Personal Business Look closer How we work How we score Questions Security and trust Talk to us Sign in Book your audit
← Briefing archive
Protector Class desk · August 22, 2026

Weekly Breach Intelligence Briefing

Six major data breaches impacted North America in 2026, ranging from 1.8M to 15M records. Healthcare and education sectors bore the heaviest impact, with supply chain compromises and social engineering remaining the primary attack vectors.

Critical 15M records May 17, 2026

DentaQuest dental insurance breach exposes 15M records

DentaQuest

Unauthorized actors accessed DentaQuest's network between May 17-20, 2026, exfiltrating names, SSNs, member IDs, Medicaid/Medicare numbers, and dental health records.

What it means: Largest healthcare data breach of 2026; victims face years of identity theft risk and are entitled to 24 months of free credit monitoring services.

Critical 275M records Apr 29, 2026

Instructure Canvas breached, 275M education records exposed

Instructure

ShinyHunters exploited unverified Free-For-Teacher accounts to breach Canvas learning platform, stealing 3.65TB of student and faculty data from 8,809 institutions.

What it means: Largest educational breach on record; affected roughly 40% of North American higher education institutions during final exam periods, causing operational disruption.

High 6.99M records Mar 16, 2026

AssuranceAmerica insurance breach compromises 7M drivers

AssuranceAmerica

Attacker used phishing to compromise employee credentials on March 16; unauthorized access to driver license numbers, insurance policy details, and contact information across 14-state network.

What it means: Largest insurance data breach of its kind in 2026; exposed data enables three distinct categories of fraud, with credit freeze addressing only one.

High 1.8M records Nov 25, 2025

NYC Health+Hospitals breach affects 1.8M patients, staff

NYC Health + Hospitals

Third-party vendor compromise allowed 3-month access (Nov 2025-Feb 2026); attackers copied medical records, SSNs, government IDs, biometric data including fingerprints and palm prints.

What it means: Biometric data exposure is permanent and irreversible; affected individuals now vulnerable to lifelong identity and medical fraud targeting.

High 5.99M records Apr 10, 2026

Carnival cruise line loses 6M customer records to ShinyHunters

Carnival Corporation

Social engineering attack on single employee granted access to corporate systems; attackers copied names, addresses, passport numbers, driver licenses, and loyalty program data across 9 cruise brands.

What it means: Passport and government ID theft enables high-value fraud with 6-18 month window before use; extortion group refused ransom negotiations and published full dataset.

High 3.75M records Mar 2026

CareCloud health data giant loses 3.75M medical records

CareCloud

Unauthorized access to CareCloud systems resulted in theft of personal information and medical records for 3.75M patients; incident detected in March and formally confirmed to federal regulators in August.

What it means: Fifth-largest health data theft of 2026; affected individuals now at elevated risk for medical identity fraud, insurance claim abuse, and targeted phishing.

← Earlier briefing Later briefing →