Major 2026 breaches affecting North America expose hundreds of millions of records across healthcare, education, financial, retail and telecommunications sectors. ShinyHunters emerges as prolific threat actor targeting cloud platforms and stealing credentials at scale.
Critical 275M records May 1, 2026
Instructure Canvas platform hit twice by ShinyHunters in May 2026
Instructure Inc.
Attackers exploited a stored cross-site scripting vulnerability in Canvas support ticket system to gain access to 275 million student and staff records across 8,809 institutions globally.
What it means: Students lost access to coursework during finals as defaced login screens disrupted exams across US universities; company paid ransom despite FBI guidance against payment.
Critical 700TB-1PB records Mar 12, 2026
Telus Digital breach exposes up to 1 petabyte of customer service data
Telus Digital
Attackers accessed Telus systems for months using stolen Google Cloud Platform credentials from a prior Salesloft vendor breach, exfiltrating customer support recordings, source code, and employee records including FBI background checks.
What it means: Data from at least 28 major corporations handled by Telus BPO services compromised; largest data theft by volume confirmed in 2026.
Critical 6M records May 27, 2026
Carnival Cruise confirms nearly 6 million customers exposed in April attack
Carnival Corporation
Social engineering attack tricked employee into granting access April 14; attacker copied personal data including passport and driver license numbers from customer systems before detection on April 22.
What it means: Affected 800,000 Texans alone; criminal group ShinyHunters leaked loyalty program data enabling targeted phishing using real booking and trip details.
Critical 1.8M records Feb 2, 2026
NYC Health + Hospitals breach affects 1.8 million via vendor compromise
NYC Health + Hospitals
Attackers accessed systems from November 2025 through February 2026 via unnamed third-party vendor vulnerability; copied medical records, biometric fingerprints and palm prints, SSNs and government IDs.
What it means: Biometric data exposure is permanent and cannot be reissued; largest public health system in US largely serves uninsured and Medicaid patients.
High 750K records Jan 14, 2026
CIRO phishing attack compromises 750,000 Canadian investor records
Canadian Investment Regulatory Organization
Sophisticated phishing attack first detected August 2025 compromised Canada's investment watchdog systems; unauthorized access to Social Insurance Numbers, government IDs and investment account statements.
What it means: Regulator responsible for protecting investors cannot protect itself; five months elapsed before full disclosure to affected Canadian investors.
High 2.8M records Mar 31, 2026
Hallmark Cards breach exposes customer and employee data after ransom refusal
Hallmark Cards Inc.
ShinyHunters accessed Salesforce environment containing customer records with names, addresses, phone numbers, emails and dates of birth; data leaked after company refused April 2 ransom deadline.
What it means: Customer support tickets exposed enabling targeted phishing; Hallmark publicly silent on breach despite company statement from threat actors.