Six major data breaches struck North American organizations across healthcare, hospitality, financial services, and retail sectors between January and March 2026. Credential theft, vendor vulnerabilities, and human error remain the primary attack vectors, affecting millions of individuals.
Critical 4.1M records Jan 19
Colorado healthcare system compromised via file transfer vulnerability
IBM MOVEit / Colorado Healthcare
Attackers exploited a known vulnerability in MOVEit transfer software to access patient records at a Colorado healthcare facility.
What it means: Healthcare organizations remain vulnerable to widely-publicized software flaws when patches are not applied promptly.
Critical 25M records Jan 31
Claims processor breach exposes 25 million health records
Conduent
A technology contractor handling Medicaid claims and benefit administration across 46 states suffered a breach revealing medical records, Social Security numbers, and insurance details.
What it means: Third-party service providers handling sensitive government data pose systemic risk to millions of beneficiaries.
High 5.1M records Jan 26
Restaurant chain customer records stolen in credential compromise
Panera Bread
Attackers compromised Microsoft identity provider access to steal customer account data including names, emails, phone numbers, and addresses.
What it means: Enterprise authentication systems remain attractive targets for threat actors seeking mass customer data access.
Significant Undisclosed records Feb 10
Major vehicle manufacturer breach via customer support platform
Stellantis
Customer information was compromised through a third-party platform supporting North American customer service operations for Chrysler, Fiat, Jeep, and Dodge brands.
What it means: Automotive manufacturers face growing supply chain risks from integrated third-party service providers.
High 980K records Feb 14
Canadian luxury retailer exposed via vendor breach
Canada Goose
Customer transaction data was exposed through a breach at a third-party vendor in August 2025, including names, addresses, phone numbers, and email addresses.
What it means: Vendor security incidents create delayed notification timelines and extend customer risk windows.
Critical 1P records Mar 11
Canadian business services firm attacked with employee impact
TELUS Digital
Attackers compromised customer data, source code, financial records, voice recordings, and background check files across multiple BPO divisions.
What it means: Business process outsourcers managing diverse client data become single points of failure for cross-sector breaches.