LeakTrace Intelligence Desk · March 19, 2026

Weekly Breach Intelligence Briefing

North America experienced significant data breaches across healthcare, finance, and retail sectors in early 2026, with millions of customer records exposed through vulnerable third-party systems and compromised credentials. Organizations are increasingly targeted through supply chain weaknesses and legacy infrastructure gaps.

Critical 750,000 records Jan 16

Investment watchdog exposes 750,000 client records

Canadian Investment Regulatory Organization (CIRO)

Attackers compromised investor data including social insurance numbers, investment account details, and government ID numbers through a sophisticated attack in August 2025.

What it means: Investors face heightened risk of identity theft and account takeover with government-issued identifiers and financial account information exposed.

Critical 25.0M records Jan 15

Healthcare processor breach impacts millions nationwide

Conduent

A business services provider handling Medicaid claims and benefit administration across 46 states lost healthcare records including medical data and insurance information.

What it means: Nationwide healthcare system vulnerability exposed as critical backend infrastructure shows inadequate security controls for sensitive patient and government benefit data.

High 5.1M records Jan 22

Restaurant chain faces lawsuit after customer data exposed

Panera Bread

Customer names, email addresses, phone numbers and physical addresses were stolen and published online after the company declined to pay an extortion demand.

What it means: Customers face targeting through exposed contact information and elevated risk of account takeover and physical security threats at home addresses.

Critical 4.1M records Jan 10

Colorado healthcare system loses 4.1 million patient records

Colorado Healthcare (IBM MOVEit)

Sensitive patient health data from a Colorado provider was stolen by exploiting a vulnerability in file transfer software used to manage healthcare systems.

What it means: Patients' medical histories and treatment information exposed, creating long-term privacy risks and potential insurance fraud opportunities.

High 697,000 records Feb 05

Newsletter platform discloses unauthorized user access

Substack

Approximately 663,000 to 697,000 user accounts had email addresses, phone numbers and account metadata exposed through API data harvesting that went undetected for four months.

What it means: User contact information compiled for targeted communication attacks, with extended exposure window indicating inadequate security monitoring.

Critical 1.2M records Aug 15

University cancer research breach affects 1.2 million

University of Hawaii Cancer Center

Epidemiology research data including names, social insurance numbers, driver's licenses and voter registration information was stolen from the center's division.

What it means: Comprehensive personal identity data exposed enabling potential voter fraud, identity theft, and fraud targeting research participants across multiple institutions.