9 days ago
TechCrunch Sep 15, 2026

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

2026 has been marked by an alarming increase in cyberattacks targeting critical infrastructure, government agencies, and private companies worldwide. One of the most concerning incidents involves the Department of Government Efficiency (DOGE), led by Elon Musk, which compromised the Social Security Administration. Allegations include uploading a live copy of the Social Security database containing sensitive personal information to an unsecured server, potentially making it the largest data breach in U.S. history. This breach has led to ongoing lawsuits and raised fears about misuse of data under political pretenses related to unfounded voter fraud claims.

Cyber offensives on civilian infrastructure continue to escalate, with Russian hackers responsible for attacks on European energy grids and water systems, causing real-world disruptions. In the U.S., Iranian-linked hackers have targeted over a hundred water providers, exploiting vulnerabilities within underfunded utilities. This wave of hybrid warfare highlights how state-sponsored cyber groups are extending their conflict beyond traditional battlefields to affect everyday services, threatening public safety and national security on multiple fronts.

Major data breaches have also rocked the corporate and tech worlds, exemplified by the Klue incident where hackers exploited a four-year-old credential to access cloud service keys from nearly 200 companies, including cybersecurity firms. Although Klue reportedly reached a ransom agreement with the extortionists to prevent data publication, another hacking group claimed possession of the stolen data, complicating the fallout. Similarly, Meta faced a significant "hack" where thousands of Instagram accounts were hijacked through abuses of its AI chatbot’s password reset feature, exposing considerable flaws in automated customer service systems.

The supply chain and identity verification sectors have also suffered devastating breaches. Open source software projects and Big Tech companies were compromised through attacks on tools like Aqua Security’s Trivy and Bitwarden, exposing user credentials and enabling widespread secondary breaches. Meanwhile, IDScan experienced an enormous data breach exposing 150 million driver’s licenses in North America, exacerbating concerns about identity theft amid growing demands for online age and identity verification. Together, these incidents underscore how pervasive and destructive hacking efforts have become, posing significant risks to privacy, security, and trust in both public and private domains.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.