Every Major Data Breach of 2026 Explained in Plain English

A living tracker of the major 2026 data breaches. Per-incident evidence, attack types, attribution and defensive lessons. Updated as disclosures land.

Featured image for Every Major Data Breach of 2026 Explained in Plain English


Abstract image of a cracked vault with cyan light leaking out
Every major breach of 2026 has the same DNA. Different names, different industries, different headlines, but the same handful of root causes.

This is a living tracker, not a one-off story. We are tracking the major disclosed data breaches of 2026 with per-incident evidence. The article is updated when a new credible disclosure lands, when an attribution is confirmed, or when a previously claimed fact is corrected.

What “major” means here: a confirmed incident affecting one million or more individuals, OR a smaller incident that materially changed attacker tradecraft, regulatory posture, or defensive practice. We exclude phishing-only credential leaks without verified PII exposure, and we exclude pure researcher-discovered misconfigurations where no third party is known to have accessed the data.

Status legend. Confirmed = documented in an official disclosure, regulator filing, or court document. Claimed = asserted by a threat actor or third-party reporter but not yet independently verified. Inferred = consistent with available evidence but not directly stated by the victim. Unknown = the victim has not commented and there is no reliable source.


Table of contents


Odido — Netherlands telecom, ~6.2–6.5 million people

Industry: Telecommunications. Attack type: Social engineering (vishing / phishing) targeting IT support staff, followed by exfiltration from a customer contact system. Initial access: ShinyHunters used phishing emails and impersonation of IT staff to bypass MFA on a Salesforce-integrated customer contact system. Data affected: Customer names, postal addresses, phone numbers, email addresses, IBANs, dates of birth, passport and driver’s license numbers with validity dates, and sensitive customer-service notes including payment disputes and guardianship records. Records affected: Approximately 6.2 million people initially disclosed, expanded to 6.5 million individuals and 600,000 companies when the full dataset was published on March 1, 2026. Attribution: ShinyHunters (Confirmed by Odido in the official update notice). Status: Confirmed (operational, identity, and financial data published).

Defensive lesson: MFA bypass through social engineering of IT staff is now the single largest cause of large customer-data leaks. Phishing-resistant MFA (FIDO2/WebAuthn hardware keys, not push prompts) reduces this class of attack to near-zero. Storing government-ID metadata in the same place as customer support notes amplifies the blast radius.

Sources:


LexisNexis Risk Solutions — US data broker, undisclosed number

Industry: Data brokerage / risk intelligence. Attack type: Exploitation of an unpatched server-side vulnerability. Initial access: Reach2Shell vulnerability, rated maximum severity (10.0) and disclosed in November 2025 with patches starting in early December 2025. The attacker exploited systems that had not been patched by the time of the incident. Data affected: LexisNexis stated the stolen data was old, non-sensitive, and limited to customer names, user IDs, business contact information, products used, customer survey responses with respondent IP addresses, and support tickets. LexisNexis explicitly stated that no Social Security numbers, driver’s license numbers, financial information, or other PII was leaked. Records affected: Undisclosed. Attribution: Not officially named. Status: Confirmed by LexisNexis; scope of PII disputed by security researchers.

Defensive lesson: Critical-severity vulnerabilities disclosed in Q4 of one year are still being exploited in Q1 of the next. Emergency patching SLAs for maximum-severity flaws need to be measured in days, not weeks. Even when a vendor describes the data as “non-sensitive,” researchers should independently verify the claim against the actual database schema.

Sources:

  • PrivacyGuides breach roundup, 9 Mar 2026: privacyguides.org
  • CRN, “10 Major Cyberattacks and Data Breaches in 2026 (So Far)”: crn.com

Hallmark Cards — US greeting card retailer, ~1.7 million confirmed (up to 7.9 million claimed)

Industry: Retail / consumer goods. Attack type: Third-party CRM compromise (Salesforce environment) with public extortion. Initial access: Threat actor gained access to a Salesforce environment shared by Hallmark Cards and the Hallmark Plus loyalty program on approximately 9 March 2026. The exact vector (OAuth token theft, vishing, or a Drift-style supply-chain compromise) has not been publicly confirmed. Data affected: Customer email addresses, names, phone numbers, physical mailing addresses, Hallmark Plus loyalty membership data and history, and the full text of customer support tickets. Also internal Hallmark employee data. Records affected: ShinyHunters initially claimed “just under 8 million” Salesforce records. Independent researchers (Have I Been Pwned, 12 Apr 2026) confirmed 1.7 million unique customer accounts after de-duplication. Attribution: ShinyHunters (Confirmed). Status: Confirmed (incident + data categories); record count is partial (ShinyHunters claim > confirmed figure, but figure itself is a threat-actor claim).

Defensive lesson: When a CRM is compromised, the historical customer-support tickets — which often contain names, addresses, dispute history, and the customer’s own description of the problem — become the highest-leverage dataset for spear-phishing. Treat any “Hallmark” inbound in the next 12 months as suspect. The lesson generalises: archive your CRM data with the same retention discipline as production data.

Sources:

  • Salesforce Ben, “ShinyHunters Claim Hallmark as Next Victim”: salesforceben.com
  • Cybernews, “Serial attackers threaten to spill Hallmark’s internal data”: cybernews.com
  • TechNadu, “Hallmark Data Breach Exposes 1.7M Customer Records”: technadu.com

Stryker Corporation — US medical technology, ~80,000 devices wiped, ~50 TB claimed exfiltrated

Industry: Medical technology. Attack type: Identity-driven destructive wiper attack (not ransomware). Initial access: Threat actor compromised a Windows domain administrator account in Stryker’s Microsoft Entra ID (Azure AD) environment, then created a new Global Administrator account. From that access, the attacker used Stryker’s own Microsoft Intune endpoint management platform to issue legitimate remote-wipe commands to enrolled corporate and BYOD devices. No malware was deployed. Data affected: Device contents were wiped. Handala claimed to have exfiltrated 50 terabytes of corporate data prior to the wipe. That figure has not been independently confirmed. Records affected: Approximately 80,000 devices were wiped between 05:00 and 08:00 UTC on 11 March 2026, according to BleepingComputer reporting; Handala’s claim of 200,000 affected systems has not been verified. Attribution: Handala, an Iran-linked group tracked by multiple vendors as Void Manticore / Storm-0842 and attributed to Iran’s Ministry of Intelligence and Security (MOIS). Status: Confirmed (wiper event and its mechanics); disputed (Handala’s 50 TB / 200,000 device claims).

Defensive lesson: An attacker who controls your identity provider can use your own management tools against you. Microsoft’s own Intune remote-wipe command — designed to protect corporate data on a stolen laptop — becomes a single command that can take down an entire fleet. Treat the identity layer (Entra ID / AD / Okta) with at least the same hardening as your endpoints: phishing-resistant MFA on every admin, just-in-time admin elevation, and tier-zero separation between identity admins and device admins.

Sources:

  • HIPAA Journal, “Stryker Cyberattack Has Impacted First Quarter Earnings”: hipaajournal.com
  • Cloud Security Alliance research note, “Handala Wiper Attack on Stryker”: labs.cloudsecurityalliance.org
  • Security Affairs, “Attack on Stryker’s Microsoft environment”: securityaffairs.com
  • Druva, “How Handala Used Global Admin Rights to Wipe Stryker”: druva.com
  • Stryker SEC filing: see SEC EDGAR for Stryker Corporation 10-Q and 8-K filings dated March 2026.

NYC Health + Hospitals — US public health, ~1.8 million people

Industry: Public healthcare. Attack type: Third-party vendor data exposure (supply-chain incident). Initial access: Unauthorized access to NYC H+H systems via an unnamed third-party vendor, with activity between late November 2025 and early February 2026. Data affected: Personally identifiable information (names, Social Security numbers, driver’s license numbers, passport numbers, taxpayer IDs, IRS identity-protection PINs), billing records and bank card data, medical and insurance data (diagnoses, medication lists, test results), and biometric data including fingerprints and palm prints. Records affected: At least 1.8 million individuals, reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights. Attribution: Not publicly attributed. Status: Confirmed (HHS filing + SecurityWeek reporting + NYC H+H statement). The inclusion of biometric data that cannot be reissued makes this one of the higher-severity 2026 healthcare breaches.

Defensive lesson: When biometric data is part of a breach, the traditional playbook (reissue credentials, monitor credit) is incomplete. Fingerprints and palm prints are forever; treat them with the same data-classification discipline as cryptographic key material. Separating third-party vendor access from production PII storage is now a board-level topic, not a procurement footnote.

Sources:

  • SecurityWeek, “Several healthcare data breaches impacting millions”: securityweek.com
  • HHS Office for Civil Rights breach portal (search “NYC Health + Hospitals”): ocrportal.hhs.gov
  • Pkware, “2026 Data Breaches: Cybersecurity Incidents Explained”: pkware.com

Instructure / Canvas — US education, ~275 million records claimed

Industry: Education technology (learning management system). Attack type: Data extortion, allegedly via the same ShinyHunters / Salesforce-integration pattern. Initial access: Per public reporting, claimed theft of roughly 3.65 TB of data and approximately 275 million records from the Canvas platform. The exact initial-access vector has not been publicly confirmed. Data affected: Not publicly itemised in detail. Records affected: Instructure reportedly paid a ransom, per Pkware’s reporting. The 275 million figure is a threat-actor claim. Attribution: ShinyHunters (Claimed). Status: Claimed only at the level of detail available. We include this incident because it is widely reported, but the 275 million figure is unverified.

Defensive lesson: Education-sector platforms hold longitudinal student records (K-12 through higher education) and are increasingly attractive targets because the data persists for years. Treat student record stores with the same data-classification discipline as adult health records. Just because a victim is a school district does not mean the data is low-value.

Sources:

  • Pkware, “2026 Data Breaches: Cybersecurity Incidents Explained”: pkware.com
  • CRN roundup: crn.com

Change log

  • 2026-07-28: Initial publication. Six incidents tracked: Odido, LexisNexis, Hallmark, Stryker, NYC Health + Hospitals, Instructure / Canvas.

Methodology and what we deliberately exclude

Inclusion criteria. We include an incident if at least one of the following is true: (1) a regulator or government has confirmed the breach (HHS OCR, AP, SEC 8-K, CISA, ENISA), (2) the victim company has issued a public disclosure, or (3) multiple independent, reputable outlets have reported the incident and the threat-actor claims are corroborated by technical evidence such as sample data, dark-web leak verification, or a class-action filing.

Excluded categories. We do not include pure researcher-discovered misconfigurations where no third-party access is confirmed, phishing-only credential leaks without PII exposure, denial-of-service incidents without data theft, or insider-only leaks that have not produced a regulatory filing.

Confidence markers. Each row distinguishes Confirmed facts (from the victim or a regulator) from Claimed facts (from the threat actor) and Inferred facts (consistent with the available evidence but not directly stated). Where a number is a threat-actor claim, we say so.

Corrections. If you spot an error, a missing incident, or a fact that has been superseded, email corrections@humanrequired.org with the URL and the claim. We verify every correction against primary sources and issue a dated note.

Scope. This tracker covers confirmed or credibly reported major data breaches of 2026. It is not comprehensive. The breach landscape is large; we focus on incidents that have a defensive lesson worth publishing.