A record year for the number of breaches
Three documented 2025 incidents illustrate the scale, across three different sectors:
Healthcare alone accounted for a disproportionate share of 2025's largest breaches: the ten biggest incidents reported to HHS affected over 20 million people combined, on top of the AT&T and other telecom and retail cases above.
Beyond telecom and retail: three sectors quietly piling up victims
Data breaches aren't only a banking or telecom problem. Healthcare, higher education and sports, and travel and hospitality all had major, named, dated incidents in 2025-2026 — and each one hands a scammer a different kind of credible detail to work with.
🏥TriZetto Provider Solutions (Cognizant)
A healthcare IT subsidiary of Cognizant confirmed in early 2026 that hackers had access to a web portal used for insurance eligibility verification from November 19, 2024 until the intrusion was discovered on October 2, 2025 — nearly a year unnoticed. HHS's Office for Civil Rights breach portal lists 3,433,965 affected individuals: names, addresses, birth dates, Social Security numbers, insurance details and provider information. No payment card or bank data was involved. Notifications to affected individuals began in February 2026, more than three months after the company itself was told.
HIPAA Journal · TechCrunch · Security Affairs, February-March 2026. HHS OCR breach portal.🎓Strategic Education (Strayer & Capella universities)
A February 2026 hacking attack copied Social Security numbers, driver's license numbers and, for some victims, passport numbers, from the servers of Strategic Education — the parent company of Strayer University, Capella University and the Jack Welch Management Institute. State-level breach filings put the confirmed total at 111,706 current and former students and staff (100,845 in Texas alone, plus Massachusetts and Maine). The company didn't discover the intrusion until May 21, 2026 — about 87 days after the attacker's initial access.
Tech Times · teiss, June 2026, citing state attorney general filings.🏀Madison Square Garden Sports & the Knicks — a claim, not a confirmation
In June 2026, the extortion group ShinyHunters said it had stolen roughly 46 GB of data from Madison Square Garden Sports and the New York Knicks and claimed the haul covered over 26 million customer records, including facial-recognition surveillance data. As of this writing, MSG has not confirmed the breach occurred, and the 26 million figure has not been independently verified by outside researchers. Analysts who examined samples of the actual leaked files — not the hackers' headline number — found around 9.8 million email addresses and roughly 5 million street addresses and full names. That gap between what an attacker announces and what can actually be verified is the same pattern seen in other high-profile breaches worldwide: treat a hacker's claimed victim count as a ceiling to investigate, not a confirmed fact to repeat.
CPO Magazine · SecureWorld · ComplianceHub.Wiki, June 2026.🏨BWH Hotels (Best Western)
BWH Hotels, the parent company of Best Western Hotels & Resorts, WorldHotels and Sure Hotels, confirmed in May 2026 that hackers had access to its reservation system for six months — from October 14, 2025 until the intrusion was discovered on April 22, 2026. Exposed data included guest names, email addresses, phone numbers and home addresses for "certain guests" drawn from a loyalty program with more than 53 million members worldwide. Payment information was stored separately and wasn't affected. Notably, BWH has not disclosed an exact number of guests impacted — a reminder that "how many were affected" isn't always answered even in a company's own confirmation.
The Register · SecurityWeek · Cybernews, May 2026.☁️CareCloud — a 6-day intrusion, disclosed 5 months later
Attackers accessed an AWS cloud environment belonging to CareCloud, a healthcare software vendor, and stayed inside for six days, from March 10 to 16, 2026, extracting patient data. CareCloud didn't disclose the breach until August 17, 2026 — via a federal filing with the US Department of Health and Human Services — five months after the intrusion, making it the 5th largest US healthcare data breach reported in 2026. The confirmed number of affected patients was revised upward the very next day, to 3.7 million. As of this writing, no attacker has claimed responsibility and it isn't known whether a ransom was paid — a reminder that "who did it" often stays unanswered even after a breach is fully confirmed.
HHS breach filing, reported by TechCrunch, August 17-19, 2026.The vocabulary to know
Have I Been Pwned
A free service built by security researcher Troy Hunt: enter your email to check whether it appears in a known data breach.
Credential stuffing
An attacker takes credentials stolen in one breach and tries them en masse on other sites, betting that you reused the same password elsewhere.
Password spraying
The reverse of classic brute-forcing: an attacker tries one very common password across a large number of different accounts, to stay under detection thresholds.
MFA fatigue
An attacker who already has your password triggers a flood of push notification approval requests, hoping you'll eventually tap "approve" out of annoyance or mistake.
SIM swap, another technique directly tied to exploiting leaked data, is detailed in the glossary.
Frequently asked questions
How can I check if my data has been exposed?
Have I Been Pwned (haveibeenpwned.com) is a free service, built by security researcher Troy Hunt, that lets you check whether your email address appears in a known data breach.
Were 2025 breaches worse than previous years?
By count, yes: the Identity Theft Resource Center tracked 3,322 data compromises in 2025, a new all-time record and a 79% jump over five years. By number of people notified, 2025 was actually lower than 2024, because 2024 included several exceptionally large "mega-breaches" that inflated the victim count.
Why does a data breach lead to fraudulent calls and texts?
Because a breach often contains a name, phone number and sometimes details about your bank, employer or health provider — enough to build a call or text that sounds credible and personal, far more effective than a generic message sent at random.
Why is healthcare data specifically so valuable to criminals?
Unlike a password or a credit card number, a medical record can't be reset. Once your diagnosis history, insurance details or provider information is exposed, it stays usable indefinitely — for insurance fraud, for blackmail, or simply as a highly credible detail in a scam call pretending to be from your health plan.
Other markets we cover
This report focuses on the US, where the ITRC publishes the most granular breach-tracking data. Data breaches aren't a US-only problem — here's what's documented in four other major English-speaking markets.
🇦🇺Australia — a record 1,205 notifications
Australia's privacy regulator received 1,205 data breach notifications in 2025, the highest number since mandatory reporting began in 2018, up 8% on 2024. Health service providers were the single most affected sector, accounting for 225 notifications, ahead of financial services (157) and the Australian Government (118). See our full Australian data breaches report.
Office of the Australian Information Commissioner (OAIC), Notifiable Data Breaches statistics, 2025 annual figures.🇬🇧United Kingdom — 3,600 incidents in one quarter
The UK's Information Commissioner's Office received 3,600 data breach incident reports in the fourth quarter of 2025 alone, a 16% year-on-year increase. Most weren't hacks: 77% were non-cyber incidents, with human error the leading cause, though the National Cyber Security Centre separately recorded four nationally significant cyber-attacks every week that year. See our full UK data breaches report.
ICO, Data Security Incident Trends dashboard, Q4 2025.🇨🇦Canada — over 20 million people notified
Canada's federal privacy regulator received nearly 700 breach reports from businesses in 2025-26, affecting more than 20 million Canadians, plus roughly 450 further reports from federal government institutions affecting over 48,000 people.
Office of the Privacy Commissioner of Canada, 2025-26 Annual Report to Parliament, June 2026.🇮🇳India — 29.44 lakh incidents handled
India's national cyber-incident response agency handled more than 29.44 lakh (2.94 million) cybersecurity incidents in 2025, including 8,386 website defacements and 806 phishing incidents. India also has one of the world's largest diasporas, with millions of families living across the US, UK and Canada while staying connected to relatives back home — exactly the kind of cross-border tie that leaked data and impersonation scams exploit. Egidio's Cercle family plan covers up to 4 devices from one purchase, letting someone abroad help protect a parent's phone in India remotely — see our full report on remittance and immigrant scams for more on that corridor.
CERT-In, 2025 Annual Report.Go further
Egidio — The Threat Laboratory, "US Data Breaches: the raw material behind personalized scams", egidio.app/en/laboratoire/us-data-breaches/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.