Searching for 2026 data breach roundup, biggest hacks first half 2026, or ransomware attacks January–June 2026? The first six months of 2026 delivered one of the densest breach calendars in recent memory—mega-forum listings, state-scale misconfigurations, OAuth supply-chain cascades, and a ShinyHunters summer that hit retailers, pharma, intergovernmental bodies, and even cybersecurity firms. This is BreachHistory's consolidated guide to H1 2026: what happened, who was affected, and what patterns defenders should carry into the second half of the year.
Scope note: Our database indexes 896 incidents with 2026 primary dates through June 30. Counts below distinguish company-confirmed or regulator-attested events from unverified actor/forum claims. Record totals can overlap (re-posted archives, row counts vs. unique individuals) — we cite source-attested figures and label uncertainty explicitly.
H1 2026 at a glance
- 896 indexed incidents (Jan–Jun 2026 primary dates)
- 362+ ransomware or extortion-linked rows (leak-site listings, double-extortion, or named gangs)
- Peak months: May (212) and February (163) by catalog volume; June concentrated high-profile retail, pharma, and infrastructure events
- Top attack patterns: extortion leak sites, OAuth/SaaS supply chain, cloud misconfiguration, infostealer-driven credential theft, and legacy data recirculation on criminal forums
Q1 2026 (January–March): Extortion meets mega-exposure
January — ShinyHunters, Target, and dating-app API abuse
January set the tone. ShinyHunters hit Match Group (~10M records across Tinder/Hinge/OkCupid APIs), Panera Bread (5.1M+ customer emails), and fueled parallel retail extortion. Nike faced WorldLeaks data-extortion marketing (~1.4 TB internal files). Target suffered a dual blow: ~860 GB proprietary source code exposed via misconfigured Git access and infostealer-compromised employee workstations (tgt2026inf). Under Armour / MyFitnessPal saw ~72.7M emails reload on HIBP after Everest-group marketing.
February — Telecom, retail, and regulatory shockwaves
Odido (Netherlands' largest telecom) confirmed hackers exfiltrated a customer-contact file potentially covering 6.2 million people—names, addresses, IBANs, passport and driver's license data. Coupang disclosed 37.55 million accounts and drew a record ₩624.6B fine from South Korea's PIPC. Canadian Tire reported 38M+ accounts breached. Cashea (Venezuela BNPL) appeared on forums with ~79M transaction rows—still treated as unverified marketing at catalog time.
March — Billion-row misconfigurations
Researcher-driven discoveries dominated headlines without traditional "hack" narratives:
- SpeedX — 840M+ delivery files on misconfigured Azure Blob storage
- Infutor — 676.8M rows in misconfigured Elasticsearch
- Cybernews China Elasticsearch — researcher estimate of 8.7B citizen/business rows (exposure, not confirmed exfiltration to criminals)
These incidents underscore that "breach volume" in 2026 often means publicly reachable data lakes, not just ransomware encryption events.
Q2 2026 (April–June): Forums, ransomware industrialization, and supply chains
April — Gaming, beauty, and recirculated national data
Rockstar Games (~78.6M rows via third-party/Snowflake-token path), L'Oréal / Alinto SMTP metadata exposures (~40M rows), and forum recirculation of Serasa Experian Brazil historic dossiers (223M+) filled April's threat-intel feeds. GrayRobinson law firm notified 65,113 individuals in April for a 2025 intrusion—typical of H1's long-delayed disclosure wave.
May — Mega-forum listings and sector ransomware
May's forum economy produced eye-watering claims:
- OnlyFans — hackers claimed 340M records; company denied a breach
- MyDukaan — ~100M user database offered for ~$10K (unverified)
- Instructure Canvas — cyberattack affecting user identifiers across education customers (~275M figure cited in trade press with caveats)
Ransomware clusters included Everest financial-sector listings (Fiserv, Symcor, Epiq Global), and West Pharmaceutical Services—which detected unauthorized activity May 4, confirmed material encryption May 7, and returned to full operations by mid-May. Kyushu Electric Power lost an unencrypted backup SSD potentially affecting 10.9 million utility customers—a physical-loss breach, not ransomware.
June — The ShinyHunters summer
June 2026 may be remembered as the month extortion went fully horizontal:
- ShinyHunters wave (June 12–18): JCPenney (~368K staff emails alleged), Ralph Lauren (220 GB claim), One Medical (8.8 TB claim), Council of Europe (297 GB HR/payroll), Eastman Kodak (2.2M+ confirmed with ShinyHunters overlap), IC Security (2.7M+ claim vs. a cybersecurity vendor)
- Oracle PeopleSoft CVE-2026-35273 tied to the wider ShinyHunters HR/payroll campaign in trade press
- Texas government: Texas Parks & Wildlife — 3,087,721 hunters/anglers; driver's licenses and passport numbers via license vendor (company-confirmed)
- Pharma twin extortion: Novo Nordisk company-confirmed clinical-trial copy (June 11) plus separate FulcrumSec ($25M) and TheUSERS007 ($50M IP) claims
- Education crisis: Global Schools Group — FulcrumSec; 183,164 student/parent/staff rows; Bombay High Court injunction on children's mental-health data
- OAuth supply chain: Klue token theft → Salesforce CRM exfiltration from Huntress, Tanium, Jamf; Icarus leak site June 21
- Developer supply chain: Mastra npm — 141 @mastra packages backdoored via
easy-day-jstyposquat RAT (June 17) - Network infrastructure: FortiBleed — 75,000 verified FortiGate admin/SSL VPN credentials across 194 countries
- France: Tchap government messaging — 73,467 civil servants in hijacked public rooms
- UK automotive forum listing: Mercedes-Benz UK 130K records (May forum listing; Mercedes cites prior dealership incident)
Ransomware & extortion: who showed up in H1?
BreachHistory tracked 362+ ransomware or extortion-linked incidents in H1 2026. Leak-site economics—not encryption alone—drove most headlines.
Group / patternH1 footprintNotable victims ShinyHuntersRetail, HR, pharma, IG bodies, cyber firmsMatch, Panera, JCPenney, Kodak, Council of Europe, IC Security QilinDaily SMB/mid-market listingsRoth Industries, Sparkle Pools, Pro-MEC Engineering, dozens of May–June rows TheGentlemenHealthcare, legal, LATAM/Asia industrialsSouth Texas Spinal Clinic, Athens Orthopedic, Calipage Humblet FulcrumSecHigh-impact education & pharmaGlobal Schools Group, Novo Nordisk overlay Everest / WorldLeaksPure data extortionNike, Fiserv cluster, Under Armour marketing IcarusOAuth/SaaS downstream extortionKlue supply-chain victims Akira / Aurora / LockBit5Steady churnALS Limited (Aurora, unverified), municipal & legal SMBsKey trend: Many June listings remain unverified—actors publish deadlines, sample files, and SEO-friendly "FINAL WARNING" copy faster than victims can confirm. BreachHistory labels these explicitly; consumers should wait for official notices before assuming exposure.
Beyond ransomware: supply chain, misconfig, and infostealers
- OAuth token theft — Klue followed the 2025 Salesloft/Drift pattern: compromise a SaaS integrator, steal OAuth tokens, query customer Salesforce instances directly.
- npm/package typosquats — Mastra/easy-day-js showed maintainer-token abuse beats source-repo integrity; install-time RATs with OS persistence.
- Infostealers → enterprise access — Target employee workstations; FortiBleed's 75K credentials likely mixed infostealer logs with firewall targeting.
- Physical media loss — Kyushu Electric's missing unencrypted SSD proves not every mega-breach starts with ransomware.
- Forum recirculation — Serasa, AT&T decrypted SSN resurfacing, and Instagram 2024 API data reposted in 2026 remind us old breaches never die—they get repriced.
Healthcare & government highlights
- Blue Fish Pediatrics — 41,485 Texans notified June 2026 for July 2025 PHI access
- HCRG Care Group — Medusa ransomware; UK patients first notified 15 months after the attack
- University of Nottingham — 454,600 students/alumni
- Nintendo of America — TinyPulse employee survey data stolen (confirmed); separate ShadowByte$ claim
What H1 2026 teaches defenders
- Treat leak sites as intelligence, not ground truth — Index actor claims separately from confirmed rows; stock markets (see Novo Nordisk) may shrug before victims finish forensics.
- Segment OAuth integrators — Any vendor holding Salesforce/HubSpot tokens is a tier-0 supplier; monitor API logs for anomalous query clients.
- HR/payroll is the new crown jewels — PeopleSoft CVE-2026-35273 and ShinyHunters' June HR corpus show payroll systems are extortion magnets.
- Firewall credentials are a global commodity — FortiBleed proved 75K verified admin logins across 194 countries; patch, rotate, and assume infostealer overlap.
- Children's data draws courts — Global Schools Group's Bombay injunction signals regulators will intervene when K-12 mental-health data is threatened.
- Assume breach fatigue among users — Billion-row headlines desensitize the public; focus consumer guidance on confirmed notices and phishing tied to real stolen fields.
Explore the full timeline
Every incident above links to its canonical BreachHistory record with sources, technical writeups, and share metadata. Browse the full 2026 catalog, read our January 2026 deep dive, or search any company for recurrence patterns across years.
Compiled from BreachHistory database indexing and public reporting through June 21, 2026. Record totals reflect source-attested figures; unverified actor claims are labeled throughout the catalog.