Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
ShinyHunters Hit Canvas, One Medical, and More: 2026's Worst Cyber Breaches So Far

ShinyHunters: One Brand, Many Victims
ShinyHunters is no longer just a hacking crew. Researchers now describe it as a durable cybercrime brand, according to PKWARE's analysis of 2026 breach data. The group runs a pay-or-leak model: steal the data, set a deadline, publish if you aren't paid.
The group's most consequential hit this year was Canvas LMS, the learning management platform operated by Instructure. Between April 25 and May 12, 2026, ShinyHunters breached Canvas systems and claimed to have taken 3.65 terabytes of data from approximately 275 million users across 8,809 universities, educational ministries, and institutions worldwide, according to Wikipedia's documented account of the incident.
This represents the largest educational security breach on record. Canvas is used by 41% of U.S. higher education institutions and an undetermined number of K-12 schools.
The breach exposed names, email addresses, student ID numbers, and private messages between students and teachers. Instructure said it found no evidence that passwords, birth dates, government IDs, or financial information were taken. ShinyHunters threatened to release everything unless paid by May 12. Instructure claimed on May 6 the situation was resolved. The next day, May 7, Canvas's login page was replaced with a ShinyHunters ransomware message.
Instructure issued an apology on May 11 for what it called a lack of transparency. The company stated it reached an agreement with "the unauthorized a" — the Wikipedia source entry cuts off there — but reported the compromised data was ultimately deleted.
One Medical's Legacy Data Problem
ShinyHunters also claimed the June breach of Amazon-owned primary care provider One Medical. According to PKWARE's incident breakdown, One Medical discovered unauthorized access on June 13, 2026, to a third-party archival file storage system. The intrusion occurred between June 8 and 11.
The exposed data belonged to One Medical Seniors patients, formerly Iora Health, a practice One Medical acquired in 2021 and parked in an archive. ShinyHunters claimed 8.8 terabytes and set a June 22 deadline. One Medical said the breach affected a subset of legacy patients within a network serving more than 830,000 patients overall, and that no main electronic medical records or other Amazon systems were involved. One Medical has not publicly named ShinyHunters as the responsible party.
The lesson PKWARE draws is direct: legacy systems are healthcare security's most common blind spot. Data acquired through a corporate purchase five years ago, sitting in an archive, received less protection than live records. The attackers didn't break through a perimeter. They logged in through valid or inherited access credentials.
The Opposing View Worth Hearing
Some security professionals push back on framing these incidents as failures of corporate negligence alone. The argument is legitimate: organizations managing millions of records from legacy acquisitions face a genuine triage problem. Retrofitting encryption and access controls onto inherited systems costs real money and operational disruption, and regulators have historically not mandated specific timelines for securing acquired data. Critics of aggressive breach reporting argue that public shaming without policy solutions just drives breach disclosure underground. That concern deserves to be heard, though it doesn't change the outcome for the 275 million Canvas users whose private messages are now someone else's leverage.
Europe's Infrastructure Under Attack
Beyond criminal extortion, TechCrunch's 2026 breach roundup documents a parallel threat: Russian-attributed attacks on European civilian infrastructure. Poland's energy grid was hit with computer-destroying malware in late 2025. A Swedish thermal plant and a Norwegian dam were also targeted, with the dam attack releasing significant volumes of water. Earlier in 2026, hackers struck Polish water treatment plants.
These are NOT ransomware plays. The goal appears to be disruption and real-world harm, not payday. The attacks track with a broader pattern of hybrid warfare, where physical conflict and digital sabotage run simultaneously.
The DOGE Question Remains Open
TechCrunch's review also flags an ongoing concern that has not resolved into confirmed fact. After DOGE operatives entered the Social Security Administration in early 2025, whistleblowers alleged that a live copy of the Social Security database was uploaded to an unsecured third-party server potentially containing the Social Security numbers and personal information of most living Americans.
The Social Security Administration, according to TechCrunch's account of court filings, cannot confirm exactly what was stored on that server. The agency acknowledged signing an agreement with an outside political advocacy group, framed as a voter fraud investigation. Two senior House Democrats called it potentially "the largest data breach in our nation's history."
What's proven: an agreement was signed, access occurred, and litigation is ongoing. What's alleged but unproven: that sensitive SSA data was actually exfiltrated or misused. No investigation by a law enforcement or regulatory body has been publicly announced, and no charges have been filed. The system design — internal government access that bypasses normal breach-notification thresholds — makes this category of concern genuinely hard to audit from the outside.
What 2026 Has Established
June's breaches, per PKWARE's analysis, shared one structural feature: perimeter defenses didn't fail. Attackers used valid credentials, exploited an Oracle PeopleSoft zero-day, or accessed legacy archives that were never hardened. Fast containment and backups didn't help, because the data was usable the moment it left.
The unresolved question for the second half of 2026 is whether ShinyHunters' pay-or-leak model, which proved effective against a healthcare provider, an education platform, and insurance regulators, will invite enough imitators to become the dominant ransomware structure, displacing the traditional encrypt-and-extort approach that backups can defeat.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.