Morning Overview

11 of the biggest data breaches that hit Americans in 2026

American companies handed over sensitive records to hackers throughout 2026, from college transcripts to cruise passenger passports to dating-app data. Extortion groups like ShinyHunters exploited stolen credentials, vishing calls and misconfigured cloud tools rather than sophisticated hacking, and confirmed victim counts often lagged far behind the number attackers claimed. Here are eleven breaches that put Americans’ personal information into criminals’ hands this year.

1. Instructure Canvas: A Finals-Week Shutdown

Instructure Canvas — Image Credit: ארז האורז - CC BY-SA 4.0/Wiki Commons
Image Credit: ארז האורז – CC BY-SA 4.0/Wiki Commons

ShinyHunters, an extortion group, claimed access to data connected to nearly 9,000 institutions and 275 million users after breaching Instructure’s Canvas platform, a figure the company never independently confirmed, while the intrusion knocked Canvas offline during final exams season.

Instructure said the confirmed exposure covered names, email addresses, student ID numbers and platform messages. No evidence emerged that passwords, birth dates, financial details or government identification numbers were included in what attackers obtained.

2. Carnival Corporation: Nearly Six Million Passengers Exposed

Carnival Corporation — Image Credit: Sergey Yarmolyuk - CC BY 4.0/Wiki Commons
Image Credit: Sergey Yarmolyuk – CC BY 4.0/Wiki Commons

Carnival Corporation reported that 5,995,277 people were affected after an attacker used social engineering to reach a restricted part of the cruise line’s IT environment, with passport and driver’s license numbers among the records exposed.

Affected data varied by individual and could include names, addresses, phone numbers, birth dates and cruise membership information. Unlike a stolen password, a passport or license number cannot simply be reset once it has been compromised.

3. Aura: An Identity-Protection Firm’s Own Breach

Aura — Image Credit: Shixart1985 - CC BY 2.0/Wiki Commons
Image Credit: Shixart1985 – CC BY 2.0/Wiki Commons

An attacker used voice phishing to compromise an employee account at identity-protection company Aura and access roughly 900,000 marketing records, most pulled from a database tied to a company Aura acquired in 2021.

The exposed information was limited to names and email addresses. Aura said core identity-protection systems, Social Security numbers, passwords, credit records and financial information were not reached, though the stolen contact list hands scammers a ready-made script for fake identity-theft alerts.

4. ADT: Partial Social Security Numbers in the Leak

ADT — Image Credit: Raysonho @ Open Grid Scheduler / Scalable Grid Engine - CC0/Wiki Commons
Image Credit: Raysonho @ Open Grid Scheduler / Scalable Grid Engine – CC0/Wiki Commons

Data reviewed by Have I Been Pwned showed the leaked ADT breach affected 5.5 million people, with names, phone numbers and home addresses stolen alongside partial Social Security numbers for a small share of customers.

The intrusion began when an employee’s Okta single sign-on account was compromised through a vishing call, after which attackers pulled records from Salesforce; ShinyHunters separately leaked 11GB, more than 10 million records. ADT said no payment information was accessed and customer security systems remained uncompromised.

5. Panera Bread: A Breach the Company Never Confirmed

Panera Bread — Image Credit: Retail Thriller - CC BY-SA 4.0/Wiki Commons
Image Credit: Retail Thriller – CC BY-SA 4.0/Wiki Commons

A leaked dataset attributed to ShinyHunters claimed roughly 14 million Panera Bread customer records, including names, email addresses, postal addresses and phone numbers, posted to dark-web marketplaces in late January.

Panera Bread had not publicly confirmed the breach at the time of reporting, leaving the scope of the intrusion resting entirely on the attackers’ own claims, which reporters traced back to postings on Daily Dark Web and a related forum. No payment card numbers or passwords appeared among the account-related data types described.

6. McGraw Hill: A Misconfiguration, Not a Break-In

McGraw Hill — Image Credit: Sixflashphoto - CC BY-SA 4.0/Wiki Commons
Image Credit: Sixflashphoto – CC BY-SA 4.0/Wiki Commons

Attackers exploited a Salesforce misconfiguration to dump more than 100GB of files tied to 13.5 million McGraw Hill accounts publicly online, with no need to breach the company’s actual courseware systems.

McGraw Hill confirmed unauthorized access to a limited set of data from a webpage hosted on Salesforce, while stating that courseware, customer databases and internal systems were not affected. The 13.5 million figure comes from Have I Been Pwned’s count of unique email addresses inside the leaked files, which also included names, physical addresses and phone numbers.

7. Medtronic: Health Records for Millions of Device Patients

Medtronic — Image Credit: Tony Webster from Minneapolis, Minnesota, United States - CC BY 2.0/Wiki Commons
Image Credit: Tony Webster from Minneapolis, Minnesota, United States – CC BY 2.0/Wiki Commons

Medtronic, the world’s largest medical-device maker, sent customer notifications in July stating that names, birth dates, Social Security numbers and health information had been taken, against an attacker claim of more than 9 million stolen records.

The company discovered the unauthorized access on April 15, tracing intrusion activity back to April 13 through 19, after ShinyHunters listed Medtronic on a leak site and set a ransom deadline days later. Medtronic said the stolen data was not published online and that its medical devices were unaffected.

8. Charter Communications: One Vishing Call, Forty Million Records Claimed

Charter Communications — Image Credit: AirportExpert - CC0/Wiki Commons
Image Credit: AirportExpert – CC0/Wiki Commons

Attackers say they breached Charter Communications in April by tricking an employee into handing over access to a Microsoft Entra account, then exporting Salesforce data that ShinyHunters claimed totaled 40 million records.

Charter confirmed a breach occurred but said no sensitive personal information or customer proprietary network information left its systems, and the company gave no victim count of its own. The attacker-listed data included names, email addresses, physical addresses, phone numbers, service plan details and support ticket contents.

9. DentaQuest: Government IDs Went With the Dental Records

DentaQuest — Image Credit: Roseneath Dental Care - CC BY-SA 4.0/Wiki Commons
Image Credit: Roseneath Dental Care – CC BY-SA 4.0/Wiki Commons

Have I Been Pwned counted 2.6 million DentaQuest accounts in a leaked archive after the dental benefits administrator, part of Sun Life, confirmed the incident in early June, following ShinyHunters listing the company on a leak site in May.

The exposure went well beyond contact information: exposed fields included government-issued identification, health insurance details, genders and dates of birth alongside emails, names and phone numbers. ShinyHunters separately claimed 234GB of data was stolen in the intrusion.

10. CarGurus: Car-Loan Applications Went Public

CarGurus — Image Credit: Atwngirl - CC BY-SA 4.0/Wiki Commons
Image Credit: Atwngirl – CC BY-SA 4.0/Wiki Commons

A 6.1GB archive holding 12.4 million CarGurus records went public in February after ShinyHunters published it and Have I Been Pwned validated the data days later, with car-finance pre-qualification applications and their outcomes among the exposed fields.

The archive also contained email and IP addresses, full names, phone numbers, physical addresses, user account IDs, dealer account details and subscription information. CarGurus issued no statement and did not respond to the reporting on the breach.

11. Match Group: Five Dating Apps, One Leak

Match Group — Image Credit: Santeri Viinamäki - CC BY-SA 4.0/Wiki Commons
Image Credit: Santeri Viinamäki – CC BY-SA 4.0/Wiki Commons

A 1.7GB leak that ShinyHunters attributed to Match Group held 10 million records spanning Tinder, Hinge, OkCupid, Match.com and Meetic at once, pulled largely from tracking and marketing analytics tied to AppsFlyer.

Match Group confirmed only a ‘limited amount’ of user data was involved and gave no figure of its own, adding that internal documents were also part of what leaked. The company said no login credentials, financial information or private messages were exposed in the incident.