LeakTrace Intelligence Desk · March 19, 2026

Weekly Breach Intelligence Briefing

Six major North American data breaches exposed over 11 million records across automotive, insurance, healthcare, legal, financial, and retail sectors. Common attack vectors include compromised third-party systems, stolen credentials, and social engineering.

Critical 5.8M records Oct 10

Credit verification provider exposes 5.8M automotive industry records

700Credit

Attackers accessed customer data through a compromised third-party API between July and October 2025.

What it means: Automotive dealers and lenders using this service face significant identity theft and fraud risk for millions of customers.

Critical 1.4M records Jul 15

Insurance giant loses customer data to vendor account compromise

Allianz Life

Attackers used social engineering to compromise a third-party cloud CRM platform used by the company.

What it means: Customer names, addresses, Social Security numbers, and financial details were exposed, creating direct identity theft risk.

Critical 2.7M records Apr 15

Dialysis provider hit by attack stealing patient medical records

DaVita

Attackers encrypted systems and extracted patient records from laboratory databases.

What it means: Medical details and identifiers of dialysis patients create lasting privacy and fraud risks.

Critical 62M records Jan 15

Student information system compromised via contractor credentials

PowerSchool

Attackers used a stolen contractor login to access school records containing student and teacher data nationwide.

What it means: Student names, Social Security numbers, and family contact details put minors at risk of identity fraud.

High 750K records Aug 15

Investment regulator suffers account takeover from email attack

CIRO

A sophisticated email attack compromised investor account credentials in August 2025, discovered in January.

What it means: 750,000 investors' Social Security numbers and financial records are now exposed.

High 3M records Mar 15

Canadian retailer delayed breach notification of millions of customers

Giant Tiger

Customer data including emails, names, addresses, and phone numbers were stolen in March but not disclosed until 2026.

What it means: Extended exposure window increases risk that stolen data was already used for fraud or sold to other attackers.