Offgrid Studio logo Offgrid Studio

Privacy News

One Breach Claims 275 Million Victims. The Public Record Confirms 18,400.

September 2026

We wrote last year about data breaches breaking a record while companies explained less and less about what actually happened. Privacy Rights Clearinghouse just published its midyear update for 2026, and the pattern hasn't just continued — one case in this report shows exactly how thin the public record can get, even for a breach that may have reached hundreds of millions of people.

The headline numbers

343M

people affected by breaches in H1 2026, more than double H1 2025's 142.8M

1,969

distinct breach events, from 5,429 notification filings

80%

of the entire 343M total comes from one single breach: Instructure (Canvas)

18,400

people the public record actually confirms in that breach — vs. 275 million claimed

1 in 3

breach events have a cause that can't be determined from public filings

113

breach events at law firms this half, up from 64 in the first half of 2022

The counting gap

In April 2026, attackers compromised Canvas, the learning management system Instructure says serves more than 30 million users at over 8,000 institutions. An extortion group called ShinyHunters claimed the attack, and by May 11, Instructure paid to have the stolen data returned and destroyed — a payment the company's own incident page describes only as an "agreement with the unauthorized actor."

Here's the part that stands out: companies generally only have to report a breach to the states where affected residents live, and only some states require a specific number of people affected in that filing. A breach that reached thousands of institutions nationwide entered the public record as just fifteen filings, from four states. Only two of those fifteen state a specific number, adding up to roughly 18,400 people. The widely cited 275 million figure comes from a single Wisconsin filing that simply quoted the attackers' own unverified claim — a number Instructure has never confirmed.

Both numbers describe the same breach. One is what a company's own paying customer, an attacker, claimed. The other is what four state governments were able to independently verify. That gap is the story.

Why one vendor can dominate a whole year's statistics

Instructure isn't an isolated case. The same shape ran through the largest breaches the report's authors tracked previously — Change Healthcare, a claims processor whose 2024 breach reached 192.7 million people; Conduent, which handled records for scores of health plans and public agencies; and PowerSchool, a education platform breach the same researchers studied in last year's report. Each of these is infrastructure other organizations run on, not a single company's own data. When one vendor holds data for thousands of clients, a single compromise can ripple across all of them simultaneously — and can single-handedly dominate a half-year of national breach statistics, exactly as Instructure did this period. Without the Instructure breach, the first half of 2026's total affected count falls from 343 million to roughly 68 million.

Who got breached

Sector Events People affected
Education 90 279.5M (almost all Instructure)
Business, other 763 25.1M
Healthcare 509 20.2M
Financial 350 12.2M
Government 90 4.7M
Nonprofit 89 1.2M
Retail 56 0.3M

Source: Privacy Rights Clearinghouse, 2026 Midyear Data Breach Report, snapshot taken August 14, 2026.

The record is getting less transparent, not more

Hacking remains the most commonly identified cause, at 58% of breach events. But the more telling number is how often no cause is named at all: 33.8% of breach events this half — about one in three — couldn't be classified from public filings, up from 22.6% in the first half of 2022. Part of that traces to how breaches are disclosed: the share of breaches whose full notification letter is public has fallen from 70% to 62% over the same period, and where the letter is missing, the cause usually is too. But that's not the whole story — even among breaches with a public letter, the share researchers couldn't classify has more than doubled since 2022. The record is saying less even where it's most complete.

Why this matters beyond the numbers

Every breach in this report happened to data that was collected and stored somewhere, by design. None of Offgrid Studio's apps have an account system or a server holding your recordings, transcripts, or video — not because we're smarter than the organizations in this report, but because there's simply nothing centralized to breach. A vendor can't leak what it was never given.

We also ran our own network audit to verify what our apps actually send, rather than asking anyone to take that on faith.

Frequently asked questions

How many people were affected by data breaches in the first half of 2026?

According to Privacy Rights Clearinghouse's 2026 Midyear Data Breach Report, at least 343 million individuals were affected across 1,969 distinct breach events reported in 5,429 notification filings. A single breach, at Instructure (Canvas), accounts for nearly 80% of that total.

What happened in the Instructure (Canvas) breach?

Attackers compromised Canvas, the learning management system used by more than 30 million users at over 8,000 institutions, in April and May 2026. An extortion group called ShinyHunters claimed responsibility, and Instructure paid to have the stolen data returned and destroyed. The company has not confirmed a total number of affected individuals; a Wisconsin filing cited the attackers' unverified claim of 275 million.

Why is there such a large gap between the claimed and confirmed number of victims?

Companies generally only have to report a breach to the states where affected residents live, and only some states require a specific resident count in that filing. Across all fifteen public filings for the Instructure breach, only two stated a specific number, adding up to roughly 18,400 people. The 275 million figure comes from a single Wisconsin filing that cited the attackers' own unverified claim.

What percentage of breaches don't disclose how they happened?

About one in three breach events (33.8%) in the first half of 2026 had a cause that could not be determined from public filings, up from 22.6% in the first half of 2022. Hacking was the most common identified cause, at 58% of events.

Why do vendor breaches like Instructure affect so many people at once?

When a single vendor provides infrastructure to thousands of client organizations, a breach at that vendor can ripple across every client at once. The same pattern occurred with Change Healthcare, Conduent, and PowerSchool in prior reports — each is infrastructure other organizations depend on, so one compromise becomes a breach at hundreds of institutions. See our Privacy Policy for how we approach this differently.

More from Offgrid Studio

Data Breaches Just Broke a Record. Companies Are Explaining Less Than Ever. · We Ran Our Own Network Audit. Here's What We Found. · 5,000 Apps, One Privacy Audit: What Your Phone Is Actually Sharing

Back to the blog