Six major North American data breaches spanning early 2026, late 2025, and mid-2024 exposed millions of customer and employee records through credential theft, ransomware, and API vulnerabilities. Recent attacks underscore rising threats from vishing and insider threats targeting financial, retail, and technology sectors.
Critical 72.7M records Jan 21
Under Armour Customer Data Exposed on Dark Web
Under Armour
In January 2026, customer data from the incident was published publicly on a popular hacking forum, including 72M email addresses.
What it means: Records contained names, dates of birth, genders, geographic locations and purchase information, creating targeted phishing and identity theft risk.
Significant 30 records Feb 03
Coinbase Insider Breach Affects 30 Customers
Coinbase
A contractor improperly accessed customer information, impacting a very small number of users (approximately 30).
What it means: The breach involved unauthorized use of support tools to obtain personal information, including email addresses, names, dates of birth, phone numbers, KYC details, and cryptocurrency wallet data.
Critical 5.1M records Jan 27
Panera Bread Customer Contact Data Breached Via SSO Exploit
Panera Bread
On January 27, 2026, the cybercriminal group ShinyHunters leaked a massive database containing approximately 14 million Panera Bread records on the dark web.
What it means: The data included 5.1M unique email addresses along with associated account information such as names, phone numbers and physical addresses, fueling scam risk.
Critical 2.9B records Aug 16
Healthcare Data Breach Affects 2.9 Billion Records Nationally
National Public Data
In August 2024, National Public Data, a Florida-based background check company, suffered one of the largest data breaches in history with personal information of approximately 2.9 billion individuals compromised, including Canadians.
What it means: The breach exposed 2.9 billion records including full names, social security numbers, mailing addresses, email addresses, and phone numbers, and occurred because the NPD website had inadvertently published a zip file with the back-end passwords for the database.
Critical 145M records Feb 04
Change Healthcare Ransomware Attack Disrupts Payment Processing
Change Healthcare
In February 2024, Change Healthcare, a healthcare technology company, was targeted in a ransomware attack that impacted 145 million individuals, with sensitive personal, medical, and billing information compromised, resulting in widespread disruption of critical healthcare operations across North America.
What it means: The attack targeted UH's Change Healthcare payment processing system, deploying ransomware to take systems offline, cascading across hospitals and clinics.
Critical 560M records May 31
Ticketmaster Data Breach Exposes 560 Million Customer Records
Ticketmaster
On May 31, 2024, Ticketmaster confirmed a significant data breach that exposed the personal and financial information of over 560 million customers.
What it means: Cybercriminals accessed 1.3 terabytes of data through unauthorized activity in a third-party cloud database environment, with stolen information including sensitive personal details such as names, addresses, email addresses, and credit card information.