Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Weekly briefing › No. 40
Weekly briefing · No. 40 · 4 Oct 2026

Five major North American data breaches spanning healthcare, education, automotive, and telecommunications sectors have exposed hundreds of millions of records.

The most severe incident, Change Healthcare, affected nearly 193 million individuals through a ransomware attack in February 2024, while PowerSchool compromised 62 million student and educator records in December 2024.

Published 4 Oct 2026Reading time 2 minDisclosures 5By LeakTrace Intelligence Desk
This issue’s disclosures
CriticalFeb 21, 2024
Change Healthcare / UnitedHealthcare
Healthcare · 192.7M records
Ransomware gang accessed Change Healthcare systems via unprotected Citrix portal lacking multifactor authentication, exfiltrating protected health information affecting 192.7 million individuals across the US.
What it means: Largest healthcare data breach on record disrupted patient care and claims processing nationwide; exposed names, addresses, SSNs, medical records, and insurance details for nearly 60% of the US population.
Feb 21, 2024
CriticalDec 28, 2024
PowerSchool
Credential Theft · 62M records
Attacker used compromised employee password to access PowerSchool's customer support portal lacking multifactor authentication and downloaded student and teacher records from thousands of school districts.
What it means: Largest education data breach in US history; exposed names, Social Security numbers, birthdates, medical and disciplinary information for approximately 62 million students and 9.5 million educators across US and Canada.
Dec 28, 2024
HighOct 25, 2025
700Credit
Financial · 5.8M records
Threat actor compromised third-party integration partner API in July 2025, gaining unauthorized access to dealership customer records; breach undetected for over three months until October.
What it means: Exposed names, addresses, dates of birth, and Social Security numbers of auto dealership customers; highlights vendor risk in financial services affecting 18000 dealerships across North America.
Oct 25, 2025
CriticalMar 30, 2024
AT&T
Credential Theft · 73M records
Dataset containing personal information of 73 million current and former customers surfaced on dark web; data appears to date from 2019 or earlier with origin from either AT&T systems or third-party vendor.
What it means: Exposed Social Security numbers, dates of birth, account passcodes, full names, email addresses, mailing addresses, and AT&T account numbers; led to $177 million settlement.
Mar 30, 2024
CriticalApr 2024
National Public Data
Credential Theft · 2.9B records
Florida background-check broker accidentally exposed database credentials publicly; threat actor USDoD accessed 2.9 billion rows of aggregated personal data and dumped publicly, becoming single largest exposure of US Social Security numbers.
What it means: Exposed full names, current and historical addresses, Social Security numbers, phone numbers, and email addresses for 1.3 billion individuals across US, Canada, and UK; affected data on 85% of US Congress members.
Apr 2024
This issue by category

Where this issue’s disclosures sit.

The 5 disclosures in issue No. 40, by the category we filed each one under.

Source: LeakTrace weekly briefing No. 40, 4 Oct 2026.