Again hundreds of millions private records and millions of sensitive medical records leaked, the US keeps dismantling your privacy with laws.

Share
We may earn a commission for purchases made through links in this post. Read more.

In May 2026 again massive data breaches across the education, healthcare, and retail sectors happened globally.

The largest incident hit Instructure, exposing 231 million users. Healthcare supply chain vulnerabilities compromised sensitive medical and biometric data for millions.

Concurrently, financial institutions faced lawsuits for ignoring cookie opt-outs, and a proposed US federal law threatened to roll back state-level privacy protections.

A woman sitting on her laptop facepalming, probably because she just read about all these leaks

The biggest data leaks and hacks in May 2026

This month again saw a massive amount of breaches and leaks, amounting to hundreds of millions being affected. The US keeps its course to undermine their citizens rights to privacy.

Also read below how to find out if you are affected and what to do.

Instructure (Canvas): 231 million affected

Instructure, the company behind the Canvas educational platform, suffered a breach originating from their Free-For-Teacher SaaS program. Attackers stole 3.65 TB (3,650 GB) of data. This dump affected an estimated 231 million unique users.

The stolen data contained names, email addresses, student ID numbers, and internal private messages. Security reports do not specify if the exfiltrated data was encrypted.

The extortion group exploited a platform vulnerability to access the data. Instructure discovered the incident on May 1 and contained it by May 6. The company was straightforward about the timeline.

NYC Health + Hospitals [US]: 1.8 million affected

NYC Health + Hospitals experienced a breach originating from an unnamed third-party vendor. The hackers gained access through a months-long intrusion into the third-party system.

The attackers compromised medical records, health insurance information, Social Security numbers, driver licenses, passports, financial account details, online account credentials, precise geolocation data, and biometric fingerprints and palm scans. Reports do not state whether this data was encrypted.

This breach is of extreme severity due to the highly sensitive biometric and medical data exposed.

The hospital system discovered the breach and publicly confirmed it on May 18. They were relatively straightforward about the impact, although the specific vendor remains unnamed.

American Lending Center [US]: 123,000 people affected

The American Lending Center suffered a breach affecting its internal applications and databases. The incident exposed sensitive personal and financial information belonging to roughly 123,000 loan applicants and customers.

The specific data points included detailed financial profiles. The encryption status remains unspecified. This a high-risk leak due to the financial nature of the compromised data.

The company discovered the breach internally and disclosed it to the public. They were straightforward about the risks, warning users about the increased potential for identity theft and financial fraud.

LHC Group [US]: 8,644 people affected

LHC Group, a home healthcare provider, suffered a data leak originating from their vendor, Doctor Alliance. The hackers gained access through a security incident at the vendor level.

The compromised data included names, dates of birth, demographic information, clinical summaries, diagnosis codes, provider information, and health insurance information. The data was likely unencrypted when accessed.

LHC Group discovered the breach after the vendor notified them. The company was straightforward in sending out HIPAA breach notifications to all affected patients.

Corporate Privacy Violations and Lawsuits in May 2026

Multiple financial institutions faced lawsuits for weakening consumer privacy and violating wiretapping laws. Consumers sued these institutions because their websites continued to track and transmit personal data even after the users explicitly rejected non-essential cookies via consent banners.

The impact on customers is significant.

Highly sensitive financial intent data was shared with third-party trackers without consent, exposing users to unwanted profiling and targeted financial advertising.

Plaintiffs also sued mortgage servicers, cryptocurrency exchanges like Crypto.com, and retail platforms like Smith & Wesson.

Unnamed banks in the Northern District of California also faced litigation after users received targeted ads for competing financial products on Facebook immediately after using the bank websites to manage or apply for credit cards.

Governmental Decisions Weakening Privacy

House Republicans in the United States introduced the SECURE Data Act.

While pitched as a unified data privacy bill, privacy advocates and a coalition of 18 state attorneys general argued that this federal decision would severely weaken existing customer rights.

The proposed act aims to preempt stronger state-level protections, such as those in California. It gives data violators a 45-day "cure period" to fix issues before facing enforcement.

It also allows data collectors to hide behind broad categories rather than naming the specific third parties buying consumer data.

Protect Your Digital Identity

Check monitoring services like Have I Been Pwned to see if these breaches exposed your information.

A password manager helps secure your accounts because it generates unique, complex passwords for every site you use. If one service leaks your credentials, hackers cannot use that same password to access your other accounts.

Stop forgetting your passwords and ditch insecure ones for a secure password manager
To instantly stop forgetting passwords and secure your digital life, you need to migrate your logins to a dedicated, encrypted vault like 1Password or Proton Pass. You probably gave up relying on your memory and either use the web browser to save passwords or simply use the same password everywhere.

Read more