North America experienced six major data breaches in the past 12 months spanning healthcare, retail, automotive, and employee records. The Canvas LMS platform, NYC Health + Hospitals, and Canadian Tire stand out as the largest by record count.
Critical 275M records Apr 25, 2026
Canvas LMS platform suffers largest educational data breach on record
Instructure (Canvas)
ShinyHunters breached Canvas LMS systems affecting 8,809 educational institutions globally, stealing 3.65 TB of data including student-teacher messages and identity information.
What it means: The largest educational breach ever recorded exposed sensitive communications and identity data for hundreds of millions of students and teachers across North America and worldwide.
Critical 1.8M records Nov 25, 2025
NYC Health + Hospitals third-party vendor breach exposes 1.8 million patient records
NYC Health + Hospitals
Unauthorized actors accessed NYC H+H systems from late November 2025 through February 2026 via a compromised third-party vendor, copying medical records, biometric fingerprints, SSNs, and financial data.
What it means: Attackers obtained 11 weeks of undetected access to one of America's largest public health systems, compromising sensitive health and biometric data with long-term identity theft risk.
High 42M records Oct 02, 2025
Canadian Tire retail e-commerce database breach impacts 38 million customer accounts
Canadian Tire Corporation
Unauthorized access to Canadian Tire's e-commerce database exposed names, addresses, emails, encrypted passwords, and partial credit card information for 38 million unique customer accounts across retail banners.
What it means: Canada's largest retail data breach exposed customer PII across Canadian Tire, SportChek, Mark's, and Party City, creating identity theft exposure despite encrypted passwords.
High 5.8M records Oct 25, 2025
700Credit automotive credit data breach affects 5.8 million dealership customers
700Credit
Attackers breached a third-party integration partner in July 2025, gaining access to 700Credit APIs and stealing automotive dealership customer data including names, addresses, birthdates, and Social Security numbers.
What it means: A months-long undetected compromise of a major North American automotive credit provider exposed SSNs and personal identity data for millions of vehicle financing applicants.
High Unreported total records May 27, 2026
Nissan Americas employee data exposed in Oracle PeopleSoft zero-day attack
Nissan Americas
ShinyHunters exploited CVE-2026-35273 zero-day vulnerability in Oracle PeopleSoft between May 27 and June 9, 2026, accessing Nissan employee records including SSNs, banking, and tax information.
What it means: Nissan and 300+ PeopleSoft instances across 100 organizations were compromised via zero-day before emergency patching, exposing employee payroll and financial records across US, Canada, Mexico, and Brazil.
Significant 900K records Mar 01, 2026
Aura identity protection company breached, exposing 900K marketing database records
Aura
ShinyHunters breached Aura's marketing database via targeted voice phishing attack on an employee account, exposing names, addresses, emails, phone numbers, and marketing data for 900K contacts.
What it means: An identity protection company became the ironic victim of its own breach, exposing customer contact information to attackers through social engineering compromise.