Tag Archives: identity theft

The Biggest Data Breaches of 2026 and What They Reveal

The biggest data breaches of 2026 have run to a pattern: fewer credit card numbers, far more health records, identity documents and account data, and at least one attack that destroyed systems rather than stealing from them. A roundup published on 15 September by TechCrunch puts the year’s incidents side by side.

Sections

The incidents by scale

Ranked by people affected, four incidents dominate the year so far.

The AI music generation platform Suno exposed information associated with 55.3 million user accounts, the largest account count of the year. Charter Communications lost more than 42 million customer records to an extortion group. The insurer DentaQuest saw health data on 15 million people stolen — the largest confirmed breach of sensitive health information in 2026. The Dutch telecoms operator Odido disclosed an attack affecting up to 6.2 million customers.

The Odido disclosure is instructive about what modern breach data looks like. Investigators found unauthorised access to a customer contact system, from which attackers downloaded varying combinations of names, addresses, email addresses, mobile numbers and personal identification details. None of that is a password. All of it is enough to open an account somewhere else in the victim’s name.

Carnival Corporation notified six million people in May that personal information had been taken in an April intrusion. Independent breach trackers, including public breach lists, record a long tail of smaller incidents behind these.

Why health data keeps topping the list

Health records have been the highest-value category for several years and 2026 has not changed that. The reason is durability. A stolen card is cancelled in a day; a diagnosis history, insurance identifier and date of birth stay valid for life and support both insurance fraud and highly credible phishing.

Healthcare and insurance environments also concentrate risk. They run large third-party ecosystems — claims processors, benefits administrators, imaging providers — each of which holds a copy of the same records. Breach numbers in the sector are frequently a count of one supplier’s customers rather than one hospital’s patients.

The attack that deleted rather than stole

The outlier of the year was at Stryker, the US medical technology company. In March, attackers described in reporting on the incident as Iranian broke in and remotely wiped tens of thousands of employee devices, disrupting the company’s operations for several days.

That attribution is as reported rather than judicially established, and should be read with that caveat. What is not in question is the shape of the attack: the objective was disruption, not extortion. Wiper incidents leave no data to negotiate over and no decryption key to buy, which makes recovery entirely a function of how well an organisation can rebuild from backups.

The most recent disclosure

The newest entry is McKesson, the pharmaceutical distributor, which discovered a cybersecurity incident on 25 August 2026 involving unauthorised access to third-party applications and data exfiltration. On 29 August the company narrowed the scope to a subset of customers within its Oncology and Multispecialty and its Medical-Surgical units.

The four-day gap between discovery and scoping is the part worth noting. Initial breach statements almost always describe a larger blast radius than the final forensic picture, or a smaller one. Early numbers should be treated as provisional in both directions.

Financial services has had its own bad month — see our report on the Revolut data breach — while the software supply chain keeps producing entry points, as our coverage of the VMware Workstation and Fusion flaw sets out.

What actually reduces exposure

For individuals, the realistic assumption is that an email address, phone number and home address are already circulating. The defences that still work are the ones that break the chain between leaked identity data and account takeover: app-based multi-factor authentication rather than SMS codes, which are vulnerable to SIM swapping; unique passwords generated and stored in a manager; and a credit freeze where the jurisdiction offers one.

For organisations, the recurring failure in this year’s list is third-party access. Suno, McKesson and DentaQuest all involve data reachable through a system that was not the company’s core product. Inventorying which suppliers hold customer data, and what each can reach, is duller than threat hunting and has prevented more incidents. Governance frameworks are catching up — our report on Microsoft’s AI code of conduct covers one vendor’s attempt to formalise those commitments.

Breach questions, answered

What is the largest known data breach of 2026?

The theft of health data belonging to 15 million people from the insurer DentaQuest is the largest confirmed breach reported so far this year.

Which incident exposed the most user accounts?

The AI music platform Suno, where information tied to 55.3 million user accounts was exposed.

What happened at Charter Communications?

An extortion group stole more than 42 million customer records, according to reporting on the incident.

What data was taken in the Odido breach?

Attackers reached a customer contact system and downloaded varying combinations of names, addresses, email addresses, mobile numbers and personal identification details for up to 6.2 million customers.

Was any 2026 attack purely destructive?

The March intrusion at the US medical technology firm Stryker was, in that attackers remotely wiped tens of thousands of employee devices and disrupted operations for several days rather than seeking a ransom for data.

What should individuals actually do?

Assume email addresses and phone numbers are already public, turn on app-based multi-factor authentication rather than SMS, use unique passwords through a manager, and freeze credit files where the jurisdiction allows it.

More on security

Revolut Data Breach Began With a Real Government Email Domain

Revolut has confirmed a Revolut data breach in which an unauthorised third party obtained customer data by sending fraudulent information requests from a legitimate government agency email domain. The fintech says a limited number of customers were affected and that funds are safe. The method is what makes this one worth reading closely: nothing was hacked in the conventional sense. The attacker used a real government domain and the legal process that obliges companies to answer it.

What Revolut has confirmed

According to TechCrunch, which reported the confirmation on 12 September, Revolut described the incident as a sophisticated external impersonation in which a third party used a genuine government agency domain to submit fraudulent requests for customer information. Bloomberg reported the company’s statement the same day.

Revolut says it blocked the address once it identified the scheme and notified the relevant government agency, financial regulators, law enforcement and data-protection authorities. The company’s characterisation of the scale — a limited number of customers — is its own, and has not been independently quantified.

What was exposed, and what was not

The exposed material, per the company’s disclosure and subsequent reporting, includes identity and contact details: date of birth, postal and email addresses and phone numbers. It also includes copies of identity documents such as passports and driving licences, and may include verification selfies, account statements and transaction histories.

Revolut says passwords and full payment card details were not accessed, and that customer funds are safe.

That split matters, and not in the reassuring direction most breach notices imply. Passwords can be changed. A passport scan paired with a verification selfie, a date of birth and an address cannot be. That combination is precisely the bundle used to pass remote identity checks at banks, crypto exchanges, mobile carriers and government portals. Help Net Security’s summary sets out what is known so far.

Why fake law-enforcement requests work

Financial firms and online platforms receive a steady stream of lawful requests for customer data from police, regulators and prosecutors. A subset are marked urgent, on the basis that a delay could cost a life or let a suspect flee. Companies are expected to respond quickly, and the main authenticity signal available to a reviewer is that the request arrived from an official government email domain.

That is a weak signal. Government mailboxes are compromised regularly, through phishing, credential stuffing or reused passwords, and a compromised mailbox grants exactly the one thing the fraud needs. The request itself can be well-drafted; the domain does the vouching.

The defence is procedural rather than technical: out-of-band verification by calling the agency back on a published number, mandatory secondary approval for identity-document disclosure, rate limiting on any single requester, and treating an urgent flag as a reason for more scrutiny rather than less. None of that is exotic. It is slow, which is why it erodes under volume.

What affected customers should do

If you receive a notification from Revolut, the useful steps are narrow and specific:

  • Assume identity-theft risk, not account-takeover risk. Passwords were not taken; your documents may have been. The threat is someone opening accounts as you elsewhere.
  • Place a credit freeze or fraud alert with the credit bureaus in your country. This is the single highest-value action and it is usually free.
  • Expect targeted phishing. An attacker holding your date of birth, address and transaction history can write a far more convincing message than the usual spam. Treat any inbound contact about the breach as suspect and use the app, not a link.
  • Enable a passkey or hardware key if your accounts support it, and review devices authorised on the Revolut app.
  • Note the date. If you later dispute a fraudulent account opened in your name, being able to point to a documented breach and notification date is useful.

For regulators, the open question is whether the disclosure meets the notification standards of the jurisdictions Revolut operates in, and whether the agency whose domain was abused will say anything about how it was compromised. That second answer is the one that would help every other company facing the same request queue.

Frequently asked

What happened in the Revolut data breach?

An unauthorised third party used a legitimate government agency email domain to send fraudulent requests for customer information, and Revolut supplied data in response before identifying the scheme.

What data was exposed?

Identity and contact details including date of birth, postal and email addresses and phone numbers, plus copies of identity documents such as passports and driving licences. It may also include verification selfies, account statements and transaction histories.

Were passwords or card details taken?

Revolut says no passwords and no full payment card details were accessed, and that customer funds are safe.

How many customers were affected?

Revolut has described it as a limited number. The company has not published a figure, and the scale has not been independently verified.

What is an emergency data request scam?

A fraud in which an attacker sends a company an urgent-looking law-enforcement request from a compromised or spoofed official email account, relying on the company’s obligation to respond quickly to lawful requests.

What should I do if I am affected?

Freeze your credit file or place a fraud alert, expect targeted phishing, strengthen authentication on your accounts, and keep a record of the notification date.

More security coverage