[weglot_switcher]
SpyCloud report on the biggest data breaches of 2026.

A Running List of 2026’s Biggest Data Breaches

Table of Contents

Check your exposure

TL;DR

What is a breach?

A breach refers to data taken from an organization or platform, whether by an outside criminal group or an insider misusing trusted access. Breaches are typically made up of a handful of exposed data types:

What’s inside a breach shapes what can be expected to happen next. Credential-heavy breaches fuel account takeover (ATO); fraud and social engineering can come from PII theft, and financial details lead to financial disasters.

Reading the numbers

Most entries report a record count, one record representing one person’s exposed data, made up of the data types listed above. Where no reliable count exists, the entry reports what is confirmed instead. Record count alone doesn’t indicate risk, so each breach warrants its own look rather than a reaction to the headline number.

Three things should shape how to read a count:

Top breaches, so far

According to SpyCloud’s own data, nearly 2,000 breach sources have been confirmed so far in 2026, totaling over 11 billion records and 780 million exposed passwords. 

Chinese PII Leak

Impact: 6.38 billion unique records confirmed by SpyCloud, including 2.5 billion Chinese national ID numbers. 

An exposed Elasticsearch cluster on a bulletproof hosting server was discovered sitting open in January 2026. SpyCloud Labs obtained a copy and parsed 6.38 billion unique records out of the original 8.7 billion raw entries, the largest known leaked dataset of Chinese PII on record.

FortiBleed

Impact: 934,381 records confirmed by SpyCloud; the scope covers roughly half of every FortiGate device exposed to the internet at the time.

Researcher Volodymyr “Bob” Diachenko surfaced SSL-VPN credentials for tens of thousands of internet-facing FortiGate firewalls. SpyCloud obtained a copy and found the actor behind it, tracked under the alias SantaAd, was running a broader spray-and-pray campaign against a range of internet-facing appliances, not just FortiGate devices.

Klue Breach

Impact: No aggregated record count has been confirmed, but at least seven orgs have publicly disclosed their exposure, including Huntress, LastPass, Recorded Future, Tanium, Jamf, and 8×8.

Attackers compromised Klue’s integrations and exfiltrated data from customer Salesforce environments, leading Salesforce to disable third-party connections to the Klue app. Icarus, a ransomware group, claimed responsibility. This incident followed the same attack chain as the Salesloft Drift and Gainsight breaches.

Canvas / Instructure Breach

Impact: ShinyHunters claimed roughly 275 million individuals across 8,809 institutions were exposed. That figure hasn’t been confirmed by Instructure or any independent source.

ShinyHunters breached Canvas LMS around April 2026, issuing a ransom demand. A second intrusion in May defaced login pages at affected institutions with a new ransom note. Instructure’s disclosure listed names, institutional emails, student ID numbers, and Canvas inbox messages as exposed.

IDMerit Data Leak

Impact: An estimated 1 billion records were confirmed; this number is backed by SpyCloud.

Cybernews discovered an unprotected database in November 2025, belonging to IDMerit, a Know Your Customer (KYC) identity verification provider. Exposed data included PII from across 26 countries. IDMerit disputed that its own systems were breached, attributing the exposure to open data ports tied to third-party data sources.

RENIEC

Impact: If verified, the three incidents would total 52 million records, but none of the underlying figures has been independently confirmed, and the overlap between them – all three draw from the same national population – is accounted for.

A Ministry of Interior employee misused their access to RENIEC’s database, leaking 15 million Peruvians’ personal data. The employee’s intent hasn’t been disclosed, but RENIEC has denied this was a breach of its own systems. A separate, unconfirmed leak of 146,199 biometric facial images was also reported. In April 2026, ‘BlindBackdoor’ claimed a further 37 million RENIEC records as part of a larger Latin American dataset.

Paidwork

A database from Paidwork, a microtask gig-work platform, was advertised on a cybercrime forum in April 2026, and was then publicly dumped in July. Exposed data included names, addresses, dates of birth, bank account numbers, transaction history, and bcrypt-hashed passwords. Paidwork hasn’t confirmed the breach.

Under Armour

Impact: 72 million email addresses were confirmed in the breach and backed up by SpyCloud findings.

Everest, a Russian ransomware group linked to several high-profile attacks, listed Under Armour on its leak site in November 2025 and gave the company a seven-day deadline to respond. Under Armour didn’t engage publicly, and Everest published the customer dataset in January 2026 after the ransom went unpaid.

DentaQuest LLC

ShinyHunters listed DentaQuest, a Medicaid and Medicare dental benefits administrator, on its leak site in May 2026 with a ransom deadline. After the negotiations failed, the group published the data days later. DentaQuest confirmed an incident in June but didn’t begin notifying those affected until July.

Exact Sciences Corporation

Impact: Initial claims put the count at 30 million records, including more than 1 million Social Security numbers, but what was published contained 10.9 million unique email addresses.

Exact Sciences, maker of Colorguard and Cancerguard and a subsidiary of Abbott Labs, was listed on July 15, 2026, with a ransom deadline. Abbott confirmed unauthorized access to a limited number of systems within the legacy Cancer Diagnostics business, separate from its core operations, and said the incident hasn’t affected manufacturing or patient care. The stolen data was later published.

Madison Square Garden Sports Corp.

Impact: ShinyHunters claimed roughly 26 million records; what was actually published contained nearly 10 million unique email addresses. SpyCloud’s log shows 55.4 million, more than double the attacker’s own claim.

A phishing call against a low-level employee gave ShinyHunters access to MSG Sports’ Microsoft Entra identity system, the entry point for a breach the group listed in its leak site in June 2026. MSG missed the ransom deadline and the group published the data the next day.

Additional confirmed breaches

Breach Description
WhatsApp User Data A scraped dataset of WhatsApp user data, 399.6 million records.
Telegram User Data Part 2 A scraped dataset of Telegram user data, 328.9 million records.
AT&T Customer Data A 176-million-record dataset built from AT&T’s 2019 and 2024 breaches resurfaced in Feb 2026 with previously encrypted Social Security numbers now decrypted.
Aggregated PII and Credential Dataset (Egypt) A compiled dataset of Egyptian PII and credentials, 132.3 million records, with no single disclosed source.
Dspy.tk 87.7 million records tied to the domain dspy.tk.
DreamUp Shared Hosting Server 84 million records exposed from a shared hosting server operating under the name DreamUp.
Credit Card CVV Data Compilation A compiled dataset of card and CVV data, 80 million records.
Aggregated Credential Dataset A compiled set of login credentials, 73.7 million records.
Brazilian PII Compilation A compiled dataset of Brazilian PII, 60.3 million records.
GetContact 55.7 million records tied to the caller-ID and contact-lookup app GetContact.
Telegram User Data A separate scraped dataset of Telegram user data, 54.2 million records.
Independent High Electoral Commission (IHEC) of Iraq 49.2 million records tied to Iraq’s electoral commission.
Charter Communications (Spectrum) ShinyHunters used a phishing call to gain Salesforce access at Charter in April 2026, with confirmed counts ranging from 4.9 million to a claimed 42 million.
Your org’s data may already be exposed

Billions of records from this year’s confirmed breaches are circulating right now.

FAQs

A confirmed breach has been verified by the affected organization, an independent researcher, or a comparable source. A claimed breach rests only on what the attacker has stated, which may be accurate, exaggerated, or unverifiable.

Not exactly. A compilation pulls data together from multiple sources with no single confirmed incident behind it, while a breach ties back to one specific organization or platform. Both appear on this list, but the distinction affects how much can be confirmed about each.

Check your exposure directly to see if your organization’s data appears in a confirmed breach, malware, or phishing dataset.

Confirm exactly what data was exposed, since the type, credentials, PII, or financial information, determines the right response. Reset or revoke exposed credentials and sessions, and notify affected individuals as required by law.

Keep reading

SpyCloud report on identity threat trends for 2026 with security insights.
The Identity Security Challenges Most Organizations Aren’t Prepared For
The 2026 SpyCloud Identity Threat Report surveyed 750 security leaders on identity-based events, non-human identity risk, and the visibility and remediation gaps that separate resilient programs.
SpyCloud report on most active phishing kits in 2026 for cybersecurity.
The Most Active Phishing-as-a-Service Kits of 2026
Phishing-as-a-service kits like Tycoon 2FA and Kali365 now steal live sessions and OAuth tokens instead of passwords, letting attackers bypass MFA entirely – here's a breakdown of 2026's most active kits and how to stop them.
Analysis of Stealc malware takedown by SpyCloud for cybersecurity.
Peers Held, StealC Didn’t: Analyzing the June 24 Takedown in SpyCloud’s Data
SpyCloud Labs data shows StealC fell 90% before the June 24 Operation Endgame takedown. See what our post-takedown analysis reveals.

Check Your Company's Exposure

See your real-time exposure details powered by SpyCloud.

NEW RESEARCH: Over 2/3 of orgs had an identity event last year – NHIs were the top cause. Read on

X