Significant Data Breaches of 2026
Home • Significant Data Breaches of 2026
- July 31, 2026
Summary of industries most targeted by data breaches
| Name of Sector | Data Breaches in Last 15 Years (2005–2019) | Data Breaches in Last 5 Years (2015–2019) | ||
|---|---|---|---|---|
| Number of Breaches | Percentage (%) | Number of Breaches | Percentage (%) | |
| EDU | 671 | 10.55 | 64 | 3.08 |
| BSF | 410 | 6.45 | 194 | 9.36 |
| BSO | 426 | 6.70 | 113 | 5.45 |
| MED | 3912 | 61.55 | 1587 | 76.59 |
| GOV | 561 | 8.82 | 45 | 2.17 |
| NGO | 75 | 1.18 | 7 | 0.33 |
| BSR | 300 | 4.72 | 62 | 2.99 |
| Total | 6355 | 99.97 | 2072 | 99.97 |
Major Data Breaches in 2026
The National Association of Insurance Commissioners Data Breach
In June 2026, the National Association of Insurance Commissioners confirmed a cyberattack that resulted in stolen data being leaked on the dark web. Ransomware group ShinyHunters claimed the theft of 3.1 terabytes of data, including insurer filings, credit rating files, and personally identifiable information.
Department of Homeland Security Information-Sharing Cyberattack
In early July 2026, the U.S. Department of Homeland Security announced it was investigating a cyberattack that compromised the Homeland Security Information Network, a cloud-based information-sharing platform used by government agencies and partners. The intrusion occurred between late May and early June during the World Cup. According to the DHS notification, the information accessed was sensitive but not classified.
Brightspeed Data Breach
In January 2026, major U.S. fiber broadband company Brightspeed announced it was investigating claims by an extortion group that it stole sensitive data from over 1 million residential customers, including personally identifiable information and billing information. Brightspeed serves customers across 20 states. Though the company did not definitively confirm a system-wide breach, it acknowledged a “potential cybersecurity event.”
Nike Internal Data Breach
In February 2026, Nike announced it was investigating a potential cybersecurity incident after a threat group claimed responsibility for stealing 1.4 terabytes of internal company data, including 188,000 files allegedly tied to the company’s design and manufacturing process. Unlike most breaches that focus on stealing customer credentials, this attack centered on intellectual property. WorldLeaks claimed responsibility for the attack.
NYC Health + Hospitals Security Breach
In March 2026, New York City Health and Hospitals Corporation notified individuals of a data security incident that may have affected personal and protected health information. NYC Health + Hospitals discovered suspicious activity on its computer network in February, and an investigation determined that an unauthorized actor had accessed certain systems between November 2025 and February 2026 due to a security breach at a third-party vendor.
Breached information included health insurance information, medical information, biometric information, billing information, and other personal information, including Social Security numbers, driver’s license numbers, financial account numbers, and more.
Charter Communications Cyberattack
In May 2026, an extortion group stole data from Charter Communications, including over 42 million customer records, and published them on a leak site. Almost five million people were affected by the breach. The data stolen included email addresses, names, addresses, phone numbers, and employee information.
Carnival Corporation Hack
In May 2026, the cruise line Carnival Corporation notified 6 million people that their personal information had been stolen in an April data breach. Hackers gained access to an employee’s account via social engineering, then stole files containing personal information, including names, addresses, dates of birth, contact information, and identification numbers.
New cases and investigations, settlement deadlines, and news straight to your inbox.
What Data Breaches Mean for Consumers
Data breaches put consumers at risk of identity theft, financial fraud, and other privacy concerns, especially when the compromised information includes sensitive, personally identifiable information.
Identity Theft Risk
Financial Fraud Exposure
Long-Term Data Exposure
What to Do After a Data Breach in 2026
If you have received a notification or suspect a data breach has exposed your personal information, you must act quickly to protect yourself. Once you’ve confirmed you’ve been impacted, secure your accounts and protect your financial information before assessing your legal options for seeking accountability and compensation.
Confirm You’ve Been Impacted
Review emails, letters, or portals from the breached organization, or check Class Action U’s current data breaches list to discover whether you were affected by a breach. Determine what information was exposed, including passwords, financial information, Social Security numbers, or health data.
Secure Your Accounts Immediately
Update the passwords for your affected accounts with unique, hard-to-guess passwords and enable multi-factor authentication when available. Additionally, check your bank and credit card statements, as well as your digital accounts, for any unusual activity.
Place Fraud Alerts or Credit Freezes
Assess Legal Opportunities
After a data breach—especially involving a large corporation—consumers may be eligible to join or start a class action lawsuit to seek compensation. Speak to an experienced data breach lawyer as soon as possible after being notified of a breach to preserve your legal rights and options.
How to Protect Yourself From Data Breaches in 2026
New cases and investigations, settlement deadlines, and news straight to your inbox.