Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Worst hacks of 2026 so far

Cybersecurity has moved to the center of major stories in 2026, with attacks affecting governments, civilian infrastructure, companies and social-media users. TechCrunch’s Zack Whittaker highlights several of the year’s most damaging incidents.

More than a year after the Elon Musk-led Department of Government Efficiency, or DOGE, entered federal agencies, a whistleblower alleged that a live copy of the Social Security database was uploaded to an unsecured third-party server. The database allegedly contained Social Security numbers and personal information belonging to most living Americans. The Social Security Administration said in court filings that it was not sure what the server contained. Two House Democrats called the exposure potentially the largest data breach in U.S. history.

Across Europe, attacks attributed to or partly blamed on Russia targeted energy and water infrastructure. Earlier this year, Russian hackers also targeted Poland’s water-treatment plants. CISA said Iranian hackers targeted over a hundred water providers in the United States over the summer.

Market research provider Klue disclosed a breach affecting close to 200 companies, including Jamf, HackerOne and LastPass. The attackers used a credential issued in 2022 that appears to have remained active for around four years. Separately, Meta’s AI chatbot was abused in early 2026 to reset passwords and hijack tens of thousands of Instagram accounts.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.