OTHER

The Most Significant Hacks and Breaches of 2026 So Far

As we reflect on the year 2026, it seems that cybersecurity has become less prioritized, overshadowed by ongoing conflicts, deteriorating climate issues, and the potential emergence of a new pandemic.

Nevertheless, cybersecurity remains a vital barometer of global events. Botnets are driving digital offensives against the West, while governments are misusing citizens’ data and essential infrastructures to control large populations. Additionally, financially motivated hackers are demanding exorbitant ransoms, leading to widespread chaos and occasional destruction in both the governmental and private sectors.

As we find ourselves in the middle of this tumultuous year, characterized by digital attacks and hybrid warfare, it’s important to analyze some of the major hacks and breaches we have witnessed and their potential long-term consequences.

Uncertainties linger regarding DOGE’s massive breach of Social Security data

A year has passed since operatives from the Elon Musk-led Department of Government Efficiency (DOGE) infiltrated and disrupted federal agencies, and we are still uncovering the data breaches that occurred during this period.

Following DOGE’s incursion into the Social Security Administration, questions remain about the security of some of the country’s most sensitive data as lawsuits unfold in federal court. Disturbing whistleblower accounts suggest that DOGE uploaded an active version of the Social Security database to an unsecured third-party server, prompting a frantic effort to determine which data was exposed. This database allegedly contained the Social Security numbers and personal information of a significant portion of the American population.

In court filings, the Social Security Administration expressed uncertainty about the contents of the server but acknowledged that DOGE had agreed to collaborate with an external political advocacy group under the guise of investigating voter fraud—a claim frequently made by President Trump without evidence. Concerns continue to mount that this database could be misused to unfairly target Americans.

Two prominent House Democrats investigating DOGE’s conduct at the Social Security Administration warned that the breach of the government’s Social Security database “could potentially be the largest data breach in our nation’s history.”

Demonstrators gather outside the Office of Personnel Management in Washington, D.C. on February 7, 2025, to protest federal layoffs and demand Elon Musk's termination from the Department of Government Efficiency (DOGE). (Photo by Bryan Dozier / Middle East Images / Middle East Images via AFP)
Image Credits: Bryan Dozier/Middle East Images via AFP / Getty Images

Hackers are increasingly targeting water systems and energy grids

An alarming rise in cyberattacks across Europe has centered on civilian energy and water resources, including power stations and water supply systems. Numerous attacks, often attributed to Russia, have posed real threats to communities and their residents.

Poland’s energy grid encountered a malware attack that compromised its computer systems towards the end of last year, along with assaults on a Swedish thermal facility and a Norwegian dam that overflowed. Earlier this year, hackers again targeted Poland, this time hitting water treatment facilities, underscoring Russia’s hybrid warfare strategies expanding beyond digital means.

Recently, amid tensions between the U.S. and Israel against Iran, warnings surfaced about Iranian hackers focusing their efforts on critical infrastructure within the United States, including privately operated water utilities that are often easy targets due to insufficient cybersecurity measures.

Iranian hackers executed a destructive attack on Stryker

In March, a cyberattack on U.S. medical technology firm Stryker led to Iranian hackers remotely wiping thousands of employee devices in one operation, causing considerable operational disruptions for several days.

This breach marks a significant shift in Iranian hacking tactics, occurring amid ongoing Middle Eastern conflicts. Iran appears to be moving from traditional espionage methods and hack-and-leak strategies for political gain to actively pursuing destructive hacks in retaliation for geopolitical tensions. The U.S. government linked the responsible hacking group to Iranian intelligence. Ultimately, the incident affected Stryker’s first-quarter revenues as systems were restored.

Instructure caught in ShinyHunters’ disruptive hacking spree

The ShinyHunters group has relentlessly expanded their hacking campaigns, targeting numerous organizations through straightforward yet highly effective voice phishing techniques. These English-speaking hackers excel at tricking companies into granting access to their internal systems by impersonating IT support or employees with forgotten passwords.

Few organizations are more acutely aware of the consequences of a ShinyHunters hack than education technology giant Instructure. The hackers breached the company’s leading learning management platform, Canvas, stealing sensitive data and personal information from over 30 million students and staff. When Instructure declined to meet the hackers’ ransom demands, they struck again, vandalizing the login pages for Canvas—used by students to access exam materials and coursework. This second attack coincided with final exams, disrupting students across the nation. Eventually, Instructure decided to pay the ransom despite the FBI’s warnings against compliance.

Instructure wasn’t the only target of ShinyHunters. The group has facilitated several of the most significant breaches regarding record theft, including around 40 million records from the internet service provider Charter and at least 6 million records from the cruise line operator Carnival, impacting various sectors, including finance, higher education, and government.

A redacted screenshot of the message left by ShinyHunters on the hacked login pages of Instructure's platform, Canvas.
Image Credits: TechCrunch

The supply chain is under attack, targeting open-source projects and major tech firms

A series of ongoing, simultaneous, and sometimes overlapping attacks against open-source developers have caused significant breaches affecting major tech companies and their customers.

Notable security tools, including Aqua Security’s Trivy, Bitwarden, and Checkmarx, as well as various significant open-source initiatives, were compromised this year. This allowed attackers to retrieve passwords, credentials, and other sensitive tokens from systems of anyone who downloaded a backdoored version of the software or had their pre-installed software auto-update to include the malware.

The stolen credentials enabled further spread of attacks, resulting in compromises of major corporations relying on the targeted software, including AI leader OpenAI and web hosting provider Vercel. With almost weekly occurrences of new hacks, the open-source community remains a high-risk target within the broader tech landscape.

The FBI’s surveillance system breach led to a “major cyber incident”

In April, the U.S. Federal Bureau of Investigation announced a “major cyber incident” after discovering that one of its surveillance systems had been breached. This prompted a legally mandated notification to Congress, revealing that the breach may have exposed phone numbers of individuals under federal surveillance.

Chinese hackers were implicated in breaching the unclassified network, which contained sensitive information about surveillance targets, including wiretap data and other communication interceptions. The notification to lawmakers indicated that the breach likely caused “demonstrable harm” to U.S. national security.

Hasbro’s hack has resulted in weeks of operational disruptions

Toy manufacturer Hasbro exemplifies the detrimental effects of insufficient cybersecurity measures when a major corporation experiences a breach. After hackers infiltrated its systems in late March, the well-known company found itself largely offline for weeks, with its website down and unable to serve customers.

The firm, recognized for popular brands like Transformers, Peppa Pig, and Dungeons & Dragons, has been reticent about divulging details concerning the incident, including whether any data was compromised or if a ransom was paid. However, the disruption is expected to have a substantial impact on the company’s finances, leading to delays in necessary disclosures as they worked to address the crisis.

As of mid-May, Hasbro announced that the hackers had been removed from its systems and that the recovery process was underway. Nonetheless, the financial impact of the breach and its repercussions on business operations are likely to emerge in the following months.

Millions of passports and driver licenses exposed

In recent months, a significant increase in data exposures involving sensitive government-issued identity documents, including passport and driver license scans, has been noted. Incidents related to a hotel check-in system, a money transfer application, a prison payphone provider, and a U.K. visa service have revealed over two million individuals’ personal documents at risk of misuse. Many of these events stemmed from basic security oversights that could have been easily prevented with fundamental cybersecurity practices.

These considerable data leaks coincide with the rising demands of closed-community applications and websites requiring “know your customer” validations, pushing users to verify their identities to gain access, as well as governments enforcing age-verification laws that similarly mandate identity checks from adults accessing various online services.

The underlying implication is that as these data leaks proliferate, the effectiveness of identity verification systems declines, as stolen or leaked passports and driver licenses can be readily misused. The broader implementation of these identity-collecting protocols may lead to additional data breaches and security vulnerabilities.

Purchases made through links in our articles may result in a small commission. This does not affect our editorial independence.