Six verified major data breaches affecting millions across North America in 2024-2026, ranging from education to healthcare and financial services. Recent disclosures underscore vendor risk and delayed detection as leading factors.
High 55.3M records Nov 25, 2025
Suno AI music platform exposed 55.3 million users via supply chain attack
Suno
Supply chain attack through compromised developer credentials gave attacker access to Suno environment for eight months before public disclosure in July 2026.
What it means: Users' email addresses, phone numbers, partial payment card data, and training documentation were stolen; company failed to notify victims.
Critical 62.2M records Oct 21, 2024
Conduent business process outsourcing hit by ransomware affecting 62.2 million
Conduent Business Services
SafePay ransomware group accessed Conduent systems for 83 days, exfiltrating healthcare claims and government benefits data from hundreds of covered entities.
What it means: Third-largest US healthcare breach ever; victim count revised from 10.5M to 62.2M over nine months, exposing healthcare accessibility and vendor risk.
High 5.8M records Jul-Oct 2025
700Credit automotive credit platform compromised via third-party API exposure
700Credit
Attacker breached 700Credit integration partner in July, discovered exposed API in October; partner failed to notify for three months, allowing ongoing data exfiltration.
What it means: North American auto dealers saw customer SSNs, DOBs, addresses stolen; class action settlement reached $17.5M covering dealer customer exposure.
Critical 62M students, 9.5M teachers records Dec 19, 2024
PowerSchool K-12 education platform exposed 62 million students and 9.5 million teachers
PowerSchool
Attacker used stolen subcontractor credentials against PowerSource support portal lacking multi-factor authentication, accessing student records for nine days undetected.
What it means: Largest education data breach in US history; exposed SSNs, addresses, grades, medical info for minors across US and Canada; attacker sentenced to 4 years.
Critical 1.8M records Nov 25, 2025
NYC Health and Hospitals third-party vendor breach exposed 1.8 million patients and staff
NYC Health + Hospitals
Unnamed third-party vendor breach gave attackers access to NYC H+H systems for 11 weeks; stolen medical records, fingerprints, government IDs, and financial data.
What it means: One of 2026's largest healthcare breaches; exposed sensitive biometric data and clinical information for largest US municipal health system serving Medicaid patients.
Critical 73M records Mar 30, 2024
AT&T customer data breach from 2019 resurfaced in 2026 with decrypted SSNs
AT&T
Data stolen in 2019 was acknowledged in March 2024; resurfaced in February 2026 on dark web with 148 million previously encrypted SSNs now fully decrypted.
What it means: Settlement of $177 million ($2.43 per person); demonstrates breach data becomes more dangerous over time as encryption keys are broken and records enriched.