Two massive data breaches emerged over the weekend, collectively affecting tens of millions of people across healthcare, education, and government services.
Conduent breach — 25 million+ records exposed: Conduent, the data management company that processes benefits and social services on behalf of state governments, confirmed unauthorized access to systems containing sensitive data for at least 25 million people across Texas and Oregon. Compromised data includes health plan records with personally identifiable information from multiple state social services programs. The breach was attributed to the ShinyHunters collective, which has been on a sustained rampage through major data processors in 2026.
Instructure (Canvas LMS) breach — 275 million student records: Instructure, the company behind the Canvas learning management system used by nearly 9,000 schools worldwide, confirmed two separate breaches by ShinyHunters affecting approximately 275 million users. Stolen data includes student names, email addresses, student IDs, and private messages exchanged within Canvas. The scale makes this one of the largest education sector breaches ever recorded. One Medical (Amazon) also confirmed during the weekend that ShinyHunters accessed a third-party storage system containing legacy patient records, with the group claiming 8.8 terabytes of data.
Sources
- Privacy Guides: Data Breach Roundup July 3–9, 2026
- Help Net Security: Week in Review
- Mashable: Biggest Data Breaches of 2026
Commentary
ShinyHunters continues to function at a pace and scale that suggests either significant infrastructure investment or multiple coordinated sub-groups operating under the same brand. The Conduent breach is particularly alarming: state social services data means the victims are disproportionately low-income individuals who depend on government benefits — people with limited resources to freeze credit, monitor accounts, or litigate identity theft. The Instructure breach affecting 275 million students is a generational data exposure; student IDs and private messages from minors have long-tail privacy implications well beyond the typical breach notification window. At some point, the data supply chain — where government agencies and educational institutions outsource sensitive data handling to third parties — needs structural scrutiny, not just incident response.
