OTHER

Hacks, Leaks, and Ransoms: Key Data Breaches of 2026 So Far

The year 2026 has highlighted that cybersecurity is no longer merely an ancillary concern; it now stands as a critical issue in numerous significant affairs. As conflicts continue, climate change intensifies, and the threat of another pandemic arises, a digital realm intertwines these events.

At the core of these global challenges lies a technological undertow: conflicts being fought in cyberspace alongside conventional battlefields, governments utilizing citizens’ sensitive information against them, botnets quietly undermining democratic processes, nation-state hackers targeting essential civilian infrastructure like power grids and water systems, and ransomware groups taking organizations and institutions hostage for substantial ransoms. These attacks are growing bolder, more damaging, and increasingly difficult to combat.

As we progress through the latter half of this troubling year marked by cyberattacks and hybrid warfare, let’s explore some of the most significant hacks and breaches thus far and their potential ramifications for the future.

Unanswered Questions Regarding DOGE’s Major Data Breach

A year has passed since the team affiliated with Elon Musk’s Department of Government Efficiency (DOGE) breached federal agencies, and we are still uncovering the full extent of the data breaches that occurred in this turmoil.

Following DOGE’s involvement with the Social Security Administration, it remains unclear what happened to some of the nation’s most sensitive information as lawsuits unfold in federal courts. Alarmingly, a whistleblower alleges that DOGE uploaded a live version of the Social Security database to an unsecured third-party server, raising serious concerns about data protection. This database reportedly contained personal data, including Social Security numbers, for the majority of living Americans.

Court documents reveal that the Social Security Administration is unsure about the contents of the server but noted that DOGE had entered an agreement with an external political lobbying group, ostensibly to gather evidence of voter fraud, a claim that remains unverified. The worry is that this database may be used for inappropriate targeting of U.S. citizens.

Two prominent House Democrats investigating DOGE’s actions at the Social Security Administration described the potential exposure of this database as “possibly the largest data breach in our nation’s history.”

Protesters outside the Office of Personnel Management in Washington, D.C. on February 7, 2025, calling for the termination of Elon Musk from DOGE. (Photo by Bryan Dozier / Middle East Images / Middle East Images via AFP)
Image Credits: Bryan Dozier/Middle East Images via AFP / Getty Images

Heightened Attacks on Water and Energy Systems by Hackers

A surge of cyberattacks across Europe has targeted civilian energy and water infrastructures, such as power plants and water treatment facilities, marking a worrying trend. Numerous hacks attributed to Russia have posed genuine threats to communities.

Poland’s energy grid endured malware assaults late last year, while both a thermal plant in Sweden and a Norwegian dam were also attacked, indicating that Russian hybrid warfare is expanding into tangible domains. Earlier this year, hackers returned to target Poland’s water treatment facilities.

In the wake of the recent U.S. and Israeli conflict with Iran, warnings have arisen that Iranian hackers are focusing on critical U.S. infrastructure, including private water utilities that frequently lack sufficient cybersecurity defenses.

Damaging Cyberattack by Iranian Hackers on Stryker

In March, Iranian hackers breached U.S. medical technology firm Stryker, erasing data from tens of thousands of employee devices and disrupting company operations for several days.

This breach marked a shift in Iranian hacking strategies amid ongoing Middle Eastern conflicts, transitioning from espionage and data leaks to executing active destructive attacks. The U.S. government indicated that the responsible hacking group was linked to Iranian intelligence. The breach significantly impacted Stryker’s financial performance for the first quarter as the company worked to regain control of its systems.

Klue’s Data Breach and Its Consequences

Market research firm Klue experienced a major data breach affecting nearly 200 companies, including cybersecurity giants like Jamf, HackerOne, and LastPass. This incident became one of the year’s largest data breaches, occurring shortly after Klue underwent significant layoffs to focus on AI.

Klue acknowledged that the cyber extortion group Icarus infiltrated its systems using credentials issued in 2022, suggesting that there was ample time to revoke access before it was exploited. The breach exposed cloud service keys, allowing hackers to access customer data and extort the affected firms.

Despite officials advising victims against paying ransoms, Klue reportedly struck a deal with the hackers to prevent the publication of the stolen data, strongly implying that a ransom was paid.

However, part of the agreement revealed that another hacking group also possessed a portion of Klue’s customers’ data and cautioned victim companies against engaging with them.

Instructure Targeted by ShinyHunters’ Campaigns

The ShinyHunters have intensified their hacking efforts, utilizing simple yet effective voice phishing tactics to target numerous companies. These English-speaking hackers trick firms into granting access to their internal systems by impersonating IT support or pretending to be employees locked out of their accounts.

Instructure, a leader in educational technology, is well aware of the chaos a ShinyHunters hack can cause. They compromised the Canvas learning management system, obtaining confidential data for over 30 million students and staff. When Instructure refused to pay the ransom, the hackers retaliated by defacing Canvas’s login interfaces during pivotal finals periods, causing widespread disruption in the U.S. education system. Ultimately, Instructure paid the ransom, despite FBI attempts to dissuade them.

ShinyHunters’ influence is extensive, with major breaches encompassing tens of millions of records, including 40 million from internet provider Charter and approximately 6 million from cruise line operator Carnival, impacting various sectors including education, finance, and government.

A redacted screenshot of a message left by ShinyHunters on the hacked login pages of Instructure's Canvas platform.
Image Credits: TechCrunch

Supply Chain Attacks Target Open Source Projects and Major Tech Firms

An ongoing series of attacks on open source developers has led to significant hacks impacting major tech companies and their clients.

Prominent security tools, including Aqua Security’s Trivy, Bitwarden, and Checkmarx, along with other key open source projects, were compromised this year. Hackers exploited these breaches to steal passwords, credentials, and other sensitive data from users who unknowingly installed compromised software or received auto-updates that contained malware.

These stolen credentials fueled further attacks, leading to additional breaches at large organizations relying on the affected software, including AI leader OpenAI and web hosting provider Vercel. With hacks emerging weekly, the open source domain remains a vulnerable target within the broader tech landscape.

FBI’s Surveillance System Breach Triggers Major Cyber Incident

In April, the U.S. Federal Bureau of Investigation reported a “major cyber incident,” requiring a formal declaration to Congress after identifying a breach in one of its surveillance systems. Reports indicate that the breach may have exposed phone numbers of surveillance targets.

Accusations have surfaced suggesting Chinese operatives were involved in breaking into this unclassified network, which housed sensitive data on wiretap subjects and communication interceptions. By notifying lawmakers, the breach likely met the threshold for causing “demonstrable harm” to U.S. national security.

A major security issue also occurred when thousands of Instagram accounts were hijacked early in 2026, with attackers exploiting Meta’s AI chatbot to reset passwords. Reports revealed that this attack unfolded over several months and became apparent after news of the vulnerability surfaced. Attackers would engage with Meta’s chatbot, falsely claiming to be locked out of their accounts, and request password reset codes sent to their email addresses, thus gaining unauthorized access.

The breach affected tens of thousands of accounts before it was discovered and contained. This incident represents a significant security lapse for one of the world’s leading tech companies.

A screenshot demonstrating a successful account takeover shared within a Telegram group among hackers.
A screenshot illustrating a successful account takeover.Image Credits: TechCrunch / screenshot

Hasbro’s Security Incident Causes Extended Downtime

Toy industry titan Hasbro demonstrates the ramifications of being underprepared for security breaches. Weeks after discovering hackers infiltrated its systems in late March, the historic company found itself offline, rendering its website inaccessible and hindering customer service.

Owner of popular brands such as Transformers, Peppa Pig, and Dungeons & Dragons, Hasbro has remained largely quiet concerning the incident, including what data may have been compromised and whether a ransom was paid. Nonetheless, this disruption is likely to result in significant financial consequences for the company, which necessitated delaying financial reports while addressing the incident.

As of mid-May, Hasbro indicated that the hackers were no longer present in its systems and that recovery efforts had commenced. However, the financial impact of the breach and its implications for business operations are expected to unfold in the coming months.

Millions of Passports and Driver Licenses Exposed

Recently, there has been a notable surge in significant data breaches involving sensitive government-issued identity documents, such as passport and driver license scans left vulnerable online. Services ranging from hotel check-in systems and money transfer applications to prison payphone providers and a UK visa service have exposed over two million individuals’ personal documents, making them susceptible to misuse. Many of these occurrences stemmed from preventable security oversights due to basic cybersecurity failures.

These extensive data leaks have emerged at a time when various closed-community applications and websites increasingly rely on “know your customer” protocols for identity verification and amid expanding governmental demands for age-verification methods to access extensive areas of the internet.

The rationale is that greater data exposure diminishes the effectiveness of identity verification methods, as stolen or leaked credentials can be readily exploited. The widespread use of these ID verification systems is likely to engender even more data breaches and security vulnerabilities.

Purchasing via the links in our articles may yield a small commission for us, but this will not affect our editorial integrity.