Weekly Breach Intelligence Briefing
Six major breaches affecting North Americans between November 2025 and September 2026 exposed over 130 million records across healthcare, education, technology, and financial services. Record counts grew significantly during investigation phases, with third-party vendor compromises emerging as the dominant attack vector.
Conduent healthcare processor hit with 62.2M records — third-largest US healthcare breach ever
Ransomware attack on business process outsourcing firm exposed health insurance and claims data from October 21, 2024 through January 13, 2025.
What it means: Third-party vendor processing patient data for hundreds of health plans and government agencies simultaneously became single point of failure affecting millions across multiple states.
Instructure Canvas learning platform exposes 275M students across 9,000 schools globally
Breach via free-for-teacher account verification bypass allowed hackers to exfiltrate 3.65 terabytes from education platform used by 40 percent of US colleges.
What it means: Student names, emails, course data, and enrollment records exposed across K-12, higher education, and educational ministries globally during finals season.
Suno AI music platform leaked 55.3M user accounts; disclosure delayed 8 months
Malware on developer laptop provided lateral access; 55.3M email addresses, phone numbers, payment records, and partial credit card data from Stripe exfiltrated.
What it means: Company did not disclose breach publicly until Have I Been Pwned added data to its database in July 2026, eight months after compromise.
CareCloud healthcare EHR provider compromised; record count revised from 345K to 3.75M over 5 months
Unauthorized access to AWS environment between March 10-16 exposed medical records, Social Security numbers, and banking information.
What it means: Healthcare EHR vendor serving 45,000+ providers discovered scope revision only after HHS updated tracker; affected individual notification delayed months.
American Tower telecom infrastructure breach exposes 5.2M records including GPS access codes
Extortion campaign by ShinyHunters exfiltrated customer PII, tower asset records with GPS coordinates, and plaintext physical access codes for US cell tower compounds.
What it means: Breach includes sensitive infrastructure data tied to T-Mobile, Verizon, and US DHS with physical security implications beyond identity theft.
700Credit automotive credit platform hit with 5.8M records via third-party API compromise
Threat actor breached integration partner in July 2025, discovered exposed API, and stole names, addresses, dates of birth, and SSNs from dealership customers through October.
What it means: Credit report provider serving 18,000+ North American auto dealers had access continue for months after partner compromise without timely notification.