The United States on top, France in explosion

Since the beginning of 2026, the global landscape of database leaks reveals a striking concentration of attacks on a few countries. According to statistics compiled by Surfshark (updated April 21, 2026), the first quarter of 2026 saw no fewer than 114 million accounts compromised in just the 15 most affected countries.

The Top 10 Countries by Number of Compromised Accounts (Q1 2026)

Rank Country Compromised Accounts (Q1 2026) Evolution vs Q4 2025
1 ๐Ÿ‡บ๐Ÿ‡ธ United States 60,324,766 +3%
2 ๐Ÿ‡ซ๐Ÿ‡ท France 23,454,318 +109%
3 ๐Ÿ‡ฎ๐Ÿ‡ณ India 7,296,531 โˆ’62%
4 ๐Ÿ‡ง๐Ÿ‡ท Brazil 4,544,088 +53%
5 ๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom 4,433,577 +107%
6 ๐Ÿ‡จ๐Ÿ‡ณ China 3,684,937 +158%
7 ๐Ÿ‡จ๐Ÿ‡ฆ Canada 3,249,834 +136%
8 ๐Ÿ‡ช๐Ÿ‡ธ Spain 2,751,804 +149%
9 ๐Ÿ‡ฉ๐Ÿ‡ช Germany 2,751,582 +4%
10 ๐Ÿ‡ท๐Ÿ‡บ Russia 2,606,269 โˆ’18%

Source: Surfshark Data Breach Statistics, Q1 2026.


France, the star victim of the quarter

With 23.4 million accounts compromised in the first quarter of 2026 alone, France rises to a surprising second place globally. Even more alarming: this spike represents an increase of +109% compared to the last quarter of 2025. Relative to the French population, this equates to approximately 35 compromised accounts per 100 inhabitants โ€” a ratio that places France in first position globally in terms of leak density per capita.

The data most frequently exfiltrated from France includes passwords (488 million in total), usernames (196 million), first names (143 million), last names (131 million), and dates of birth (123 million). This profile suggests that attackers are targeting databases containing complete identification information, ideal for targeted phishing campaigns or resale on darknet forums.

The United States remains essential

The United States maintains its position as the global leader with 60.3 million accounts compromised in Q1 2026. Cumulatively since 2004, the country totals 4.7 billion compromised accounts, about double that of Russia (3.3 billion) and more than double that of China (1.9 billion). The most stolen types of data include passwords (2.26 billion), cities of residence (1.57 billion), and first names (1.54 billion).

Several major incidents marked the country in the first half of 2026, as documented by BleepingComputer: the data leak at Medtronic (attributed to the ShinyHunters group), the compromise of the HSIN platform from the Department of Homeland Security (DHS), and the exposure of over 900 Oracle E-Business Suite instances to active attacks.

A wave that also strikes Europe

The United Kingdom (+107%), Spain (+149%), and Canada (+136%) all show spectacular increases compared to the previous quarter. China, with +158%, sees the highest relative increase, although its absolute volume remains moderate (3.7 million) relative to its population.

In contrast, several countries are seeing their situation improve: India (โˆ’62%), Australia (โˆ’59%), Poland (โˆ’51%), and Indonesia (โˆ’43%) report significant decreases.

The exponential cost of breaches

According to the IBM Cost of a Data Breach Report 2025, the global average cost of a data leak stands at $4.4 million, down 9% from the previous year โ€” an improvement attributed to faster detection and containment. However, the report highlights a new emerging risk: 97% of organizations that suffered an AI-related incident lacked appropriate access controls, and 63% had no AI governance policy in place.

The arrival of AI in the threat landscape is further confirmed by the discovery in July 2026 of JadePuffer, considered the first documented case of ransomware fully orchestrated by an LLM (language model), reported by BleepingComputer.

The global context

Globally, 23.7 billion accounts have been compromised since 2004 according to Surfshark, with around 7.9 billion unique email addresses affected. On average, the same email address is compromised about 3 times. The site Have I Been Pwned lists 1,015 hacked sites and 17.6 billion accounts in its database.

Recommendations

In light of this intensification of database thefts, the recommendations remain the same but gain urgency:

  • Enable multi-factor authentication (MFA), preferably with phishing-resistant passkeys
  • Use a password manager to generate and store unique credentials
  • Monitor your email addresses via services like Have I Been Pwned
  • Implement an AI governance policy if your organization uses AI systems, as the gap between adoption and security is widening dangerously

The first quarter of 2026 confirms a heavy trend: highly digitalized Western countries remain the preferred targets for cybercriminals, and the arrival of AI as an automation tool for attacks only amplifies the phenomenon.