporate employees covered under group benefits are at risk for targeted fraud and identity theft using their workplace benefit information.
Critical 275M records May 7, 2026
Instructure Canvas breach affects 9000 schools globally with 275M users
Instructure
Attackers breached Canvas learning management system twice in five days, stealing names, email addresses, student IDs and private messages between students and teachers.
What it means: Millions of students worldwide have personal communications and academic records exposed, enabling highly targeted phishing and social engineering attacks on minors.
Critical 1.8M records Feb 2, 2026
NYC Health + Hospitals breach exposes 1.8M patients and employees with biometrics
NYC Health + Hospitals
Attackers accessed the largest public health system in the U.S. for three months through a third-party vendor breach, stealing medical records, fingerprints, and government IDs.
What it means: Exposure of biometric data like fingerprints is permanent and irreplaceable, putting patients and employees at lifelong risk despite any password resets.
High 6M records May 27, 2026
Carnival Corporation social engineering attack compromises 6M cruise customers
Carnival Corporation
An attacker used social engineering to trick a Carnival employee into granting system access on April 14, leading to theft of customer names, addresses, and booking details.
What it means: Millions of travelers had payment and personal information stolen, increasing risk of fraud tied to upcoming vacation bookings.
Critical Unknown records May 7, 2026
West Pharmaceutical ransomware attack forces global operations shutdown
West Pharmaceutical Services
A ransomware attack detected May 4 encrypted systems and exfiltrated data across the pharmaceutical packaging supplier's global operations, forcing production shutdowns.
What it means: Disruption to critical drug supply chains affects patient access to medications, while stolen data from a healthcare supplier puts customer confidentiality at risk.