Weekly Breach Intelligence Briefing
Six major data breaches spanning May–June 2026 have exposed over 350 million North American records, driven by education ransomware, healthcare business-associate failure, and government infrastructure compromise. Supply-chain vulnerabilities and credential extortion remain the dominant attack vectors.
Canvas LMS ransomware attack hits 9,000 schools, 275M education records exposed
ShinyHunters exploited Instructure's Free-for-Teacher program to gain API access, exfiltrating student names, email addresses, student IDs, and messages across 8,809 educational institutions before defacing 330 login portals during final exams.
What it means: The largest education breach on record now exposes 40% of North American universities to credential phishing, identity fraud, and future targeted social engineering against minors and families.
Conduent Medicaid processor breach hits 62.2M, third-largest US healthcare breach ever
SafePay ransomware accessed Conduent's network for 83 days (Oct 2024–Jan 2025), stealing 8.5TB of Medicaid claims, HR records, and personal health data for 30+ U.S. states before detection and disclosure in June 2026.
What it means: Business associates processing sensitive data for multiple covered entities remain critical infrastructure targets; a single vendor failure cascades to one-in-five Americans and undermines HIPAA vendor liability enforcement.
NYC Health + Hospitals breach exposes 1.8M patient records including biometric data
An unauthorized actor accessed NYC Health + Hospitals' third-party vendor systems from November 2025 through February 2026, stealing medical records, government IDs, geolocation, Social Security numbers, and fingerprint/palm-print biometrics for 1.8 million patients and staff.
What it means: Large municipal health systems are now exposed to persistent compromise through vendor trust chains; biometric and medical records fusion enables sophisticated identity reconstruction and targeted extortion.
Canada Life insurance breach hits 70,000 after ShinyHunters extortion deadline
ShinyHunters breached Canada Life in mid-April 2026 and issued a ransom deadline of April 21 with a pay-or-leak demand before public disclosure on April 23, compromising personal information of 70,000 customers, primarily from one large corporate group plan.
What it means: Canadian financial services and insurance firms are now routine targets for extortion ransomware; families face heightened fraud risk and credit monitoring costs amid record-high breach response costs in Canada.
National Association of Insurance Commissioners suffers 3.1TB data theft via ShinyHunters
ShinyHunters breached NAIC systems in June 2026, stealing 3.1 terabytes of data including insurance company filings, credit rating files, and personally identifiable information that was subsequently leaked on the dark web.
What it means: Regulatory infrastructure compromise exposes aggregated financial profiles of millions of consumers and undermines insurance industry integrity; breach data now available to competitors and fraudsters globally.
Foxconn North American factories hit by Nitrogen ransomware claiming 8TB theft
Nitrogen ransomware group claimed a cyberattack on Foxconn's North American factories on May 12, 2026, alleging theft of 8 terabytes of schematics, project details, and customer documents for major technology clients including Apple, Dell, Google, and Nvidia.
What it means: Supply-chain manufacturing partners remain vulnerable to intellectual property theft; trade secret exposure to Foxconn's top-tier clients creates competitive risk and potential technology leakage to state-backed actors.