Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

How human error in OpenAI led to the AI-powered Hugging Face hack

July 22, 2026

Travis Kalanick's robotics company raises $1.7 billion led by a16z

July 22, 2026

If you pay the hackers a ransom, they're likely to come back for more money.

July 22, 2026
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    Google brings Pixel 6 and new devices to Material3 Expressive, along with other features, to the Pixel 6 and new devices

    September 3, 2025

    Google's NoteBookLM now allows you to customize the tone of your AI podcasts

    September 3, 2025

    Roblox expands the use of age estimation techniques and introduces standardized assessments

    September 3, 2025

    Instagram finally launches the iPad app

    September 3, 2025

    Complete the 2025 Confusion Builder Stage Agenda with the Maximum Scaling Voice

    September 3, 2025
  • Crypto

    Trump Meme Coin Investors Lost $3.8 Billion, Analysis Finds

    July 5, 2026

    Venice AI becomes unicorn with $65M Series A as privacy-first AI platform takes off

    July 1, 2026

    Disrupt 2026 Builders Stage Agenda Revealed

    July 1, 2026

    Crypto exchange OKX wants to hire AI agents and pay each other

    June 30, 2026

    Founder Summit early bird pricing ends tonight

    June 26, 2026
  • Security

    How human error in OpenAI led to the AI-powered Hugging Face hack

    July 22, 2026

    If you pay the hackers a ransom, they're likely to come back for more money.

    July 22, 2026

    Glow emerges from stealth with $1.2 billion valuation to take on endpoint security in the age of AI

    July 22, 2026

    Breach of AI music generator Suno affects 55 million users (via Have I Been Pwned)

    July 21, 2026

    Hackers are exploiting a recently patched WordPress bug, putting millions of websites at risk

    July 20, 2026
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    Travis Kalanick's robotics company raises $1.7 billion led by a16z

    July 22, 2026

    Menlo Ventures' Matt Murphy explains what AI startup founders should do differently

    July 22, 2026

    Cascade raises $3.5 million to help construction companies discover and win projects

    July 22, 2026

    Dimension Capital's $800 million third fund shows the intersection of science and computing is burgeoning

    July 22, 2026

    BlueCore Energy raises $10 million to build portable nuclear reactor on barge

    July 21, 2026
TechBrunchTechBrunch

Hacked, leaked, and held for ransom: The worst breaches of 2026 so far

TechBrunchBy TechBrunchJuly 7, 202610 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


If anything, 2026 has made clear that cybersecurity is no longer a background concern — it’s front and center, woven into almost every major story of the year. Yes, wars are still raging, the climate keeps worsening, and we’re seemingly one dodgy sneeze away from the next global pandemic.

But running beneath all of it is a digital current that touches everything: wars being fought on digital fronts as well as physical ones, governments weaponizing citizens’ own data against them, botnets quietly undermining democratic institutions, nation-state hackers targeting civilian infrastructure from power grids to water systems, and ransomware gangs holding companies and institutions hostage for massive payouts. The attacks are getting bolder, more destructive, and harder to contain.

As we enter the second half of this already horrendous year of digital attacks and hybrid warfare, here’s a look at some of the worst hacks and breaches so far, and how they might affect us going forward.

Questions of DOGE’s massive swipe of Social Security data linger

A year on, after operatives with the Elon Musk-led band of government destroyers known as the Department of Government Efficiency (or DOGE) swept through and dismantled federal agencies from the inside out, we’re still learning about the data lapses that happened under their watch.

After DOGE entered the Social Security Administration, it remains unclear as to what happened with some of the nation’s most sensitive data, as lawsuits battle on in federal court. The most alarming whistleblower’s claim is that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server, leading to a scramble to understand what was stored in it. This database allegedly contained the Social Security numbers and associated personal information of most living Americans.

In court filings, the Social Security Administration doesn’t know for sure what was on the server, but said that the DOGE signed an agreement with an outside political advocacy group under the guise of finding evidence of voter fraud, something that President Trump continues to claim without any evidence. The fears are that the database could be misused to target Americans for spurious reasons. 

Two of the top House Democrats investigating some of DOGE’s activities at the Social Security Administration said that the exposure of the government’s Social Security database “could very well be the largest data breach in our nation’s history.”

Demonstrators gather outside of the Office of Personnel Management in Washington, D.C. on February 7, 2025 to protest federal layoffs and demand the termination of Elon Musk from the Department of Government Efficiency (DOGE). (Photo by Bryan Dozier / Middle East Images / Middle East Images via AFP)Image Credits:Bryan Dozier/Middle East Images via AFP / Getty Images

Hackers are increasingly targeting water systems and energy grids

A rash of cyberattacks across Europe targeting civilian energy and water supplies, like power plants and water dams, has set a troubling trend of late. Several hacks attributed to (or at least in part blamed on) Russia have risked real-world harm to communities and populations. 

Poland’s energy grid was targeted with computer-destroying malware at the tail end of last year, as well as a Swedish thermal plant and a Norwegian dam that spilled swimming pools’ worth of water. Hackers targeted Poland again earlier this year, this time its water treatment plants, showing that Russia’s hybrid war antagonism continues to extend beyond the digital realm.

Now, thanks to the recent war between the U.S. and Israel against Iran, there are warnings that Iranian hackers are targeting critical infrastructure in the United States. This includes privately owned water utilities, which remain a soft target for hackers, often lacking basic cybersecurity protections.

Iranian government hackers struck Stryker with a destructive device hack

Speaking of Iran, a cyberattack on a U.S. medical tech company, Stryker, in March saw Iranian hackers break in and remotely wipe tens of thousands of employee devices in one fell swoop, causing widespread disruption to the company’s operations for several days. 

The breach was a marked shift in Iranian hacking tactics at a time of ongoing war in the Middle East, with Iran moving from its typical focus of espionage and hack-and-leak operations in aid of the country’s political gains, toward actively causing destructive hacks in apparent retaliation for the war. The U.S. government attributed the hacking group behind the breach to an arm of Iranian intelligence. The breach ended up having a material impact on Stryker’s first-quarter earnings after regaining control of its systems.

Klue reached a deal with its hackers, but still lost control of its customers’ data

Market research provider Klue was at the center of a mass data breach that affected close to 200 companies, of which several were cybersecurity giants such as Jamf, HackerOne, and LastPass. It was one of the broadest data breaches of the year, affecting a multitude of Klue’s customers, less than a year after the company laid off half of its staff in favor of doubling down on AI.

Klue admitted that the extortion gang, dubbed Icarus, broke into its systems using a credential that it issued in 2022 for a limited pilot, implying that the company had around four years to decommission the credential before it was stolen and used to break into its systems. In the data breach, Klue exposed the keys to its customers’ cloud services, allowing the hackers to break in and steal those stores of data to extort those companies for a ransom.

While governments and researchers often urge victims not to pay ransoms to prevent hackers from profiting from cybercrime, Klue told its customers that it had reached an agreement with the hackers not to publish the stolen data — strongly suggesting that it had paid them.

But as part of the deal, the hackers conceded that another hacking group also had a portion of Klue’s customers’ data and urged those victim companies not to pay them.

Instructure also falls victim to ShinyHunters’ disruptive hacking campaigns

The ShinyHunters continued their hacking campaigns, targeting dozens of companies with simple but highly effective voice phishing techniques. The English-speaking hackers are adept at tricking companies into turning over access to their internal systems by pretending to be IT support, or conversely, an employee who forgot their password.

Few companies know better the toll a hack from the ShinyHunters can have than education tech giant Instructure. The hackers breached the company’s flagship learning management system Canvas to steal private data and personal information belonging to over 30 million students and staff. When the company didn’t pay the hackers’ ransom, the hackers broke in — again — and defaced the school’s login screens for Canvas, used by students to access their exam and coursework material. This second hack happened during school finals, disrupting exams for students across the United States. Instructure eventually paid the ransom, despite efforts by the FBI to dissuade the company from paying.

Instructure wasn’t the only company targeted by the ShinyHunters hackers by far. The gang has been behind some of the largest breaches by the number of records stolen, including some 40 million records from internet provider Charter and at least 6 million customer records from cruise liner Carnival, among other victims in higher education, finance, and government.

A redacted screenshot of the message ShinyHunters left on the hacked login pages of Instructure's platform Canvas.Image Credits:TechCrunch

The supply chain is under attack, targeting open source projects and Big Tech companies

A series of ongoing, concurrent, and occasionally overlapping attacks on open source developers has resulted in massive hacks targeting Big Tech companies and their customers. 

Some of the biggest names in security, including Aqua Security’s Trivy tool, Bitwarden, and Checkmarx, alongside other major open source projects, were compromised this year, allowing the hackers to steal passwords, credentials, and other sensitive tokens from the computers of anyone who installed a backdoored copy of the software, or their pre-installed software auto-updated to download the malware. 

These attacks used the stolen credentials to spread further, and opened the door to downstream compromises of big companies that rely on the targeted software, including AI giant OpenAI and web hosting company Vercel. With a new hack almost every week, the open source world remains a vulnerable target in the broader tech ecosystem. 

FBI’s surveillance system was breached, sparking a “major cyber incident”

The U.S. Federal Bureau of Investigation was forced to declare a “major cyber incident” in April, prompting a legally required disclosure with Congress, after identifying that one of its surveillance systems was compromised. According to reports, the breach potentially exposed phone numbers of targets under surveillance by federal agents. 

Chinese spies were accused of the breach of the unclassified network, which held sensitive information about the surveillance targets of wiretaps and other communication intercepts, such as pen register returns. By notifying lawmakers, the breach is likely to have met a bar of causing “demonstrable harm” to U.S. national security.

When is a hack not quite a hack? When you simply ask for access and get it. That was what happened with thousands of Instagram accounts that were hijacked in early 2026 as people abused Meta’s AI chatbot to reset account passwords.

The account hijackings, first reported by 404 Media, happened over the course of several months and were only noticed after news of the exploit began to leak online. Here’s how the attack worked: People would open a chat with Meta’s AI chatbot and pretend that they had been locked out of an account. By requesting the chatbot to send a password reset code to an email address of the attacker’s choosing, the attacker gained access to their victim’s account.

The incident affected tens of thousands of accounts before the improper access was discovered and cut off. It was an embarrassing and high-profile lapse in security — and trust — for one of the world’s largest tech companies.

A screenshot that shows a successful takeover, posted in a Telegram group where hackers were sharing the technique, as well as bragged about their hacks.A screenshot showing a successful takeover.Image Credits:TechCrunch / screenshot

Hasbro’s hack led to weeks of downtime

Toymaker giant Hasbro is the latest example of what happens when a large corporation is hit by a security incident and isn’t prepared for it. Weeks after discovering hackers in its systems in late March, the 103-year-old company remained largely offline, its website unavailable, and unable to serve its customers.

The company, which owns big name brands such as Transformers, Peppa Pig, and Dungeons & Dragons, has said little about the incident itself, what data was taken (if any), and whether it paid the hackers. But the disruption alone is likely to affect the company’s financials, which it was forced to delay, as the company scrambled to handle the incident. 

Hasbro said as of mid-May that the hackers are no longer in its systems and that its recovery was underway. But the financial costs of the breach and the knock-on effect to its business are likely to be realized in the coming months, and are expected to be substantial.

Millions of passports and driver’s licenses have been exposed

Over the past few months alone, there has been an uptick in major data exposures involving people’s sensitive government-issued identity documents, including passport and driver license scans left exposed to the web. From a hotel check-in system and a money transfer app to a prison payphone provider and a U.K. visa service, these services exposed over two million people’s personal documents that can be easily misused. Many were caused by simple security lapses that were easily avoidable with basic cybersecurity practices.

These massive data spills come at a time when closed-community apps and websites are increasingly leaning on “know your customer” checks to force users to verify their identity before being allowed in, and governments are pushing age-verification laws demanding similar identity checks from adults to access a vast swath of the internet. 

The logic goes that the greater the spills, the less effective these identity checking systems are, as they can be easily misused with a stolen or leaked passport or driver license. The further rollout of these ID-collecting systems will inevitably lead to more data breaches and security lapses.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

How human error in OpenAI led to the AI-powered Hugging Face hack

July 22, 2026

If you pay the hackers a ransom, they're likely to come back for more money.

July 22, 2026

Glow emerges from stealth with $1.2 billion valuation to take on endpoint security in the age of AI

July 22, 2026

Breach of AI music generator Suno affects 55 million users (via Have I Been Pwned)

July 21, 2026

Hackers are exploiting a recently patched WordPress bug, putting millions of websites at risk

July 20, 2026

Hackers steal 'vast amounts' of data from technology company used by thousands of US hospitals and pharmacies

July 20, 2026

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

How human error in OpenAI led to the AI-powered Hugging Face hack

July 22, 2026

Travis Kalanick's robotics company raises $1.7 billion led by a16z

July 22, 2026

If you pay the hackers a ransom, they're likely to come back for more money.

July 22, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2026 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.