Threat analysis, breach reports, and security guidance for North American businesses.
Six major North American breaches disclosed in 2026 span education, healthcare, financial services, and utilities, with claimed record-setting volumes affecting millions. Recent incidents reveal supply-chain exposure and ransomware persistence as dominant attack vectors.
Six major breaches have struck North American organizations across healthcare, education, and telecom sectors in 2026. Combined impact exceeds 65 million records, with credential theft and ransomware as primary attack vectors.
Major education, healthcare, and infrastructure breaches dominate 2026 threat landscape. Instructure Canvas suffered the largest education breach on record, while NYC Health+Hospitals and Foxconn manufacturing revealed persistent vulnerabilities in critical supply chains.
Five major verified breaches impacting North Americans in 2024-2026, ranging from 280,000 to 192.7 million individuals. Mega-breaches dominate the landscape, with Instructure's Canvas LMS, Change Healthcare, and 700Credit leading by volume and cascading impact.
North America experienced six major data breaches in the past 12 months spanning healthcare, retail, automotive, and employee records. The Canvas LMS platform, NYC Health + Hospitals, and Canadian Tire stand out as the largest by record count.
Six major 2026 breaches exposed over 300 million personal records across North America, from education platforms and telecommunications giants to government systems, driven primarily by credential theft and third-party compromises. Attackers focused on voice phishing and vendor access rather than sophisticated exploits.
Six major data breaches impacted North Americans in 2026, exposing hundreds of millions of records across education, telecommunications, government, legal, and manufacturing sectors. Breaches ranged from credential theft and social engineering to wiper attacks and ransomware, with impacts spanning educational institutions, government agencies, healthcare manufacturers, and critical infrastructure.
Six critical breaches in 2026 exposed millions of North Americans across education, telecommunications, healthcare, cruise lines, insurance oversight, and utilities sectors. Credential compromise and social engineering emerged as the dominant attack vectors, with ransom demands and extortion campaigns marking a shift toward organized data-theft operations.
This week's data breach intelligence: a 12.9M-account Carhartt breach, a live Stripe API key leak hitting North America…
This week's business data breach roundup: a Stripe merchant credential leak, an Azure enterprise credential theft campa…
In March 2026, HHS OCR settled a HIPAA investigation involving MMG Fusion, a dental software vendor whose 2020 breach a…
In September 2025, Ontario's Information and Privacy Commissioner issued the first administrative monetary penalty unde…
AssetMark financial data breach exposes Social Security numbers and financial accounts of 570,000 Americans. Delaware N…
This week saw major data breaches affecting millions, including Carnival Cruise Line's 6 million customer breach and on…
The ShinyHunters threat group escalated attacks this week targeting 275 million education records, 5.5 million ADT cust…
ShinyHunters breached Instructure's Canvas LMS affecting 275 million users at 8,809 institutions. Company paid ransom t…
BWH Hotels breach exposed guest emails and reservations for 6 months while Microsoft warns of massive credential theft …
US cybersecurity agency CISA exposed government credentials via GitHub while ShinyHunters targeted major platforms. Cri…
ShinyHunters breached Canvas LMS affecting 275 million users across 9,000 schools, while Medtronic and Cushman & Wakefi…
ShinyHunters' massive Instructure Canvas breach affects 9,000 North American schools and 275 million individuals, expos…
An analysis of 214 confirmed breach incidents affecting Canadian small and mid-size businesses in Q1 2026. Credential exposure remains the leading initial access vector.
Privileged client data, high-value transactions, and underfunded IT departments make legal practices disproportionately targeted by credential-based campaigns.
OSFI's B-10 guideline sets expectations for technology and cyber risk management. We break down what federally regulated financial institutions need to demonstrate.
Your risk score is a composite of 19 weighted signals. Here's what each band means, how severity is calculated, and what actions to prioritize at each level.
Research shows the median time from credential dump publication to first unauthorized access attempt is under 48 hours. What that means for your response timeline.
Under PIPEDA, organizations must report breaches that pose a real risk of significant harm. We outline the notification timeline, OPC reporting requirements, and documentation obligations.