Major education, healthcare, and infrastructure breaches dominate 2026 threat landscape. Instructure Canvas suffered the largest education breach on record, while NYC Health+Hospitals and Foxconn manufacturing revealed persistent vulnerabilities in critical supply chains.
Critical 275M (attacker claim; 231M unique emails confirmed) records Apr 29, 2026
Canvas Learning Platform Hit by ShinyHunters: 275M Records Claimed Across 8,809 Institutions
Instructure (Canvas LMS)
ShinyHunters exploited vulnerabilities in Canvas beginning April 25, then returned May 7 with second exploit to deface 8,809 institution portals during exam week.
What it means: Largest education sector breach on record affects 41% of North American higher education; students and faculty exposed across Harvard, Princeton, MIT, and thousands of K-12 districts.
Critical 1.8M records Nov 25, 2025
NYC Health+Hospitals Breach Exposes Medical Records and Biometrics of 1.8M via Third-Party Vendor
NYC Health and Hospitals Corporation
Third-party vendor compromise gave threat actors network access for 11 weeks; attackers copied medical records, SSNs, government IDs, geolocation data, and fingerprint biometrics.
What it means: One of 2026's largest healthcare breaches affects largest U.S. public health system serving low-income, immigrant, and underserved populations with limited identity protection resources.
Critical 11M files; 8TB exfiltrated records May 12, 2026
Foxconn North American Manufacturing Hit by Nitrogen Ransomware: 8TB Intel Property Theft
Foxconn (Hon Hai Technology Group)
Nitrogen ransomware group breached Foxconn's Mount Pleasant (Wisconsin) and Houston (Texas) facilities, stealing 8TB of schematics and engineering data tied to Apple, Nvidia, Intel, Google, and AMD.
What it means: Manufacturing supply chain vulnerability exposed; global tech giants face intellectual property loss; fourth ransomware attack on Foxconn since 2020 signals unresolved infrastructure weakness.
High 280K records Mar 19, 2025
Nova Scotia Power Ransomware Attack Exposes SINs and Bank Data of 280K Canadian Customers
Nova Scotia Power
Undetected breach lasted five weeks from March 19 until detection April 25; attackers exfiltrated Social Insurance Numbers, driver's licenses, and bank account details before encryption deployment.
What it means: Canadian critical infrastructure operator targeted; customers face elevated identity theft and fraud risk; company declined ransom and data published online by attackers.
Critical 100M+ records Feb 18, 2024
Change Healthcare Ransomware Breach Remains 2024's Largest: 100M Americans Affected by Payment System Attack
UnitedHealth / Change Healthcare
Attackers stole or purchased Citrix remote-access credentials lacking MFA; ransomware encrypted payment and prescription systems, disrupting healthcare nationwide.
What it means: Largest healthcare breach in U.S. history; exposed medical records, SSNs, insurance data; parent company faced $2.4B total impact including $1.5B response costs and $22M ransom.
Critical 2.9B records Aug 16, 2024
National Public Data Breach Affects 2.9B Records: SSNs Exposed Across US, Canada, UK
National Public Data (background check provider)
Florida background-check company exposed plaintext credentials on public website; attackers accessed database containing SSNs, names, addresses, and dates of birth for ~170M US and Canadian citizens.
What it means: One of largest data exposures in history; company filed Chapter 11 bankruptcy; demonstrates credential exposure of background-check firm compromises its core function and trust.