Never lose a customer to a missed message
An AI agent trained on your own business, replying in seconds, in any language, on every channel your customers already use.
The biggest data breaches of 2026 have run to a pattern: fewer credit card numbers, far more health records, identity documents and account data, and at least one attack that destroyed systems rather than stealing from them. A roundup published on 15 September by TechCrunch puts the year’s incidents side by side.
Sections
- The incidents by scale
- Why health data keeps topping the list
- The attack that deleted rather than stole
- The most recent disclosure
- What actually reduces exposure
The incidents by scale
Ranked by people affected, four incidents dominate the year so far.
The AI music generation platform Suno exposed information associated with 55.3 million user accounts, the largest account count of the year. Charter Communications lost more than 42 million customer records to an extortion group. The insurer DentaQuest saw health data on 15 million people stolen — the largest confirmed breach of sensitive health information in 2026. The Dutch telecoms operator Odido disclosed an attack affecting up to 6.2 million customers.
The Odido disclosure is instructive about what modern breach data looks like. Investigators found unauthorised access to a customer contact system, from which attackers downloaded varying combinations of names, addresses, email addresses, mobile numbers and personal identification details. None of that is a password. All of it is enough to open an account somewhere else in the victim’s name.
Carnival Corporation notified six million people in May that personal information had been taken in an April intrusion. Independent breach trackers, including public breach lists, record a long tail of smaller incidents behind these.
Why health data keeps topping the list
Health records have been the highest-value category for several years and 2026 has not changed that. The reason is durability. A stolen card is cancelled in a day; a diagnosis history, insurance identifier and date of birth stay valid for life and support both insurance fraud and highly credible phishing.
Healthcare and insurance environments also concentrate risk. They run large third-party ecosystems — claims processors, benefits administrators, imaging providers — each of which holds a copy of the same records. Breach numbers in the sector are frequently a count of one supplier’s customers rather than one hospital’s patients.
The attack that deleted rather than stole
The outlier of the year was at Stryker, the US medical technology company. In March, attackers described in reporting on the incident as Iranian broke in and remotely wiped tens of thousands of employee devices, disrupting the company’s operations for several days.
That attribution is as reported rather than judicially established, and should be read with that caveat. What is not in question is the shape of the attack: the objective was disruption, not extortion. Wiper incidents leave no data to negotiate over and no decryption key to buy, which makes recovery entirely a function of how well an organisation can rebuild from backups.
The most recent disclosure
The newest entry is McKesson, the pharmaceutical distributor, which discovered a cybersecurity incident on 25 August 2026 involving unauthorised access to third-party applications and data exfiltration. On 29 August the company narrowed the scope to a subset of customers within its Oncology and Multispecialty and its Medical-Surgical units.
The four-day gap between discovery and scoping is the part worth noting. Initial breach statements almost always describe a larger blast radius than the final forensic picture, or a smaller one. Early numbers should be treated as provisional in both directions.
Financial services has had its own bad month — see our report on the Revolut data breach — while the software supply chain keeps producing entry points, as our coverage of the VMware Workstation and Fusion flaw sets out.
What actually reduces exposure
For individuals, the realistic assumption is that an email address, phone number and home address are already circulating. The defences that still work are the ones that break the chain between leaked identity data and account takeover: app-based multi-factor authentication rather than SMS codes, which are vulnerable to SIM swapping; unique passwords generated and stored in a manager; and a credit freeze where the jurisdiction offers one.
For organisations, the recurring failure in this year’s list is third-party access. Suno, McKesson and DentaQuest all involve data reachable through a system that was not the company’s core product. Inventorying which suppliers hold customer data, and what each can reach, is duller than threat hunting and has prevented more incidents. Governance frameworks are catching up — our report on Microsoft’s AI code of conduct covers one vendor’s attempt to formalise those commitments.
Breach questions, answered
What is the largest known data breach of 2026?
The theft of health data belonging to 15 million people from the insurer DentaQuest is the largest confirmed breach reported so far this year.
Which incident exposed the most user accounts?
The AI music platform Suno, where information tied to 55.3 million user accounts was exposed.
What happened at Charter Communications?
An extortion group stole more than 42 million customer records, according to reporting on the incident.
What data was taken in the Odido breach?
Attackers reached a customer contact system and downloaded varying combinations of names, addresses, email addresses, mobile numbers and personal identification details for up to 6.2 million customers.
Was any 2026 attack purely destructive?
The March intrusion at the US medical technology firm Stryker was, in that attackers remotely wiped tens of thousands of employee devices and disrupted operations for several days rather than seeking a ransom for data.
What should individuals actually do?
Assume email addresses and phone numbers are already public, turn on app-based multi-factor authentication rather than SMS, use unique passwords through a manager, and freeze credit files where the jurisdiction allows it.
More on security
- Inside the Revolut data breach
- VMware patches a Workstation and Fusion flaw
- Microsoft’s AI code of conduct
Verification your users actually receive.
Send one-time passcodes over WhatsApp with a single API call. Replio can generate, hash and verify the code for you.

