8 Breaches, Millions Affected: The Biggest Cybersecurity Incidents of May 2026
May 2026 delivered another reminder that no industry is immune to cyber threats. From cruise operators and telecommunications providers to pharmaceutical manufacturers, automakers, gaming platforms, and educational technology companies, organizations across the globe faced significant security incidents this month. At the same time, new research from Verizon highlighted how artificial intelligence is accelerating cyberattacks, allowing threat actors to identify and exploit vulnerabilities faster than ever before. In this month’s roundup, we examine some of the most notable breaches, the tactics used by attackers, and the key lessons organizations should take away to strengthen their cyber resilience.
Carnival Breach Exposes Data of Nearly 6 Million Customers:
Carnival Corporation disclosed a major data breach affecting nearly 6 million individuals after attackers gained access to an employee account through a social engineering attack. The unauthorized access allowed the threat actors to enter internal systems and steal files containing sensitive personal information, including names, contact details, dates of birth, and government-issued identification numbers. The breach was later linked to the ShinyHunters extortion group, which claimed to have stolen millions of records and subsequently leaked the data online. Impacted customers are being offered two years of complimentary credit monitoring services as the company continues its investigation. The incident highlights the ongoing effectiveness of social engineering attacks and the importance of strengthening identity security controls, employee verification processes, and phishing-resistant authentication measures.
NVIDIA Confirms GeForce NOW User Data Exposure:
NVIDIA confirmed a data breach affecting users of GeForce NOW in Armenia after a cybersecurity incident impacted systems operated by a regional service partner. The company stated that its own infrastructure and NVIDIA-operated services were not compromised, with the breach limited to the partner-managed environment. Exposed information reportedly included names, email addresses, phone numbers, usernames, and dates of birth, though no passwords were stolen. The incident highlights the growing cybersecurity risks associated with third-party providers and partner ecosystems, where attackers can gain access to customer data without directly compromising the primary organization. NVIDIA and its regional partner continue to investigate the breach and notify affected users while working to strengthen security controls.
Škoda Warns Customers After Online Store Security Breach:
Škoda disclosed a data breach after attackers exploited a vulnerability in software used by its German online accessories store, gaining unauthorized access to customer information. The potentially exposed data included names, addresses, email addresses, phone numbers, order details, and encrypted account passwords, although the company stated that payment card information was not stored on the affected systems and was therefore not compromised. Following the discovery of the incident, Škoda took the online shop offline, fixed the vulnerability, engaged external forensic specialists, and notified data protection authorities. While the company said it has no evidence that customer data has been misused, it warned affected individuals to remain vigilant against phishing attempts and credential-stuffing attacks, particularly if they reused passwords across multiple services. The breach was limited to the German online accessories store and did not affect Škoda Connect services, vehicle data, or other company systems.
Retail Giant 7-Eleven Hit by Cyberattack Linked to ShinyHunters:
7-Eleven disclosed a data breach that exposed the personal information of approximately 185,000 individuals after attackers gained unauthorized access to systems used for storing franchisee-related documents. While the company did not publicly identify the threat actor, the ShinyHunters extortion group claimed responsibility and alleged that it had compromised the retailer’s Salesforce environment, stealing hundreds of thousands of records. According to analyses of the leaked data, exposed information included names, email addresses, phone numbers, physical addresses, and dates of birth. The attackers reportedly published the stolen data after ransom demands were not met. The incident underscores the continued targeting of cloud-based business platforms by cybercriminal groups and highlights the growing risks associated with third-party and customer data stored in SaaS environments.
Canvas Cyberattack Disrupts Schools and Exposes User Data:
Instructure, the company behind the widely used Canvas learning management platform, disclosed a major cybersecurity incident that affected schools, universities, and educational organizations worldwide. The company reported that attackers first gained unauthorized access to Canvas on April 29 and later exploited a second vulnerability on May 7, temporarily defacing login pages and forcing the platform into maintenance mode while security teams investigated and contained the threat. According to Instructure, the attackers accessed user information that may have included names, email addresses, student ID numbers, and user communications, though there was no evidence that passwords, financial information, or government-issued identifiers were compromised. The company traced the attacks to vulnerabilities associated with its Free-For-Teacher accounts, which were subsequently taken offline. The incident caused widespread disruption during a critical academic period and highlighted the growing cybersecurity risks facing educational technology platforms that store large volumes of student and institutional data.
West Pharmaceutical Hit by Data Theft and System Encryption Attack:
West Pharmaceutical Services disclosed a cyberattack in May that resulted in unauthorized access to company systems, data theft, and the encryption of portions of its network. Upon detecting the incident, the pharmaceutical manufacturer activated its incident response procedures, took affected systems offline to contain the threat, engaged external forensic experts, and notified law enforcement. The attack disrupted global operations, although the company reported that core enterprise systems were restored and critical manufacturing and shipping activities were being resumed in a phased manner. Investigators are still working to determine the full scope of the incident and whether sensitive data was impacted. The breach highlights the growing cybersecurity challenges facing critical healthcare and pharmaceutical supply chains, where operational disruptions can have significant downstream effects.
Charter Confirms Breach After Extortion Group Claims 40 Million Records:
Charter Communications confirmed a cybersecurity incident after the ShinyHunters extortion group claimed responsibility for stealing data from the telecommunications provider. According to the threat actors, the breach originated from a voice phishing attack that compromised an employee account, allowing access to customer information stored in Salesforce. While Charter stated that no sensitive personal information or customer proprietary network information was exfiltrated, ShinyHunters alleges it obtained millions of customer records, including contact details, service plan information, and support ticket data. The incident reflects a growing trend of attackers using social engineering techniques to bypass traditional security controls and gain access to cloud-based business applications. It also highlights the increasing focus on SaaS platforms as high-value targets for data theft and extortion campaigns.
Cybersecurity Firm Trellix Confirms Source Code Repository Breach:
Cybersecurity firm Trellix disclosed a security incident involving unauthorized access to a portion of its source code repository, prompting an internal investigation and engagement with external forensic experts. The company stated that it found no evidence that its software release process was compromised or that the exposed source code had been used in attacks against customers. Shortly after the disclosure, the RansomHouse extortion group claimed responsibility for the intrusion and published screenshots allegedly showing access to internal systems, although the authenticity of the leaked material has not been independently verified. According to the threat actors, the attack occurred in April and included data encryption as part of the compromise. The incident highlights the growing trend of cybercriminal groups targeting software vendors and technology providers, where access to source code repositories can create significant security and intellectual property risks.
Verizon Report: AI-Powered Attacks Are Fueling a New Wave of Breaches:
A new Verizon cybersecurity report highlights the growing role of artificial intelligence in both cyberattacks and data breaches. Analyzing more than 31,000 security incidents, the report found that vulnerability exploitation has now surpassed stolen credentials as the leading cause of breaches, accounting for 31% of cases. Researchers noted that attackers are increasingly leveraging generative AI to identify software weaknesses, automate reconnaissance, and accelerate malware development, significantly reducing the time organizations have to respond to emerging threats. The report also warned about the rise of “Shadow AI,” where employees unknowingly expose sensitive data by uploading source code and other information to unauthorized AI tools. As AI capabilities continue to advance, security leaders are increasingly turning to AI-powered defensive technologies to keep pace with rapidly evolving attack techniques.
Key Takeaways from May’s Biggest Breaches
A common theme emerged throughout May’s incidents: attackers continue to find success by targeting trusted systems, third-party providers, cloud applications, and human vulnerabilities. Many of the breaches were linked to social engineering, SaaS platform compromises, and the growing use of AI to accelerate attacks, demonstrating how rapidly the threat landscape is evolving. Organizations can no longer rely solely on annual assessments or point-in-time security reviews to manage risk. Continuous monitoring, stronger identity controls, and greater visibility into third-party environments are becoming essential for reducing exposure. As cybercriminals continue to adapt their tactics, proactive and evidence-based security practices remain the strongest defense against the next breach.