TL;DR
- Scale: SpyCloud has confirmed nearly 2,000 breach sources in 2026 so far, together exposing more than 11 billion records and 780 million passwords.
- One actor, many victims: ShinyHunters is tied to at least four of this year’s largest breaches: Canvas/Instrucure, DentaQuest, Exact Sciences, and MSG Sports Corp.
- PII outpaces credentials: Roughly 70% of this year’s exposed records carry no passwords at all, shifting more of 2026’s risk toward fraud and social engineering than straightforward account takeover.
What is a breach?
A breach refers to data taken from an organization or platform, whether by an outside criminal group or an insider misusing trusted access. Breaches are typically made up of a handful of exposed data types:
- Credentials: usernames and passwords, sometimes paired together, written in plaintext or as a hash
- Personally identifiable information (PII): names, email & physical addresses, phone numbers, ID numbers, etc.
- Financial data: card numbers, bank account details, payment records
What’s inside a breach shapes what can be expected to happen next. Credential-heavy breaches fuel account takeover (ATO); fraud and social engineering can come from PII theft, and financial details lead to financial disasters.
Reading the numbers
Most entries report a record count, one record representing one person’s exposed data, made up of the data types listed above. Where no reliable count exists, the entry reports what is confirmed instead. Record count alone doesn’t indicate risk, so each breach warrants its own look rather than a reaction to the headline number.
Three things should shape how to read a count:
- Whether passwords are included. A breach built mostly from names and IDs poses less threat than one of equal size built from exposed passwords, even though the headline number looks the same.
- Where the number comes from. A count from the criminal group behind a breach carries less certainty than one confirmed by the affected org or an independent researcher.
Top breaches, so far
According to SpyCloud’s own data, nearly 2,000 breach sources have been confirmed so far in 2026, totaling over 11 billion records and 780 million exposed passwords.
Chinese PII Leak
Impact: 6.38 billion unique records confirmed by SpyCloud, including 2.5 billion Chinese national ID numbers.
An exposed Elasticsearch cluster on a bulletproof hosting server was discovered sitting open in January 2026. SpyCloud Labs obtained a copy and parsed 6.38 billion unique records out of the original 8.7 billion raw entries, the largest known leaked dataset of Chinese PII on record.
FortiBleed
Impact: 934,381 records confirmed by SpyCloud; the scope covers roughly half of every FortiGate device exposed to the internet at the time.
Researcher Volodymyr “Bob” Diachenko surfaced SSL-VPN credentials for tens of thousands of internet-facing FortiGate firewalls. SpyCloud obtained a copy and found the actor behind it, tracked under the alias SantaAd, was running a broader spray-and-pray campaign against a range of internet-facing appliances, not just FortiGate devices.
Klue Breach
Impact: No aggregated record count has been confirmed, but at least seven orgs have publicly disclosed their exposure, including Huntress, LastPass, Recorded Future, Tanium, Jamf, and 8×8.
Attackers compromised Klue’s integrations and exfiltrated data from customer Salesforce environments, leading Salesforce to disable third-party connections to the Klue app. Icarus, a ransomware group, claimed responsibility. This incident followed the same attack chain as the Salesloft Drift and Gainsight breaches.
Canvas / Instructure Breach
Impact: ShinyHunters claimed roughly 275 million individuals across 8,809 institutions were exposed. That figure hasn’t been confirmed by Instructure or any independent source.
ShinyHunters breached Canvas LMS around April 2026, issuing a ransom demand. A second intrusion in May defaced login pages at affected institutions with a new ransom note. Instructure’s disclosure listed names, institutional emails, student ID numbers, and Canvas inbox messages as exposed.
IDMerit Data Leak
Impact: An estimated 1 billion records were confirmed; this number is backed by SpyCloud.
Cybernews discovered an unprotected database in November 2025, belonging to IDMerit, a Know Your Customer (KYC) identity verification provider. Exposed data included PII from across 26 countries. IDMerit disputed that its own systems were breached, attributing the exposure to open data ports tied to third-party data sources.
RENIEC
Impact: If verified, the three incidents would total 52 million records, but none of the underlying figures has been independently confirmed, and the overlap between them – all three draw from the same national population – is accounted for.
A Ministry of Interior employee misused their access to RENIEC’s database, leaking 15 million Peruvians’ personal data. The employee’s intent hasn’t been disclosed, but RENIEC has denied this was a breach of its own systems. A separate, unconfirmed leak of 146,199 biometric facial images was also reported. In April 2026, ‘BlindBackdoor’ claimed a further 37 million RENIEC records as part of a larger Latin American dataset.
Paidwork
A database from Paidwork, a microtask gig-work platform, was advertised on a cybercrime forum in April 2026, and was then publicly dumped in July. Exposed data included names, addresses, dates of birth, bank account numbers, transaction history, and bcrypt-hashed passwords. Paidwork hasn’t confirmed the breach.
Under Armour
Impact: 72 million email addresses were confirmed in the breach and backed up by SpyCloud findings.
Everest, a Russian ransomware group linked to several high-profile attacks, listed Under Armour on its leak site in November 2025 and gave the company a seven-day deadline to respond. Under Armour didn’t engage publicly, and Everest published the customer dataset in January 2026 after the ransom went unpaid.
DentaQuest LLC
Impact: 2.6 million unique email addresses were confirmed in the leaked dataset; DentaQuest separately notified roughly 15 million individuals by mail, with outside estimates running as high as 23.4 million.
ShinyHunters listed DentaQuest, a Medicaid and Medicare dental benefits administrator, on its leak site in May 2026 with a ransom deadline. After the negotiations failed, the group published the data days later. DentaQuest confirmed an incident in June but didn’t begin notifying those affected until July.
Exact Sciences Corporation
Impact: Initial claims put the count at 30 million records, including more than 1 million Social Security numbers, but what was published contained 10.9 million unique email addresses.
Exact Sciences, maker of Colorguard and Cancerguard and a subsidiary of Abbott Labs, was listed on July 15, 2026, with a ransom deadline. Abbott confirmed unauthorized access to a limited number of systems within the legacy Cancer Diagnostics business, separate from its core operations, and said the incident hasn’t affected manufacturing or patient care. The stolen data was later published.
Madison Square Garden Sports Corp.
Impact: ShinyHunters claimed roughly 26 million records; what was actually published contained nearly 10 million unique email addresses. SpyCloud’s log shows 55.4 million, more than double the attacker’s own claim.
A phishing call against a low-level employee gave ShinyHunters access to MSG Sports’ Microsoft Entra identity system, the entry point for a breach the group listed in its leak site in June 2026. MSG missed the ransom deadline and the group published the data the next day.
Additional confirmed breaches
| Breach | Description |
|---|---|
| WhatsApp User Data | A scraped dataset of WhatsApp user data, 399.6 million records. |
| Telegram User Data Part 2 | A scraped dataset of Telegram user data, 328.9 million records. |
| AT&T Customer Data | A 176-million-record dataset built from AT&T’s 2019 and 2024 breaches resurfaced in Feb 2026 with previously encrypted Social Security numbers now decrypted. |
| Aggregated PII and Credential Dataset (Egypt) | A compiled dataset of Egyptian PII and credentials, 132.3 million records, with no single disclosed source. |
| Dspy.tk | 87.7 million records tied to the domain dspy.tk. |
| DreamUp Shared Hosting Server | 84 million records exposed from a shared hosting server operating under the name DreamUp. |
| Credit Card CVV Data Compilation | A compiled dataset of card and CVV data, 80 million records. |
| Aggregated Credential Dataset | A compiled set of login credentials, 73.7 million records. |
| Brazilian PII Compilation | A compiled dataset of Brazilian PII, 60.3 million records. |
| GetContact | 55.7 million records tied to the caller-ID and contact-lookup app GetContact. |
| Telegram User Data | A separate scraped dataset of Telegram user data, 54.2 million records. |
| Independent High Electoral Commission (IHEC) of Iraq | 49.2 million records tied to Iraq’s electoral commission. |
| Charter Communications (Spectrum) | ShinyHunters used a phishing call to gain Salesforce access at Charter in April 2026, with confirmed counts ranging from 4.9 million to a claimed 42 million. |
Your org’s data may already be exposed
Billions of records from this year’s confirmed breaches are circulating right now.
FAQs
A confirmed breach has been verified by the affected organization, an independent researcher, or a comparable source. A claimed breach rests only on what the attacker has stated, which may be accurate, exaggerated, or unverifiable.
Not exactly. A compilation pulls data together from multiple sources with no single confirmed incident behind it, while a breach ties back to one specific organization or platform. Both appear on this list, but the distinction affects how much can be confirmed about each.
Check your exposure directly to see if your organization’s data appears in a confirmed breach, malware, or phishing dataset.
Confirm exactly what data was exposed, since the type, credentials, PII, or financial information, determines the right response. Reset or revoke exposed credentials and sessions, and notify affected individuals as required by law.