CYBER NEWS

The 10 Biggest Cyber Hacks of 2026

From a New Zealand hospital portal to a lost hard drive at a Japanese power utility, here are ten of the year's most significant confirmed and reported breaches — a genuinely global snapshot of how 2026 has gone wrong for cybersecurity.

Last updated: 13/09/2026
A note on accuracy before you read on: this list is compiled from independent breach-tracking sources and news reporting. Entries 1, 2, 3, 5, 8 and 9 were re-verified against primary sources in September 2026, including the Office of the Privacy Commissioner, South Korea's PIPC, Have I Been Pwned and company disclosures. Some entries describe incidents that began in 2025 but were confirmed, disclosed or penalised during 2026 — each is dated so you can see which. A few figures below (marked clearly) are claims made by attackers or third-party trackers rather than numbers the affected company has confirmed itself — we've flagged those explicitly rather than presenting disputed figures as settled fact. 2026 isn't over, so this list reflects the year so far, not the full picture.
1 🇺🇸

Instructure (Canvas LMS) — United States

Up to 275 million people (claimed)

Education technology giant Instructure — whose Canvas platform is used by schools and universities worldwide — was breached twice by the same hacking group, ShinyHunters, within eight months. Attackers reportedly abused Instructure's "Free-For-Teacher" program to gain a foothold, then exfiltrated roughly 3.65TB of student and faculty data, including names, emails, student ID numbers, course enrolment details, and private messages sent inside Canvas.

Instructure reached an agreement with the group on 11 May 2026, after which the data was reportedly returned and destroyed. The 275 million figure remains an attacker claim, not independently confirmed by Instructure — but even conservative counts make this the largest education-sector breach on record.

2 🇨🇦

Canadian Tire — Canada

~38 million accounts

One of Canada's largest retail and automotive companies confirmed a breach of its e-commerce database, first detected on 2 October 2025 and affecting accounts across Canadian Tire, SportChek, Mark's/L'Équipeur and Party City. The full dataset only surfaced publicly in February 2026, meaning the records circulated for roughly five months before customers could know. Exposed data included names, addresses, dates of birth, hashed passwords and, for some records, masked card details.

3 🇰🇷

Coupang — South Korea

37.55 million accounts

South Korea's largest e-commerce platform disclosed this breach in late 2025, but it belongs on a 2026 list because of what followed: in June 2026 the Personal Information Protection Commission fined Coupang 624.6 billion won (around US$409 million), the largest data protection penalty in Korean history. The regulator confirmed 37.55 million people affected — 33.22 million members plus 4.34 million non-members whose details had been stored as delivery recipients by other customers, and who had no way of knowing the company held their data. The PIPC attributed it to basic failures in authentication key management and access control rather than sophisticated hacking.

4 🇻🇳

Vietnam Airlines — Vietnam

23 million records

Hackers uploaded 23 million customer records to a public forum, spanning data collected between November 2020 and June 2025. Vietnam Airlines said the breach stemmed from a compromised third-party platform, not its own core systems — a good example of how your data can be exposed even when the company you trust directly wasn't the one that was hacked.

5 🇯🇵

Kyushu Electric Power — Japan

Up to 10.9 million customers

Not every major breach on this list is a sophisticated hack. This one happened because a backup SSD containing customer data went missing from an unlocked cabinet in a server room between 27 April and 26 May 2026. The drive was neither encrypted nor password-protected, 57 people from ten contracting firms had access to the room during that window, and police are investigating a suspected theft. No firewall could have helped. It is a reminder that physical handling of storage devices, and encrypting them, matters just as much as network security.

6 🇳🇱

Odido — Netherlands

6.2 million accounts

A major Dutch telecommunications provider confirmed a breach affecting millions of customer accounts, ranking among Europe's largest confirmed 2026 incidents.

7 🇸🇪

Miljödata — Sweden

1.5+ million people

A breach at a Swedish government IT supplier exposed personal identity numbers, addresses, employment details, and — for some individuals — sensitive sick-leave and protected personal data across multiple public sector organisations. Sweden's privacy regulator opened GDPR investigations into the supplier and several affected public bodies. It's a clear example of "supply chain risk" — you can trust the organisation you deal with directly and still be exposed through a supplier you've never heard of.

8 🇷🇺

SplitVPN — Russia

~865,000 users

A Russian VPN provider — a service people specifically choose to protect their privacy — was reportedly breached itself, exposing the personal records of hundreds of thousands of users. A useful reminder that no single tool makes you immune; good habits (like the ones covered throughout this site) matter regardless of which privacy tools you use.

9 🇳🇿

ManageMyHealth — New Zealand

99,416 confirmed patients

Closer to home: New Zealand's largest patient-facing health portal, used by around 1.8 million registered users, was breached in late December 2025, with the exfiltration of hundreds of thousands of sensitive medical documents. ManageMyHealth confirmed 99,416 individuals were ultimately impacted — down from initial estimates of around 126,000 — with effects heavily concentrated in Northland, where roughly 91% of affected patients were based, many of them Māori. It's described as one of the most damaging cybersecurity incidents in New Zealand's history, and prompted both a government review and a Privacy Commissioner inquiry.

10 🌐

Massive Stealer Logs Breach — Global

Millions of credentials

Not tied to one country or one company: in June 2026, a huge repository of "infostealer" logs — malware that quietly harvests saved browser passwords and cookies — was published, exposing millions of people's login credentials worldwide. Unlike a single-company breach, this is the kind of exposure that comes from malware already sitting on someone's own device. It's exactly the sort of thing our free Password Strength Checker and Passphrase Generator tools are built to help with — using strong, unique passwords limits the damage if any one of your accounts ever turns up in a leak like this.

What this list actually tells us

Looking at these ten together, a few patterns stand out: breaches keep happening through trusted third parties and suppliers, not just direct hacks of the company you dealt with. Physical mistakes (a lost hard drive) can be just as damaging as sophisticated cyberattacks. And no sector — healthcare, airlines, energy, even privacy tools themselves — is off-limits. The good news is that most of the everyday risk to you personally comes down to a small number of habits: unique passwords per account, caution with unexpected messages, and knowing what to do if your information does turn up somewhere it shouldn't. That's exactly what the rest of this site is here to help with.

Worried your details might be part of a breach?

Start with a strong, unique password for your most important accounts — it takes two minutes and makes a real difference.

Check your password strength