Six critical breaches in 2026 exposed millions of North Americans across education, telecommunications, healthcare, cruise lines, insurance oversight, and utilities sectors. Credential compromise and social engineering emerged as the dominant attack vectors, with ransom demands and extortion campaigns marking a shift toward organized data-theft operations.
Critical 30M+ records May 1, 2026
Instructure Canvas hit twice in May extortion campaign
Instructure
Education platform Canvas used by 41% of North American higher education institutions was breached twice by extortion group, first exposing student and staff data, then defacing login portals during final exam periods.
What it means: Academic institutions across the U.S. and Canada faced operational disruption and student data exposure during critical exam periods.
Critical 6M records April 22, 2026
Carnival cruise line exposes 6 million customer records
Carnival Corporation
Social engineering attack against single employee account opened path to IT systems allowing attackers to copy personal information including names, addresses, email addresses, phone numbers, and dates of birth.
What it means: Millions of cruise passengers face identity theft and fraud risks from leaked personal identity information.
Critical Millions records March 2026
Telus telecom breach exposes 700TB of Canadian customer data
Telus
Canadian telecommunications firm breached with personally identifiable information, call data, background check details, and source code stolen.
What it means: Canadian customers exposed to identity fraud, financial abuse, and surveillance risks from leaked call records and personal data.
High 170K records June 2026
London Hydro utility breach affects 170,000 Ontario customers
London Hydro
Canadian electricity provider's systems breached exposing customer names, addresses, email addresses, phone numbers, account numbers, billing data, and meter information.
What it means: Ontario residents face phishing and account takeover risk from leaked utility account and contact information.
Critical Credit data records Jun 17, 2026
NAIC insurance regulatory agency compromised in June attack
NAIC
National Association of Insurance Commissioners database breached compromising credit rating data from Moody's, S&P, and other agencies, forcing suspension of investment risk designations.
What it means: U.S. insurance market disrupted as regulatory oversight of capital requirements halted, affecting insurer operations nationwide.
Critical 2.6M records June 2026
DentaQuest dental benefits breach leaks 2.6 million member records
DentaQuest
Dental benefits administrator breached in May extortion campaign with 234GB archive containing names, phone numbers, addresses, birth dates, gender data, government-issued IDs, and health insurance information.
What it means: Millions of U.S. dental plan members exposed to identity theft and healthcare fraud through leaked insurance and government ID data.