Six major North American breaches disclosed in 2026 span education, healthcare, financial services, and utilities, with claimed record-setting volumes affecting millions. Recent incidents reveal supply-chain exposure and ransomware persistence as dominant attack vectors.
Critical 275M records Apr 30, 2026
Canvas Learning Platform Breached Affecting 275 Million Users at 9,000 Schools
Instructure (Canvas)
Hackers from ShinyHunters exploited vulnerability in Canvas production systems and exfiltrated 3.65 terabytes of data from 8,809 educational institutions globally.
What it means: Largest education sector breach on record disrupted final exams at thousands of institutions and exposed student names, email, IDs, and private messages across North American and international campuses.
Critical 1.8M records Nov 25, 2025
NYC Health + Hospitals Suffers Months-Long Breach Via Vendor Access
NYC Health + Hospitals
Unauthorized actor maintained access to NYC Health + Hospitals network from November 2025 through February 2026 via unnamed third-party vendor breach, exfiltrating medical records, IDs, SSNs, biometrics including fingerprints and palm prints.
What it means: One of 2026's largest healthcare breaches exposed sensitive patient data for largest US public health system serving primarily Medicaid recipients, affecting nearly one million New Yorkers.
Critical 5.8M records Jul 01, 2025
700Credit Breach Exposes 5.8 Million Automotive Customers' SSNs and Financial Data
700Credit
Hackers compromised third-party API integration partner in July 2025 and accessed 700Credit's dealership customer records for five months until October 25 discovery, stealing names, SSNs, DOB, and addresses.
What it means: Credit and identity verification provider serving 18,000 North American auto dealers exposed financial records of customers who never directly interacted with 700Credit, highlighting supply-chain risk in financing ecosystems.
High 280K records Mar 19, 2025
Nova Scotia Power Ransomware Attack Impacts 280,000 Canadian Customers
Nova Scotia Power
Ransomware attack compromised Canadian utility systems for 37 days undetected until April 25 discovery, exfiltrating customer names, addresses, driver's licenses, SINs, and banking details; no ransom paid.
What it means: Critical infrastructure targeting demonstrated sophisticated double-extortion tactics against essential services, affecting one of Canada's largest utilities and exposing payment and credit histories.
High 1.4K+ records Mar 28, 2026
Ernst & Young Tax Data Breach Exposes Client Financial Records and SSNs
Ernst & Young (EY)
Unauthorized party accessed EY's third-party IT support ticket platform from March 28 to April 12, downloading documents containing client tax filings, SSNs, government IDs, and financial account codes; ShinyHunters claimed responsibility.
What it means: Big Four accounting firm breach exposed sensitive tax and financial data of institutional clients worldwide, including investment-related records, affecting individuals who never directly dealt with EY.
High 1M records Jul 04, 2026
Abbott Cancer Diagnostics Breach Exposes One Million SSNs via Legacy Systems
Abbott Laboratories (Exact Sciences Cancer Diagnostics)
ShinyHunters claimed unauthorized access to legacy Exact Sciences cancer diagnostics systems via vishing social engineering attack, exfiltrating one million SSNs, names, contact information, and dates of birth.
What it means: Healthcare diagnostics provider serving oncology patients exposed sensitive records tied to Abbott systems, with ShinyHunters threatening data publication and creating potential for identity theft and medical fraud.