Worst Cybersecurity Breaches of 2026 So Far
TechCrunch summarizes major cybersecurity breaches and hacks through the first half of 2026, highlighting attacks on government systems, critical infrastructure, supply chains, and large enterprises. Reported incidents include alleged exposure of the U.S. Social Security database after operatives tied to the so‑called Department of Government Efficiency (DOGE) accessed SSA systems; destructive wiping of Stryker employee devices attributed to Iranian state-linked actors; a broad Klue breach that exposed customer cloud keys and affected nearly 200 companies; ShinyHunters’ mass campaigns including an Instructure Canvas intrusion affecting ~30 million students and staff; supply‑chain compromises of open‑source tools (affecting vendors such as Aqua Security/Trivy, Bitwarden and Checkmarx) that led to downstream breaches at firms including OpenAI and Vercel; an FBI surveillance-system breach declared a “major cyber incident”; and an exploit of Meta’s AI chatbot used to reset Instagram passwords. The piece stresses rising scale, destructive tactics, and cascading risks to identity, operations, and downstream partners.
- •A whistleblower and court filings allege operatives associated with the Elon Musk-led Department of Government Efficiency (DOGE) uploaded a live copy of the U.S. Social Security database to an unsecured third-party server, raising concerns it could be one of the largest breaches in U.S. history.
- •Iranian-linked hackers remotely wiped tens of thousands of Stryker employee devices in March, causing multi-day operational disruption and contributing to a material impact on Stryker's first-quarter earnings.
- •Market research vendor Klue was breached by an extortion gang (Icarus), exposing cloud-service keys and customer data across about 200 companies, including Jamf, HackerOne and LastPass; Klue told customers it reached a deal with the hackers to avoid publication of stolen data.
