Major Data Breaches – May 2026
This report compiles the major data breach incidents publicly disclosed between May 1 and May 31, 2026. Incidents are de-duplicated and selected based on disclosure date (not the date of the underlying intrusion). The primary inclusion threshold is one million affected individuals or records. Additional notable disclosures with smaller user-record counts but strategic significance (e.g., source code theft, sovereign IT infrastructure, software supply-chain campaigns) are covered in the Incident Details section as secondary entries.
The Attack Vector taxonomy used in this report is based on the categorization framework adopted by the IBM Cost of a Data Breach Report. Each Attack Vector is mapped to the corresponding MITRE ATT&CK techniques to provide threat-informed context for defenders.
Executive Summary
Top Incidents by Exposure Scale
Only incidents at or above the one-million-record threshold are summarized in the ranking table. Other notable disclosures with smaller user-record counts or undisclosed scale are covered in the Incident Details section below.
| Rank | Incident | Scale | Sector | Disclosed |
|---|---|---|---|---|
| 1 | Instructure (Canvas LMS) | 275M users / 3.65 TB / 8,809 institutions (ShinyHunters claim; Instructure has not officially confirmed the figures) | Education | May 1 (initial); May 7 (re-breach); May 11–12 (ransom paid) |
| 2 | Carnival Corporation (ShinyHunters) | 5,995,277 individuals confirmed (~6M); 8.7M total records leaked | Travel / Cruise | May 27, 2026 |
| 3 | Charter Communications / Spectrum (ShinyHunters) | 4.9M unique accounts confirmed by HIBP; 13M+ per Cybernews analysis; 42M claimed by attacker | Telecommunications | May 27–29, 2026 |
| 4 | Alberta voter list (Centurion Project) | 2.9M Albertans | Government / Electoral | May 1–13, 2026 (continuing disclosure) |
| 5 | NYC Health + Hospitals | 1.8M individuals | Healthcare / Government | May 19, 2026 |
| 6 | Tabiq (Reqrea) hotel check-in platform | 1M+ passports, driver’s licenses, and selfie verification photos | Hospitality Technology | May 15, 2026 |
Note on the Alberta voter list incident: The Court of King’s Bench injunction was issued on April 30, 2026 and the initial Privacy Commissioner statement quoting the 2.9M figure was made that same day. We classify this as a May incident in this report because the substantive scope, chain-of-custody investigation, and major operational disclosures (cease-and-desist letters to 568 individuals, identification of full-list recipients, third investigation launch, US 10XVotes link, and UCP caucus staff involvement) all unfolded between May 1 and May 13. Readers tracking this case strictly by first-disclosure date should treat April 30 as the boundary.

Most Frequently Exposed Data Types
The month was dominated by Personally Identifiable Information (PII) — names, email addresses, phone numbers, dates of birth, postal addresses, and customer/voter identifiers — followed by government identity documents (passport numbers, driver’s license numbers, Social Security numbers) and protected health information (medical records, diagnoses, insurance data). Carnival exposed passport numbers and driver’s license numbers for nearly 6 million individuals; Tabiq exposed more than 1 million scanned passports, driver’s licenses, and facial verification selfies; the Alberta voter list exposed the full home address, phone number, and elector ID of nearly 3 million Canadian voters — a particularly sensitive disclosure given that domestic violence survivors, law enforcement officers, and other at-risk individuals were among the affected.
The NYC Health + Hospitals disclosure introduced a particularly consequential category: biometric data (fingerprint and palm-print scans) and precise geolocation data extracted from photographed identity documents, neither of which can be rotated like a password.
Developer credentials and code-signing material emerged as the second major target category through the TeamPCP campaigns. OpenAI lost code-signing certificates for ChatGPT Desktop, Codex, and Atlas across macOS, Windows, iOS, and Android, forcing certificate rotation and a June 12 deadline for macOS users to update. GitHub lost approximately 3,800 internal repositories.
Top Attack Vectors
- Phishing and social engineering — the dominant vector this month. Charter Communications was breached via a voice phishing (vishing) attack against an employee that compromised a Microsoft Entra account, which the attackers then pivoted into Salesforce; Carnival’s intrusion began with social engineering of an employee account; the GitHub VS Code extension intrusion tricked a developer into installing a poisoned marketplace extension.
- Third-party vendor and supply chain compromise — observed in NYC Health + Hospitals (unnamed vendor), Mini Shai-Hulud (TanStack / npm), Vimeo and Zara (Anodot analytics platform), and the broader cascading impact of Canvas across 8,809 institutions.
- Vulnerability exploitation — central to the Instructure intrusion (Free-For-Teacher product-tier vulnerability), the suspected Salt Typhoon edge-device exploitation, and Finland Valtori (Ivanti EPMM zero-day).
- Compromised credentials — central to Lithuania Centre of Registers (abuse of authorized Migration Department logins), Mini Shai-Hulud (OIDC tokens extracted from CI/CD memory), and the post-vishing access in both Charter and Carnival.
- System error / IT failure / misconfiguration — defining vector for Tabiq (publicly readable Amazon S3 bucket exposed more than 1 million identity documents).
- Insider misuse and onward sharing — defining vector for the Alberta voter list incident, where a List of Electors legitimately issued to a political party was passed to a third-party separatist group and made publicly searchable.
Notable Attack Patterns
The month is defined by the Instructure / Canvas compromise — by exposure scale, sectoral disruption, and operational pattern, it is the dominant incident of the period and arguably the largest single education-sector breach in history. ShinyHunters’ “pay or leak” campaign reached its operational climax with the Instructure ransom payment on May 11–12, with shred logs returned as ransom-payment proof. The Instructure case is the second ShinyHunters compromise of the same vendor within eight months, indicating that ShinyHunters now treats certain victims as repeat-target portfolios.
The month also reveals the maturation of the broader ShinyHunters Salesforce / Microsoft Entra vishing campaign. Two of the largest individual disclosures of the month — Carnival (~6M individuals, May 27) and Charter Communications / Spectrum (4.9M HIBP-confirmed, May 27–29) — share the same operational pattern: vishing or social engineering against a single employee, pivot to a Microsoft Entra or Okta SSO account, then bulk exfiltration from Salesforce CRM. In 2026 alone, ShinyHunters has now confirmed breaches at Panera, Aura, ADT, Instructure, Vimeo, Zara, Carnival, and Charter using variations of this same playbook. The May 27 cluster suggests synchronized operational tempo.
The TeamPCP-attributed Mini Shai-Hulud and GitHub VS Code campaigns (May 11–20) demonstrated a new class of developer-targeted supply-chain attack: poisoned marketplace extensions and GitHub Actions cache poisoning extract OIDC tokens and credentials directly from CI/CD memory, then propagate through cryptographically valid provenance signatures — bypassing two-factor authentication and traditional package signing safeguards entirely.
Two further patterns appeared this month that defenders should not overlook. The Alberta voter list disclosure illustrates that a “breach” need not involve any external attacker at all: legitimately issued voter data was passed onward to an unauthorized third party and published in a publicly searchable form. Insider misuse and onward sharing of authorized data is now producing breaches at the scale of nation-state attacks. Separately, the Tabiq incident shows that one of the simplest and longest-recognized cloud misconfigurations (an Amazon S3 bucket left set to public) can still produce a million-record disclosure of identity documents and biometric selfies. The Lithuania Centre of Registers breach and the suspected Salt Typhoon attribution against an IBM Italy subsidiary reinforce that nation-state actors continue to exploit IT service providers and authorized third-party credentials as strategic supply-chain footholds in Europe.

Incident Details
1. Instructure (Canvas LMS) — ShinyHunters
Victim: Instructure Inc., the parent company of the Canvas Learning Management System used by approximately 41 percent of higher education institutions in North America and a large share of K-12 districts globally.
Impact / Why It Matters: The breach affected approximately 8,809 schools, universities, and online learning platforms — including all eight Ivy League universities, the University of California system, California State University, USC, Stanford, Princeton, Duke, Columbia, the University of Pennsylvania (306,000 affiliates), North Carolina K-12 districts, NUS in Singapore, multiple Australian universities, and Dutch universities. The breach occurred during finals season in many districts, disabling student access to assignments, grades, and coursework. It is the second confirmed Instructure compromise within eight months. On May 7, ShinyHunters defaced login pages at approximately 330 institutions and pivoted to direct school-by-school extortion. On May 11–12, Instructure paid an undisclosed ransom; ShinyHunters returned shred logs claiming data destruction and removed Instructure from its leak site. Security experts note that ransom payment provides no verifiable guarantee that copies were not retained.
Threat Actor: ShinyHunters extortion group.
Attack Method (Overview): On approximately April 25, 2026, ShinyHunters exploited a vulnerability in the Canvas Free-For-Teacher account program — a product-tier weakness rather than a peripheral business system compromise. Instructure detected the intrusion on April 29, revoked privileged credentials and rotated API keys, and publicly disclosed on May 1. After Instructure attempted “security patches” without engaging the attackers, ShinyHunters re-breached the platform on May 7. Instructure paid the ransom on May 11 and engaged the FBI, CISA, and overseas law enforcement.
Attack Vector(s): – Vulnerability exploitation (T1190 Exploit Public-Facing Application): The initial intrusion exploited a vulnerability in the Free-For-Teacher account program. – Compromised credentials (T1078 Valid Accounts): Stolen API keys and privileged credentials enabled persistent access; Instructure was forced to revoke and rotate them as part of incident response. – Third-party vendor and supply chain compromise (T1199 Trusted Relationship): The impact propagated to ~8,809 downstream education institutions because Canvas operates as a shared SaaS platform.
Data Exposed: Names, email addresses, student ID numbers, and a large volume of private messages between students and teachers (3.65 TB total). Instructure confirmed exposure of these categories and stated no evidence of compromise to passwords, dates of birth, government identifiers, or financial information.
Volume: 275 million users across approximately 8,809 institutions; 3.65 TB of data (ShinyHunters claim; Instructure has not officially confirmed the figures).
2. Carnival Corporation — ShinyHunters
Victim: Carnival Corporation, the world’s largest cruise line operator, parent of Carnival Cruise Line, Princess Cruises, Cunard, Seabourn, Costa Cruises, and Holland America Line. Analysis of leaked data indicates the records primarily originated from Holland America Line.
Impact / Why It Matters: On May 27, 2026, Carnival began sending notification letters to 5,995,277 individuals (~6M) and filed with the Maine Attorney General’s office. This is the long-tail confirmed-scale disclosure of an April 14 intrusion that ShinyHunters initially claimed in mid-April with an 8.7M record figure. The six-week gap between intrusion detection and formal notification reflects forensic scope determination. Carnival has a history of cybersecurity issues, including four separate cybersecurity events reported to New York Department of Financial Services between 2019 and 2021, two of which were ransomware attacks.
Threat Actor: ShinyHunters extortion group.
Attack Method (Overview): On April 14, 2026, ShinyHunters used social engineering against a Carnival employee to compromise an employee account, then used that valid account to access a limited portion of Carnival’s IT environment and exfiltrate files containing personal information. After Carnival refused to pay ransom, ShinyHunters leaked the 8.7M-record archive; the forensic analysis distinguishing 5,995,277 individuals affected was completed in late May.
Attack Vector(s): – Phishing — Social engineering variant (T1566 Phishing): The initial intrusion was a social engineering attack against a Carnival employee. – Compromised credentials (T1078 Valid Accounts): After the social engineering succeeded, the attackers authenticated as the legitimate employee to access Carnival’s internal systems.
Data Exposed: Names, addresses, email addresses, phone numbers, dates of birth, driver’s license numbers, passport numbers, gender details, geographic data, salutations, and cruise loyalty program status information. Payment card data does not appear to have been compromised.
Volume: 5,995,277 individuals confirmed (Maine AG filing); 8.7M total records leaked.
3. Charter Communications / Spectrum — ShinyHunters
Victim: Charter Communications, one of the largest broadband and cable providers in the United States, operating under the Spectrum brand and serving tens of millions of residential and business customers. Independent analysis of the leaked dataset indicates that most of the affected customer data originated from Spectrum Enterprise, the division providing telecommunications services to large businesses, corporations, government agencies, and other large clients.
Impact / Why It Matters: This is a parallel ShinyHunters extortion event to Carnival, surfacing publicly during the same final week of May. The breach exposes a structural weakness affecting the entire ShinyHunters target portfolio: a single successful voice phishing (vishing) call against an employee, followed by Microsoft Entra SSO compromise, can grant adversaries broad access to the entire Salesforce CRM environment behind it. The Spectrum dataset’s enterprise weighting is operationally important: many of the affected individuals are employees of companies that purchase Spectrum business services, expanding the attack surface for follow-on B2B phishing and business email compromise campaigns targeting those organizations. ShinyHunters claimed 42 million records and set a May 27 ransom deadline; after Charter refused to pay, ShinyHunters published the data on its dark web leak site. Charter publicly denied that sensitive personal information (PI) or customer proprietary network information (CPNI) was exfiltrated.
Threat Actor: ShinyHunters extortion group.
Attack Method (Overview): On approximately April 1, 2026, ShinyHunters used a voice phishing (vishing) attack to compromise the Microsoft Entra (Azure Active Directory) account of a Charter employee. The attackers then pivoted into Charter’s Salesforce CRM environment and exfiltrated a large volume of customer and employee data. Charter was listed on the ShinyHunters dark web leak site in mid-May with a May 27 ransom deadline. After Charter refused to pay, the group published the dataset on May 27–29, 2026.
Attack Vector(s): – Phishing — Vishing variant (T1566 Phishing): The defining vector. The operationally critical step was a voice phishing call to an employee, who was tricked into providing the credentials necessary to access their Microsoft Entra account. – Compromised credentials (T1078 Valid Accounts; T1528 Steal Application Access Token): After the vishing call succeeded, attackers authenticated as the legitimate employee to Microsoft Entra and Salesforce. – Third-party vendor and supply chain compromise (T1199 Trusted Relationship): The pivot from Entra into Salesforce was made possible by the trust relationship between Charter’s identity provider and its CRM SaaS application — a structural pattern recurring across the ShinyHunters campaign.
Data Exposed: Full names, email addresses (work and personal), home and company addresses, phone numbers, account plan details, customer support ticket subjects and timestamps, and limited Customer Proprietary Network Information per ShinyHunters’ claim (Charter denies CPNI exfiltration). Approximately 27,000 employee records were also leaked, including full names, work emails, and job titles. No passwords or payment information were observed in the leaked dataset.
Volume: 4.9M unique accounts confirmed by Have I Been Pwned analysis; 13M+ individuals per Cybernews research team analysis; 42M total records claimed by ShinyHunters; approximately 27,000 employee records.
4. Alberta Voter List (Centurion Project)
Victim: Almost 3 million Albertan voters (approximately 2.9 million records) whose personal information from the Alberta provincial List of Electors was made publicly searchable on a database operated by the Centurion Project, a pro-sovereignty (separatist) political organization led by political activist David Parker.
Impact / Why It Matters: Lorne Gibson, former Election Commissioner at Elections Alberta, has described this as “the largest data breach in Canada — I haven’t heard of anything that surpasses that scale.” Alberta NDP Leader Naheed Nenshi has characterized it as “probably the largest data breach in Canadian history.” The case is operationally unusual because it did not involve any external intrusion: the List of Electors was legitimately issued by Elections Alberta to the Republican Party of Alberta (a registered provincial political party), then onward-shared to vendors (including a US-based political technology firm named 10XVotes), and ultimately incorporated into the Centurion Project’s publicly searchable database. Elections Alberta confirmed the database’s source by verifying “salted” fictitious entries embedded in each issued copy. Affected populations include domestic violence survivors, law enforcement officers, and others for whom even name-plus-home-address disclosure carries significant safety risk. The Centurion Project’s app architecture — designed to identify low-engagement voters and pressure them to turn out — drew further concern because it was built by US Republican operatives and replicates technology previously deployed in the 2024 US presidential election; cross-border data transfer to a US firm raises additional concerns about US government access under the CLOUD Act.
Threat Actor: Not an external threat actor in the conventional sense. Elections Alberta and the RCMP are investigating onward-sharing and unauthorized publication by the Republican Party of Alberta, the Centurion Project Ltd., and intermediary vendors.
Attack Method (Overview): Elections Alberta issued an electors list to the Republican Party of Alberta in June 2025. The list was passed to vendors (reportedly including US-based 10XVotes) and ultimately incorporated into a publicly searchable database hosted on the Centurion Project’s website. Independent journalist Jen Gerson notified Elections Alberta on March 31, 2026 that anyone with rudimentary web skills could download the entire database. Elections Alberta issued a cease-and-desist letter on April 28; the Court of King’s Bench granted an emergency injunction on April 30, 2026; the database was taken offline. Throughout May, follow-on disclosures continued: cease-and-desist letters to 568 individuals (May 7), Privacy Commissioner third investigation launch, US 10XVotes website found to host similar Albertan data (May 20), and UCP caucus staffer participation in a Centurion Project meeting two weeks before the breach surfaced.
Attack Vector(s): – Insider misuse / onward sharing of authorized data (Malicious insider, T1078 Valid Accounts; T1567 Exfiltration Over Web Services): The defining vector. A political party authorized to receive the List of Electors passed it onward to vendors and, ultimately, to a third-party organization that published it on the open web. No external compromise was involved. – Third-party vendor and supply chain compromise (T1199 Trusted Relationship): The onward chain from political party to vendor to Centurion Project to publicly hosted database is itself a trust-relationship pattern: each handoff was based on a legitimate-looking request from a party that had been granted access by the previous holder.
Data Exposed: Full names, home addresses, phone numbers, unique elector identifiers, electoral divisions, and polling station designations for approximately 2.9 million Albertans.
Volume: 2.9 million records.
5. NYC Health + Hospitals
Victim: NYC Health + Hospitals (NYCHHC), the largest public healthcare system in the United States, providing care to over one million New Yorkers, most of whom are uninsured or receive state benefits such as Medicaid.
Impact / Why It Matters: The May 19, 2026 disclosure publicly confirmed the 1.8M individual scale and the full category list of compromised data, making this one of the largest healthcare breaches of 2026 by both scale and sensitivity. The data category list is unusually severe: in addition to standard PII and PHI, it includes biometric fingerprint and palm-print scans (which cannot be rotated like a password), precise geolocation data extracted from photographs of uploaded identity documents, taxpayer identification numbers, IRS-issued identity protection numbers, and online account credentials. The breach was traced to an unnamed third-party vendor. NYCHHC reported the incident to HHS on March 24, but the publicly accessible 1.8M scale disclosure and complete data category list was published on the website on May 19.
Threat Actor: Undisclosed; unauthorized actor accessed systems via a vendor breach.
Attack Method (Overview): In November 2025, an unauthorized actor exploited a vulnerability at an unnamed third-party vendor that had access to NYCHHC’s network. The intrusion remained undetected from approximately November 25, 2025 through February 2026, with attackers exfiltrating files during the window. NYCHHC detected suspicious network activity on February 2, 2026, secured the network, and engaged third-party forensic specialists. The investigation determined the scope and was disclosed to the public on May 19, 2026.
Attack Vector(s): – Third-party vendor and supply chain compromise (T1195 Supply Chain Compromise; T1199 Trusted Relationship): The defining vector — the intrusion originated at an unnamed third-party vendor with authorized network access. NYCHHC itself was not directly attacked. – Compromised credentials (T1078 Valid Accounts): Once inside via the vendor relationship, attackers leveraged authorized access to copy files for approximately three months.
Data Exposed: Health insurance plan and policy information, Medicaid/Medicare/government payor ID numbers, medical record numbers, disability codes, diagnoses, medications, test results, medical imagery, treatment plans, billing/claims/payment information, Social Security numbers, driver’s license numbers, passport numbers, taxpayer identification numbers, IRS-issued identity protection numbers, precise geolocation data, credit/debit card numbers, financial account information or credentials, online account credentials, and biometric data including fingerprints and palm prints.
Volume: 1.8 million individuals.
6. Tabiq (Reqrea) Hotel Check-in Platform — Public Amazon S3 Bucket Exposure
Victim: Tabiq, a hotel check-in system maintained by Japan-based startup Reqrea. Tabiq is used in multiple hotels across Japan and relies on facial recognition and document scanning to check arriving guests in. The exposure affected hotel guests from many countries worldwide, with files dating from early 2020 through May 2026.
Impact / Why It Matters: More than one million scanned passports, driver’s licenses, and selfie verification photos were left publicly readable on the open internet — accessible to anyone who knew the storage bucket name “tabiq,” with no authentication required. The data category is particularly damaging because unlike credit card numbers, passport numbers and driver’s license numbers cannot be easily reissued, and facial verification selfies cannot be rotated. The exposed dataset is sufficient to enable both physical-document identity fraud and synthetic-identity creation, and crosses mandatory data breach notification thresholds in multiple jurisdictions (Japan, EU, UK, US states). This is one of the largest cloud-misconfiguration disclosures of 2026.
Threat Actor: Not applicable — no external intrusion occurred. Independent security researcher Anurag Sen discovered the public bucket and notified TechCrunch, which alerted Reqrea and Japan’s cybersecurity coordination team JPCERT. Reqrea locked down the bucket after the notification.
Attack Method (Overview): An Amazon S3 bucket used by the Tabiq check-in system was configured to be publicly accessible, allowing anyone with a web browser and knowledge of the bucket name to view all stored customer documents without a password. Reqrea has stated it does not know how the bucket was set to public — Amazon S3 buckets default to private and now include explicit warnings against public configuration. Reqrea is still reviewing logs to determine whether any unauthorized parties accessed the data prior to the researcher’s discovery.
Attack Vector(s): – System error / IT failure / misconfiguration (T1562 Impair Defenses; Misconfiguration exploitation): The defining vector. An Amazon S3 bucket containing highly sensitive identity documents was configured to allow unauthenticated public read access. No external compromise or credential theft was involved — the security boundary itself was incorrectly defined.
Data Exposed: Full names, addresses, dates of birth, passport numbers and scanned passport images, driver’s license numbers and scanned driver’s license images, and facial verification selfies of more than 1 million hotel guests worldwide.
Volume: More than 1 million identity documents and verification images.
7. Mini Shai-Hulud Supply-Chain Campaign — TeamPCP (OpenAI, Mistral AI, UiPath, OpenSearch, TanStack)
Victim: Hundreds of open-source projects in the npm and PyPI ecosystems, with named confirmed-impact organizations including OpenAI (two employee devices compromised; limited credential exfiltration from internal source-code repositories), Mistral AI, UiPath, OpenSearch, Guardrails AI, and TanStack itself. TanStack’s React Router alone is downloaded approximately 12 million times per week.
Impact / Why It Matters: This is one of the most consequential software supply-chain compromises of 2026 to date. The campaign bypassed two-factor authentication and carried cryptographically valid provenance signatures — exposing a major blind spot in current software security defenses. OpenAI lost code-signing certificates for macOS, Windows, iOS, and Android applications, with macOS users required to update by June 12, 2026 or face application failure. Microsoft Threat Intelligence reported a Linux information-stealing tool with a destructive sabotage component that would randomly execute a recursive wipe on Israeli or Iranian systems.
Threat Actor: TeamPCP, a cloud-focused cybercriminal group that emerged in late 2025 and is also credited with the original Shai-Hulud, SAP, Checkmarx, Bitwarden, Lightning, Intercom, Trivy, and (via the same broader campaign) the GitHub VS Code extension compromises.
Attack Method (Overview): On May 11, 2026, TeamPCP launched a coordinated chain attack against the TanStack/router repository: a fork (renamed to evade fork-list searches) opened a pull request triggering a pull_request_target workflow, executed attacker code that poisoned the GitHub Actions cache with a malicious pnpm store, then waited for legitimate maintainer PRs to merge — at which point the release workflow restored the poisoned cache and extracted OIDC tokens directly from /proc/<pid>/mem. The OIDC tokens were used to publish malicious package versions.
Attack Vector(s): – Third-party vendor and supply chain compromise (T1195.002 Compromise Software Supply Chain): The defining vector — attackers compromised trusted open-source packages used by tens of thousands of downstream organizations. – Vulnerability exploitation (T1190 Exploit Public-Facing Application): The attack chained three vulnerabilities in GitHub Actions configurations (pull_request_target misuse, cache poisoning, OIDC token extraction from process memory). CISA added the related CVEs to its Known Exploited Vulnerabilities catalog on May 27, 2026. – Compromised credentials (T1528 Steal Application Access Token; T1552.001 Credentials in Files): The malware harvested GitHub tokens, npm publish tokens, AWS credentials, Kubernetes secrets, SSH keys, and .env files.
Data Exposed: At OpenAI specifically — limited credential material from a small set of internal source-code repositories accessible to two employees, plus code-signing certificates for ChatGPT Desktop, Codex App, Codex CLI, and Atlas across macOS/Windows/iOS/Android. OpenAI stated no customer data, production systems, or intellectual property were compromised. Across the ecosystem broadly — GitHub PATs, npm publish tokens, AWS credentials, Kubernetes service accounts, SSH keys, CI/CD secrets, and Vault tokens were targeted.
Volume: Hundreds of compromised packages across npm and PyPI; ecosystem-wide impact still being measured. OpenAI characterized exposure as limited credential material only.
8. GitHub (Internal Repositories via Nx Console VS Code Extension)
Victim: GitHub, the Microsoft-owned source-code hosting platform.
Impact / Why It Matters: On May 19–20, 2026, GitHub detected and contained the compromise of an employee device that had installed a poisoned version of the Nx Console VS Code extension (a verified-publisher extension with 2.2 million installs). The trojanized version was live on the Visual Studio Marketplace for only 18 minutes (12:30 PM to 12:48 PM UTC on May 18, 2026), but that window was sufficient for attackers to distribute a credential stealer that harvested 1Password vault data, Claude Code configurations, npm tokens, GitHub tokens, and AWS credentials from anyone with auto-update enabled. TeamPCP listed roughly 3,800 GitHub-internal repositories and source code for sale on the Breached cybercrime forum, demanding at least $50,000. GitHub states it found no evidence of impact to customer repositories or enterprise environments. This and the Mini Shai-Hulud TanStack incident are tracked together as CVE-related supply-chain attacks; CISA added them to KEV on May 27 with a June 10 federal remediation deadline.
Threat Actor: TeamPCP.
Attack Method (Overview): An attacker compromised the Nx Console VS Code extension’s release pipeline and published a malicious update on May 18 at 12:30 PM UTC. The extension behaved like the legitimate Nx Console but silently ran a shell command at startup that downloaded and executed a hidden package from a planted commit on the nrwl/nx GitHub repository. A GitHub employee’s device picked up the update via auto-update during the 18-minute window. GitHub detected the compromise on May 19 and isolated the endpoint. GitHub rotated critical secrets and credentials overnight.
Attack Vector(s): – Third-party vendor and supply chain compromise (T1195.002 Compromise Software Supply Chain): The defining vector — a poisoned update to a trusted, verified-publisher VS Code marketplace extension propagated automatically to any user with auto-update enabled. – Compromised credentials (T1552 Unsecured Credentials; T1528 Steal Application Access Token): The malicious extension’s payload was a credential stealer targeting 1Password, Claude Code, npm, GitHub, and AWS credentials.
Data Exposed: Approximately 3,800 GitHub-internal source-code repositories. GitHub has stated that no customer data was exfiltrated.
Volume: 3,800 internal repositories (TeamPCP claims ~4,000).
9. UK Biobank (Genomic Data — Re-disclosure with Strategic Reframing)
Victim: UK Biobank, the major UK genomic research platform holding genetic and health data on approximately 500,000 British volunteers.
Impact / Why It Matters: Nature published research on May 13, 2026 documenting that the UK Biobank breach has prompted the entire field of genomics to rethink open science. The breach has structural implications: genomic data is uniquely irreplaceable, and exposure extends to genetic relatives who never consented to inclusion. The Guardian reported that private health records of half a million Britons appeared for sale on a Chinese-language website. The incident is reshaping international debate on open-science models in genomics.
Threat Actor: Undisclosed; data was offered for sale on a Chinese-language website.
Attack Method (Overview): Public details of the intrusion technique have not been disclosed. UK Biobank suspended platform access as a forensic measure while conducting a board-led investigation.
Attack Vector(s): – Others (intrusion vector undisclosed): The specific entry vector has not been publicly disclosed.
Data Exposed: Genetic data and health records on approximately 500,000 individuals.
Volume: 500,000 records.
10. Lithuania Centre of Registers (Foreign Intelligence Operation)
Victim: Centre of Registers (Registrų centras), the Lithuanian state agency responsible for the country’s real estate and legal-entity registries. Personal data exposed includes records of intelligence officers, political emigrants from Russia and Belarus, the President of Lithuania, and ordinary citizens.
Impact / Why It Matters: Lithuanian President Gitanas Nausėda declared on May 27 that “hostile states” orchestrated the breach, characterizing it as a state-sponsored intelligence operation. The case is acutely concerning given Lithuania’s role as host to numerous Russian and Belarusian political emigrants, and the country’s ongoing tensions with Russia. In April 2026, Lithuanian and international authorities charged 13 defendants in a GRU-linked network that had planned assassinations of two individuals in Vilnius. Knowing where targets live is a first operational step in physical attack. The President’s own data was among those accessed. Adrijus Jusas, the head of the Centre of Registers, resigned on May 25. The Lithuanian State Security Department confirmed intelligence officers among the victims.
Threat Actor: Suspected foreign state actor (publicly characterized by Lithuania’s President as “hostile states”; Russia is the most heavily suspected actor based on context, but Lithuanian authorities have not publicly named a state).
Attack Method (Overview): Attackers obtained valid login credentials belonging to user accounts at Lithuania’s Migration Department — an institution authorized to query the registers — and used those credentials to issue queries from a foreign country at scale over a period of months. The Centre of Registers itself was not directly breached; the strength of the system was set by the weakest authorized credential held outside it.
Attack Vector(s): – Compromised credentials (T1078 Valid Accounts): The defining vector — valid Migration Department login credentials were used to authenticate as legitimate authorized users. – Third-party vendor and supply chain compromise (T1199 Trusted Relationship): The Migration Department’s authorized access to the registry was the trust boundary that was exploited.
Data Exposed: Names, surnames, identification numbers, dates of birth, and property information for 600,000+ records. Phone numbers, email addresses, bank account details, service payment information, real estate transaction documents, court rulings, and building plans were stated to be not among the compromised data.
Volume: 600,000+ records.
11. Zara (Anodot Supply-Chain)
Victim: Zara (Inditex Group), the Spanish fast-fashion retailer.
Impact / Why It Matters: Latest confirmed downstream victim of the Anodot analytics platform compromise — joining Vimeo, Rockstar Games, Mytheresa, Carnival (separately compromised), 7-Eleven, McGraw Hill, and dozens of other organizations. Have I Been Pwned loaded the Zara dataset on May 8, 2026. While credentials and payment data were not exposed, the customer-support-ticket content provides material for targeted phishing referencing real order and purchase history.
Threat Actor: ShinyHunters.
Attack Method (Overview): ShinyHunters compromised Anodot and used stolen Anodot authentication tokens to authenticate to Zara’s BigQuery instance. After Inditex refused to engage, ShinyHunters leaked a 140 GB archive.
Attack Vector(s): – Third-party vendor and supply chain compromise (T1195 Supply Chain Compromise; T1199 Trusted Relationship): Zara’s data was accessed via the Anodot trust relationship. – Compromised credentials (T1078 Valid Accounts; T1528 Steal Application Access Token): Anodot OAuth/authentication tokens were used to authenticate as a legitimate analytics integration.
Data Exposed: 197,400 unique email addresses, product SKUs, order IDs, geographic locations, customer support ticket content.
Volume: 197,400 customers; 140 GB archive leaked.
12. Asian Football Confederation (AFC) + Al Nassr FC
Victim: The Asian Football Confederation (the-afc.com), the governing body for football across Asia, and Al Nassr FC, the Saudi Premier League club home to Cristiano Ronaldo, Sadio Mané, and Marcelo Brozović.
Impact / Why It Matters: The breach exposed sensitive identity documents and contracts for over 150,000 players, coaches, and officials — including diplomatic passport scans tied to football officials. The 2026 FIFA World Cup begins June 11, 2026 across Canada, Mexico, and the US. The exposure creates risks of contract manipulation, financial fraud, targeted phishing of high-profile athletes, and physical security threats.
Threat Actor: An actor operating under the handle “fuckiewuckie” on the PwnForums marketplace, who credited ShinyHunters with facilitating the leak. Dataminr researchers suggest the credit may be a credibility-building tactic.
Attack Method (Overview): The actor advertised and posted the database to the PwnForums dark web marketplace on or around April 27, 2026. The exact intrusion vector against AFC’s systems has not been disclosed publicly.
Attack Vector(s): – Others (intrusion vector undisclosed): The technical method of compromise of AFC infrastructure has not been disclosed.
Data Exposed: Passport scans (including diplomatic passports), professional contracts, email addresses, AFC Champions League Elite preliminary player registration forms, full names, dates of birth, nationalities, player positions, match details, and registration files.
Volume: 150,000+ players, coaches, and officials.
13. Vimeo (Anodot Supply-Chain)
Victim: Vimeo, the video-hosting platform.
Impact / Why It Matters: Although Vimeo’s own infrastructure was not directly breached, attackers compromised its third-party analytics integration (Anodot) and pivoted into Vimeo’s cloud data warehouses on Snowflake and BigQuery. After ransom negotiations failed, ShinyHunters publicly leaked a 106 GB archive on its dark web site on May 5, 2026.
Threat Actor: ShinyHunters.
Attack Method (Overview): ShinyHunters stole Anodot authentication tokens and used those tokens to authenticate to Vimeo’s Snowflake and BigQuery cloud data warehouses. Anodot’s status page indicates the incident began on April 4, 2026.
Attack Vector(s): – Third-party vendor and supply chain compromise (T1195 Supply Chain Compromise; T1199 Trusted Relationship): The attackers leveraged the trust relationship between Vimeo and Anodot. – Compromised credentials (T1078 Valid Accounts; T1528 Steal Application Access Token): Stolen Anodot OAuth/authentication tokens were used to authenticate as a legitimate analytics integration.
Data Exposed: 119,200 unique customer email addresses, customer names, video metadata.
Volume: 119,200 affected accounts.
14. Sandhills Medical (South Carolina)
Victim: Sandhills Medical, a healthcare provider in South Carolina.
Impact / Why It Matters: Healthcare data breaches consistently produce the most expensive long-term consequences for affected individuals because medical records combine PII, insurance, and clinical data.
Threat Actor: Undisclosed (ransomware operator).
Attack Method (Overview): A ransomware attack in 2025 on Sandhills Medical led to data exfiltration; state officials disclosed the scope of impact in early May 2026.
Attack Vector(s): – Others (intrusion vector undisclosed): The specific entry vector was not disclosed.
Data Exposed: Personal information of patients.
Volume: 78,000 individuals.
15. Finland Valtori (Espionage Probe Expansion)
Victim: Valtori, Finland’s Government ICT Centre, which provides mobile device management services to approximately 50,000 government users including ministries, prosecutors, the Office of the President, the National Police Board, and Finnish Customs.
Impact / Why It Matters: On May 7–8, Yle reported that the breach reached the Office of the President (data linked to more than 50 people) and Finnish Customs. The case is being investigated by the Finnish National Bureau of Investigation as suspected espionage and aggravated unauthorized access. Compromised material is fragmentary in isolation, but when combined “could form information that affects Finland’s security.” Part of a coordinated wave of European government breaches exploiting Ivanti EPMM vulnerabilities (CVE-2026-1281, CVE-2026-1340).
Threat Actor: Unattributed; investigation ongoing as suspected espionage.
Attack Method (Overview): The attacker exploited a then-unpatched Ivanti EPMM vulnerability allowing unauthenticated remote code execution. A patch was applied the same day it was released, but data marked as “deleted” had not actually been erased.
Attack Vector(s): – Vulnerability exploitation (T1190 Exploit Public-Facing Application): Ivanti EPMM zero-day exploitation enabled unauthenticated remote code execution. – System error / IT failure / misconfiguration: The MDM system marked deleted records as removed without actually erasing them.
Data Exposed: Names, work email addresses, phone numbers, device identifiers, configuration details, country-level device location data of approximately 50,000 government users.
Volume: ~50,000 government users.
16. Trellix (Source Code Repository Breach)
Victim: Trellix, the cybersecurity vendor formed from the 2022 merger of McAfee Enterprise and FireEye. Trellix protects more than 50,000 business and government customers and over 200 million endpoints.
Impact / Why It Matters: Source code theft from a security vendor creates cascading downstream risk: attackers gain a technical blueprint of detection logic, signatures, and product architecture. On May 7, 2026, the RansomHouse group publicly claimed responsibility, posting screenshots indicating access to Trellix’s appliance management system. Third major security-vendor source code incident in 2026 alongside the Checkmarx GitHub leak and the Cisco internal development environment breach.
Threat Actor: RansomHouse.
Attack Method (Overview): An unauthorized party gained access to a portion of Trellix’s internal source code repository, including its appliance management system. Trellix discovered the intrusion, engaged forensic experts, and notified law enforcement.
Attack Vector(s): – Others (intrusion vector undisclosed): Trellix has not disclosed whether the breach resulted from a zero-day vulnerability, weak or stolen credentials, supply-chain compromise of a code-hosting platform, or an insider.
Data Exposed: An undisclosed portion of internal source code, including content related to the appliance management system.
Volume: Undisclosed; 50,000+ business and government customers indirectly exposed.
17. Salt Typhoon — IBM Sistemi Informativi (Italy)
Victim: Sistemi Informativi, an IBM Italy subsidiary providing IT infrastructure management to numerous Italian public agencies and private institutions.
Impact / Why It Matters: The breach is reportedly linked to Salt Typhoon, a sophisticated Chinese state-sponsored APT active since at least 2019. Prior Salt Typhoon victims include US House staff emails, the US National Guard, Viasat, Canadian telecom firms, and European telecoms. The intrusion temporarily took the subsidiary’s website offline. IBM confirmed the incident on May 3, 2026; some reporting questions the Salt Typhoon attribution.
Threat Actor: Salt Typhoon (China-linked APT, attribution under continued analysis).
Attack Method (Overview): Salt Typhoon’s hallmark TTP is the silent exploitation of edge device vulnerabilities (Citrix, Cisco) for initial access, followed by long-dwell-time data staging. The exact vector against Sistemi Informativi has not been publicly disclosed.
Attack Vector(s): – Vulnerability exploitation (T1190 Exploit Public-Facing Application): Salt Typhoon’s hallmark technique is exploitation of unpatched edge appliances. – Third-party vendor and supply chain compromise (T1199 Trusted Relationship): Sistemi Informativi sits at the center of an Italian IT supply chain serving public administration.
Data Exposed: Undisclosed by IBM.
Volume: Undisclosed.
18. NVIDIA GeForce NOW (Armenia)
Victim: NVIDIA GeForce NOW users located in Armenia.
Impact / Why It Matters: NVIDIA confirmed on May 7, 2026 that GeForce NOW user information was exposed in a regionally scoped breach affecting Armenian users. The disclosure is significant because a ShinyHunters impersonator publicly claimed to have hacked NVIDIA’s GeForce Now infrastructure — illustrating that the ShinyHunters “brand” is being co-opted by unrelated actors to amplify the perceived credibility of unrelated claims.
Threat Actor: Undisclosed by NVIDIA; an unrelated actor falsely impersonating ShinyHunters claimed responsibility.
Attack Method (Overview): NVIDIA confirmed the breach to Bleeping Computer but did not disclose the technical entry vector.
Attack Vector(s): – Others (intrusion vector undisclosed): NVIDIA has not publicly disclosed the technical vector.
Data Exposed: User information for GeForce NOW Armenia users.
Volume: Undisclosed (Armenian users only).
References
- Wikipedia — 2026 Canvas security incident
- Inside Higher Ed — Instructure Pays Ransom to Canvas Hackers
- The Hacker News — Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
- Bitdefender Business Insights — Technical Advisory: ShinyHunters Breach of Instructure Canvas LMS
- The Register — Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline
- Halcyon — Education Sector in the Crosshairs: ShinyHunters’ Extortion Campaign Against Instructure
- Security Week — Carnival Data Breach Exposed 6 Million People
- Bleeping Computer — Carnival Cruise confirms data breach affecting nearly 6 million people
- The Record — Cruise giant Carnival confirms data breach affecting nearly 6 million people
- Malwarebytes — Carnival confirms data breach impacting nearly 6 million
- Bleeping Computer — Charter confirms data breach after ShinyHunters extortion threat
- Cybernews — Inside the Charter data breach: hackers leak 13M+ customer data
- The Register — ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak
- TechRepublic — ShinyHunters Alleges 42M Records Stolen from Charter Communications
- Techlicious — Charter confirms Spectrum data breach: 13 million customers exposed
- CBC News — Elections Alberta granted injunction to pull down electoral list posted publicly by separatist group
- CBC News — Elections Alberta issues cease-and-desist letters over voter info breach, privacy commissioner launches probe
- The Tyee — Alberta’s Voters Data Breach Was Very Bad. And Inevitable
- Canada’s National Observer — Alberta voter data found on website of US company linked to Centurion Project
- Elections Alberta — Message to Albertans from the Chief Electoral Officer re: Unauthorized Use of List of Electors
- TechCrunch — NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people
- Biometric Update — Data breach exposes medical, financial, biometric data of 1.8 million
- TechRadar — NYC Health + Hospitals mega data breach
- TechCrunch — A hotel check-in system left a million passports and driver’s licenses open for anyone to see
- Security Affairs — Public Amazon bucket leaks sensitive guest data from Japanese hotel platform Tabiq
- Privacy Guides — Data Breach Roundup (May 15 – 21, 2026) — Tabiq misconfiguration
- OpenAI — Our response to the TanStack npm supply chain attack
- Bleeping Computer — OpenAI confirms security breach in TanStack supply chain attack
- CyberScoop — ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages
- The Hacker News — GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
- Bleeping Computer — GitHub confirms breach of 3,800 repos via malicious VSCode extension
- Help Net Security — TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension
- Nature — UK Biobank breach prompts the field of genomics to rethink open science
- The Guardian — Private health records of half a million Britons offered for sale on Chinese website
- Tech Times — Lithuania Data Breach: 600,000 Records Expose Spy Home Addresses to Hostile States
- Security Week — Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries
- LRT — Lithuania investigates massive data breach, suspects foreign intelligence operation
- Infosecurity Magazine — Zara Data Breach Impacts Nearly 200,000 Customers
- Bleeping Computer — Zara data breach exposed personal information of 197,000 people
- UpGuard — ShinyHunters claims Asian Football Confederation data breach
- SC Media — Asian Football Confederation reportedly suffers massive data breach
- TechRadar — The Vimeo data breach exposed personal information of 119,000 people
- Bleeping Computer — Vimeo data breach exposes personal information of 119,000 people
- WLTX — 78,000 impacted by data breach in South Carolina
- Yle News — Finnish state data ‘espionage’ breach reached president’s office, documents show
- The Hacker News — Trellix Confirms Source Code Breach With Unauthorized Repository Access
- Bleeping Computer — Trellix source code breach claimed by RansomHouse hackers
- Security Affairs — Salt Typhoon breach IBM subsidiary in Italy
- Bleeping Computer — NVIDIA confirms GeForce NOW data breach affecting Armenian users