Contacts
1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806
Let's discuss your project
Business Address: 1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806

Data Breach Tracker: Major Incidents 2026 (Updated in Real Time)

Data Breach Tracker 2026

Last updated: October 4, 2026 — Updated weekly or on any incident exceeding 1 million records exposed Coverage: January 1, 2026 – present | Format: reverse chronological | Maintained by: Axis Intelligence Research & Marcus Chen

Quick Answer

The Axis Data Breach Tracker logs confirmed data breaches disclosed in 2026 where an unauthorized party accessed or exfiltrated personal data, with primary-source documentation for every entry. As of October 4, 2026, Axis Intelligence Research has confirmed 20 entries. The Pentagon’s Defense Manpower Data Center (DMDC) began notifying 2.76 million living individuals and 294,000 deceased individuals in letters dated September 18, 2026, after unauthorized users accessed unencrypted personnel records through a file-sharing vulnerability between October 2025 and July 16, 2026. The tracker’s confirmed record total across entries with official counts stands at 107 million individuals.

Key Findings

  1. Healthcare business associates — third-party vendors that process protected health information on behalf of HIPAA-covered entities — account for 6 of the 10 largest confirmed incidents in this tracker as of October 4, 2026: Conduent (62.2M), Unlimited Technology Systems (3.8M), CareCloud (3.75M), AdaptHealth (4.1M), One Medical/Amazon Health (count pending), and Trellix (corporate IP). The HIPAA Journal June 2026 report notes that six of the top ten healthcare data breaches of 2026 YTD occurred at business associates.
  2. AdaptHealth — a home medical equipment and supplies provider serving 4.1 million patients across all 50 U.S. states — filed 4,115,802 individuals with HHS OCR in September 2026, following a June 5, 2026 social engineering attack in which a third-party contractor’s privileged account was compromised. ShinyHunters was linked to the attack per HIPAA Journal’s earlier reporting; BleepingComputer could not confirm an active ShinyHunters listing at time of this entry.
  3. McKesson — the largest U.S. pharmaceutical distributor — disclosed a breach on August 28, 2026, with ShinyHunters claiming responsibility via social engineering targeting Snowflake and Salesforce cloud environments. McKesson’s September 8 update confirmed 6.4 million unique email addresses were among the exfiltrated data; the individual count for HHS OCR purposes has not yet been established and the investigation remains active.
  4. IBM’s 2026 Cost of a Data Breach Report (July 29, 2026; 602 organizations) puts the global average at a record $4.99 million (+12% YoY) and the U.S. average at $11.5 million. One in four malicious breaches were AI-enabled — a 56% year-over-year increase — averaging $6 million per incident.
  5. The Axis Intelligence Research Breach Concentration Index™ (BCI) reads 0.363 as of October 4, 2026, down from 0.383, after the DMDC’s 3,054,000 confirmed records entered the denominator. CenterPoint Energy (count unconfirmed by the company) and McKesson (HHS OCR count expected before late October 2026) remain excluded until official figures are filed. The methodology is disclosed in the BCI section below.

Axis Data Breach Tracker 2026

Confirmed incidents with primary-source documentation · Updated October 4, 2026 · Full tracker + methodology

Entries shown
20

of 20 tracked

Confirmed records
107M+

Across entries with official counts

BCI™ reading
0.363

Oct 4, 2026 · v1.0

IBM avg breach cost
$4.99M

Global record, 2026 COBR

Axis Data Breach Tracker 2026 · Axis Intelligence Research · 20 entries · as of 2026-10-04 · BCI™ v1.0 · Download CSV (CC BY 4.0)
Date Organization Sector Attribution Records Data exposed Severity Primary source
Defense Manpower Data Center (U.S. DoD)DBT-2026-019 Government / Defense Unknown 3,054,000 (2.76M living + 294K deceased) SSNs, names, DOB, sex, race, contact info, military service and occupational details (unencrypted) Critical DMDC notification letter / DoD statement
CenterPoint Energy, Inc.DBT-2026-018count_unconfirmed_by_company Electric & Gas Utility Alias “4d722e4d656f77” (no group) unconfirmed (7.49M claimed) Names, phone, address, account numbers, billing amounts, partial SSNs (per threat actor; company has not confirmed data types) Significant CenterPoint Energy SEC Form 8-K, Sep 14, 2026
McKesson CorporationDBT-2026-017official_count_pending Pharmaceutical Distribution / Healthcare ShinyHunters (claimed) under investigation (6.4M emails confirmed) Names, addresses, DOB, email, patient IDs, health insurance (Medicaid/Medicare), diagnoses, medications, test results, medical images Critical HIPAA Journal / McKesson statements
AdaptHealth LLCDBT-2026-015 Home Medical Equipment / Healthcare Unconfirmed 4,115,802 Names, addresses, DOB, SSN, health insurance, medical information Major BleepingComputer citing HHS OCR
Unlimited Technology Systems LLCDBT-2026-016 Healthcare IT / Revenue Cycle Mgmt Unknown 3,803,750 Patient names, DOB, SSN, health insurance, medical information (breach: Oct 2025) Major BleepingComputer / HIPAA Journal citing HHS OCR
CareCloud Inc.DBT-2026-013 Healthcare Technology / EHR SaaS Unknown 3,756,469 Names, addresses, DOB, SSN, driver’s license, financial account numbers, credit/debit card numbers, medical & insurance data Critical HIPAA Journal citing HHS OCR
RingCentralDBT-2026-014 Cloud Communications / SaaS ShinyHunters 1,600,000 Names, email addresses, phone numbers, physical addresses Significant BleepingComputer / HaveIBeenPwned
SM Energy CompanyDBT-2026-011national_total_undisclosed Energy / Oil and Gas Unknown 3,931 (3 states only) Names, addresses, phone, email, SSN or taxpayer ID Significant State AG filings (TX, MA, VT); company breach notification letters, July 30, 2026
KDDI CorporationDBT-2026-010count_not_published Telecommunications Unknown not confirmed Email addresses, account metadata (ISP-scale) Significant SecurityWeek citing KDDI disclosure
AccentureDBT-2026-009corporate_ip_no_pii_count Professional Services Unknown threat actor N/A (IP exfil) Source code, RSA/SSH keys, Azure PAT tokens, config files (~35 GB) Significant BleepingComputer / Accenture statement
Conduent Business Services LLCDBT-2026-012 Govt. Services / BPO (Healthcare) SafePay ransomware 62,224,658 Names, addresses, DOB, SSN, medical info, health insurance, Medicaid claims data Critical HIPAA Journal citing HHS OCR
AssuranceAmericaDBT-2026-008 Insurance Unknown 6,998,886 Names, contact info, auto insurance policy details, driver’s license numbers Major BleepingComputer citing Maine AG
Carnival Corporation & plcDBT-2026-006 Travel / Hospitality ShinyHunters 5,995,277 (7.5M per HIBP) Names, DOB, gender, email, loyalty program data (Mariner Society / Holland America) Major HaveIBeenPwned + state AG filings
Canvas LMS / InstructureDBT-2026-005count_not_confirmed_officially Education Technology ShinyHunters not confirmed Names, email addresses, student IDs, messages (global higher education scale) Significant Wikipedia citing Instructure disclosure
France Titres / ANTSDBT-2026-003 Govt. / National Infrastructure Threat actor “breach3d” 11,700,000 Names, email, DOB, postal address, phone, login IDs, unique account identifiers Critical BrightDefense citing France Titres disclosure
AuraDBT-2026-002 Cybersecurity / Consumer Identity ShinyHunters ~900,000 Names, home addresses, phone numbers, email addresses (marketing database; no SSN, financial data) Moderate SecurityWeek / company disclosure
Figure Lending LLCDBT-2026-001 Fintech / Financial Services ShinyHunters 3,000,000+ Names, DOB, addresses, phone, email, passwords, SSNs Major Proton Business citing company notification
CrunchbaseDBT-2026-000 Business Intelligence / SaaS ShinyHunters 1,500,000+ Names, DOB, addresses, phone, email, usernames, internal corporate documents Significant Proton Business citing company notification
One Medical / Amazon HealthDBT-2026-007official_count_pending Healthcare ShinyHunters (claimed) under investigation PHI for One Medical Seniors (legacy Iora Health) patients; clinical data scope not yet confirmed Significant PKWARE citing company disclosure
IBM 2026 Cost of Data Breach ReportIBM-2026-COBR Benchmark reference N/A $4.99M avg 602 orgs surveyed, March 2025–Feb 2026. US avg $11.5M. Healthcare highest sector $6.64M. AI-enabled: 1 in 4 malicious breaches. Reference IBM Newsroom, July 29, 2026

Every incident row is sourced from the announcing organization’s own filing or an official regulatory body (HHS OCR, state AG). not confirmed means no regulatory filing has established a count — it is never estimated. BCI™ = Axis Intelligence Research Breach Concentration Index, an HHI-based measure of exposure distribution. Full methodology and CSV download (CC BY 4.0). Cite as: Axis Intelligence Research, Data Breach Tracker 2026, October 2026.

How We Curate This List

What counts as a tracker entry

An incident earns a row when all three conditions are met:

  1. Confirmed unauthorized access to personal data — the organization has disclosed a breach, filed with a state Attorney General, submitted to the HHS OCR breach portal (healthcare), or published an official security notice. Claims by threat actors that have not been independently verified by a notification authority or have not been acknowledged by the organization are flagged [Unconfirmed attribution] but not entered as confirmed breaches.
  2. Scope reaches ≥ 100,000 records — smaller incidents are logged in the downloadable CSV for data completeness but do not appear in the main article table.
  3. Primary-source documentation exists — a state AG filing, official company notification, HHS OCR portal entry, national data protection authority decision, or official security notice. Secondary reporting alone is never the basis for a row; it is used only to locate the primary source.

What does not count

  • Threat actor claims with no organization acknowledgment or regulatory filing
  • Incidents where only operational disruption (downtime, ransomware encryption) was confirmed, with no exfiltration of personal data established
  • Data scraping events where publicly accessible information was aggregated rather than protected systems accessed
  • Incidents where aggregate exposure is confirmed but the organization is not yet identified

Definitions

Records exposed: the number stated in official breach notifications, state AG filings, or HHS OCR portal entries. Where the organization’s figure and HaveIBeenPwned’s independently analyzed figure diverge, both are stated; the organization’s official notification figure is used as the canonical entry.

Attack vector: per official disclosure or forensic investigation finding, not threat actor self-report. Where only the threat actor’s description is available, it is noted as such.

Sector: the primary operating sector of the breached entity. Subsidiaries are classified under their actual operating sector, not the parent’s.

2026 Breach Log — Reverse Chronological

September 2026

2026-09-18 (notification letters dated) | Defense Manpower Data Center (DMDC), U.S. Department of Defense | Government / Defense | USA | 3,054,000 individuals (2,760,000 living + 294,000 deceased)

The Defense Manpower Data Center — the Pentagon’s central repository for personnel, ID credential, and benefits records, holding more than 60 million records on service members, civilian staff, veterans, and dependents — began notifying affected individuals in letters dated September 18, 2026. Per the notification letter, DMDC discovered on July 16, 2026 a vulnerability in a file-sharing system that allowed unauthorized users to access files; analysis found that “a small number of unauthorized users” accessed a server containing unencrypted PII between October 2025 and the date of discovery — roughly nine months of dwell time. A Department of Defense official confirmed to multiple outlets that 2.76 million living individuals and 294,000 deceased individuals were affected. Exposed data varies by person and includes Social Security numbers, names, dates of birth, sex, race, contact information, and military service details including occupational specialty. The Pentagon has not identified the unauthorized users and states it has no indication of misuse. Twelve months of credit monitoring and identity restoration are offered through IDX.

Severity: Critical (government identity infrastructure; unencrypted SSNs) | Records: 3,054,000 (DoD official count: 2,760,000 living + 294,000 deceased) | Access window: October 2025 – July 16, 2026 | Attack vector: Exploited vulnerability in a DMDC file-sharing system | Attribution: Unknown; not disclosed by DoD | Primary source: DMDC breach notification letter dated September 18, 2026; Department of Defense official statement — https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/

2026-09-14 (SEC Form 8-K filed) | CenterPoint Energy, Inc. | Electric & Gas Utility | USA | Count not yet confirmed by company (threat actor claims 7.49M)

CenterPoint Energy — a Houston-based electric and gas utility serving approximately 7 million metered customer accounts across Texas, Indiana, Minnesota, and Ohio — confirmed a data breach in a Form 8-K filed with the SEC on September 14, 2026. The company stated it had become aware “in September 2026” of a third-party post claiming to possess a dataset of customer information, and that its investigation confirmed an unauthorized party “obtained personal information relating to a portion of the Company’s customers” through an external-facing system. Electric and gas service delivery was not affected. CenterPoint has not confirmed the record count, the data types involved, or the attacker’s identity in its SEC filing. The threat actor, using the alias “4d722e4d656f77,” posted on BreachForums on September 12, claiming to have extracted 7.49 million customer records — names, phone numbers, addresses, account numbers, billing amounts, and partial Social Security numbers — from an unauthenticated, rate-limit-free external API. The actor stated a CAPTCHA response cut the extraction short of a claimed 17.44 million records. Class action lawsuits filed in Texas place the breach window between August 17 and September 1, 2026. CenterPoint stated it intends to notify affected customers, regulators, and law enforcement “as required.”

Severity: Significant (utility customer PII; count unconfirmed) | Records: Not confirmed by company; threat actor claims 7.49M (unverified by CenterPoint or any regulatory body as of September 26, 2026) | Breach window: August 17–September 1, 2026 (per civil complaints; not confirmed by CenterPoint) | Attack vector: Unauthenticated external-facing API with no WAF, rate limiting, or JWT/auth token protection (threat actor description; CenterPoint has confirmed “external-facing system” only) | Attribution: Threat actor alias “4d722e4d656f77” (no known group affiliation publicly confirmed) | Primary source: CenterPoint Energy Form 8-K, September 14, 2026 — https://www.sec.gov/Archives/edgar/data/0001130310/000110465926107560/tm2625326d1_8k.htm

2026-09-08 (investigation update) | McKesson Corporation | Pharmaceutical Distribution / Healthcare | USA | Count under investigation — 6.4M unique email addresses confirmed

McKesson, the largest U.S. pharmaceutical distributor by revenue — serving hospitals, pharmacies, health systems, and physician offices across all 50 states — disclosed on August 28, 2026 a cybersecurity incident involving unauthorized access to several cloud-hosted accounts and exfiltration of data. Its September 8 update confirmed the stolen data includes names, addresses, phone numbers, email addresses, patient IDs, and dates of birth, plus health insurance (including Medicaid/Medicare IDs) and medical information: dates of service, diagnoses, medications, test results, medical images, and care records. HIPAA Journal confirmed 6.4 million unique email addresses were among the exfiltrated data. ShinyHunters claimed responsibility to TechCrunch, stating the group used phishing and social engineering to access McKesson’s Snowflake and Salesforce cloud environments. ShinyHunters claimed 284 million rows of patient data — a raw row count the group itself acknowledged had not been analyzed for unique individuals. McKesson has not publicly attributed the attack. The official individual count for HHS OCR has not yet been established; this entry reflects confirmed unauthorized access and confirmed exfiltration per the company’s own disclosures.

Severity: Critical (PHI at pharmaceutical-distributor scale; investigation ongoing) | Records: Under investigation; 6.4M unique email addresses confirmed per HIPAA Journal | Breach date: ~August 25, 2026 | Disclosed: August 28, 2026 | Attack vector: Phishing and social engineering targeting Snowflake and Salesforce cloud environments | Attribution: ShinyHunters (claimed to TechCrunch; McKesson has not publicly attributed) | Primary source: McKesson official statements August 28 + September 8, 2026; HIPAA Journal — https://www.hipaajournal.com/mckesson-data-breach/ | TechCrunch — https://techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson/

2026-09-08 (HHS OCR count confirmed) | AdaptHealth LLC | Home Medical Equipment / Healthcare | USA | 4,115,802 individuals

AdaptHealth — a home medical equipment and supplies company serving approximately 4.1 million patients across all 50 U.S. states through 680 locations — filed 4,115,802 individuals with HHS OCR in September 2026. A social engineering attack on June 5, 2026 compromised the privileged account of a third-party contractor, giving unauthorized access to cloud-based patient management systems, document storage, and EHR portals. On June 15 the attacker demanded a ransom. AdaptHealth disclosed the incident via SEC 8-K on July 2; its August 14 update confirmed the June 5 intrusion date. Attribution remains unconfirmed: HIPAA Journal linked ShinyHunters to the attack; BleepingComputer found no active AdaptHealth listing on ShinyHunters’ portal at publication, suggesting possible removal after a settlement or other resolution. Exposed data includes names, addresses, dates of birth, Social Security numbers, health insurance, and medical information.

Severity: Major | Records: 4,115,802 (HHS OCR submission, September 2026) | Breach date: June 5, 2026 | Attack vector: Social engineering compromising a third-party contractor’s privileged account | Attribution: Unconfirmed (ShinyHunters linked per HIPAA Journal; not confirmed by AdaptHealth) | Primary source: HHS OCR breach portal; BleepingComputer — https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/

August 2026 (count confirmed)

2026-08-06 (HHS OCR count posted) | Unlimited Technology Systems LLC | Healthcare IT / Revenue Cycle Management | USA | 3,803,750 individuals

Unlimited Technology Systems (UTS), a Cincinnati, Ohio-based revenue cycle management and practice management software provider serving 4,500 clinics and 6,500 specialty healthcare providers and processing more than $70 billion in net healthcare charges annually, had its HHS OCR count posted on August 6, 2026: 3,803,750 individuals. The intrusion window was October 5–10, 2025 — five days of unauthorized access to UTS’s commercial data center, detected on October 19, 2025. Affected individuals began receiving notifications on July 1, 2026 — 254 days after detection. No ransomware group has claimed responsibility; UTS has not identified the perpetrators. Exposed data includes patient names, dates of birth, Social Security numbers, health insurance, and medical information belonging to patients of UTS’s healthcare provider clients.

Severity: Major | Records: 3,803,750 (HHS OCR breach portal, posted August 6, 2026) | Breach window: October 5–10, 2025 | Detection: October 19, 2025 | Notifications sent: July 1, 2026 (254 days post-detection) | Attack vector: Unauthorized access to commercial data center server; initial access method not disclosed | Attribution: Unknown | Primary source: HHS OCR breach portal; BleepingComputer — https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/ | HIPAA Journal — https://www.hipaajournal.com/patient-data-exposed-ohio-revenue-cycle-management-company/

August 2026

2026-06-04 (final HHS OCR filing) | Conduent Business Services LLC | Government Services / Business Process Outsourcing | USA | 62,224,658 individuals

Conduent Business Services LLC — a business process outsourcing firm that administers Medicaid claims, benefits disbursements, and HR services for more than 500 government and corporate clients across 30+ U.S. states — filed its final breach count with the HHS Office for Civil Rights on June 4, 2026: 62,224,658 individuals. That figure makes it the third-largest U.S. healthcare-linked data breach ever recorded, behind Change Healthcare (192.7 million, 2024) and Anthem (78.8 million, 2015). The breach window ran from October 21, 2024 to January 13, 2025 — 83 days of unauthorized network access before detection. The SafePay ransomware group claimed responsibility, asserting it had exfiltrated approximately 8.5 terabytes of data before deploying any encryption. The count climbed in three stages: initial estimates in the low tens of millions; a February 2026 revision to 25.5 million after Texas regulators pressed for detail; and the June 4 final total of 62,224,658, more than double the February figure. Exposed data includes names, postal addresses, dates of birth, Social Security numbers, medical information, health insurance details, and Medicaid claims data. Most affected individuals never interacted with Conduent directly — their data flowed through Conduent as a processing intermediary for their government benefit programs or employers. Conduent faces multiple federal class-action lawsuits and active investigations from Missouri, Montana, and Texas, as well as an HHS OCR HIPAA investigation. The company holds a cyber insurance policy and anticipated policy coverage for notification costs.

Severity: Critical | Records: 62,224,658 (HHS OCR final filing, June 4, 2026) | Breach window: October 21, 2024 – January 13, 2025 | Attack vector: SafePay ransomware; initial access via compromised credentials | Attribution: SafePay ransomware group (claimed; Conduent has not publicly named the group) | Primary source: HHS OCR breach portal filing June 4, 2026; HIPAA Journal analysis — https://www.hipaajournal.com/conduent-business-solutions-data-breach/ | BankInfoSecurity — https://www.bankinfosecurity.com/conduent-hack-victim-count-now-tops-622-million-a-31900

July 2026

2026-07-30 (notifications mailed) | SM Energy Company | Energy / Oil & Gas | USA | Scope not yet fully disclosed

Denver-based oil and gas producer SM Energy began mailing breach notifications on July 30, 2026, informing affected individuals that an intruder took files containing their Social Security numbers. The unauthorized access occurred on or around May 15, 2026; notifications were mailed 76 days later. State-level filings account for 3,931 affected residents across Texas, Massachusetts, and Vermont, while the national total has not been disclosed. Exposed records include names, postal addresses, email addresses, phone numbers, and Social Security or taxpayer identification numbers. SM Energy is offering 24 months of free Experian IdentityWorks credit monitoring, with enrollment deadline October 31, 2026.

Severity: Significant | Records: 3,931 confirmed across three state filings; national total undisclosed | Breach date: On or around May 15, 2026 | Attack vector: Not specified in available disclosures | Primary source: State AG breach notification filings (Texas, Massachusetts, Vermont); SM Energy breach notification letters, July 30, 2026

August 2026

2026-08-19 (HHS OCR confirmation) | CareCloud Inc. | Healthcare Technology / EHR SaaS | USA | 3,756,469 individuals

CareCloud, a New Jersey-based healthcare technology company providing electronic health records, medical billing, and practice management services to tens of thousands of U.S. providers, filed 3,756,469 affected individuals with the U.S. Department of Health and Human Services Office for Civil Rights in August 2026 — confirming the fifth-largest U.S. healthcare breach of 2026. The breach originated March 10–16, 2026, when an unauthorized third party accessed one of CareCloud’s six AWS environments, causing an eight-hour disruption. CareCloud first disclosed the incident via an SEC filing in March; state AG filings through late July had indicated roughly 345,000 affected individuals. The HHS OCR filing revealed the true scope was more than ten times larger. Stolen data — which varies by individual per notification letters filed with multiple state AGs — includes names, addresses, dates of birth, Social Security numbers, driver’s license and government ID numbers, financial account numbers, credit and debit card numbers, and medical and health insurance information. Notification letters began reaching affected individuals July 25, with identity protection through IDX offered to certain recipients through December 17, 2026. No threat actor has publicly claimed responsibility; CareCloud has not disclosed the attack vector beyond “unauthorized third party” accessing an AWS environment.

Severity: Critical (PHI + financial identifiers at scale) | Records: 3,756,469 (HHS OCR portal filing, August 2026) | Breach window: March 10–16, 2026 | Attack vector: Unauthorized access to AWS environment; method of initial access not publicly disclosed | Primary source: HHS OCR breach portal; HIPAA Journal — https://www.hipaajournal.com/carecloud-data-breach/ | BleepingComputer — https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/

2026-08-12 (HaveIBeenPwned confirmed) | RingCentral | Cloud Communications / SaaS | USA | 1,600,000 accounts

RingCentral, a cloud-based collaboration and communications platform used by more than 600,000 businesses globally, disclosed on July 28, 2026 that its systems were compromised in what it described as a “sophisticated social engineering campaign.” ShinyHunters claimed responsibility. HaveIBeenPwned confirmed on August 12, analyzing the leaked dataset, that 1,600,000 accounts were affected, with exposed data including names, email addresses, phone numbers, and physical addresses. RingCentral stated the attack did not impact the core platform and that no new unauthorized activity had been detected since remediation. The company has not confirmed whether the method was the Salesforce Aura vishing pattern ShinyHunters has used across dozens of 2026 incidents, or a separate vector. RingCentral did not publicly attribute the attack; the ShinyHunters attribution comes from the group’s own claim and HaveIBeenPwned’s independent analysis.

Severity: Significant | Records: 1,600,000 (HaveIBeenPwned analysis of published dataset, August 12, 2026) | Breach date: July 28, 2026 (disclosed) | Attack vector: Social engineering (“sophisticated social engineering campaign” per RingCentral); ShinyHunters claimed responsibility | Attribution: ShinyHunters (claimed; RingCentral has not publicly attributed) | Primary source: RingCentral disclosure July 28, 2026; BleepingComputer citing HaveIBeenPwned confirmation — https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/

2026-07-29 | IBM 2026 Cost of a Data Breach Report | Reference benchmark — not an incident entry

This is a reference entry for the IBM benchmark cited in Key Findings, not a breach incident. Included here for inline citation transparency.

IBM released its 2026 Cost of a Data Breach Report on July 29, 2026, based on data from 602 organizations that experienced breaches between March 2025 and February 2026. Global average: $4.99 million (record, +12% YoY). U.S. average: $11.5 million. Healthcare: highest-cost sector at $6.64 million (13th consecutive year at top). One in four malicious breaches were AI-enabled (deepfake impersonation and AI-generated malware), a 56% increase year-over-year; those incidents averaged $6 million. Mean time to identify and contain: 247 days. Organizations using security AI and automation averaged $1.9 million lower breach costs.

Primary source: IBM newsroom press release, July 29, 2026 — https://newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled,-costing-companies-6-million-on-average

2026-07-30 (notifications mailed) | SM Energy Company | Energy / Oil & Gas | USA | Scope not yet fully disclosed

KDDI Corporation, Japan’s second-largest telecommunications operator, disclosed on July 9, 2026 that threat actors exploited a zero-day vulnerability in a third-party system to access an email infrastructure used by five internet service providers operating under KDDI. The breach affected ISP-tier email accounts; the full count of individually impacted subscribers had not been published as of July 21, 2026. KDDI filed an official disclosure with Japanese regulatory authorities and engaged forensic experts. Attack vector: zero-day exploit in third-party email system. Extent of personal data accessed: email addresses and account metadata; financial data not confirmed exposed.

Severity: Significant | Records: Not yet quantified (ISP-scale) | Primary source: KDDI official security notice via SecurityWeek, July 9, 2026 — https://www.securityweek.com/category/data-breaches/

2026-07-07 | Accenture | Professional Services | USA | ~35 GB source code

A threat actor in early July 2026 claimed to have stolen approximately 35 GB of source code from Accenture, advertising the data for sale and sharing apparent evidence of access to an Azure DevOps repository. Accenture confirmed to BleepingComputer it was investigating the incident and that it contained the breach and experienced no operational impact. The stolen material was primarily source code, RSA keys, SSH keys, and Azure access tokens — a corporate IP incident rather than a consumer PII breach in the conventional sense. No record count of individually affected people has been established; this entry is included for its significance to enterprise supply chain risk.

Severity: Significant (corporate IP) | Records: N/A (source code exfiltration) | Attribution: Unconfirmed threat actor claim; Accenture confirmed investigation | Primary source: BleepingComputer, July 2026 — https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/

June–July 2026

2026-06-15 (investigation completed) | AssuranceAmerica | Insurance | USA | 6,998,886 individuals

AssuranceAmerica, an auto and renters insurance provider operating through over 9,500 independent agents across 14 U.S. states, detected suspicious activity on March 17, 2026, tracing the initial intrusion to March 16. The company completed its file review on June 15, 2026 and filed a breach notification with Maine’s Office of the Attorney General disclosing that 6,998,886 individuals were affected. Stolen data included names, contact information, automobile insurance policy details, and driver’s license numbers. The investigation was conducted with third-party cybersecurity experts. No ransomware was deployed; the incident was a targeted data exfiltration via a compromised employee account.

Severity: Major | Records: 6,998,886 (Maine AG filing) | Attack vector: Compromised employee account, social engineering | Primary source: Maine Office of the Attorney General breach notification, filed June 2026 — https://www.bleepingcomputer.com/news/security/assuranceamerica-data-breach-exposes-records-of-69-million-drivers/

2026-06-13 (detected) | One Medical / Amazon Health Services | Healthcare | USA | Scope under investigation

Amazon-owned primary care provider One Medical disclosed that an unauthorized party accessed a third-party file storage system holding archived records for its senior care division (formerly Iora Health, acquired 2021 from Amazon’s earlier acquisition). One Medical detected the access on June 13, 2026, and determined unauthorized actors reached the platform between June 8 and 11. The company stated the incident was limited to legacy data for One Medical Seniors patients and did not affect main EMR systems or other divisions. ShinyHunters claimed 8.8 terabytes of data and set a June 22 deadline before publishing. The exact number of individuals affected had not been confirmed in an official notification as of July 21, 2026; this entry reflects confirmed unauthorized access per the company’s own disclosure.

Severity: Significant | Records: Under investigation (official figure not yet filed) | Attribution: Company-confirmed access; ShinyHunters claimed responsibility | Primary source: pkware.com summary citing company disclosure — https://www.pkware.com/blog/2026-data-breaches

May 2026

2026-05-27 (notifications sent) | Carnival Corporation & plc | Travel / Hospitality | USA / UK | 5,995,277 individuals (official filing)

Carnival Corporation, the world’s largest cruise line operator, notified approximately 6 million customers beginning May 27, 2026 that personal information was illegally copied from its systems in an April 2026 social engineering attack. An unauthorized actor deceived an employee and gained access to limited portions of Carnival’s IT infrastructure. Carnival detected the breach on April 14, 2026 and determined on April 22 that personal information had been copied. State AG filings — including Maine — confirm 5,995,277 affected individuals. The attack was claimed by ShinyHunters, which published 8.7 million records after its extortion attempt failed; HaveIBeenPwned independently analyzed the published dataset and found 7.5 million unique email addresses, appearing to relate specifically to the Mariner Society loyalty program operated by Holland America Line. Exposed data includes names, dates of birth, genders, email addresses, and loyalty program data. Three class action lawsuits (Pottle v. Carnival Corp., Case No. 1:26-cv-22801; Vasquez v. Carnival Corporation, Case No. 1:26-cv-22866-CMA) were filed in the U.S. District Court for the Southern District of Florida.

Severity: Major | Records: 5,995,277 (official state AG filings); 7.5M unique emails per HaveIBeenPwned analysis | Attack vector: Social engineering / compromised employee account | Attribution: ShinyHunters (claimed; Carnival has not publicly attributed) | Primary source: Carnival Corporation data breach notification letters dated May 27, 2026; Maine AG filing; HaveIBeenPwned breach record — https://haveibeenpwned.com/Breach/Carnival | BleepingComputer: https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/

2026-05-07 (second intrusion) | Canvas LMS / Instructure | Education Technology | USA / International | Scope: names, emails, student IDs, messages

Canvas LMS, operated by Instructure and used by universities and school districts globally, suffered two intrusions in April–May 2026, both attributed to ShinyHunters. Unauthorized actors first accessed Canvas systems on April 25; Instructure detected the intrusion on April 29, revoked access, and disclosed the incident on May 1. On May 7, despite Instructure’s claim of containment, ShinyHunters replaced Canvas’s login page with a ransomware message, confirming continued or re-established access. Instructure disclosed that exposed data included names, email addresses, student ID numbers, and messages among users. The company found no evidence that passwords, dates of birth, government IDs, or financial information were involved. Total individual count was not confirmed in an official filing as of July 21, 2026; given Canvas’s global install base across higher education, the exposure scale is significant.

Severity: Significant | Records: Not yet quantified (global higher education scale) | Attack vector: Not disclosed by Instructure | Attribution: ShinyHunters | Primary source: Instructure status page disclosure, May 1, 2026; Wikipedia incident summary citing Instructure — https://en.wikipedia.org/wiki/2026_Canvas_data_breach

2026-05-04 (disclosed) | Trellix | Cybersecurity / Technology | USA | Source code repository accessed

Trellix, the cybersecurity firm formed from the merger of McAfee Enterprise and FireEye in 2021 and serving more than 50,000 enterprise and government customers globally, disclosed on May 4, 2026 that unauthorized access to part of its source code repository had been identified. Trellix stated it engaged forensic experts, notified law enforcement, and found no evidence that source code was released publicly. No count of individually affected people was established; this is a corporate IP incident without confirmed consumer PII exposure. Included for its significance to the 50,000+ organizations relying on Trellix’s security products.

Severity: Significant (corporate IP, no confirmed PII breach) | Records: N/A | Primary source: Company disclosure cited by BrightDefense — https://www.brightdefense.com/resources/recent-data-breaches/

April 2026

2026-04-20 (disclosed) | France Titres / ANTS | Government / National Infrastructure | France | 11.7 million accounts confirmed affected

France Titres (Agence Nationale des Titres Sécurisés, the French agency responsible for national identity documents, driver’s licenses, and passports) detected suspicious activity on April 13, 2026, notified French authorities on April 16, and disclosed publicly on April 20. A threat actor using the handle “breach3d” claimed up to 19 million records. France Titres’ own updated count confirmed 11.7 million affected accounts. Exposed fields per the agency’s disclosure include names, email addresses, dates of birth, postal addresses, phone numbers, login IDs, and unique account identifiers from the ants.gouv.fr portal. Access involved both individual and professional accounts. This is among the largest confirmed breaches of a European government identity infrastructure in 2026.

Severity: Critical | Records: 11.7 million (France Titres official confirmed count) | Sector: National government identity infrastructure | Primary source: France Titres official disclosure; BrightDefense incident log citing agency update — https://www.brightdefense.com/resources/recent-data-breaches/

March 2026

2026-03-19 (disclosed) | Aura | Cybersecurity / Consumer Identity Protection | USA | 900,000 records

Aura, a Burlington, Massachusetts-based digital safety company selling identity theft protection and credit monitoring, disclosed on March 19, 2026 that ShinyHunters had gained access to an employee account via a targeted voice phishing attack and accessed approximately 900,000 records from a marketing database. Exposed data included names, home addresses, telephone numbers, and email addresses. Aura confirmed that core identity protection systems were not compromised and that Social Security numbers, passwords, credit records, and financial information were not exposed. The incident drew attention partly due to the role reversal: a firm that sells protection against identity compromise had itself been breached via a social engineering method its own services warn against.

Severity: Moderate | Records: ~900,000 (company disclosure) | Attack vector: Voice phishing (vishing) targeting Okta SSO credential | Attribution: ShinyHunters | Primary source: SecurityWeek, Ionut Arghire, March 19, 2026 — https://securityweek.com/security-firm-aura-discloses-data-breach-impacting-900000-records/ | HaveIBeenPwned breach record

February 2026

2026-02 (notified) | Figure Lending LLC | Fintech / Financial Services | USA | 3 million+ records

Figure Lending LLC, a U.S. fintech lender, confirmed in February 2026 that a social engineering attack gave hackers access to its internal systems via the company’s Okta SSO environment. ShinyHunters claimed responsibility and published 2.5 GB of stolen files after Figure declined to pay a ransom. The breach exposed more than 3 million records including names, dates of birth, physical addresses, phone numbers, email addresses, passwords, and Social Security numbers. Figure notified affected individuals in late February 2026 and offered complimentary credit monitoring services. Attack vector mirrors the pattern used by ShinyHunters across its 2025–2026 campaign: voice phishing targeting Okta SSO credentials.

Severity: Major | Records: 3 million+ (company disclosure cited by Proton Business) | Attack vector: Vishing targeting Okta SSO credentials | Attribution: ShinyHunters | Primary source: Company breach notification; Proton Business breach observatory — https://proton.me/business/pass/breach-observatory-details

January 2026

2026-01 (disclosed) | Crunchbase | Business Intelligence / SaaS | USA | 1.5 million+ records

Crunchbase, the market intelligence platform, confirmed a data breach in January 2026 after ShinyHunters published over 400 MB of files stolen from its corporate network following a failed ransom attempt. The attack originated from a voice phishing campaign targeting Okta SSO credentials. Exposed data affecting more than 1.5 million records included names, dates of birth, physical addresses, phone numbers, email addresses, usernames, and internal corporate documents and contracts. Crunchbase engaged cybersecurity experts and notified federal law enforcement, stating no business operations were disrupted.

Severity: Significant | Records: 1.5 million+ (company disclosure cited by Proton Business) | Attack vector: Voice phishing targeting Okta SSO credentials | Attribution: ShinyHunters | Primary source: Company breach notification; Proton Business breach observatory — https://proton.me/business/pass/breach-observatory-details

Axis Intelligence Research Breach Concentration Index™ (BCI)

What the BCI measures

The Axis Intelligence Research Breach Concentration Index™ measures how concentrated the total exposure across a given period is among the largest incidents. A BCI of 1.0 means a single incident accounts for all tracked exposure. A BCI of 0.0 means exposure is perfectly distributed across all incidents. High concentration indicates that a small number of mega-breaches drive the aggregate count, which matters for risk modeling: organizations operating in sectors that produced the mega-breaches face disproportionate regulatory and litigation exposure that aggregate statistics obscure.

Formula

The BCI is calculated using the Herfindahl-Hirschman Index adapted to breach records:

BCI = Σ (records_i / total_records)²
      for each incident i with a confirmed record count

Incidents without a confirmed record count (source code exfiltrations, investigations in progress) are excluded from the calculation but flagged in the tracker.

Reading v1.0 — October 4, 2026

Confirmed record counts in calculation (entries with official counts):

IncidentRecords (official)Source
Conduent Business Services62,224,658HHS OCR filing, June 4, 2026
France Titres / ANTS11,700,000France Titres disclosure, April 2026
AssuranceAmerica6,998,886Maine AG filing, June 2026
Carnival Corporation5,995,277State AG filings, May 2026
AdaptHealth4,115,802HHS OCR submission, September 2026
Unlimited Technology Systems3,803,750HHS OCR portal, August 6, 2026
CareCloud3,756,469HHS OCR portal, August 2026
DMDC (U.S. Department of Defense)3,054,000DoD official count, notification letters Sept 18, 2026
Figure Lending3,000,000Company notification, February 2026
Crunchbase1,500,000Company notification, January 2026
Aura900,000Company disclosure, March 2026

Total confirmed records in calculation: 107,048,842

BCI calculation (v1.0, reading 5, October 4, 2026):

  • Conduent: 62,224,658 / 107,048,842 = 0.5813 → squared: 0.3379
  • France Titres: 11,700,000 / 107,048,842 = 0.1093 → squared: 0.01195
  • AssuranceAmerica: 6,998,886 / 107,048,842 = 0.06538 → squared: 0.004275
  • Carnival: 5,995,277 / 107,048,842 = 0.05601 → squared: 0.003137
  • AdaptHealth: 4,115,802 / 107,048,842 = 0.03845 → squared: 0.001478
  • UTS: 3,803,750 / 107,048,842 = 0.03553 → squared: 0.001263
  • CareCloud: 3,756,469 / 107,048,842 = 0.03509 → squared: 0.001231
  • DMDC: 3,054,000 / 107,048,842 = 0.02853 → squared: 0.000814
  • Figure Lending: 3,000,000 / 107,048,842 = 0.02803 → squared: 0.000785
  • Crunchbase: 1,500,000 / 107,048,842 = 0.01401 → squared: 0.000196
  • Aura: 900,000 / 107,048,842 = 0.008407 → squared: 0.0000707

BCI (October 4, 2026): 0.363

Change from prior reading: −0.020 (from 0.383 on September 20, 2026)

Interpretation: The DMDC is the first U.S. federal government entry in this tracker, and it moves the index the same direction every mid-scale confirmation has since August: down, as the denominator widens. Conduent still supplies 0.338 of the 0.363 reading. The more telling number is not the BCI but the dwell time — roughly nine months of access to unencrypted Social Security numbers inside a Pentagon system, set against the 83 days Conduent’s attackers spent inside its network. McKesson’s HHS OCR filing, due within the statutory 60-day window, is the next event likely to move the index materially.

Note: Canvas/Instructure has not filed a confirmed individual count with HHS OCR or a U.S. state AG. The ITRC’s 275M victim-notice attribution is a supply-chain notice estimate, not a regulatory record count. Canvas remains in the tracker as a significant entry without a BCI-eligible count.

Methodology

Source hierarchy

  1. Tier 1 (primary, required for entry): State Attorney General breach notification filings (Maine, California, Texas most commonly public); HHS OCR breach portal entries (healthcare); official company notification letters; national data protection authority decisions (CNIL for France, ICO for UK); official regulatory filings (SEC 8-K for public companies).
  2. Tier 2 (used to locate Tier 1 sources): BleepingComputer, SecurityWeek, Malwarebytes blog, HaveIBeenPwned breach records. These are referenced in entry citations only where they directly cite Tier 1 documentation.
  3. Not used as sole source: General news aggregators, forum posts, threat actor claims without organizational acknowledgment.

Record counts

Official notification figures govern. Where an organization files with multiple state AGs, the largest disclosed count is used (states differ in reporting requirements). HaveIBeenPwned analysis figures are cited alongside but do not replace official notification counts.

Severity classification

  • Critical: Government identity infrastructure or critical national infrastructure; healthcare at 1M+ records including clinical data; multi-sector cascading impact
  • Major: 1M+ consumer records exposed, including financial identifiers (SSN, IBAN, account numbers) or healthcare data
  • Significant: Large-scale consumer PII (name, email, address) without financial identifiers, or major corporate IP exfiltration
  • Moderate: Under 1M records, PII limited to contact information

BCI methodology

Disclosed in full in the Axis Intelligence Research Breach Concentration Index section above. The index is recomputed as new confirmed counts become available. Incidents with unconfirmed record counts are excluded from the calculation until official figures are filed. The index version is recorded per reading: current version is v1.0.

About This Dataset

Dataset: Axis Intelligence Research Data Breach Tracker 2026

Creator/Publisher: Axis Intelligence Research Coverage: January 1, 2026 – present

Geographic scope: Global; primary focus on incidents with U.S. regulatory filings or EU/UK data protection authority disclosures

Update cadence: Weekly, or immediately upon any incident exceeding 1 million confirmed records

License: CC BY 4.0 — Axis Intelligence Research, Axis Data Breach Tracker 2026 (https://axis-intelligence.com/data-breach-tracker/)

Citation: Axis Intelligence Research. (2026). Axis Data Breach Tracker 2026. https://axis-intelligence.com/data-breach-tracker/

Last updated: October 4, 2026

Frequently Asked Questions

What is the largest confirmed data breach of 2026 so far?

By official notification count, France Titres (ANTS) confirmed 11.7 million affected accounts in April 2026 — the largest single incident in this tracker with an official figure. Carnival Corporation confirmed 5,995,277 in state AG filings, though HaveIBeenPwned’s independent analysis of the published data found 7.5 million unique email addresses in the leaked dataset. The two figures are not contradictory; they reflect different measurement approaches (official notification vs. independently analyzed leak content).

Is ShinyHunters responsible for all 2026 breaches?

No, but ShinyHunters is the confirmed or claimed actor in a disproportionate share of tracked incidents. The group’s 2025–2026 campaign leveraged a consistent attack pattern: voice phishing (vishing) targeting Okta SSO credentials, followed by data exfiltration and ransom demands, with public data publication if the target declined to pay. Confirmed or claimed ShinyHunters incidents in this tracker include Carnival, Canvas/Instructure, Aura, Figure Lending, and Crunchbase. France Titres, AssuranceAmerica, and KDDI are not attributed to ShinyHunters in official disclosures.

How is the Axis Breach Concentration Index different from a simple record count?

A total record count tells you aggregate scale. The BCI tells you whether that scale is driven by a single catastrophic event or distributed across many incidents. An index of 0.85 (near 2024 H1 with Change Healthcare dominant) and an index of 0.25 (2026 H1) can represent similar total exposed records, but carry completely different implications for sector risk, regulatory exposure, and whether the “headline number” reflects a systemic problem or an outlier event.

Where do you get breach record counts?

The primary source for record counts is official breach notification filings — Maine’s Office of the Attorney General publishes all breach filings publicly, as does Texas, California, and several other states. For healthcare entities, the HHS OCR breach portal is the primary source. For EU incidents, national DPA decisions (CNIL for France, ICO for UK) provide official figures. HaveIBeenPwned independently analyzes published leak datasets and provides alternative counts, which we cite alongside official figures where they differ.

What about breaches that haven’t been publicly confirmed?

Unconfirmed threat actor claims are noted in our research queue but not entered as tracker rows. A claim by ShinyHunters or any other group without an official disclosure, state AG filing, or regulatory acknowledgment does not meet our inclusion criteria. We monitor primary sources — state AG filings, SEC 8-Ks, HHS OCR portal updates — for confirmation, at which point a row is added.

How often is this tracker updated?

Weekly at minimum. Any incident confirmed with 1 million or more records triggers an immediate update, regardless of day of week.


External primary sources:

  • ITRC H1 2026 Data Breach Report (July 22, 2026): https://www.idtheftcenter.org/post/mega-breaches-malicious-insiders-h1-2026-data-breach-report/
  • Verizon 2026 Data Breach Investigations Report (PDF): https://www.verizon.com/business/resources/T1ae/reports/2026-dbir-data-breach-investigations-report.pdf
  • HHS OCR Breach Portal (healthcare breaches 500+): https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
  • Maine AG breach notification database: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/mainpage.html
  • HaveIBeenPwned breach list: https://haveibeenpwned.com/Breaches

Go Deeper

Axis Intelligence Research

Stay ahead on tech & data

Get notified when we publish or update datasets, trackers, research, and reports across technology, business, AI, cybersecurity, finance, infrastructure, energy, and more.

Research updates only. No spam. Unsubscribe anytime.