An entire country lost their data, and the US advocates to know all about you by law
This February 2026 was totally cooked again, with massive global data breaches affecting tens of millions of people. Compared to January, this time even critical infrastructure, healthcare platforms, and telecommunications networks suffered severe intrusions.
Major leaks included Senegal's government citizen database, the CarGurus automotive platform, and Dutch telecom provider Odido.
Lawsuits followed several of these breaches, while proposed federal legislation in the United States threatened to severely limit consumer privacy protections.

The biggest data leaks and hacks in February 2026
Also read below how to find out if you are affected and what to do.
Directorate of File Automation [Senegal]: 19,500,000 compromised
If you think that breach is not about you, remember that for example in the US the DOGE team had untrained teenagers with FULL access to the personal government data of all citizen. In parts of the EU, police officers or employment agency workers can widely access citizen data as well without established guidelines.
The data leak originated from the Directorate of File Automation servers, the national identification agency of Senegal. Hackers stole 139 TB (Your computer likely has 1 TB or less) of unencrypted government records.
The insane dump contains the entire citizen database, biometric data, immigration documents, and ID card personalization files. Given the sheer size of the dump, the breach likely affects the entire 19.5 million population of the country.
The leak is widely considered a catastrophic failure of national security.
It is so devastating, that the government temporarily suspended passport and ID card production.
CarGurus [USA]: 12,600,000 compromised
The data leak originated from the CarGurus automotive research website and its associated databases. Hackers compromised 12.6 million user accounts.
The stolen information included unencrypted email addresses, full names, phone numbers, physical addresses, IP addresses, finance pre-qualification application outcomes, and user account ID mappings.
The threat actor ShinyHunters breached the systems and attempted to extort the company. When CarGurus refused to pay the ransom, the hackers published the data publicly on dark web forums.
The company addressed the issue only after the extortion attempt failed and the unprotected data became a public spectacle.
Washington Hotel [Japan] - 6,200,000 compromised
The data leak originated from the internal servers and credit card terminals of the Washington Hotel chain in Japan. Hackers compromised the personal information of 6.2 million customers.
The unencrypted data included full names, physical addresses, mobile numbers, email addresses, dates of birth, IBANs, and passport or driver license numbers with validity dates.
This is highly damaging due to the dangerous combination of financial details and government identity documents.
The hotel management confirmed the breach and initiated an investigation once the operational disruption became obvious to guests. Action only if they cannot hide it.
Odido [Netherlands] - 6,200,00 compromised
The data leak originated from a third party customer contact system used by the telecommunications provider Odido. Hackers exfiltrated unencrypted records belonging to 6.2 million customers.
The stolen data included bank account numbers, passport details, home addresses, phone numbers, and email addresses.
Dutch security experts described the stolen data as "worth gold for criminals," marking it as one of the most severe breaches in Dutch history.
Odido admitted the breach and began notifying customers after external analysts verified the scale of the data theft.
700Credit [USA] - 5,800,000 compromised
The data leak originated from the 700Dealer web application, a credit screening service used by automotive dealerships.
The unencrypted data included full names, mailing addresses, Social Security numbers, and dates of birth. Social Security numbers!
Hackers accessed the data by exploiting weak application programming interfaces on the web platform.
QualDerm Partners [USA] - 3,100,000 compromised
The data leak originated from the internal IT network of QualDerm Partners, a healthcare management provider.
Hackers exfiltrated the protected health information of 3.1 million patients. The unencrypted data included medical records, diagnoses, medical treatments, and personal contact details.
It's a critical failure in patient confidentiality. An unknown threat actor breached the systems in late December 2025, but the company officially reported the discovery in February 2026.
TriZetto Provider Health Solutions [USA] - 3,000,000 compromised
The breach exposed the health information of 3.0 million individuals. The leaked files contained unencrypted medical billing data, patient names, and detailed health insurance information.
TriZetto was straightforward with federal authorities, reporting the incident in February 2026 and actively working with associated healthcare practices to notify the affected patients.
National Bank Account Registry FICOBA [France] - 1,200,000 compromised
The data leak originated from FICOBA, the centralized national bank account registry operated by the French government. The breach exposed 1.2 million French bank accounts. The compromised unencrypted data included IBANs, account holder names, physical addresses, and tax identification numbers.
This is highly alarming because the attackers targeted core national financial infrastructure.
A hacker used the stolen credentials of a government official to authenticate into the system without triggering immediate security alarms.
YouX [Australia]: 444,538 compromised
The data leak originated from the YouX fintech asset finance technology platform. Hackers exfiltrated a 141 GB dump from an unsecured MongoDB cloud database. This 141 GB dump contains the personal records of 444,538 unique borrowers, including 629,597 loan applications.
The unencrypted data included driver licenses, income details, residential addresses, and bank statements.
Most victims did not even know YouX held their data. A threat group named FulcrumSec found the exposed database. YouX contacted authorities and affected customers after independent researchers and the hackers themselves made the vulnerability known.
Governmental Decisions Weakening Privacy
In February 2026, lawmakers in the United States Congress debated the SECURE Data Act, a proposed bill that directly attacks consumer privacy rights. Privacy advocates strongly opposed this legislation because it aims to preempt state level protections like the California Consumer Privacy Act.
If passed, the act would eliminate the global data broker deletion mechanism. It would also cap the number of free privacy requests a consumer can make to two per year. This legislative push heavily favors corporate data collection and restricts the ability of citizens to control their personal information.
How to protect yourself
Start using a trusted password manager with two factor authentication (2FA) enabled. A password manager generates and stores complex, unique passwords for every site, meaning a breach on one platform will not compromise your other accounts. Adding 2FA ensures that even if hackers acquire your password, they cannot access your accounts without a secondary physical approval.

