Hundreds of millions private records and messages leaked, millions of confidential health records, and the US wants to forbid you to sue companies for not protecting your private data

Share
We may earn a commission for purchases made through links in this post. Read more.

April 2026 brought us massive data breaches affecting hundreds of millions globally.

The educational platform Canvas LMS leads the list with 275 million leaked records. Major incidents also occurred at McGraw Hill, Rituals, and government agencies. Lawsuits hit companies for failing to encrypt data.

New legislation in the United States threatens to override stronger state privacy protections.

A woman facepalming, probably because she read about all the breaches of this month

The biggest data leaks and hacks in April 2026

This month had a massive amount of breaches and leaks, amounting to hundreds of millions being affected. The US tries to prevent you from suing companies for their misconduct.

Also read below how to find out if you are affected and what to do.

Instructure (Canvas LMS / canvas.net): ~275 million affected

The hacking group ShinyHunters stole a 3.65 terabyte data dump.

This massive dataset contained private messages between students and teachers, full names, email addresses, and student ID numbers. Passwords and financial data were not compromised.

The stolen data was stored unencrypted. It was readable immediately upon unauthorized access, which is a catastrophic failure in data security.

Instructure detected the intrusion four days later and published a vague status update. The public only learned the true scale a week later, when students posted screenshots of defaced login pages online. The company faced heavy criticism for lacking transparency. They later apologized and admitted they paid a reported $10 million ransom to prevent the data release.

McGraw Hill (mheducation.com): ~45 million affected

Threat actors stole personal information belonging to tens of millions of students and educators.

The specific data types include names, email addresses, and course enrollment data. The database lacked proper encryption, leaving the information exposed in plain text.

It is highly alarming that a major educational publisher failed to secure a basic cloud database. The data leaked due to a misconfigured Salesforce database that the company left exposed to the open internet. The company has not provided a detailed public timeline regarding their internal discovery process.

Rituals (rituals.com): ~41 million affected

An unauthorized actor downloaded the data directly from the company network.

The stolen cosmetics membership data includes full names, email addresses, phone numbers, dates of birth, genders, postal addresses, and preferred store locations. The company did not state if this data was encrypted. The nature of the leak suggests the files were fully accessible in plain text.

Rituals disclosed the breach and stated they took immediate containment measures. They refused to give the exact number of affected users to the press. Security researchers base the 41 million figure on the total size of their membership program.

France Titres / ANTS (ants.gouv.fr) [France]: ~19 million affected

Hackers breached the government agency systems and offered the citizen data for sale online.

This stolen government database contains highly sensitive citizen information. The dump includes login IDs, full names, email addresses, dates of birth, unique account numbers, postal addresses, and phone numbers. The data was unencrypted.

This is highly concerning regarding the risk of identity theft since this agency manages driver licenses, passports, and national ID cards.

The agency confirmed the breach a week after the attack occurred. They stated that their internal investigation is still ongoing.

Medtronic (medtronic.com): ~9 million affected

A ransomware group orchestrated a cyberattack against the corporate IT systems of the company.

This breach exposed highly sensitive medical and personal files. The leaked records contain names, Social Security numbers, medical data, physical addresses, and birth dates. The data lacked adequate encryption.

To put it plainly: Millions of medical records and Social Security numbers fell into the hands of extortionists.

Medtronic discovered the breach internally. The company maintained that its core operational and medical device systems remained secure and unaffected.

7-Eleven (7-eleven.com) [United States]: ~8.7 million affected

The stolen corporate files contain names, Social Security numbers, dates of birth, physical addresses, contact information, and driver license numbers. The data was completely unencrypted and unredacted.

The convenience store chain collected and stored Social Security numbers without basic encryption.

Customers now face a high risk of identity theft and tax return fraud.

Carnival Corporation (carnival.com): ~6 million affected

Carnival has suffered multiple severe data breaches over the last few years. An attacker used social engineering to deceive an employee and gain access to the IT systems.

The extracted files include names, physical addresses, email addresses, phone numbers, dates of birth, and government identification numbers like passports. This data was not encrypted.

The company detected the unauthorized activity the same day and stopped it. Several days later they confirmed the data theft. As of end of April, Carnival did not start sending notification emails to victims.

Charter Communications / Spectrum (spectrum.com) [United States]: ~4.9 million affected

An attacker executed a voice phishing call to compromise an employee account. This granted the attacker access to the internal network.

This breach exposed sensitive customer records. The data includes account details, physical addresses, and personal contact information. The data was readable the moment the attacker reached it. It lacked any encryption at rest.

The company discovered the unauthorized access shortly after the intrusion.

Amtrak (amtrak.com) [United States]: ~2.1 million affected

Hackers breached the systems and extracted the customer support database.

The breach exposed email addresses, full names, physical addresses, personal travel habits and customer support tickets. The data was stored unencrypted.

The company has released very limited information regarding their exact discovery timeline.

7-Eleven faced a major class action lawsuit regarding their data breach.

The lawsuit alleges that the company failed to implement reasonable cybersecurity safeguards. The primary complaint states that 7-Eleven collected highly sensitive information, including Social Security numbers, but failed to encrypt the data.

Customers now face a high risk of identity theft and tax return fraud.

Medtronic is also facing similar legal action for their April breach. These lawsuits highlight the severe impact on consumers when corporations refuse to invest in proper data security.

Governmental decisions weakening privacy in April 2026

On April 22, 2026, United States lawmakers introduced the SECURE Data Act.

While marketed as a comprehensive federal privacy law, it contains provisions that weaken existing customer rights. The bill explicitly excludes a private right of action. This means consumers cannot directly sue companies that misuse their data or fail to protect it.

The bill also aims to establish a national standard that overrides stronger state level privacy laws. This decision would force residents of states with strict privacy protections to accept a weaker federal standard.

Protect Your Digital Identity

Check your email addresses on data breach notification websites to see if your information was exposed in these recent incidents.

If your data is compromised, change your passwords immediately.

Using a password manager helps you generate and store unique, complex passwords for every single account you own. A good password manager also supports two-factor authentication (2FA).

This combination ensures that even if a company leaks your password in plain text, attackers cannot access your account without your secondary physical device.

Stop forgetting your passwords and ditch insecure ones for a secure password manager
To instantly stop forgetting passwords and secure your digital life, you need to migrate your logins to a dedicated, encrypted vault like 1Password or Proton Pass. You probably gave up relying on your memory and either use the web browser to save passwords or simply use the same password everywhere.

Read more