Key facts
- A federal whistleblower alleged DOGE uploaded a live copy of the Social Security database to an unsecured third-party server.
- Russian hackers targeted Poland's energy grid with computer-destroying malware.
- Iranian hackers targeted over a hundred water providers in the U.S. over the summer.
- Klue's data breach affected close to 200 companies, including cybersecurity giants.
- Meta's AI chatbot was abused to reset thousands of Instagram account passwords.
- The FBI's breach potentially exposed phone numbers of surveillance targets.
- The ATF confirmed a ransomware attack on a system containing targets of investigations.
- Compromises of open-source projects like Aqua Security's Trivy tool, Bitwarden, and Checkmarx impacted Big Tech companies.
2026 has seen a significant escalation in cybersecurity threats, with major data breaches affecting government agencies, critical infrastructure, and prominent technology companies. These attacks underscore the growing digital risks faced by individuals and institutions globally.
The Social Security Administration is still grappling with the aftermath of data lapses that occurred under the watch of the Department of Government Efficiency (DOGE). A federal whistleblower has claimed that DOGE uploaded a live copy of the Social Security database, containing sensitive personal information of most Americans, to an unsecured third-party server. Lawsuits are ongoing, and the administration is uncertain about the exact contents of the server, raising fears of potential misuse for targeting Americans.
Cyberattacks targeting civilian infrastructure have become a troubling trend. Russia has been implicated in attacks on Poland's energy grid and a Swedish thermal plant, as well as a Norwegian dam. More recently, hackers linked to the Iranian regime have targeted over a hundred water providers across the United States, exploiting vulnerabilities in privately owned utilities that often lack adequate funding and cybersecurity protections.
Market research provider Klue experienced one of the year's broadest data breaches, affecting nearly 200 companies, including cybersecurity firms like Jamf, HackerOne, and LastPass. The breach, attributed to an extortion gang dubbed Icarus, exploited a four-year-old credential. Klue reportedly reached an agreement with the hackers to prevent the publication of stolen data, suggesting a ransom payment was made. However, another hacking group also obtained a portion of the data.
Thousands of Instagram accounts were compromised through an abuse of Meta's AI chatbot. Attackers impersonated users to request password resets, directing the reset codes to their own email addresses. This exploit affected tens of thousands of accounts before Meta discovered and halted the improper access.
The U.S. Federal Bureau of Investigation declared a "major cyber incident" in April after a breach of an unclassified surveillance system, which potentially exposed phone numbers of surveillance targets. The breach, attributed to Chinese spies, is believed to have caused "demonstrable harm" to U.S. national security. In August, the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed its own "major incident" due to a ransomware attack on a system containing targets of its investigations.
Furthermore, the software supply chain has been a target, with ongoing attacks on open-source projects. Major security firms like Aqua Security, Bitwarden, and Checkmarx were compromised, allowing attackers to steal credentials and sensitive tokens from users who installed backdoored software.
