The United States on top, France in explosion
Since the beginning of 2026, the global landscape of database leaks reveals a striking concentration of attacks on a few countries. According to statistics compiled by Surfshark (updated April 21, 2026), the first quarter of 2026 saw no fewer than 114 million accounts compromised in just the 15 most affected countries.
The Top 10 Countries by Number of Compromised Accounts (Q1 2026)
| Rank | Country | Compromised Accounts (Q1 2026) | Evolution vs Q4 2025 |
|---|---|---|---|
| 1 | ๐บ๐ธ United States | 60,324,766 | +3% |
| 2 | ๐ซ๐ท France | 23,454,318 | +109% |
| 3 | ๐ฎ๐ณ India | 7,296,531 | โ62% |
| 4 | ๐ง๐ท Brazil | 4,544,088 | +53% |
| 5 | ๐ฌ๐ง United Kingdom | 4,433,577 | +107% |
| 6 | ๐จ๐ณ China | 3,684,937 | +158% |
| 7 | ๐จ๐ฆ Canada | 3,249,834 | +136% |
| 8 | ๐ช๐ธ Spain | 2,751,804 | +149% |
| 9 | ๐ฉ๐ช Germany | 2,751,582 | +4% |
| 10 | ๐ท๐บ Russia | 2,606,269 | โ18% |
Source: Surfshark Data Breach Statistics, Q1 2026.
France, the star victim of the quarter
With 23.4 million accounts compromised in the first quarter of 2026 alone, France rises to a surprising second place globally. Even more alarming: this spike represents an increase of +109% compared to the last quarter of 2025. Relative to the French population, this equates to approximately 35 compromised accounts per 100 inhabitants โ a ratio that places France in first position globally in terms of leak density per capita.
The data most frequently exfiltrated from France includes passwords (488 million in total), usernames (196 million), first names (143 million), last names (131 million), and dates of birth (123 million). This profile suggests that attackers are targeting databases containing complete identification information, ideal for targeted phishing campaigns or resale on darknet forums.
The United States remains essential
The United States maintains its position as the global leader with 60.3 million accounts compromised in Q1 2026. Cumulatively since 2004, the country totals 4.7 billion compromised accounts, about double that of Russia (3.3 billion) and more than double that of China (1.9 billion). The most stolen types of data include passwords (2.26 billion), cities of residence (1.57 billion), and first names (1.54 billion).
Several major incidents marked the country in the first half of 2026, as documented by BleepingComputer: the data leak at Medtronic (attributed to the ShinyHunters group), the compromise of the HSIN platform from the Department of Homeland Security (DHS), and the exposure of over 900 Oracle E-Business Suite instances to active attacks.
A wave that also strikes Europe
The United Kingdom (+107%), Spain (+149%), and Canada (+136%) all show spectacular increases compared to the previous quarter. China, with +158%, sees the highest relative increase, although its absolute volume remains moderate (3.7 million) relative to its population.
In contrast, several countries are seeing their situation improve: India (โ62%), Australia (โ59%), Poland (โ51%), and Indonesia (โ43%) report significant decreases.
The exponential cost of breaches
According to the IBM Cost of a Data Breach Report 2025, the global average cost of a data leak stands at $4.4 million, down 9% from the previous year โ an improvement attributed to faster detection and containment. However, the report highlights a new emerging risk: 97% of organizations that suffered an AI-related incident lacked appropriate access controls, and 63% had no AI governance policy in place.
The arrival of AI in the threat landscape is further confirmed by the discovery in July 2026 of JadePuffer, considered the first documented case of ransomware fully orchestrated by an LLM (language model), reported by BleepingComputer.
The global context
Globally, 23.7 billion accounts have been compromised since 2004 according to Surfshark, with around 7.9 billion unique email addresses affected. On average, the same email address is compromised about 3 times. The site Have I Been Pwned lists 1,015 hacked sites and 17.6 billion accounts in its database.
Recommendations
In light of this intensification of database thefts, the recommendations remain the same but gain urgency:
- Enable multi-factor authentication (MFA), preferably with phishing-resistant passkeys
- Use a password manager to generate and store unique credentials
- Monitor your email addresses via services like Have I Been Pwned
- Implement an AI governance policy if your organization uses AI systems, as the gap between adoption and security is widening dangerously
The first quarter of 2026 confirms a heavy trend: highly digitalized Western countries remain the preferred targets for cybercriminals, and the arrival of AI as an automation tool for attacks only amplifies the phenomenon.