Five major verified breaches impacting North Americans in 2024-2026, ranging from 280,000 to 192.7 million individuals. Mega-breaches dominate the landscape, with Instructure's Canvas LMS, Change Healthcare, and 700Credit leading by volume and cascading impact.
Critical 275M records Apr 30, 2026
Instructure Canvas: 275M educational records exposed by ShinyHunters ransomware
Instructure Holdings (Canvas LMS)
ShinyHunters exploited unpatched support ticket vulnerability in Canvas free-for-teacher environment, exfiltrating 3.65TB of student and faculty records across 8,809 North American institutions.
What it means: Most widely used learning management system in US colleges became single point of failure affecting students during finals week; ransom paid but no guarantee data destroyed.
Critical 192.7M records Feb 2024
Change Healthcare: 192.7M affected in largest US healthcare breach ever
Change Healthcare (UnitedHealth Group)
BlackCat ransomware group compromised clearinghouse processing 1 in 3 US patient records, disrupting healthcare claims nationwide and stealing protected health information from nearly two-thirds of American population.
What it means: Single vendor failure cascaded across entire US healthcare system; demonstrates systemic dependence on centralized claims processors and fragility of payment infrastructure.
High 5.8M records May 2025
700Credit: 5.8M automotive loan applicants exposed via third-party API
700Credit
Attacker compromised third-party integration partner in July 2025, gaining persistent API access to dealership customer records across North America; SSNs, addresses, birthdates stolen over 5-month window.
What it means: Undetected third-party compromise enabled credential stuffing and potential identity fraud for millions of car, RV, and boat buyers; breach remained undetected until October.
High 280K records Mar 19, 2025
Nova Scotia Power: 280K ransomware victims; SINs and bank account data published
Nova Scotia Power
Sophisticated ransomware attack breached utility infrastructure March 19, remained undetected 37 days, then exfiltrated Social Insurance Numbers, driver licenses, and bank account details before encryption.
What it means: Canadian critical infrastructure targeted with double-extortion; company refused ransom citing sanctions law; attackers published stolen data despite containment claims.
High 1.8M records Nov 25, 2025
NYC Health + Hospitals: 1.8M records leaked via unnamed third-party vendor breach
NYC Health + Hospitals (largest US public health system)
Unnamed vendor breach gave attackers 78-day window into largest public health system, exfiltrating patient and employee medical records, fingerprint scans, SSNs, and insurance data from November through February 2026.
What it means: Third-party vendor compromise at safety-net healthcare system serving mostly uninsured and Medicaid patients; two months of undetected access exposed biometric and financial data.