Top 10 Data Breaches of 2026 (YTD)

Let’s recap the Top 10 data breaches from 2026 so far:

Instructure (Canvas): The U.S.-based education-tech company behind the Canvas LMS confirmed a spring data theft tied to its Free-for-Teacher environment, with ShinyHunters claiming on the order of 275 million records across thousands of schools—while public company statements and later TechCrunch coverage centered on tens of millions of students and staff, exam-week portal disruption, and an eventual agreement to stop a leak.[1]

IDScan.net: The Louisiana identity-verification vendor confirmed unauthorized access to customer cloud data after Krebs and others tied a dark-web “Nexus” marketplace offering more than 153 million U.S. and Canadian driver’s-license scans (plus other ID types) to its systems in September—company notices cite names and government ID numbers without confirming that marketplace headcount.[2]

Under Armour: The U.S. apparel giant said it was investigating after Have I Been Pwned indexed about 72.7 million unique emails from a January dump tied to a late-2025 Everest ransomware claim, with many records also carrying names, dates of birth, gender, location, and purchase history—while the company disputed that sensitive data for tens of millions of customers was compromised.[3]

SoundCloud: The global music platform’s December 2025 unauthorized-access incident was quantified in January when Have I Been Pwned reported about 29.8 million accounts whose emails were mapped to profile data (names, usernames, locations, stats), with ShinyHunters linked to follow-on extortion pressure and no passwords or financial data accessed per the company.[3]

Gyazo (Helpfeel): The Kyoto company behind the screenshot-sharing service confirmed that a September server vulnerability led to unauthorized disclosure of about 23.62 million user records and roughly 490 million image-metadata records, including emails, password hashes, tokens, and image-URL metadata that could expose older uploads.

DentaQuest: The large U.S. dental-benefits administrator (Medicaid/CHIP-heavy) began notifying at least 15 million people after a May network intrusion—claimed by ShinyHunters—exposed names, addresses, Social Security and member IDs, and dental/vision health information, with some outside analyses suggesting the unique-person total could climb higher as review continues.[4]

CarGurus: Have I Been Pwned validated a February ShinyHunters dump of about 12.4 million auto-marketplace accounts (names, contacts, addresses, IPs, and auto-finance application fields); the company had not issued a matching public census in early major coverage.[5]

Exact Sciences (Abbott): Abbott’s cancer-diagnostics business disclosed a July voice-phishing intrusion that later spilled a Have I Been Pwned set of about 10.9 million unique emails with personal and health information, while ShinyHunters’ larger claims (tens of millions of rows and more than a million Social Security numbers) remained unverified beyond the published corpus.[6]

McKesson: The U.S. healthcare distribution giant disclosed an August cybersecurity incident involving third-party applications and data theft after ShinyHunters claimed a vishing-to-Okta path into Salesforce and Snowflake and touted roughly 284 million patient-related *records* (rows, not unique patients)—with no company unique-person total published as of mid-September.[7]

Carnival Corporation: The world’s largest cruise operator confirmed that an April social-engineering intrusion led to personal information on 5,995,277 people being copied, including contact details and government-issued identification numbers such as passports and driver’s licenses across its brands.

DataBreaches.com would like to highlight that 2026 so far has been dominated less by exotic zero-days than by voice phishing, stolen SSO sessions, and SaaS/CRM exports—Canvas Free-for-Teacher abuse and exam-week disruption, Exact Sciences and McKesson vishing into cloud apps, Carnival’s social-engineered employee account, Charter/Spectrum-style Salesforce thefts in the same wave, and identity-vendor failures like IDScan that undermine the very documents organizations use to “prove” trust. It’s crucial for organizations to use a trustworthy digital identity that can’t easily be Phished. Their domain name choice has never been more critical. Having the most authoritative version of your brand/product name in the exact match .Com along with training your staff on how to recognize these attacks can be far more effective than blindly investing millions in cybersecurity infrastructure.

Footnotes

[1] The ~275 million Canvas figure is primarily a ShinyHunters claim (also reflected in ITRC H1 2026 victim-notice estimates). Instructure confirmed data types stolen and later said it reached an agreement and received destruction confirmation, but has not published a matching public person-count; TechCrunch’s September roundup described impact on over 30 million students and staff.

[2] The ~153 million driver’s-license figure comes from dark-web marketplace inventory and investigative reporting (Krebs / The Record / TechCrunch), not an IDScan-published census. IDScan confirmed unauthorized access/copy of certain customer cloud information (names; driver’s license or other government ID numbers) and began notifications/credit monitoring.

[3] Under Armour’s intrusion claim dates to November 2025 (Everest); mass public dump and HIBP indexing were January 2026—included here for 2026 YTD association. SoundCloud’s discovery was December 2025; the ~29.8 million HIBP quantification and January extortion updates drive the 2026 listing. Company statements downplay sensitivity relative to raw email counts (UA: disputes “tens of millions” of sensitive records; SoundCloud: emails + public-profile fields).

[4] DentaQuest’s ≥15 million figure is from company notification letters / HIPAA Journal reporting as of July 2026; HIBP’s earlier leaked-file analysis covered about 2.6 million unique emails (a subset). A researcher’s unique name+DOB estimate cited by HIPAA Journal suggested a possible ceiling near ~23.4 million—treat as provisional.

[5] CarGurus had not released an official breach statement in BleepingComputer’s February coverage; inclusion rests on HIBP’s authenticity checks of the published dump.

[6] Prefer the ~10.9 million HIBP unique-email figure over ShinyHunters’ ~30 million rows / >1 million SSN marketing claims until Abbott or regulators publish a final affected-individual count.

[7] ShinyHunters explicitly clarified to BleepingComputer that ~284 million is a raw Snowflake *record/line* count, not unique patients. McKesson’s SEC filing confirmed an incident and ongoing investigation without adopting that headcount.