The first half of 2026 has already produced some of the largest data breaches in history. The Conduent Business Services breach may be the biggest ever in the US, while edtech giant Instructure got hit twice in two weeks by the same hacking group.
Conduent: Potentially the Largest US Breach Ever
Conduent Business Services, a government contractor that processes everything from toll payments to healthcare claims, suffered a breach that could be the largest in US history. The scale of exposed data dwarfs previous records, though exact numbers are still being confirmed. Conduent handles services for multiple federal and state agencies, meaning the breach extends far beyond corporate data.

The breach highlights a recurring problem: government contractors handle massive amounts of citizen data but often lack the security infrastructure of the agencies they serve.
Instructure Hit Twice by ShinyHunters
Instructure, the company behind the Canvas learning management system used by thousands of schools and universities, was breached twice within roughly two weeks by extortion group ShinyHunters. The group has been behind several high-profile education sector attacks.
Canvas serves over 30 million students globally, raising concerns about student data exposure including grades, personal information, and institutional records.
Match Group and the Dating App Breach
Early in 2026, ShinyHunters also claimed a breach of Match Group, the parent company behind Tinder, Hinge, and OkCupid. The exposure of dating app data carries particular sensitivity because of the personal nature of profiles, messages, and location data.
149 Million Credentials Exposed
A separate incident exposed approximately 149 million credentials across multiple platforms, according to breach tracking services. The dataset, circulating on dark web forums, combines credentials from several smaller breaches into one massive dump.
Additional Major Incidents
Stryker Cyberattack: Medical device manufacturer Suffered a cyberattack that disrupted operations. Details remain limited, but the incident was significant enough to trigger regulatory disclosures.
Brightspeed Ransomware: Internet service provider Brightspeed was hit with ransomware that disrupted service for customers across multiple states.
Nike Internal Data Breach: Approximately 1.4 terabytes of internal Nike data was exposed, including corporate documents and employee information.
Patterns to Watch
ShinyHunters continues to be the most active extortion group of 2026, targeting education, dating, and enterprise platforms. Their strategy of hitting the same company twice within weeks shows a pattern of exploiting incomplete remediation.
Government contractors remain a weak link in the security chain. The Conduent breach underscores how a single contractor compromise can cascade across multiple agencies and millions of citizens.
Credential reuse is fueling the scale of these breaches. The 149 million credential dump likely contains thousands of passwords that still work on active accounts because users never changed them after earlier leaks.
Frequently Asked Questions
What was the Conduent data breach?
Conduent Business Services, a government contractor processing tolls and healthcare data, suffered a breach potentially the largest in US history. The full scope is still being assessed.
Who is ShinyHunters?
ShinyHunters is an extortion hacking group responsible for multiple 2026 breaches including Instructure (Canvas LMS) and Match Group (Tinder, Hinge). They have a pattern of hitting the same target multiple times.
How do I check if my data was in the breach?
Use breach notification services like Have I Been Pwned (haveibeenpwned.com) or BreachSense to search your email addresses against known breach databases.
What can I do to protect myself after a data breach?
Change passwords on any account that shares credentials with the breached service. Enable two-factor authentication everywhere. Use a password manager to generate unique passwords for each site.
