A single cyberattack can compromise millions of individuals, interrupt vital services, and leave those affected grappling with the aftermath for years.
The most significant security incidents of 2026 have impacted educational institutions, travel operators, home security subscribers, and countless regular account holders. This list takes into account the total number of individuals impacted, the nature of the compromised data, service interruptions, and the potential for financial fraud or subsequent cyberattacks.
Editor’s note: This story is based on data accessible up to July 16, 2026. Inquiries into breaches often evolve as companies gain a clearer picture of what was accessed by attackers.
Contents
- How we ranked the breaches
- 5. Aura
- 4. Panera Bread
- 3. ADT
- 2. Carnival
- 1. Instructure’s Canvas learning platform
- FBI cyber incident remains one to watch
- What these breaches have in common
- What to do after a breach
How we ranked the breaches
TechRepublic evaluated incidents based on four criteria:
- The number of individuals or entities impacted
- The level of sensitivity of the data that was exposed
- The degree of disruption suffered by clients or business operations
- The potential for identity theft, phishing schemes, or further attacks
No single metric determined the final order. Figures reported exclusively by hackers are clearly noted and were not considered confirmed victim totals.
5. Aura
Why it ranks No. 5: A security failure at a firm specializing in identity protection opened the door to an especially believable phishing threat.
Aura reported that an attacker employed voice phishing to take over an employee account, gaining access to around 900,000 marketing records. The bulk of this data originated from a database tied to a company Aura purchased in 2021.
The compromised data consisted of names and email addresses. Aura stated that its primary identity protection services remained secure, and that Social Security numbers, passwords, credit details, and financial data were not affected.
Reader takeaway: Stay cautious about unsolicited identity theft warnings. Go directly to the provider’s official website or application rather than clicking on hyperlinks within emails or text messages.
Advertisement
4. Panera Bread
Why it ranks No. 4: Millions of customer contact details were reportedly made accessible to the public.
Panera Bread verified a data leak that exposed customer contact information. An evaluation by the breach-notification service Have I Been Pwned discovered roughly 5.1 million distinct email addresses within an estimated 14 million exposed records.
The data reportedly contained names, email addresses, phone numbers, and physical addresses. Such information could assist criminals in crafting targeted phishing attacks involving loyalty programs, deliveries, refunds, or supposed account problems.
Reader takeaway: View unexpected restaurant rewards, refund alerts, delivery messages, and account notifications with skepticism. Navigate to Panera’s website or app directly rather than clicking links in unsolicited communications.
3. ADT
Why it ranks No. 3: The compromised data reportedly included residential addresses and fragments of personal identification details.
ADT acknowledged that a hacker acquired customer data during a cybersecurity event.




