Major Data Breaches – Q1 2026
This report compiles major data breaches disclosed between January 1 and March 31, 2026 that affected 1 million+ individuals. The selection criterion is the disclosure / notification date, not the date of the underlying breach — some incidents involved earlier intrusions but were publicly disclosed (or had their scope materially expanded) during Q1 2026.
Each case is analyzed for victim profile, threat actor, attack methodology, Attack Vector, exposed data types, and impact volume. The Attack Vector taxonomy used in this report follows the IBM Cost of a Data Breach Report categories, with the corresponding MITRE ATT&CK technique mappings noted for each vector to support threat-modeling and detection-engineering use cases.
Executive Summary
Top 10 Incidents by Exposure Volume (Disclosure Date)
| Rank | Incident | Scale | Disclosed |
|---|---|---|---|
| 1 | IDMerit (KYC identity verification SaaS) | ~3 billion records exposed (~1B sensitive KYC records, 1TB, 26 countries) | Feb 18, 2026 |
| 2 | Infutor (Verisk Marketing Solutions) | ~676.8 million records (KYC/PII) | March 2026 |
| 3 | Conduent (US gov IT services contractor) | 25 million+ people (8TB+) | February 2026 (expanded) |
| 4 | Cegedim MonLogicielMedical (French healthcare SW) | 15.8 million patients | March 3, 2026 |
| 5 | CarGurus (online auto marketplace) | 12.6M accounts / 17M records | February 2026 |
| 6 | Match Group (Hinge / Match / OkCupid) | 10+ million records | January 28, 2026 |
| 7 | Crunchyroll (anime streaming) | ~6.8 million users | March 2026 |
| 8 | Odido (Netherlands telecom) | 6.2 million customers | February 2026 |
| 9 | Mercer Advisors (wealth management) | 5.7 million records | Feb 16-23, 2026 |
| 10 | Kyowon Group (South Korean education / lifestyle) | 5.5+ million customers | January 2026 |

Most Frequently Exposed Data Types
- Personally Identifiable Information (PII) — names, addresses, emails, phone numbers (in nearly every incident)
- Social Security Numbers / National IDs — Conduent, Navia, Infutor, IDMerit, FICOBA, Mercer, Hightower, TriZetto, etc.
- Health/Medical Information (PHI) — Conduent, Cegedim, TriZetto, QualDerm, NYC Health, Navia (HSA/FSA), UH Cancer Center
- Financial / Banking Information — Odido (IBAN), FICOBA, Mercer Advisors, Figure Technology, Brightspeed
- Behavioral / Usage Data — Match Group (dating profiles), Crunchyroll (viewing), Panera (orders), CarGurus
Top 3 Attack Vectors of Q1 2026
- Compromised credentials (SSO Vishing-driven theft) — Dominant #1 of the quarter
- ShinyHunters’ Okta SSO vishing campaign was the common root cause of most mega-breaches.
- Match Group, CarGurus, Panera, Crunchbase, Mercer Advisors, Beacon Pointe, Pathstone, Betterment, Allianz Life — a single threat actor hit ~100 organizations simultaneously.
- Third-party vendor & Supply chain compromise
- Conduent → state governments + Volvo, AppsFlyer → Match Group, Navia → HackerOne + hundreds, TriZetto → OCHIN + dozens, QualDerm → 158 dermatology practices, NYC Health Hospitals → external vendor.
- System error / Cloud Misconfiguration (the new mega-exposure standard)
- IDMerit (unauthenticated MongoDB, 3B records), Infutor (Elasticsearch, 676M records), Illinois DHS (4-year public exposure) — mega-scale exposure without an external attacker even needing to break in.
Notable Attack Patterns
- ShinyHunters’ SSO Vishing Campaign — the threat actor of the quarter: Throughout January–February 2026, the group struck ~100 organizations simultaneously. Voice phishing (vishing) to steal Okta/Microsoft/Google SSO credentials, then exfiltration from SaaS data stores (AppsFlyer, Salesforce, Google Drive, etc.). Standard MFA (SMS, OTP) is defeated by AiTM phishing — only phishing-resistant MFA (FIDO2/Passkey) is effective.
- Healthcare Business Associate (BA) Onslaught: Conduent, TriZetto, QualDerm, Navia and other HIPAA business associates became single points of failure for hundreds of providers and employers. According to HIPAA Journal, ~9.6 million individuals’ US healthcare records were exposed in the first two months of 2026 alone.
- Wealth Management (RIA) Industry Under Coordinated Attack: Mercer Advisors (5.7M), Beacon Pointe, Pathstone, Hightower, Edelman Financial Engines, EP Wealth, Cetera, Ameriprise, Betterment (1.4M) — wealth management firms became targets of ShinyHunters’ campaign. Lack of MFA is the common allegation across class actions.
- Cloud Misconfiguration produced the #1 and #2 incidents of the quarter: IDMerit and Infutor were both exposures, not break-ins. Attackers didn’t need to penetrate anything.
- Iran-linked Wiper Attack on Stryker (March 11) — not data theft but MS Intune-abused global device wipe. 79 countries, 200,000+ devices affected.

Incident-by-Incident Detailed Analysis
1. IDMerit — ~3 Billion Records Exposed (~1B sensitive KYC records, 26 countries)
- Affected entity: IDMerit (California-based AI-powered KYC identity verification SaaS provider). Serves fintech, financial services, telecom, and other regulated sectors with real-time identity verification and AML screening.
- Why this matters: The single largest exposure of Q1 2026. US: ~203M records, Mexico: 124M, Philippines: 72M, Germany / Italy / France: 50M+ each. KYC data is uniquely dangerous — SSNs, national IDs, telecom metadata are permanent identifiers that cannot be reset like passwords. Fuels SIM-swapping, account takeover, targeted phishing, credit fraud, “long-tail privacy harms” (damage years later). Discovery November 11, 2025 → secured November 12 → public disclosure February 18, 2026 (99 days later) — disclosure delay carries regulatory significance.
- Threat actor: None confirmed (no evidence of malicious access; Cybernews researchers warned automated crawlers continuously scan for exposed databases and typically index them within hours).
- Attack methodology: A MongoDB instance was left exposed to the public internet with no authentication required. Anyone with the URL could read, copy, export, or delete the entire 1TB of contents without credentials. Not an external attack — a cloud misconfiguration.
- Attack Vector:
- System error (IT failure / misconfiguration): Missing authentication and access controls on the MongoDB instance. A basic authentication control — standard in any production database deployment — would have prevented the entire exposure. Maps indirectly to T1562 (Impair Defenses).
- Exposed data: Full names, residential addresses and postal codes, dates of birth, national identity numbers (SSN or equivalent), phone numbers, gender, email addresses, telecom metadata (mobile network info — exploitable for SIM swapping), breach status / social profile annotations
- Volume: ~3 billion records (1TB), of which ~1 billion are sensitive KYC PII. 26 countries. > ※ After Cybernews published, IDMerit issued a statement (Feb 26, 2026) saying that “while the company owns and operates its own proprietary platform, IDMerit does not own, control, or store customer data or the underlying data maintained by independent data sources.” Some KYC industry outlets (e.g., KYCFrance) raised questions about Cybernews’s reporting. However, Cybernews published screenshots and samples of the exposed MongoDB instance, and multiple outlets corroborated. This report records both the multi-source confirmation and IDMerit’s partial denial.
2. Infutor (Verisk Marketing Solutions) — ~676.8 Million Records Exposed
- Affected entity: Infutor (consumer identity verification and identification data analytics platform), serving insurance, consumer finance, higher education, real estate.
- Why this matters: The #2 single-incident exposure of Q1 2026 (676M records). KYC-grade identity data including SSNs becomes raw fuel for large-scale identity fraud campaigns on the dark web. Even consumers who never directly transacted with Infutor are affected — they had no way of knowing their data was even held by Infutor.
- Threat actor: Not publicly attributed (discovered via dark web posting)
- Attack methodology: Per SOCRadar’s analysis, a misconfigured Elasticsearch database was publicly exposed to the open internet. No authentication required — over 676 million records were accessible. Closer to persistent exposure than active intrusion.
- Attack Vector:
- System error (IT failure / misconfiguration): Missing authentication and access controls on the Elasticsearch index, exposed directly to the internet. (T1562 indirect mapping.)
- Exposed data: Full names, dates of birth, physical addresses, phone numbers, Social Security Numbers (SSNs)
- Volume: 676,798,866 unique records
3. Conduent — 25 Million+ Affected (8TB+) — Disclosure Expanded in Feb 2026
- Affected entity: Conduent Inc. (NJ-based US government IT services contractor). Processes medical billing, toll transactions, prepaid cards for government programs. Manages data for 100M+ individuals.
- Why this matters: Texas alone reported 15.4 million affected; Oregon reported 10.5 million. One of the largest healthcare-related breaches in US history. Permanent identifiers (SSNs cannot be changed) make this a lifelong identity-theft risk. A single government contractor became a systemic single point of failure for nationwide PII/PHI exposure. Multiple consolidated class actions. The Texas Attorney General announced an investigation in February 2026 referencing potential 192M+ impact (under investigation).
- Threat actor: SafePay ransomware group
- Attack methodology: Initial access October 21, 2024; detected January 13, 2025 — roughly 3 months of dwell time during which 8TB+ was exfiltrated. After the initial 2025 SEC filing, the affected count steadily expanded: ~4 million → 10 million → finally 25 million+ confirmed in February 2026.
- Attack Vector:
- Vulnerability exploitation (T1190): Initial access vector not officially disclosed; presumed exploitation of an internet-facing system.
- Compromised credentials (T1078): Three-month dwell with lateral movement using valid accounts.
- Third-party / Trusted relationship (T1199): Conduent itself is a trusted third-party vendor to state governments and major employers; its compromise propagated to clients including Volvo Group (~17,000 employees confirmed exposed).
- Exposed data: Full names, Social Security Numbers, dates of birth, addresses, medical records, health insurance details, treatment information, claims data
- Volume: 25+ million people (8.5TB)
4. Cegedim MonLogicielMedical — 15.8 Million French Patients
- Affected entity: Cegedim (French healthcare software company); MonLogicielMedical platform used by 3,800 French physicians
- Why this matters: One of the largest healthcare data breaches in European history. 165,000 files contained doctors’ free-text notes including HIV status, psychiatric diagnoses, sexual orientation, and mental-health conditions. Politicians were among the exposed. The most damning detail: France’s CNIL had already fined Cegedim €800,000 in September 2024 for unlawfully processing this exact category of health data — clearly insufficient remediation. Late 2025 intrusion → criminal complaint filed October 2025 → silence for four months until France24’s report forced March 3, 2026 confirmation. Disclosure delay is itself a major issue.
- Threat actor: Not publicly attributed
- Attack methodology: Late 2025 intrusion into the MonLogicielMedical platform. 15.8 million patient records exfiltrated.
- Attack Vector:
- Vulnerability exploitation (T1190) or Compromised credentials (T1078): Specific entry path not disclosed.
- Third-party / Supply Chain (T1199): SaaS for 3,800 doctors — single compromise cascaded to all those physicians’ patient records.
- Exposed data: Full names, dates of birth, medical records, doctors’ free-text notes (HIV status, psychiatric diagnoses, sexual orientation, mental-health conditions), prescriptions, health insurance information
- Volume: 15.8 million patient records
5. CarGurus — 12.6M Accounts / 17M Records
- Affected entity: CarGurus (Boston-based online automotive marketplace)
- Why this matters: One of the largest publicly-reported consumer breaches in February 2026. Australian security researcher Troy Hunt was the first to flag it via Have I Been Pwned, before CarGurus issued formal disclosure. A class-action suit alleges CarGurus failed to provide adequate breach notification. Part of the broader ShinyHunters social-engineering wave.
- Threat actor: ShinyHunters
- Attack methodology: ShinyHunters used social engineering (vishing) to compromise credentials and infiltrate CarGurus systems. ~17 million records and 12.6 million accounts exfiltrated.
- Attack Vector:
- Compromised credentials (T1078): Employee SSO credentials stolen via ShinyHunters’ vishing — attacker accessed systems as a legitimate user.
- Phishing (T1566): Voice phishing (vishing) of employees.
- Exposed data: Email addresses, account creation dates, user UUIDs, internal IDs, internal corporate records, IP addresses, PII (names, addresses, etc.)
- Volume: ~17 million records / 12.6 million accounts
6. Match Group (Hinge / Match.com / OkCupid) — 10+ Million Records
- Affected entity: Match Group (operator of Tinder, Hinge, Match.com, OkCupid, Meetic, etc.)
- Why this matters: Dating-app data is among the most psychologically sensitive consumer data. Exposure of user IDs, IPs, locations, matches, and subscription transaction details enables highly targeted phishing, romance scams, and extortion. Match stated passwords, financial data, and private messages were not impacted. The flagship example of ShinyHunters’ Okta SSO vishing campaign.
- Threat actor: ShinyHunters (also known as Scattered LAPSUS$ Hunters)
- Attack methodology: Voice phishing to steal a Match Group employee’s Okta SSO credentials → access to AppsFlyer marketing-analytics instance → exfiltration of user usage data. Phishing domain
matchinternal.comwas confirmed. - Attack Vector:
- Phishing (T1566) — specifically vishing. T1566.002 (Spearphishing Link) when combined with the lookalike Okta login domain.
- Compromised credentials (T1078) — stolen Okta SSO account.
- Third-party vendor & Supply chain (T1199) — AppsFlyer, a trusted third-party analytics platform, was the exfiltration channel (though AppsFlyer denies its own systems were breached).
- Exposed data: User IDs, IP addresses, Hinge subscription transaction IDs and amounts, match records, dating profile bios, locations, phone numbers, authentication tokens, internal employee emails, internal corporate contracts
- Volume: 10+ million records (1.7GB compressed archive)
7. Crunchyroll — ~6.8 Million Users (Anime Streaming)
- Affected entity: Crunchyroll (major anime streaming platform)
- Why this matters: Global user base affected. ~100GB of data including customer service ticket data — exposure of email + support inquiries makes for excellent targeted-phishing fuel.
- Threat actor: Not publicly attributed (hacker self-claim)
- Attack methodology: March 2026 unauthorized access. Customer service ticket system breach.
- Attack Vector:
- Compromised credentials (T1078) or Vulnerability exploitation (T1190): Specific path not disclosed.
- Exposed data: ~100GB of data — user information and customer service ticket content (likely emails, inquiry contents)
- Volume: ~6.8 million (per hacker claim)
8. Odido — 6.2 Million Customers (Netherlands Telecom)
- Affected entity: Odido (major Dutch telecom operator)
- Why this matters: One of the largest single-telco incidents of Q1. Includes passport / driver’s license details for some customers, raising significant identity-theft risk. GDPR-applicable — Dutch DPA notified. Passwords, call records, billing, and location data were not impacted.
- Threat actor: Not publicly attributed
- Attack methodology: Unauthorized access detected over the weekend of February 7, 2026. Customer contact system breached, data exfiltrated.
- Attack Vector:
- Compromised credentials (T1078) or Vulnerability exploitation (T1190): Specific vector not disclosed.
- Exposed data: Full names, addresses, email addresses, mobile numbers, customer numbers, IBANs, dates of birth, passport or driver’s license details (for some)
- Volume: 6.2 million customers
9. Mercer Advisors — 5.7 Million Records (Wealth Management)
- Affected entity: Mercer Advisors (Denver-based, one of the largest US RIAs — $96B+ AUM)
- Why this matters: The flagship example of ShinyHunters’ coordinated attack against the wealth management industry. Lack of MFA is the central allegation in the class actions. Wealth-management data — SSNs, asset levels, tax IDs — becomes raw material for high-stakes targeted fraud, hyper-credible phishing, and even physical extortion of high-net-worth individuals. Mercer refused ransom → data dumped to dark web. Two class actions filed (March 2 — Berger v. Mercer; March 6 — Amick v. Mercer).
- Threat actor: ShinyHunters
- Attack methodology: ~February 16, 2026 — vishing-based intrusion. Data exfiltrated from Salesforce environment. 48-hour ransom ultimatum → Mercer refused → February 18 data publication. Of 5,704,000 records, approximately 1.3 million contain deep PII.
- Attack Vector:
- Phishing (T1566) — vishing impersonating IT support, persuading employees to install malicious Salesforce Data Loader or grant access tokens.
- Compromised credentials (T1078) — stolen credentials used to access Salesforce.
- Third-party vendor (T1199) — Salesforce environment used as the breach pathway.
- Exposed data: Full names, contact information (postal/email addresses, phone), full or partial SSNs, driver’s license numbers, government-issued IDs (passport), dates of birth, financial account numbers, Tax IDs, reported annual income and net worth valuations, emergency contacts, contract documents, legal documents
- Volume: ~5.7 million records (~1.3M with deep PII)
10. Kyowon Group — 5.5+ Million Customers (South Korean Education / Lifestyle)
- Affected entity: Kyowon (major South Korean education / culture / hospitality conglomerate; offers educational services, health appliances, hotels)
- Why this matters: Largest South Korean breach of Q1 2026. 600 of Kyowon’s 800 servers were impacted — operational disruption alongside data theft. Subject to South Korea’s PIPA — regulatory response will be closely watched.
- Threat actor: Not publicly attributed (ransomware group)
- Attack methodology: January 2026 ransomware attack — 600 of 800 servers impacted, operations significantly disrupted alongside data exfiltration.
- Attack Vector:
- Vulnerability exploitation (T1190) or Compromised credentials (T1078): Specific entry path not disclosed; classic ransomware pattern.
- Exposed data: Customer data of ~5.5 million people (specific data types still under investigation)
- Volume: 5.5+ million people
11. Panera Bread — 5.1 Million Accounts (Jan breach, disclosed in Feb)
- Affected entity: Panera Bread (large US bakery-cafe chain)
- Why this matters: ShinyHunters extortion → refusal → data leak pattern. Panera had already settled a 2024 breach for $2.5 million in January 2026, and was breached again — a repeat-offender pattern raising governance concerns. ShinyHunters claimed 14M records, but Have I Been Pwned analysis confirmed ~5.1M unique accounts.
- Threat actor: ShinyHunters
- Attack methodology: January 2026 social-engineering-based intrusion. Panera refused ransom; ShinyHunters released a 760MB archive in retaliation.
- Attack Vector:
- Phishing (T1566) + Compromised credentials (T1078): Same ShinyHunters vishing playbook.
- Exposed data: Names, email addresses, phone numbers, physical addresses
- Volume: ~5.1 million unique accounts (ShinyHunters claimed 14M)
12. TriZetto Provider Solutions (Cognizant) — 3.43 Million Patients
- Affected entity: TriZetto Provider Solutions (Cognizant subsidiary, US healthcare IT provider). Eligibility/verification SaaS used by health insurers and providers.
- Why this matters: One of Q1’s largest healthcare incidents. Initial access November 19, 2024; detected October 2, 2025 — ~11 months of undetected dwell. Potential HIPAA violation. Notification began February 6, 2026; March 2026 confirmed scope (3,433,965 individuals). OCHIN (an EHR SaaS) also impacted — ~9% of OCHIN’s patient base (~700,000) separately affected. 44+ HIPAA-covered entities have issued their own notifications — actual blast radius is likely larger.
- Threat actor: Not publicly attributed (no ransomware group has claimed responsibility)
- Attack methodology: November 19, 2024 — unauthorized external network access began → October 2, 2025 — suspicious activity detected on TriZetto’s web portal → external cybersecurity experts engaged → November 28, 2025 — confirmed PHI exfiltration → February 6, 2026 — Maine AG notification + individual notifications begin.
- Attack Vector:
- Vulnerability exploitation (T1190): External network → web portal compromise (specific CVE not disclosed).
- Compromised credentials (T1078): 11-month dwell — likely use of valid accounts.
- Third-party / Supply Chain (T1199): TriZetto is a business associate to many healthcare entities — single breach cascaded across dozens of organizations and 3.4M patients.
- Exposed data: Names, addresses, dates of birth, SSNs, insurance details, provider information (financial data not affected)
- Volume: 3,433,965 individuals
13. QualDerm Partners — 3.12 Million Patients
- Affected entity: QualDerm Partners (Tennessee-based; provides healthcare management services to 158 dermatology, skin cancer care, cosmetics, plastic surgery, and pathology practices in 17 US states). Serves ~15M patients annually.
- Why this matters: One of the largest healthcare incidents of Q1. Despite a brief intrusion window (December 23-24, 2025), 3.12M patient records were extracted in just 2 days — aggressive, surgical data hunting. Affects 17 states. Date of death also exposed — heightened identity-theft risk for surviving family members. Notification delay (Dec 24 detection → Feb 22 notification start) raises class-action exposure.
- Threat actor: Not publicly attributed
- Attack methodology: December 24, 2025 — anomalous activity identified. Forensic investigation confirmed unauthorized access between December 23-24, 2025. February 22, 2026 — notification mailing began. March 2026 — formal reporting to Oregon AG / OCR.
- Attack Vector:
- Specific vector not disclosed — Compromised credentials (T1078) or Vulnerability exploitation (T1190) likely.
- Third-party / Supply Chain (T1199): Single management-services provider compromise → 158 practices’ patient data exposed.
- Exposed data: Names, addresses, dates of birth, doctor names, medical record numbers, dates of death, email addresses, treatment and diagnosis information, health insurance information; for some, government-issued ID (driver’s license)
- Volume: 3,117,874 individuals
14. Navia Benefit Solutions — 2.7 Million
- Affected entity: Navia (US benefits administration company managing HSA, FSA, HRA, COBRA services). 10,000+ client companies, 1M+ direct participants.
- Why this matters: A single benefits-SaaS provider’s breach exposed employee data across hundreds of client companies simultaneously — including HackerOne (yes, the bug bounty platform). HackerOne identified the root cause as a BOLA (Broken Object Level Authorization) vulnerability in Navia’s API. Classic supply-chain blast radius. Washington State Health Care Authority also impacted — ~27,000 Medicaid members and other state employees.
- Threat actor: Not publicly attributed
- Attack methodology: Intrusion between December 22, 2025 and January 15, 2026. Exploitation of an exposed API with a Broken Object Level Authorization flaw — authenticated users could access other users’ objects without authorization. January 23 — Navia detected suspicious activity. March 13, 2026 — substitute notice posted; March 18 — individual notifications.
- Attack Vector:
- Vulnerability exploitation (T1190): BOLA flaw in API — object-level authorization missing; authenticated users could read other users’ data.
- Third-party vendor / Supply chain (T1199): Navia is a benefits administrator for hundreds of clients — single breach cascaded to all client employees.
- Exposed data: Social Security Numbers, names, dates of birth, phone numbers, email addresses, addresses, HRA/FSA/COBRA enrollment information, plan dates (enrollment, effective, termination), Navia ID numbers, employee IDs, dependent information
- Volume: 2,697,540 individuals
15. Crunchbase — 2M+ Records
- Affected entity: Crunchbase (global business intelligence / company information platform)
- Why this matters: A platform widely used by investors, startups, and VCs was compromised. Exposed data includes PII alongside contracts and executive contact details — superb fuel for targeted spear-phishing. Part of the same January cluster of ShinyHunters’ SSO vishing campaign.
- Threat actor: ShinyHunters
- Attack methodology: December 2025 vishing campaign targeting Google/Microsoft/Okta SSO. January 23, 2026 — ShinyHunters posted ~400MB compressed archive on the dark web after Crunchbase declined to pay ransom. January 26 — Crunchbase confirmed the breach.
- Attack Vector:
- Phishing (T1566) — vishing.
- Compromised credentials (T1078) — stolen SSO credentials.
- Exposed data: Names, contact details (addresses, phone, email), job information, contracts, internal corporate documents, executive contact details
- Volume: 2M+ records (~400MB compressed archive)
16. Allianz Life — ~1.4 Million (Investigation/Notification Expanded, Feb 2026)
- Affected entity: Allianz Life Insurance Company of North America (Minnesota-based, subsidiary of German Allianz Group)
- Why this matters: July 2025 cloud CRM breach (Salesforce-based) had its scope significantly expanded in Q1 2026, with class-action investigation announced February 25, 2026 at 1,497,036 individuals affected. Have I Been Pwned confirmed exposure of 1.1M records. Part of ShinyHunters’ Salesforce-targeting campaign — the precursor to the broader RIA / insurance-industry mega-breaches in this quarter.
- Threat actor: ShinyHunters (Scattered Spider suspected)
- Attack methodology: July 16, 2025 — social engineering (vishing) compromised a third-party cloud-CRM system. ShinyHunters extracted ~2.8M data records (individual customers + business partners) from Salesforce instances.
- Attack Vector:
- Phishing (T1566) — vishing.
- Compromised credentials (T1078) — Salesforce SSO.
- Third-party vendor (T1199) — third-party CRM (Salesforce).
- Exposed data: Names, addresses, dates of birth, SSNs, email addresses, gender, phone numbers
- Volume: 1,497,036 individuals (HIBP confirmed 1.1M) > ※ Original breach occurred July 2025, but scope expansion (1.4M) and class-action investigations were disclosed in Q1 2026 — included on disclosure-date basis.
17. Betterment — ~1.4 Million (Robo-Investing Platform)
- Affected entity: Betterment (automated investment / robo-advisor platform)
- Why this matters: Part of ShinyHunters’ coordinated RIA / fintech campaign. A notable detail: a DDoS attack was used as a diversion tactic during data exfiltration. Follow-up fraud campaigns impersonating Betterment staff target users.
- Threat actor: ShinyHunters
- Attack methodology: January 9, 2026 — social-engineering attack began. Threat actors gained access to third-party operational platforms used for marketing and customer support. January 13 — DDoS attack mitigated within hours but suspected to be a diversion tactic during active data exfiltration. February 5 — leaked dataset surfaced on Have I Been Pwned.
- Attack Vector:
- Phishing (T1566) — exploiting human vulnerabilities.
- Compromised credentials (T1078) — third-party platform credential theft.
- Denial-of-service (DoS) (T1498/T1499) — January 13 DDoS as diversion during exfiltration.
- Exposed data: Names, email addresses; for some customers, physical addresses, phone numbers, dates of birth, employer details
- Volume: ~1.4 million customers
18. Brightspeed — 1M+ Customers (Broadband Telecom)
- Affected entity: Brightspeed (US fiber broadband provider, 20 states; Connect Holding II LLC)
- Why this matters: Single-ISP incident. Attackers (Crimson Collective) claim ability to remotely disconnect customers from service — a threat dimension beyond data theft. Four class actions filed (federal courts in NC, OH, VA, TX).
- Threat actor: Crimson Collective (extortion gang)
- Attack methodology: January 4, 2026 — Telegram post claiming 1M+ records stolen. January 6 — sample data released as proof. Demand: 3 BTC (~$276,000).
- Attack Vector:
- Compromised credentials (T1078) or Vulnerability exploitation (T1190): Specific vector not disclosed.
- Exposed data: Names, emails, phone numbers, billing/service addresses, account status, network type, consent flags, billing system, payment history, partial payment-card information, appointment/order records, site IDs
- Volume: 1M+ customers
19. NYC Health + Hospitals — 1M+ Patients (March 24 Notification)
- Affected entity: New York City Health and Hospitals Corporation (largest US public healthcare system, serving 1M+ patients annually)
- Why this matters: Compromise of America’s largest public healthcare system. Unauthorized access from November 25, 2025 to February 11, 2026 — ~2.5 months. Highly sensitive data exposed (biometrics, SSNs, financial accounts). Entry pathway identified as a third-party vendor breach.
- Threat actor: Not publicly attributed
- Attack methodology: February 2, 2026 — suspicious activity detected. Investigation with external cybersecurity professionals confirmed unauthorized access November 25, 2025 to February 11, 2026, with file copying. Initial pathway: third-party vendor security breach. March 24 — public notice issued.
- Attack Vector:
- Third-party vendor (T1199): Vendor compromise → access to NYC Health systems.
- Compromised credentials (T1078): Long dwell suggests valid-account lateral movement.
- Exposed data: Health insurance details, medical records (diagnoses, medications, test results, treatment plans), biometric data (fingerprints, palm prints), billing/payment information, SSNs, driver’s license numbers, financial account details, online account credentials
- Volume: 1M+ patients (specific count under investigation; system serves 1M+ patients per year)
20. FICOBA (French National Bank Account Registry) — 1.2 Million
- Affected entity: Fichier National des Comptes Bancaires et Assimilés (FICOBA) — French national bank account registry
- Why this matters: Compromise of national financial infrastructure — a government system holding metadata on every bank account in France. Sharply elevates targeted-financial-fraud risk against French citizens.
- Threat actor: Not publicly attributed
- Attack methodology: Late January 2026 breach. 1.2 million accounts impacted. Specific intrusion path not disclosed.
- Attack Vector:
- Specific vector not disclosed. Likely Vulnerability exploitation (T1190) or Compromised credentials (T1078).
- Exposed data: Bank account metadata (presumably account holder names, account numbers, banking institutions)
- Volume: 1.2 million accounts
21. University of Hawaii Cancer Center — ~1.2 Million (Expanded Disclosure)
- Affected entity: University of Hawaii Cancer Center (Epidemiology Division)
- Why this matters: A textbook research-data risk. Long-retained research data (collected 1993–2007) highlights the importance of data retention policy — old data that arguably should have been deleted became a liability. Contrary to early reporting, the breach includes names, SSNs, driver’s license data, voter registration data, plus four research studies and two additional files of names/SSNs collected for epidemiological research.
- Threat actor: Ransomware group (specifics not disclosed)
- Attack methodology: August 2025 intrusion; scope expanded to ~1.15M and disclosed in February–March 2026.
- Attack Vector:
- Vulnerability exploitation (T1190): Ransomware pattern.
- Exposed data: Names, Social Security Numbers, driver’s license data, voter registration data, epidemiological research data (with SSNs)
- Volume: ~1.2 million people
22. Eurail — 1.3TB Data Offered for Sale (January)
- Affected entity: Eurail (European integrated rail pass provider)
- Why this matters: GDPR-applicable. Includes passport details for travelers — high identity-theft and targeted-phishing risk. Data offered for sale on Telegram with samples.
- Threat actor: Not publicly attributed
- Attack methodology: ~January 10, 2026 — unauthorized access discovered. Attackers claim 1.3TB exfiltrated from cloud storage and support systems.
- Attack Vector:
- Compromised credentials (T1078) or Cloud misconfiguration (T1530 — Data from Cloud Storage): Specific vector not disclosed.
- Exposed data: Names, contact details, travel companion details, passport information (numbers and expiry dates)
- Volume: 1.3TB (specific headcount under investigation, but Eurail’s user base suggests likely 1M+)
23. LexisNexis — ~3.9 Million Database Records (March Disclosure)
- Affected entity: LexisNexis (legal and data analytics firm)
- Why this matters: Exposed users include federal judges, DOJ attorneys, and SEC staff (118 confirmed) — extreme sensitivity. Root cause was an unpatched, publicly known critical CVE (React2Shell, CVSS 10.0) — a hard-to-defend governance failure. Class-action exposure rising post-disclosure.
- Threat actor: FulcrumSec
- Attack methodology: Initial access February 24, 2026; confirmed March 3. Exploited React2Shell vulnerability (publicly known since November 2025; patches available since early December) on an unpatched frontend application to enter the AWS environment. Over-permissioned IAM roles then enabled lateral movement from the frontend container into production databases and into AWS Secrets Manager (where 53 credentials were stored in plaintext). 2.04GB exfiltrated.
- Attack Vector:
- Vulnerability exploitation (T1190 — Exploit Public-Facing Application): React2Shell (CVSS 10.0) used against an unpatched frontend.
- Compromised credentials (T1078, T1555): 53 plaintext credentials harvested from AWS Secrets Manager and used for lateral movement.
- Exposed data: 3.9 million database records, 21,042 customer accounts, 400,000 user profiles (118 belonging to federal judges, DOJ attorneys, and SEC staff)
- Volume: 2.04GB / 3.9M database records / 400K user profiles
24. Nike — 1.4TB Internal Data Exfiltrated (January Disclosure)
- Affected entity: Nike
- Why this matters: While the affected-individual count is undisclosed, the 1.4TB of internal files represents serious internal design and manufacturing IP exposure rather than primarily user data. 188,347 items — claimed by the WorldLeaks extortion gang. Sustained intrusion (not a smash-and-grab) implied by data volume.
- Threat actor: WorldLeaks extortion group
- Attack methodology: Specific intrusion path not disclosed. ~1.4TB of design and manufacturing-related internal files exfiltrated. Volume implies long-dwell access.
- Attack Vector:
- Specific entry vector not disclosed — possible Compromised credentials (T1078), Third-party (T1199), or Vulnerability exploitation (T1190).
- Exposed data: 188,347 internal files (design and manufacturing-related, 1.4TB)
- Volume: 1.4TB / 188,347 files (consumer-PII headcount unclear, but included for scale and sensitivity)
25. Stryker — Global Device Wiper Attack (March 11)
- Affected entity: Stryker (Fortune 500 medical device manufacturer; 56,000 employees, 79 countries; $25.1B in 2025 revenue)
- Why this matters: The most jolting attack of Q1 2026 — operational paralysis rather than data theft. Iran-linked group Handala abused Stryker’s MS Intune console to issue an enterprise-wide remote wipe command. Across 79 countries, employees watched in real time as their corporate laptops and BYOD personal phones were factory-reset. Stryker’s Lifenet ECG transmission system became nonfunctional across most of Maryland, forcing emergency services to fall back to radio. Separate from the wipe, employee data was stolen — 6+ employee class-action lawsuits filed (also tied to a previously undisclosed 2024 breach with PII/medical-records exfiltration). Handala claimed 50TB exfiltration (likely inflated).
- Threat actor: Handala (Iran-linked, suspected MOIS connection, overlap with MuddyWater / TA450)
- Attack methodology: March 11, 2026, ~03:30 EST — attack launched. AiTM (Adversary-in-the-Middle) phishing (Tycoon 2FA suspected) → MFA bypass → Intune admin credential theft → enterprise wipe policy executed via Intune console → 200,000+ devices wiped. Attacker also used a non-malware file to execute commands and evade threat detection.
- Attack Vector:
- Phishing (T1566) — AiTM phishing campaign defeats standard MFA (SMS/OTP). Tycoon 2FA platform suspected.
- Compromised credentials (T1078) — Intune admin credentials stolen and used as a valid account.
- Denial-of-service (T1499 — Endpoint DoS): Mass endpoint wipe equates to operational shutdown.
- Valid accounts + Living-off-the-land: No malware deployed — abuse of native Intune functionality evades detection.
- Exposed data: Employee PII, medical records (including from a separate 2024 breach now under class-action review). For the March 2026 attack itself, 50TB exfiltration claim remains unverified.
- Volume: 200,000+ devices wiped / 79 countries, employee PII (specific count being established through class actions)
26. Coinbase — Insider Breach (Feb 3 Disclosure)
- Affected entity: Coinbase (global cryptocurrency exchange)
- Why this matters: Insider breach — a fundamentally different governance problem from external attacks. Internal support tool screenshots were leaked online. Specific impact headcount undisclosed but reputationally significant for a major exchange.
- Threat actor: Malicious insider
- Attack methodology: Disclosed February 3, 2026. Internal support tool screenshots leaked online and later removed.
- Attack Vector:
- Malicious insider: Authorized internal user intentionally exposed data (potentially T1078 — Valid Accounts, T1530 — Data from Cloud Storage).
- Exposed data: Internal support tool screenshots (specific underlying data not disclosed)
- Volume: Not disclosed > ※ Whether the affected count exceeds 1 million is not confirmed, but included for symbolic relevance as a major-exchange incident.
27. Illinois & Minnesota Department of Human Services — ~1 Million Combined (January Disclosure)
- Affected entities: Illinois DHS (700K+) and Minnesota DHS (303K) — US state human services agencies
- Why this matters: In the Illinois incident, sensitive information sat publicly accessible on the open internet for FOUR YEARS — an internal-use website for resource allocation and decision-making was inadvertently made publicly accessible. The Minnesota breach resulted from excessive internal access leading to improper disclosure. Both incidents required no external attacker — pure system error and insider-error categories — yet produced mega-scale exposure. Strong signal that misconfiguration is now first-class breach risk.
- Threat actor: None (internal error / system failure)
- Attack methodology: Illinois — internal-use website unintentionally exposed to public internet for 4 years. Minnesota — excessive internal access permissions resulted in improper information disclosure.
- Attack Vector:
- System error (IT failure / misconfiguration): Illinois — public-exposure misconfiguration. (T1562 indirect.)
- Insider error: Minnesota — overprivileged internal access leading to improper exposure.
- Exposed data: Illinois — names, addresses, case numbers, case status, referral information. Minnesota — names, addresses, emails, dates of birth, phone numbers, Medicaid IDs, first 4 digits of SSNs, other PHI.
- Volume: ~1 million combined
References
- PKWARE — 2026 Data Breaches
- SharkStriker — January 2026
- SharkStriker — February 2026
- Strobes Security — February 2026
- Strobes Security — March 2026
- Security Boulevard — January 2026
- Security Boulevard — Navia 2.7M
- Security Magazine — January 2026
- Security Magazine — February 2026
- HIPAA Journal — January 2026 Healthcare Report
- HIPAA Journal — February 2026 Healthcare Report
- HIPAA Journal — Navia
- HIPAA Journal — TriZetto
- HIPAA Journal — QualDerm
- HIPAA Journal — Stryker
- Cyber Management Alliance — January 2026
- Cyber Management Alliance — March 2026
- PrivacyGuides — Data Breach Roundup
- BleepingComputer — Match Group
- BleepingComputer — TriZetto
- BleepingComputer — Allianz Life
- The Register — ShinyHunters Match Group
- The Register — Brightspeed
- Cybernews — Hinge/OkCupid leak
- Cybernews — IDMerit
- Cybernews — QualDerm
- Cybernews — Mercer / Beacon Pointe
- Cybernews — ShinyHunters RIA
- Malwarebytes — Conduent
- Malwarebytes — Brightspeed
- TechRepublic — Conduent
- SC Media — Conduent 25M
- Fox Business — Conduent 25M
- IDStrong — Conduent
- ClassAction.org — Infutor
- ClassAction.org — Mercer Advisors
- CPO Magazine — Navia
- InvestmentNews — Hightower (industry-wide RIA attacks)
- InvestmentNews — Mercer Advisors
- WealthManagement — Mercer
- Financial Planning — Mercer
- CyberPress — Betterment
- CyberSecurityNews — TriZetto
- SecurityWeek — QualDerm
- SecurityWeek — Allianz Life
- NYC Health — Notice of Data Breach
- Beckers Hospital Review — NYC Health
- Tech.co — 2026 Data Breaches
- BrightDefense — Recent Data Breaches
- BrightDefense — IDMerit
- BrightDefense — Crunchbase
- Zyphe — IDMerit
- Lumos Blog — Stryker Hack
- Guardz — Stryker
- The National CIO Review — Brightspeed
- Anonhaven — AppsFlyer SDK
- UpGuard — Match Group
- SWK Technologies — February 2026 Recap
- KYCFrance (counter-narrative) — Cybernews-Fueled Cyber Anxiety: Fake IDMerit Breach Story