Six major 2026 breaches exposed over 300 million personal records across North America, from education platforms and telecommunications giants to government systems, driven primarily by credential theft and third-party compromises. Attackers focused on voice phishing and vendor access rather than sophisticated exploits.
Critical ~300M records Feb 13, 2026
Social Security Administration Database Exposed on Unsecured Cloud Server
U.S. Social Security Administration
A live copy of the Social Security database containing records of most living Americans was placed on an unsecured cloud server without proper oversight.
What it means: Hundreds of millions of Americans now face permanent risk of identity fraud and financial exploitation as the master Social Security database has potentially been exposed indefinitely.
Critical 275M records May 6, 2026
Canvas Education Platform Breach Affects 275 Million Students and Staff
Instructure (Canvas)
Voice phishing attackers gained access and stole 3.65 terabytes of data including student names, emails, private messages, and course enrollment details from 8,809 global institutions.
What it means: The largest education sector breach on record exposed private communications between millions of students and teachers worldwide, creating unprecedented risk for targeted phishing.
High 13M records May 28, 2026
Charter Communications Data Leak Affects 13 Million Customers
Charter Communications (Spectrum)
Voice phishing attackers obtained employee credentials and accessed customer names, emails, addresses, phone numbers, and support ticket contents from Salesforce systems.
What it means: Millions of cable and broadband customers across 40 U.S. states now face targeted phishing and account takeover risk with their complete contact details and service history exposed.
Critical 1PB records Mar 12, 2026
TELUS Digital Breach Exposes 1 Petabyte of Data Across Canadian Operations
TELUS Digital
Attackers used leaked Google Cloud credentials to access BigQuery instances and multiple company systems, exfiltrating customer support records, voice recordings, and source code.
What it means: Dozens of downstream organizations using the business process outsourcing provider had their customer data compromised, affecting hundreds of thousands across Canada and beyond.
Critical 200K devices records Mar 11, 2026
Stryker Medical Device Manufacturer Hit with Destructive Wiper Attack
Stryker Corporation
Nation-state actors wiped over 200,000 company devices across the U.S., Ireland, and India, forcing global manufacturing shutdowns and cancellation of scheduled surgeries.
What it means: A critical medical device manufacturer lost operational capacity for weeks, halting production and disrupting patient care across hospitals globally in a targeted infrastructure attack.
High 582K records Feb 15, 2026
Canada Goose Customer Records Leaked via Third-Party Payment Processor
Canada Goose
A third-party payment processor was breached, exposing 920,000 records including customer names, emails, phone numbers, shipping addresses, and partial credit card data for the Toronto-based retailer.
What it means: Canadian luxury brand customers worldwide face phishing and fraud risk as their detailed purchase histories and partial payment information became available to threat actors.