Six major data breaches impacted North Americans in 2026, exposing hundreds of millions of records across education, telecommunications, government, legal, and manufacturing sectors. Breaches ranged from credential theft and social engineering to wiper attacks and ransomware, with impacts spanning educational institutions, government agencies, healthcare manufacturers, and critical infrastructure.
Critical 275M records May 7, 2026
Instructure Canvas Platform Hit by ShinyHunters, 275M Student Records Exposed
Instructure
ShinyHunters exploited the Free-For-Teacher program in late April 2026 to breach Canvas, exfiltrating usernames, emails, student IDs, course enrollment details, and private messages from 8,809 institutions.
What it means: The largest education sector breach on record compromised the learning records and communications of roughly 40% of North American higher education students during finals week.
Critical 13M records May 26, 2026
Charter Communications Suffers Vishing Attack, 13M Customer Records Leaked
Charter Communications
ShinyHunters used social engineering calls to compromise Microsoft Entra accounts, then pivoted to Salesforce to extract customer names, addresses, phone numbers, and nearly 10 million support ticket records.
What it means: The breach exposed about 40% of Charter's customer base to targeted phishing, fraud, and account takeover attacks across the largest US broadband provider.
Critical 500M+ records January 21, 2026
Social Security Administration DOGE Data Sharing Exposes Hundreds of Millions
Social Security Administration
DOGE employees uploaded sensitive Social Security data to unauthorized cloud servers without agency approval and attempted to share records with a political advocacy group seeking to match voter rolls.
What it means: Hundreds of millions of Social Security numbers, birth dates, and citizenship records were exposed through policy violations and sent outside government control, potentially enabling widespread identity fraud.
Significant Thousands records February 19, 2026
VIQ Solutions Breach Exposes Australian and Canadian Court Records Through Subcontractor
VIQ Solutions
The Canadian transcription firm subcontracted work to India-based e24 Technologies in violation of government contracts, exposing thousands of sensitive court files including domestic violence and national security cases.
What it means: Internal warnings about offshore data access were ignored for months, resulting in a vendor governance failure that compromised confidential court proceedings across multiple jurisdictions.
Critical N/A records Mar 11, 2026
Stryker Medical Device Manufacturer Hit by Iranian Wiper Attack, 200K Devices Destroyed
Stryker
Iran-linked group Handala weaponized Stryker's Microsoft Intune device management platform to wipe more than 200,000 endpoints globally, destroying data and halting manufacturing, shipping, and surgery scheduling.
What it means: A state-sponsored wiper attack targeting critical medical device manufacturing disrupted hospital operations across 79 countries and forced surgical procedure cancellations.
Critical 8TB records May 12, 2026
Foxconn North American Factories Breached by Nitrogen Ransomware, 8TB Stolen from Apple Supply Chain
Foxconn
Nitrogen ransomware group compromised Foxconn's North American operations and exfiltrated 8 terabytes containing engineering schematics, circuit board layouts, and confidential data from Apple, Nvidia, Google, Intel, AMD, and Dell.
What it means: A single electronics manufacturer serving six Fortune 500 companies became a central point of failure exposing proprietary technology blueprints and supply chain intelligence globally.