Weekly Breach Intelligence Briefing
Six major data breaches impacted North America in 2026, ranging from 1.8M to 15M records. Healthcare and education sectors bore the heaviest impact, with supply chain compromises and social engineering remaining the primary attack vectors.
DentaQuest dental insurance breach exposes 15M records
Unauthorized actors accessed DentaQuest's network between May 17-20, 2026, exfiltrating names, SSNs, member IDs, Medicaid/Medicare numbers, and dental health records.
What it means: Largest healthcare data breach of 2026; victims face years of identity theft risk and are entitled to 24 months of free credit monitoring services.
Instructure Canvas breached, 275M education records exposed
ShinyHunters exploited unverified Free-For-Teacher accounts to breach Canvas learning platform, stealing 3.65TB of student and faculty data from 8,809 institutions.
What it means: Largest educational breach on record; affected roughly 40% of North American higher education institutions during final exam periods, causing operational disruption.
AssuranceAmerica insurance breach compromises 7M drivers
Attacker used phishing to compromise employee credentials on March 16; unauthorized access to driver license numbers, insurance policy details, and contact information across 14-state network.
What it means: Largest insurance data breach of its kind in 2026; exposed data enables three distinct categories of fraud, with credit freeze addressing only one.
NYC Health+Hospitals breach affects 1.8M patients, staff
Third-party vendor compromise allowed 3-month access (Nov 2025-Feb 2026); attackers copied medical records, SSNs, government IDs, biometric data including fingerprints and palm prints.
What it means: Biometric data exposure is permanent and irreversible; affected individuals now vulnerable to lifelong identity and medical fraud targeting.
Carnival cruise line loses 6M customer records to ShinyHunters
Social engineering attack on single employee granted access to corporate systems; attackers copied names, addresses, passport numbers, driver licenses, and loyalty program data across 9 cruise brands.
What it means: Passport and government ID theft enables high-value fraud with 6-18 month window before use; extortion group refused ransom negotiations and published full dataset.
CareCloud health data giant loses 3.75M medical records
Unauthorized access to CareCloud systems resulted in theft of personal information and medical records for 3.75M patients; incident detected in March and formally confirmed to federal regulators in August.
What it means: Fifth-largest health data theft of 2026; affected individuals now at elevated risk for medical identity fraud, insurance claim abuse, and targeted phishing.