LeakTrace Intelligence Desk · August 22, 2026

Weekly Breach Intelligence Briefing

Six major breaches have struck North American organizations across healthcare, education, and telecom sectors in 2026. Combined impact exceeds 65 million records, with credential theft and ransomware as primary attack vectors.

Critical 62.2M records Oct 21, 2024 - Jan 13, 2025

Conduent Business Services breach impacts 62M healthcare records

Conduent Business Services LLC

Medicaid claims processor experienced 83-day unauthorized network access, exposing names, Social Security numbers, health insurance details, and medical records.

What it means: Third-largest U.S. healthcare breach on record; affected individuals across 30+ states face long-term identity theft risk.

Critical 1.8M records Nov 2025 - Feb 2026

NYC Health+Hospitals breach exposes 1.8M patient records

NYC Health + Hospitals

Third-party vendor compromise allowed attackers to copy personal, medical, financial, and biometric information from hospital systems.

What it means: One of 2026's largest healthcare breaches; sensitive patient data including SSNs and diagnoses exposed across NYC hospital system.

Critical 41M student/faculty records records Apr 26, 2026 - May 7, 2026

Instructure Canvas platform breached by education extortion group

Instructure (Canvas)

ShinyHunters exploited free-for-teacher program and defaced portals at 330 institutions including Harvard and Princeton during exam periods.

What it means: Largest education-sector breach on record; Canvas serves 41% of North American higher education institutions.

High 13M+ records May 2026

Charter Communications loses customer data in extortion incident

Charter Communications

Extortion group stole 42M customer records and published data covering support interactions and billing information.

What it means: Major telecom breach affecting millions of cable and internet customers; data published on leak sites.

High 3,931+ records May 15, 2026

SM Energy breach exposes Social Security numbers of oil and gas employees

SM Energy

Zero-day exploit in third-party email system led to theft of names, addresses, emails, and Social Security numbers from 3,931 state-level registrants.

What it means: Energy sector employee data exposed; company offering 24-month credit monitoring with October 31 enrollment deadline.

High 5.8M records Jul 2025 - Oct 2025

700Credit exposes 5.8M automotive industry background records

700Credit

Largest North American credit check provider compromised via third-party API; hackers accessed customer information for automotive businesses.

What it means: Major supply chain risk for auto dealers and finance companies; 5.8 million individuals affected across North America.