H1 2026 saw record-breaking breach volume with 471.2M victim notices in six months, exceeding all of 2025. Critical incidents include Instructure Canvas (275M users), Conduent (62.2M healthcare records, third-largest ever), and DentaQuest (15M dental patients), driven primarily by vendor compromise and ransomware.
Critical 275M records Apr 25, 2026
Instructure Canvas education platform breached by ShinyHunters
Instructure Canvas
ShinyHunters exfiltrated approximately 275 million records across 8,800 educational institutions worldwide between April 25–May 12, 2026, including names, email addresses, student IDs, and in-platform messages.
What it means: Nearly 40% of U.S. schools use Canvas; the breach enables highly targeted phishing at students, parents, and faculty via verified institutional context, posing immediate account-takeover and financial fraud risk.
Critical 62.2M records Oct 21, 2024
Conduent Medicaid processor reports third-largest US healthcare breach
Conduent Business Services
SafePay ransomware group maintained access for 83 days (October 21, 2024 to January 13, 2025) to Medicaid claims and benefits data before encryption; victim count grew from 10M (initial) to 62.2M by final June 4, 2026 HHS OCR filing.
What it means: Vendor processes claims for 500+ clients across 30+ states; delayed discovery and cascading victim count revisions expose weaknesses in breach-impact scoping in high-volume processing environments affecting state welfare systems.
Critical 15M records May 17, 2026
DentaQuest dental insurance breach exposes 15M patient records
DentaQuest
ShinyHunters accessed DentaQuest network for three days (May 17–20, 2026) and exfiltrated dental, vision, and Medicaid/Medicare records including SSNs, treatment details, and member IDs from the largest U.S. Medicaid dental administrator.
What it means: The largest healthcare breach of 2026 by single-entity count; attackers leaked ~234 GB online, creating immediate identity-theft risk and exposing 32M total beneficiaries to downstream targeted fraud.
Critical 1.8M records Nov 25, 2025
NYC Health + Hospitals third-party vendor breach exposes 1.8M patients
NYC Health + Hospitals
Unauthorized actor accessed NYC H+H systems via third-party vendor compromise from November 25, 2025 through February 11, 2026, exfiltrating medical records, SSNs, biometric fingerprints and palm prints, and financial account data.
What it means: Biometric data exposure is rare; combined with government IDs and financial records, stolen information enables identity fraud, credential stuffing, and physical/digital impersonation targeting safety-net population mostly on Medicaid.
High 5.8M records May 2025
700Credit automotive credit platform breach exposes 5.8M dealer customers
700Credit
Threat actor compromised third-party API connected to 700Credit web application and exfiltrated customer records from automotive dealerships between May and October 2025; detected October 25; contains SSNs, addresses, dates of birth.
What it means: 700Credit serves 18,000 North American dealerships; breach exposes car buyers and loan applicants to identity theft and financial fraud; third-party API compromise reflects 2026 pattern of vendor-chain attacks.
High 70K records Apr 2026
Canada Life insurance breach exposes 70K employee and group plan members
Canada Life
ShinyHunters accessed Canada Life systems through compromised employee account and exfiltrated personal data of up to 70,000 people, primarily from one large corporate group benefits customer; incident contained within two weeks of discovery.
What it means: Attack vectors names, addresses, SSNs, and financial data used in group benefits administration; targeted at Canada's largest life and health insurer, signaling ongoing focus on financial-services employee credentials.