Tech
EN AZ
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

techcrunch.com 15.09.2026 18:00 3 views
From the massive DOGE data breach and the compromise of critical infrastructure to the hack of federal surveillance systems, here are the most damaging security incidents and data breaches of 2026 so far.

If anything, 2026 has made clear that cybersecurity is no longer a background concern. Today, security is at the front and center of many conversations, woven into almost every major story of the year. Inequalities are still common, the climate is worsening, and we’re seemingly one dodgy sneeze away from the next global pandemic.

But running beneath all of it is a digital current that touches everything: Wars are fought on digital fronts as well as physical ones, governments are weaponizing citizens’ own data against them, botnets are quietly undermining democratic institutions, nation-state hackers are targeting civilian infrastructure from power grids to water systems, and ransomware gangs are holding companies and institutions hostage for massive payouts. The attacks are getting bolder, more destructive, and harder to contain. As we cross into the closing quarter of this already horrendous year of digital attacks and hybrid warfare, here is a look at some of the worst hacks and breaches so far, and how they might affect us going forward.

More than a year after operatives with the Elon Musk-led band of government destroyers known as the Department of Government Efficiency (or DOGE) swept through and dismantled federal agencies from the inside out, we’re still learning about the data lapses that happened under their watch. After DOGE entered the Social Security Administration, it’s not yet known what happened with some of the nation’s most sensitive data, as lawsuits are still going on in federal courts. The most alarming claim by a federal whistleblower is that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server, which led to a scramble to understand what was stored on the server.

This database allegedly contained the Social Security numbers and associated personal information of most living Americans. In court filings, the Social Security Administration isn’t sure what was on the server, but said that the DOGE signed an agreement with an outside political advocacy group under the guise of finding evidence of voter fraud, which President Trump continues to claim without any evidence. The fears are that the database could be misused to target Americans for spurious reasons.

Two of the top House Democrats investigating some of DOGE’s activities at the Social Security Administration said the exposure “could very well be the largest data breach in our nation’s history.” A rash of cyberattacks across Europe targeting civilian energy and water supplies, like power plants and water dams, has set a troubling trend. Several hacks attributed to (or partly blamed on) Russia have risked real-world harm to communities and populations. Poland’s energy grid was targeted with computer-destroying malware late last year, as was a Swedish thermal plant and a Norwegian dam that spilled entire swimming pools’ worth of water.

Then earlier this year, Russian hackers targeted Poland’s water treatment plants, showing that Moscow’s hybrid war antagonism continues to extend beyond the digital realm. Now, thanks to the recent war waged by the U.S. and Israel against Iran, hackers working for the Iranian regime are actively hacking critical infrastructure across the United States in opportunistic attempts to disrupt neighborhoods and communities. CISA said Iranian hackers targeted over a hundred water providers over the summer, including privately owned water utilities, which remain a soft target as they often lack basic funding and cybersecurity protections.

Extract — continue reading at the source.

Read full story