May 2026 data breach round up
Back to Blog
Security Intelligence

May 2026 Data Breach Round-Up

PublishedMay 28, 2026
Read time6 min read
Share
Originally reported viaHaveIBeenPwned · SEC Form 8-K Disclosures · EU DPA Breach Notifications — May 2026

May 2026 saw 89 publicly confirmed data breach disclosures affecting organisations across 24 countries. The total confirmed exposed record count exceeded 47 million individuals — the highest single-month figure since the 2024 healthcare sector wave. Regulatory notifications filed with EU data protection authorities reached a new monthly high of 234, reflecting both increased breach volumes and NIS2's tightened 24-hour notification requirements.

Notable breaches: May 2026

A major European retail bank disclosed unauthorised access to 2.1 million customer records including partial payment card data. A US-based cloud storage provider confirmed that credentials from a phishing campaign were used to access approximately 8 million end-user files. A UK NHS trust reported the theft of patient appointment records for 1.2 million individuals following a ransomware attack that began with a compromised contractor VPN account.

Source: EU DPA Breach Notification Portal — May 2026
EU DPAs reported that 61% of May breach notifications cited 'insufficient access controls' as the root cause — consistent with prior months. Inadequate MFA enforcement and over-privileged service accounts remain the dominant contributing factors across notifications.

Notification timelines: NIS2 compliance pressure

Regulatory analysis of May disclosures shows that only 38% of EU-scoped organisations met the NIS2 24-hour significant incident notification requirement. The most common failure mode is absence of a documented notification decision procedure — organisations discover the incident but lack a pre-defined escalation path to identify it as 'significant' and notify the relevant CSIRT within the required window.

  • Document and test your NIS2 24-hour notification procedure — run a tabletop exercise specifically targeting the notification decision and CSIRT contact process.
  • Audit contractor VPN accounts monthly — the NHS trust incident involved a contractor account that had not been deprovisioned 6 weeks after contract termination.
  • Classify data assets by regulatory sensitivity to enable rapid scope assessment when a breach is detected.

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.