Six major breaches have impacted millions of North Americans in 2026, spanning healthcare, identity verification, insurance, and education. Credential theft and social engineering remain the dominant attack vectors, with one Canadian insurer and five US entities affected.
Critical 150M records Sep 1, 2026
150M North American driver IDs exposed at identity verification firm
IDScan.net
Hackers compromised identity verification platform serving Hertz, FedEx, and Target; exposed driver license photos for 150 million drivers in US and Canada via dark web search engine.
What it means: Victims face elevated risk of synthetic identity fraud, account takeover, and long-term identity theft as biometric and personal documents are now publicly searchable.
Critical 15M records May 2026
15M patients lose health data in largest healthcare breach of year
DentaQuest
Major dental insurance company suffered cyberattack exposing protected health information for 15 million patients; breach disclosed publicly in July after HHS reporting.
What it means: Affected patients face fraud risk from exposed healthcare data; company must provide mandated breach notifications and credit monitoring.
Critical 6.999M records Mar 16, 2026
7M insurance customers exposed via social engineering attack
AssuranceAmerica
Auto insurance provider detected malicious activity targeting single employee on March 16; attackers copied files containing names, contact info, policy details, and driver license numbers affecting nearly 7 million individuals.
What it means: Largest known exposure of US driver license numbers in 2026; victims exposed to identity theft and fraud from complete credential sets.
High 5.995M records Apr 10, 2026
6M cruise passengers exposed in social engineering breach
Carnival Corporation
Cruise operator detected breach April 14 and confirmed April 22 that 6M individuals had personal information copied via social engineering; ShinyHunters published 8.7M records after extortion demand failed.
What it means: Exposed data includes names, dates of birth, emails, and loyalty program info; victims at risk for credential reuse attacks and targeted fraud.
Critical 1.8M records Nov 25, 2025
1.8M NYC healthcare workers and patients exposed via network intrusion
NYC Health + Hospitals
Unauthorized actor accessed safety-net hospital network from November 2025 through February 2026; stolen data included medical records, SSNs, banking data, and biometric fingerprints and palm prints.
What it means: Biometric data theft creates permanent identity risk; system serves Medicaid population with limited fraud monitoring access.
High 70K records Apr 18, 2026
70K Canadian insurance customers compromised via employee account takeover
Canada Life
ShinyHunters used single employee account to access Salesforce environment and steal personal information for 70K individuals; ransom deadline set April 21 before public disclosure April 23.
What it means: Exposed data includes PII for large corporate group; Canada Life offering credit monitoring as incident was contained after ransomware threat.