Personal Business Look closer How we work How we score Questions Security and trust Talk to us Sign in Book your audit
← Briefing archive
Protector Class desk · August 29, 2026

Weekly Breach Intelligence Briefing

North American organizations faced significant data exposures in the first half of 2026, with credential theft and phishing attacks driving major breaches in financial services, healthcare, and education. Five major incidents affected millions across the US and Canada.

High 1.7M records Mar 31, 2026

Hallmark Cards Salesforce breach exposes customer records after extortion deadline

Hallmark Cards

ShinyHunters accessed Hallmark Salesforce environment containing customer records and support tickets; group leaked data after company declined extortion demand on April 2.

What it means: Customer contact details and support history now usable for targeted phishing and social engineering against 1.7 million individuals.

Critical 750K records Aug 11, 2025

CIRO phishing attack compromises 750K Canadian investor financial records

CIRO (Canadian Investment Regulatory Organization)

Sophisticated phishing attack gave attackers access to investor personal and financial data; forensic investigation completed January 14, 2026 confirmed full scope.

What it means: Canadian investors exposed to identity theft and fraud through leaked SINs, government IDs, income statements, and account details.

High 900K records Mar 16, 2026

Aura identity protection company breached via voice phishing, 900K records stolen

Aura

Attackers used targeted voice phishing to compromise Aura employee account; ShinyHunters accessed names, addresses, phone numbers, and email addresses from marketing database.

What it means: Ironic breach of identity protection company's own users, enabling highly credible phishing and vishing attacks against security-conscious individuals.

Critical 275M records Apr 25, 2026

Canvas LMS educational breach hits 275M users globally via ShinyHunters

Instructure (Canvas)

Unauthorized actors accessed Canvas systems affecting 8,809 institutions; ShinyHunters claimed theft of 3.65TB from 275 million users including private student-teacher messages.

What it means: Largest educational security breach on record impacting US higher education (41% of institutions use Canvas) with private messages and student IDs exposed.

Critical 15M records May 2026

Dental insurance company cyberattack impacts 15M US patients in 2026 healthcare record

Unnamed dental insurance carrier (Massachusetts)

Second-largest US dental insurance company suffered cyberattack in May; company issued public notice in July and HHS OCR confirmed 15 million victim count.

What it means: Largest healthcare data breach of 2026; 15 million patients at risk from exposed protected health information.

Critical 2.9B records Apr 2024

National Public Data 2.9B record breach affects US, UK, and Canadian citizens

National Public Data

Attackers accessed 2.9 billion records including full names, addresses, SSNs, dates of birth and phone numbers; company confirmed breach August 16, 2024 after hacker posted on dark web.

What it means: Background check company data breach exposed individuals across US, UK, and Canada to identity theft and social engineering.

← Earlier briefing Later briefing →