Statistics

📊 H1 2026 Data Breach Report: 500+ Million Accounts Exposed

By Ateeq Y Tanoli, BestPasswordGenerator.org · 01 June 2026 · 11 min read · 2,359 words

H1 2026 by the Numbers

The first half of 2026 has been the most damaging six-month period for data breaches in recorded history. By our count, more than 500 million individual accounts have been exposed across at least 50 confirmed breach incidents reported to Have I Been Pwned between January and June 2026.

The scale is staggering. A single infostealer malware campaign — detected by Synthient in April 2026 — exposed 2 billion credential pairs from compromised browsers and password managers. The Addi fintech breach leaked 34.5 million customer records. Canadian Tire exposed 38.3 million. Health insurer McGraw Hill lost 13.5 million. And those are just the headline numbers.

This report breaks down every major incident, the attack vectors behind them, and — most importantly — what these breaches mean for your personal password security. We have analysed breach data from HIBP, the Verizon DBIR 2026 findings, the Specops 2026 Breached Password Report, and dark-web threat intelligence to produce this complete mid-year assessment.

Complete H1 2026 Breach Timeline

Date Reported Organisation Accounts Exposed Attack Vector
01 Jun 2026 Edmunds 177,900 Unsecured database
30 May 2026 Atlas Menu 63,900 Unknown
28 May 2026 Charter Communications 4,900,000 Extortion (ShinyHunters)
27 May 2026 Mytheresa 84,100 Unknown
26 May 2026 Ameriprise Financial 502,600 Insider threat
24 May 2026 7-Eleven (Japan) 185,300 Credential stuffing
19 May 2026 CTT Portugal 468,100 Ransomware
18 May 2026 Addi (Fintech) 34,500,000 Database exposure
14 May 2026 Abrigo 711,100 Ransomware
13 May 2026 Canada Life 237,800 Supply chain attack
12 May 2026 Cushman & Wakefield 310,400 Social engineering
08 May 2026 Zara 197,400 Insider breach
05 May 2026 Vimeo 119,200 Credential stuffing
04 May 2026 Reborn Gaming 126 Credential stuffing
03 May 2026 Marcus & Millichap 1,800,000 Database exposure
02 May 2026 ZenBusiness 5,100,000 API vulnerability
27 Apr 2026 Pitney Bowes 8,200,000 Ransomware
27 Apr 2026 ADT Security 5,500,000 Credential stuffing
26 Apr 2026 Udemy 1,400,000 Credential stuffing
24 Apr 2026 Carnival Corporation 7,500,000 Social engineering (ShinyHunters)
17 Apr 2026 Amtrak 2,100,000 Phishing
16 Apr 2026 McGraw Hill 13,500,000 Database exposure
12 Apr 2026 Hallmark 1,700,000 Credential stuffing
08 Apr 2026 My Lovely AI 106,300 AI platform exploit
31 Jan 2026 Panera Bread 5,100,000 Credential stuffing
27 Jan 2026 SoundCloud 29,800,000 Credential stuffing
21 Jan 2026 Under Armour re-breach 72,700,000 Reused credentials
11 Jan 2026 Instagram (celebrity) 6,200,000 SIM swapping
06 Jan 2026 Synthient Stealer Logs 183,000,000 Infostealer malware

The Five Biggest Breaches of H1 2026

1. Synthient Infostealer Campaign — 183 Million Records (January 2026)

The largest single credential dump of the year came not from a targeted breach, but from a prolonged infostealer malware campaign. Synthient Research identified logs from multiple stealer families — including RedLine, Vidar, and Raccoon — that had been operating undetected since mid-2025.

What was exposed: Browser-saved passwords, cookie databases, cryptocurrency wallet seeds, and autofill profiles containing names, addresses, phone numbers, and credit card details. The Synthient Stealer Logs Threat Data was loaded into Have I Been Pwned in October 2025 and continued growing through January 2026 to 183 million unique credential pairs.

Why it matters: Infostealer malware bypasses all forms of password-based security because it steals credentials after the user has already authenticated. A password manager that auto-fills credentials is equally vulnerable if the browser itself is compromised. The only defence is endpoint protection, regular malware scans, and never saving passwords in unprotected browser storage.

2. Addi Fintech Breach — 34.5 Million Records (May 2026)

Colombian fintech company Addi suffered a catastrophic database exposure in March 2026, with the data appearing on breach monitoring services in May. The exposed database contained customer KYC (Know Your Customer) documentation, including government ID scans, proof-of-address documents, and financial account details.

What was exposed: Full identity portfolios — names, ID numbers, addresses, income details, and loan application histories. This is the kind of data that enables complete identity takeover.

Why it matters: Fintech companies are prime targets because they hold the richest identity data. The Addi breach underscores why using unique passwords for every financial service is critical. If you used the same email and password for Addi that you use for other services, credential stuffing bots are already trying those credentials elsewhere.

3. Canadian Tire — 38.3 Million Records (February 2026)

Canadian Tire suffered a breach through a compromised third-party vendor with access to the retailer's customer database. The data appeared on dark-web forums in February and included records spanning more than a decade of customer transactions.

What was exposed: Customer names, email addresses, phone numbers, physical addresses, encrypted credit card numbers, and purchase history. While the credit card data was encrypted (and Canadian Tire confirmed PCI-DSS compliance), the personal data was in plain text — enabling targeted phishing.

4. Under Armour (MyFitnessPal) — 72.7 Million Records (March 2026)

In one of the most revealing breaches of the year, Under Armour's MyFitnessPal platform was re-breached using credentials that had been stolen in the original 2018 data breach. Seven years after the initial incident, users who had never changed their MyFitnessPal passwords found their old credentials still worked.

What was exposed: Email addresses, usernames, and passwords (bcrypt hashed, but weak passwords were crackable). The profiles also contained height, weight, age, and dietary information — enough to build detailed personal profiles for social engineering.

Why it matters: The Under Armour re-breach is the single best example of why password rotation after a breach matters. The 2018 breach was one of the largest in history at the time (150 million users). Anyone who never changed their password had an active seven-year-old credential reused against them in 2026.

5. Pitney Bowes — 8.2 Million Records (April 2026)

The global shipping and mailing giant was hit by a ransomware attack in early April. The attackers exfiltrated customer data before triggering the encryption payload, then demanded payment for both the decryption key and a promise not to publish the stolen data.

What was exposed: Customer names, mailing addresses, email addresses, phone numbers, and account credentials stored as bcrypt hashes.

How Credential Stuffing Dominates H1 2026

Looking at the breach timeline above, one attack vector stands out: credential stuffing appears more frequently than any other method. Out of the 30 incidents we tracked, at least 10 involved credential stuffing as the primary vector, and several more used it as an escalation path after initial compromise.

Credential stuffing works because of a single, stubborn human habit: password reuse. According to Specops' 2026 Breached Password Report, 94% of the 19.03 billion leaked credentials in circulation are duplicates — only 6% are unique. Attackers know this. They do not need to crack your password; they just need to use it.

The credential stuffing attacks surge in 2026 that we reported in May has only accelerated. Microsoft now blocks over 7,000 password attacks per second across its platforms — up from 4,000 per second in 2024. The economics of credential stuffing are brutally simple: attackers buy breached credential lists on dark-web forums for as little as $50 and let automated bots test them against hundreds of websites simultaneously. A single successful login on a banking or email platform can yield thousands of dollars in fraudulent transactions.

Password Security Lessons from H1 2026

Lesson 1: A Strong Password Is Pointless If You Reuse It

The biggest misconception exposed by these breaches is that using a "strong" password protects you. A password like g7$Kp#9mQ!2xL@4r is cryptographically strong — but if you use it on ten different sites and one of those sites gets breached (like Under Armour's MyFitnessPal), every account sharing that password is instantly compromised.

The fix: Generate a unique, random password for every single account. Our free password generator creates cryptographically strong passwords instantly. Do this for every new account you create, and use a password manager to store them.

Lesson 2: Password Managers Protect You From Breach Cascading

When Pitney Bowes, Carnival, and ADT all lose customer credentials in the same month, anyone reusing passwords across those services would lose control of all three accounts simultaneously.

A password manager generates unique 20+ character passwords for each account, stores them in an encrypted vault, and auto-fills them so you never need to type them. If one service is breached, the damage stops at that single account. For enterprise-grade protection with breach monitoring, Kaspersky Password Manager alerts you when your credentials appear in known leaks.

Lesson 3: Enable MFA — But Know Its Limits

Multi-factor authentication (MFA) blocks 99.9% of automated credential-stuffing attacks, according to Microsoft research. That is the good news.

The bad news: credential theft through infostealer malware (like the Synthient campaign) often captures session cookies alongside passwords, allowing attackers to bypass MFA entirely. The MFA prompt bombing attacks that surged in May 2026 exploit a different weakness — user fatigue — by spamming MFA push notifications until the user accidentally approves one.

The fix: Enable MFA on every account that supports it. Use authenticator apps (TOTP) rather than SMS codes. Be suspicious of unexpected MFA prompts. And keep your browser and operating system updated so infostealer malware has fewer entry points.

Lesson 4: Check If You Have Been Breached

After every major breach in this list, the stolen credential lists circulate on dark-web forums. Services like Have I Been Pwned let you check if your email address appears in any known breach. You can check if your password has been leaked using our step-by-step guide.

For accounts that appear in a breach: change the password immediately, enable MFA, and check that account's security settings for any unauthorised changes. Turbo VPN adds an extra layer of privacy when checking your accounts from public or untrusted networks.

Lesson 5: Treat Infostealer Malware as the New Frontline Threat

The Synthient 183-million-record dump represents a paradigm shift in credential theft. Infostealer malware does not crack passwords — it waits until you log in, then copies your authenticated session. This makes it the most dangerous threat in the current landscape.

The fix: Run regular malware scans. Use a good antivirus solution. Avoid downloading software from unofficial sources. Use browser isolation for sensitive account access. And never save passwords directly in your browser — use a dedicated password manager instead, which encrypts your vault with a master password that infostealers cannot extract from browser storage.

Lesson 6: Treat Every Breach Notification Seriously

When Have I Been Pwned notifies you that your email appears in a breach database, do not ignore it. Each notification represents a real credential pair that is already circulating among attackers. The personal password security audit guide covers a complete checklist for what to do after receiving a breach notification, including password rotation, MFA setup, and monitored account review.

The H1 2026 Security Action Plan

If you take away nothing else from this report, follow these five steps to protect every account you own:

  1. Check Have I Been Pwned with every email address you use. If any appear in the breaches above, change those passwords immediately.
  2. Generate unique passwords for every account using our secure password generator.
  3. Adopt a password manager to store and auto-fill those unique passwords. See our password manager review for recommendations.
  4. Enable MFA on every account — especially email, banking, and social media.
  5. Run a malware scan if you have downloaded any files or software from unofficial sources in the last six months.

For families looking to secure shared accounts and children's devices, SafePassBuilder offers practical tools for household password management. If you manage teams or enterprise accounts, IronVaultKeys provides policy-compliant password solutions with enforced MFA policies and breach monitoring. For ongoing credential monitoring, the tools reviewed on TrustyPassword can help you track whether your accounts appear in active credential-stuffing campaigns. Businesses looking for enterprise-grade security analytics should explore the tools reviewed on SecureKeyGenerator.

FAQs

How many data breaches happened in H1 2026?

More than 50 confirmed incidents were reported to Have I Been Pwned between January and June 2026, affecting over 500 million individual accounts. This does not include the Synthient campaign data, which alone adds another 183 million breached credential records.

Which was the biggest data breach of 2026 so far?

The largest single incident was the Synthient infostealer campaign exposing 183 million credential records, followed by the Canadian Tire breach (38.3 million records), the Addi fintech breach (34.5 million accounts), and the Under Armour MyFitnessPal re-breach (72.7 million — though many accounts overlapped with the 2018 breach).

Is my password still safe if it is strong but reused?

No. A strong reused password is cracked once and usable everywhere. Credential stuffing bots use automated tools to test leaked credentials across hundreds of websites. The strength of the password does not matter — what matters is that it is unique to each account.

How do I know if I was in a 2026 breach?

Visit Have I Been Pwned and enter your email address. You can also use our step-by-step guide for checking your credentials against all known breach databases.

What is the most common attack vector in 2026?

Credential stuffing is the most common single vector, appearing in more than 25% of tracked incidents. Infostealer malware is the fastest-growing threat, with data volumes increasing more than 500% year-over-year. Social engineering and ransomware remain significant, with the ShinyHunters group alone claiming responsibility for three major breaches this year (Charter, Carnival, and Cushman & Wakefield).

Should I use a password manager after these breaches?

Yes. A password manager is the only practical way to maintain unique passwords across every account you own. It also protects you from credential stuffing (unique passwords per site), phishing (auto-fill only works on legitimate sites), and brute-force attacks (long random passwords are uncrackable). Our best password managers 2026 comparison breaks down the top options for every use case.

How many people still reuse passwords in 2026?

Studies consistently show that 60-84% of people reuse passwords across multiple accounts. Specops found that only 6% of the 19.03 billion credentials in breach databases are unique — meaning the vast majority of breached passwords are duplicates that an attacker can immediately use elsewhere. The Bright Defense 2026 study found that 73.6% of Americans reuse passwords, with 79.1% using only slight variations like adding a number or changing a single character.

Generate a Free Strong Password →

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🔐 Free Strong Password⚡ Instant Password🗝️ Iron Vault Keys🔑 Random Pwd Tool👨‍👩‍👧‍👦 Safe Pass Builder🛡️ Trusty Password⚙️ StrongPassFactory🔑 SecureKeyGen.org📚 TrustyPassword.org
We use cookies to improve your experience. Learn more

🛡️ Security Picks This Week

Hand-picked security tools — updated weekly.

Thetis Pro-C FIDO2 Key

Thetis Pro-C FIDO2 Key

Budget USB-C/NFC security key with TOTP authenticator app.

Check price →
Yubico Security Key NFC

Yubico Security Key NFC

Budget-friendly 2FA key — USB-A & NFC, FIDO2 certified.

Check price →
TP-Link ER605 VPN Router

TP-Link ER605 VPN Router

Multi-WAN VPN gateway — secure every device on your network.

Check price →

As an Amazon Associate we earn from qualifying purchases.