Weekly Breach Intelligence Briefing
Six major breaches affecting North Americans in 2026 span healthcare, education, finance, and insurance sectors. Notable incidents include the largest healthcare breach (Conduent at 62.2M records), record education sector breach (Instructure Canvas affecting 41% of North American higher education), and a major Canadian bank breach (CIBC at 1.2M).
Conduent Medicaid processor breach affects 62.2M individuals
Business process outsourcing firm administering Medicaid claims across 30+ U.S. states suffered unauthorized network access for 83 days from October 2024 to January 2025, exposing claims and benefits data.
What it means: Third-largest U.S. healthcare-linked breach ever; SafePay ransomware group claimed 8.5TB exfiltration; final count filed with HHS June 4, 2026.
Instructure Canvas education platform breached, 275M notifications issued
ShinyHunters exploited Free-For-Teacher feature to gain initial access in late April; breached Canvas again on May 7 after defacing portals at 330 institutions including Harvard and Princeton during final exam periods.
What it means: Largest education-sector breach on record; Canvas used by 41% of North American higher education; affected names, emails, student IDs, and private messages; ransom paid May 11.
CIBC Canada breach exposes 1.2M customer records via vendor
Third-party mortgage processing vendor serving CIBC's North American customer service operations suffered breach compromising customer data.
What it means: Major Canadian financial institution; supply-chain compromise; demonstrates third-party vendor risk in banking sector.
NYC Health + Hospitals breach exposes 1.8M patient records including biometrics
Unauthorized actor accessed systems via third-party vendor from late November 2025 through February 2026; copied files containing medical records, government IDs, fingerprints, palm-prints, and financial information.
What it means: Largest municipal healthcare system in U.S.; biometric data exposure raises identity theft risk; affected health insurance, medical records, and billing data.
Charter Communications breach exposes 42M customer records
Extortion group stole data and published records on leak site; ShinyHunters used voice phishing to compromise employee credentials for Microsoft Entra account.
What it means: One of largest U.S. broadband providers; exposed email addresses, names, addresses, phone numbers, and employee information; approximately 5M affected individuals.
Dental insurance breach affects 15M patients, largest healthcare incident of 2026
Second-largest dental insurance company suffered cyberattack in May; incident set record as largest healthcare entity breach of 2026; breach notice issued July 2026.
What it means: 15M patient records exposed; largest healthcare breach of 2026; HHS Office for Civil Rights confirmed victim count; sensitive health plan and patient information compromised.