24 Billlion records dumped, millions of sensitive health records leaked, Texas sues Netflix, and new US & UK laws want to end anonymity in the internet
June 2026 saw a 24-billion-record dump coined "The mother of all breaches", and major leaks from KDDI and Amazon One Medical.
The Texas attorney general sued Netflix for secretly tracking and selling user data, while new bills in the US and UK threaten user privacy by entirely stripping away online anonymity.

The biggest data leaks and hacks in June 2026
This month "The mother of all breaches" happened and again millions of sensitive health records leaked. The US and UK advance age verification laws that require citizen to identify themselves on specific websites - completely stripping away their anonymity.
Also read below how to find out if you are affected and what to do.
The mother of all breaches: Various platforms, unsecured server [Global], 24 Billion records dumped
This massive data dump contains approximately 24 billion stolen records. It includes exposed credentials, system fingerprints, and authentication tokens scraped directly from infected devices globally.
Experts estimate it spans several terabytes of plaintext and hashed passwords. The data is entirely unencrypted.
Security researchers widely view this as a catastrophic event, comparing it to the "mother of all breaches." Researchers discovered the dump exposed online on an unsecured server. The original source remains unidentified, meaning no single company could be straightforward about the leak.
KDDI [Japan]: 14.22 million accounts
The leak occurred because hackers exploited a known vulnerability in third-party software used by KDDI.
The leaked data consists of email addresses and passwords belonging to active, dormant, and canceled accounts across six Japanese internet service providers. These include KDDI, STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe.
KDDI stated that some of the passwords were encrypted. They did not specify the exact encryption method or the exact number of protected accounts.
The sheer volume of major ISPs affected caused massive alarm in Japan.
KDDI detected the unauthorized access on June 17, 2026, and publicly disclosed the breach a few days later on June 23, showing a relatively straightforward response.
Amazon One Medical [United States]: 5 to 10 million patients affected
A threat group claimed to have stolen 8.8 terabytes of data after they gained access through a third-party file storage platform used by Amazon One Medical. Based on this massive volume, experts guesstimate that between 5 and 10 million legacy Iora Health and One Medical Seniors patients are affected.
The data dump allegedly contains deeply sensitive protected health information, medical archives, and personal identification details. The hackers did not indicate that the stolen files were encrypted.
The medical privacy community views this breach as highly severe given the extreme sensitivity of legacy health records. The company confirmed a security event occurred but was not completely straightforward. They refused to immediately verify ShinyHunters' claims regarding the 8.8 terabytes of data or the exact number of affected patients.
Qantas [Australia]: 6 million records
Hackers breached Qantas by compromising a provider of their check-in and boarding systems. This breach exposed approximately 6 million customer records.
The stolen data includes passenger contact details and frequent flyer numbers. There is no indication that the data was encrypted. Customer identities remain directly exposed to potential phishing attacks or account takeovers.
The company acknowledged the breach following the operational disruptions it caused.
Texas Parks and Wildlife Department [United States]: 3 million+ people affected
The data leaked through a third-party vendor system used by the department to sell licenses.
The compromised data includes driver's license information, passport numbers, email addresses, phone numbers, and residential addresses of people who purchased hunting and fishing licenses.
None of this personal identification data was reported as encrypted. It gives identity thieves a complete profile of the affected individuals.
Passport and driver's license numbers are prime materials for identity fraud.
Texas Cyber Command detected the unauthorized access on June 18, 2026. The department was transparent and promptly disclosed the breach once flagged.
Aflac Japan [Japan, United States]: ~2 million customers affected
An unauthorized third party infiltrated Aflac Japan's systems between June 15 and June 25, 2026 and accessed highly sensitive personal and financial information.
The impacted files contain insurance policy and coverage details, personal identification information, and bank account information. The direct access to policy details suggests much of it was in plaintext.
Financial sector analysts categorize this breach as critical due to the combination of banking and insurance data.
The company discovered the intrusion on June 25 and reported it in a filing with the US Securities and Exchange Commission on June 30. Aflac was straightforward with regulators, though the ongoing investigation left customers waiting for specific details.
Corporate surveillance and privacy lawsuits in June 2026
In late June 2026, Texas Attorney General Ken Paxton sued Netflix for spying on Texas residents, including children.
The lawsuit alleges that Netflix intentionally collected extensive behavioral data without user consent. The company tracked viewing habits, platform preferences, device information, and household network usage.
Netflix then allegedly sold this detailed information to commercial data brokers and advertising technology companies.
This practice allowed external data brokers to combine Netflix's tracking points with data from other platforms to build hyper-detailed consumer profiles.
The primary impact on customers is the severe violation of their privacy and the unauthorized monetization of their intimate viewing habits.
Governmental decisions weakening privacy in June 2026
During June, lawmakers in multiple countries advanced legislation that fundamentally weakens digital privacy.
In the United States, lawmakers pushed the KIDS Act forward. This bill forces online services to verify all users' ages. This effectively strips away internet anonymity by requiring users to provide government ID or other identifying information to access basic websites. The bill also introduces new regulations on private and encrypted communications.
In the United Kingdom, the government advanced a new Under-16 Social Media Ban. Similar to the US legislation, this mandate relies on widespread age verification technologies.
Privacy experts and organizations like the Electronic Frontier Foundation heavily criticized these moves. They argued that forcing companies to collect identity data just to verify age creates new honeypots of sensitive data, thereby endangering the very users the laws claim to protect.
Protect Your Digital Identity
Check monitoring services like Have I Been Pwned to see if these breaches exposed your information.
A password manager helps secure your accounts because it generates unique, complex passwords for every site you use. If one service leaks your credentials, hackers cannot use that same password to access your other accounts.

