Searching for the biggest data breaches of 2026, a top hacks 2026 list, or largest cyber attacks this year? This page ranks the incidents BreachHistory tracks by impact—record counts, sector risk, and disclosure quality—with direct links to each company's canonical breach timeline. We separate confirmed disclosures from unverified forum or leak-site claims so you know what is attested vs. actor marketing.
Last updated: June 2026. BreachHistory indexes 900+ incidents with 2026 dates; this list highlights the top tier by scale and public significance.
Quick answer: top 10 data breaches of 2026
- Texas Parks & Wildlife — 3.09M hunters/anglers; DL + passport data (confirmed)
- Kyushu Electric Power — up to 10.9M utility customers; lost backup SSD (confirmed)
- Coupang — 37.55M accounts; record regulatory fine (confirmed)
- Canadian Tire — 38M+ accounts (confirmed)
- Odido — 6.2M telecom customers; passport/DL data (confirmed)
- Eastman Kodak — 2.2M+ (confirmed; ShinyHunters overlap)
- SpeedX — 840M+ files on misconfigured Azure storage (researcher discovery)
- Infutor — 676.8M rows in exposed Elasticsearch (researcher discovery)
- FortiBleed — 75,000 verified FortiGate admin/VPN credentials across 194 countries
- Global Schools Group — 183K+ student/parent accounts; children's sensitive data (FulcrumSec; court injunction)
Largest data breaches of 2026 by records exposed
Record totals are not additive—many forum listings recycle old archives or cite database rows rather than unique individuals. The table below ranks source-attested volumes BreachHistory indexes.
RankIncidentRecordsStatus 1China Elasticsearch exposure8.7B (est.)Researcher discovery 2UpGuard Hetzner Elasticsearch5.7B (est.)Researcher discovery 3SpeedX Azure misconfiguration840M+Exposure 4Infutor676.8MMisconfiguration 5OnlyFans forum claim340MUnverified; company denied 6Instructure Canvas275M (cited)Cyberattack 7Under Armour / MyFitnessPal72.7MHIBP / extortion marketing 8Rockstar Games78.6MThird-party path 9MyDukaan forum listing100MUnverified 10Coupang37.55MConfirmedTop confirmed corporate & government breaches of 2026
These incidents have company, regulator, or forensic attestation—not just leak-site marketing.
Texas Parks & Wildlife — 3.09 million license customers
June 2026's clearest U.S. government mega-breach: an external hunting/fishing license vendor compromise exposed driver's license numbers, passport numbers, addresses, email, and phone for 3,087,721 customers. TPWD confirmed SSNs and payment cards were not impacted. Full timeline →
Odido — 6.2 million Dutch telecom subscribers
Netherlands' largest carrier confirmed a customer-contact file theft including IBANs, passport data, and driver's licenses—potentially half the country's population. Full timeline →
Coupang & Canadian Tire — ~38 million accounts each
Two retail giants disclosed eight-figure account breaches in the same quarter. Coupang also received a record South Korean privacy fine. Coupang · Canadian Tire
Kyushu Electric Power — up to 10.9 million customers
A missing unencrypted backup SSD from a server-room cabinet—not ransomware—potentially exposed names, addresses, usage data, and phone numbers across the Kyushu region. Full timeline →
Eastman Kodak — 2.2 million+
One of June's few brand-name confirmations amid the ShinyHunters wave. Customer and corporate data categories confirmed while actor overlap remains under investigation. Full timeline →
University of Nottingham — 454,600 students and alumni
Student record system breach affecting nearly half a million people—representative of continued higher-ed targeting in 2026. Full timeline →
Top ransomware & extortion incidents of 2026
2026 ransomware increasingly meant leak-site deadlines rather than encrypted files alone. Major groups and victims:
- ShinyHunters — Match Group (~10M), Panera (5.1M+), JCPenney (~368K alleged), Council of Europe, IC Security (2.7M+ claim)
- FulcrumSec — Global Schools Group (183K+; children's data; court injunction)
- Everest / WorldLeaks — Nike (~1.4 TB extortion), Fiserv financial-sector listings
- Icarus — downstream extortion after Klue OAuth Salesforce CRM theft
- Novo Nordisk — company-confirmed clinical-trial incident plus separate $25M and $50M dual extortion claims
Many June listings remain unverified until victims publish notices. BreachHistory labels actor-only rows explicitly.
Top supply-chain & infrastructure breaches of 2026
- FortiBleed — 75,000 verified FortiGate administrator and SSL VPN credentials; 320K+ devices targeted worldwide
- Klue OAuth — stolen integration tokens used to exfiltrate Salesforce data from Huntress, Tanium, Jamf, and others
- Mastra npm — 141 @mastra packages backdoored via easy-day-js typosquat RAT
- Target source code — ~860 GB internal repos exposed via misconfigured Git access
Retail, dating & consumer apps in 2026 breach headlines
- ManoMano — 38M accounts (Zendesk third-party path)
- SoundCloud — 29.8M (ShinyHunters)
- Match Group — Tinder, Hinge, OkCupid API scrape (~10M)
- Betterment — 1.4M (social-engineering internal messaging compromise)
- Mercedes-Benz UK — 130K forum listing (company cites prior dealership incident)
How to check if you were affected
- Search the company on BreachHistory for confirmed data categories and official source links.
- Wait for official notices — letters, email, or regulator postings. Ignore Tor leak downloads and "check your SSN" phishing.
- Enable MFA on every account that supports it; rotate passwords that were reused.
- Credit freeze or fraud alert if SSNs, passport numbers, or driver's licenses were confirmed exposed.
- Check Have I Been Pwned for email matches — but HIBP is not exhaustive for 2026 disclosures still in investigation.
FAQ
What was the biggest confirmed data breach of 2026 so far?
Among attested corporate/government disclosures with clear victim impact, Texas Parks & Wildlife (3.09M), Coupang and Canadian Tire (~38M each), Kyushu Electric (up to 10.9M), and Odido (6.2M) rank at the top. Billion-row figures usually reflect cloud misconfigurations or unverified forum marketing rather than a single confirmed theft event.
Is ShinyHunters the biggest threat in 2026?
ShinyHunters generated the most high-profile headlines in June 2026—retail HR, pharma, intergovernmental HR, and cybersecurity firms listed within days. Trade press tied the campaign to Oracle PeopleSoft CVE-2026-35273. Many listings remain unverified until victims confirm scope.
Where can I find the full 2026 breach timeline?
Browse BreachHistory by company or read our H1 2026 detailed roundup for quarter-by-quarter analysis.
Bottom line
2026's top data breaches span government ID theft at scale, retail account mega-disclosures, billion-row cloud exposures, firewall credential catastrophes, and an extortion economy that posts victims faster than companies can respond. Use this list as a starting point—every link above opens the full BreachHistory record with sources, technical writeups, and updates as disclosures mature.
Sources: BreachHistory database indexing and public reporting through June 2026. Record counts reflect source-attested figures; unverified claims are labeled in the catalog.