Weekly briefing › No. 41
Weekly briefing · No. 41 · 4 Oct 2026
Six major data breaches affecting North Americans emerged within the last 90 days and earlier 2026, exposing over 200 million records.
Incidents span insurance, healthcare, identity verification, education, and telecommunications, with incidents crossing both Canadian and U.S. jurisdictions.
This issue’s disclosures
CriticalSep 1, 2026
IDScan.net
Credential Theft · 153M records
Unauthorized access to IDScan's cloud infrastructure from April 4 to September 2, 2026 exposed scanned driver's licenses, passports, and government IDs for over 150 million U.S. and Canadian residents.
What it means: Individuals face unprecedented exposure of verified identity documents that cannot be changed, enabling sophisticated fraud across border and requiring credit monitoring and identity theft protection indefinitely.
Sep 1, 2026
CriticalMay 17, 2026
DentaQuest
Healthcare · 15M records
Unauthorized access to DentaQuest network from May 17 to 20, 2026 compromised names, addresses, Social Security numbers, Medicaid/Medicare numbers, and detailed dental and vision treatment records.
What it means: 15 million primarily Medicaid-enrolled patients face exposure of health data and government IDs that can be used to commit medical identity fraud against vulnerable populations.
May 17, 2026
CriticalMar 17, 2026
AssuranceAmerica
Financial · 6.9M records
Attackers targeted an employee credential on March 17 and extracted customer names, contact details, driver's license numbers, and auto insurance policy information before detection one day later.
What it means: 6.9 million U.S. drivers have immutable identity credentials exposed that cannot be revoked, creating permanent fraud and impersonation risk despite the company declining to fund identity protection.
Mar 17, 2026
CriticalNov 25, 2025
NYC Health + Hospitals
Healthcare · 1.8M records
Unauthorized actor accessed NYC Health + Hospitals' network from November 25, 2025 through February 11, 2026 via a third-party vendor, exfiltrating full names, SSNs, medical records, banking details, and biometric data.
What it means: 1.8 million patients have comprehensive health and financial identities exposed, including fingerprints and palm prints, creating risk of fraudulent medical claims and financial account takeover.
Nov 25, 2025
CriticalFeb 2026
TELUS Digital
Credential Theft · Unknown (1 PB claimed) records
ShinyHunters gained initial access through Google Cloud Platform credentials exposed in the Salesloft Drift breach, then pivoted into TELUS Digital's BigQuery instance and multiple systems to exfiltrate approximately 1 petabyte of data.
What it means: Customer support records, financial information, voice call recordings, Salesforce data, FBI background check results, and agent performance ratings are now available to criminals; ShinyHunters demanded $65 million USD ransom.
Feb 2026
HighApr 20, 2026
Canada Life
Financial · 70K records
ShinyHunters exploited a single compromised Canada Life employee credential to access the company's Salesforce CRM system in mid-April 2026, extracting names, addresses, phone numbers, dates of birth, and account details for 70,000 verified individuals.
What it means: Canadians face identity theft and targeted phishing campaigns; ShinyHunters claimed access to 5.6 million broader Salesforce records but Canada Life confirmed only 70,000 actual exposures were accessed.
Apr 20, 2026
This issue by category
Where this issue’s disclosures sit.
The 6 disclosures in issue No. 41, by the category we filed each one under.