Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

How human error in OpenAI led to the AI-powered Hugging Face hack

July 22, 2026

Travis Kalanick's robotics company raises $1.7 billion led by a16z

July 22, 2026

If you pay the hackers a ransom, they're likely to come back for more money.

July 22, 2026
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    Google brings Pixel 6 and new devices to Material3 Expressive, along with other features, to the Pixel 6 and new devices

    September 3, 2025

    Google's NoteBookLM now allows you to customize the tone of your AI podcasts

    September 3, 2025

    Roblox expands the use of age estimation techniques and introduces standardized assessments

    September 3, 2025

    Instagram finally launches the iPad app

    September 3, 2025

    Complete the 2025 Confusion Builder Stage Agenda with the Maximum Scaling Voice

    September 3, 2025
  • Crypto

    Trump Meme Coin Investors Lost $3.8 Billion, Analysis Finds

    July 5, 2026

    Venice AI becomes unicorn with $65M Series A as privacy-first AI platform takes off

    July 1, 2026

    Disrupt 2026 Builders Stage Agenda Revealed

    July 1, 2026

    Crypto exchange OKX wants to hire AI agents and pay each other

    June 30, 2026

    Founder Summit early bird pricing ends tonight

    June 26, 2026
  • Security

    How human error in OpenAI led to the AI-powered Hugging Face hack

    July 22, 2026

    If you pay the hackers a ransom, they're likely to come back for more money.

    July 22, 2026

    Glow emerges from stealth with $1.2 billion valuation to take on endpoint security in the age of AI

    July 22, 2026

    Breach of AI music generator Suno affects 55 million users (via Have I Been Pwned)

    July 21, 2026

    Hackers are exploiting a recently patched WordPress bug, putting millions of websites at risk

    July 20, 2026
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    Travis Kalanick's robotics company raises $1.7 billion led by a16z

    July 22, 2026

    Menlo Ventures' Matt Murphy explains what AI startup founders should do differently

    July 22, 2026

    Cascade raises $3.5 million to help construction companies discover and win projects

    July 22, 2026

    Dimension Capital's $800 million third fund shows the intersection of science and computing is burgeoning

    July 22, 2026

    BlueCore Energy raises $10 million to build portable nuclear reactor on barge

    July 21, 2026
TechBrunchTechBrunch

Hacks, breaches and ransom demands: the worst breaches of 2026 so far

TechBrunchBy TechBrunchJune 7, 20268 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


If anything, 2026 has made it clear that cybersecurity is no longer a background concern. It's a front-and-center issue that's woven into nearly every major news story this year. Yes, wars are still raging, the climate is getting worse, and the next global pandemic seems to be within reach.

However, underlying this is a digital trend that affects everything. Wars that are being waged digitally as well as physically; botnets where governments are weaponizing their own citizens' data to undermine democratic institutions; nation-state hackers targeting civilian infrastructure from power grids to water systems; ransomware gangs holding businesses and institutions hostage and demanding huge payments. Attacks are becoming bolder, more destructive, and harder to contain.

As we reach the halfway mark of an already frightening year of digital attacks and hybrid warfare, we take a look at some of the worst hacks and breaches to date and how they may affect us in the future.

DOGE's large-scale scan of Social Security data leaves doubts

A year after operatives from Elon Musk's Destroyer Squad, known as the Department of Government Efficiency (DOGE), thoroughly investigated and dismantled federal agencies, we are still learning about data breaches that occurred on their watch.

It remains unclear what happened to some of the nation's most sensitive data after DOGE joined the Social Security Administration, as litigation continues in federal court. The most alarming whistleblower allegation is that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server, sparking a scramble to figure out what was stored there. This database allegedly contained the Social Security numbers and related personal information of most living Americans.

In court filings, the Social Security Administration says it doesn't know exactly what happened to its servers, but that DOGE has entered into agreements with outside political advocacy groups in the name of finding evidence of voter fraud, a claim Trump continues to make without any evidence. The concern is that this database could be misused to target Americans on false grounds.

Two senior House Democrats investigating some of DOGE's activities at the Social Security Administration said the disclosure of the government's Social Security database “very likely represents the largest data breach in our nation's history.”

Demonstrators gather outside the Office of Personnel Management in Washington, DC, on February 7, 2025, to protest federal layoffs and demand Elon Musk's firing from the Department of Government Efficiency (DOGE). (Photo by Bryan Dozier/Middle East Images/Middle East Images via AFP)Image credit: Bryan Dozier/AFP/Middle East Images via Getty Images

Hackers are increasingly targeting water systems and energy grids

A worrying trend has recently emerged with cyberattacks targeting private energy and water supplies, such as power plants and dams, occurring across Europe. Several hacks attributed to (or at least partially responsible for) Russia risk real-world harm to communities and populations.

Late last year, Poland's energy grid was targeted by malware that destroyed computers, while a thermal power plant in Sweden and a dam in Norway spilled a swimming pool's worth of water. Hackers targeted Poland again earlier this year, this time at its water treatment plant, showing that Russia's hybrid warfare adversaries continue to extend beyond the digital realm.

Now, thanks to the recent US-Israel war against Iran, there are warnings that Iranian hackers are targeting America's critical infrastructure. This includes private water utilities, which often lack basic cybersecurity protections and remain targets for hackers.

Iranian government hackers attack Stryker with destructive device hack

Speaking of Iran, in March, there was a cyberattack on the US medical technology company Stryker in which Iranian hackers infiltrated and remotely wiped tens of thousands of employee devices at once, causing widespread disruption to the company's operations for several days.

The leak marks a notable shift in Iran's hacking tactics amid ongoing wars in the Middle East, with Iran moving from its typical focus on espionage and hack-and-leaks to support the country's political interests to actively provoking destructive hacks in apparent retaliation for war. The US government has determined that the hacker group behind the intrusion is Iranian intelligence. The breach ultimately had a significant impact on Stryker's first quarter revenue after it regained control of its systems.

Organize a destructive ShinyHunters hacking campaign

ShinyHunters continued its hacking campaign, targeting dozens of businesses using simple but highly effective voice phishing techniques. English-speaking hackers are good at tricking companies into handing over access to internal systems by posing as IT support or, conversely, employees who have forgotten their passwords.

Few people know better than educational technology giant Instructor how damaging the ShinyHunters hack can be. Hackers breached the company's flagship learning management system, Canvas, and stole the personal data and personal information of more than 30 million students, faculty and staff. When the company failed to pay the hackers a ransom, the hackers re-entered the school and defaced the school's login screen for Canvas, which students use to access exams and study materials. This second hack occurred during the final school year and disrupted exams for students across the country. Instructor eventually paid the ransom, despite FBI attempts to dissuade the company from paying.

Instructor is not the only target targeted by ShinyHunters hackers so far. The gang is behind some of the largest breaches in terms of number of records, including victims in higher education, finance, and government, including about 40 million records from internet provider Charter and at least 6 million customer records from cruise ship Carnival.

An edited screenshot of a message left by ShinyHunters on the hacked login page of In Structure's platform Canvas.Image credit: TechCrunch

Supply chains are under attack, with open source projects and big tech companies targeted

A series of sustained, simultaneous, and sometimes overlapping attacks against open source developers has resulted in a massive hack targeting major technology companies and their customers.

Several of the biggest names in the security industry, including Aqua Security's Trivy tools, Bitwarden, and Checkmarx, along with other major open source projects, were compromised this year, allowing hackers to install backdoor copies of software or steal passwords, credentials, and other sensitive tokens from the computers of people who installed automatically updated preinstalled software to download malware.

These attacks leveraged stolen credentials to spread further, opening the door to downstream compromises of large companies that rely on the targeted software, including AI giant OpenAI and web hosting company Vercel. With new hacks occurring almost every week, the open source world remains a vulnerable target within the broader technology ecosystem.

FBI surveillance system breached, triggering 'major cyber incident'

The US Federal Bureau of Investigation was forced to declare a “major cyber incident” in April after identifying that one of its surveillance systems had been compromised, and was required to make legally required disclosures to Congress. The breach may have exposed the target's phone numbers, which are under surveillance by federal agents, according to the report.

Chinese spies were accused of infiltrating an unclassified network that held classified information about the targets of wiretapping and communications interception, including the return of pen registrations. By notifying lawmakers, the violation likely met the standard of causing “obvious harm” to U.S. national security.

Hasbro hack causes weeks of downtime

Toy giant Hasbro is the latest example of what happens when a large company is unprepared for a security incident. Weeks after discovering hackers in its systems in late March, the 103-year-old company remained largely offline, with its website unavailable and unable to serve customers.

The company, which owns well-known brands such as Transformers, Peppa Pig and Dungeons & Dragons, has said little about the incident itself, what data (if any) was taken, or whether it paid the hackers. However, this disruption alone was likely to affect the company's finances, and as the company was busy responding to the incident, it was forced to postpone.

Hasbro said that as of mid-May, the hacker was no longer in the system and recovery was underway. However, the economic loss and ripple effects on the company's business due to this information leak are likely to become apparent within the next few months, and are expected to be substantial.

Millions of passports and driver's licenses were mass leaked

The past few months alone have seen an increase in large-scale data breaches involving sensitive government-issued documents, such as scans of passports and driver's licenses, that are left exposed on the web. From hotel check-in systems and money transfer apps to prison payphone providers and UK visa services, these services exposed the personal documents of more than two million people that could easily be misused. Many were caused by simple security flaws that could be easily avoided with basic cybersecurity practices.

These massive data breaches come as closed community apps and websites increasingly rely on “know-your-customer” checks that force users to verify their identity before being allowed entry, and as governments push through age-verification laws that would require similar identity verification for adults accessing vast swathes of the internet.

The logic is that the larger the breach, the less effective these identity verification systems will be and the more easily they can be exploited with stolen or compromised passports and driver's licenses. Further deployment of these ID collection systems will inevitably lead to more data breaches and security flaws.

If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

How human error in OpenAI led to the AI-powered Hugging Face hack

July 22, 2026

If you pay the hackers a ransom, they're likely to come back for more money.

July 22, 2026

Glow emerges from stealth with $1.2 billion valuation to take on endpoint security in the age of AI

July 22, 2026

Breach of AI music generator Suno affects 55 million users (via Have I Been Pwned)

July 21, 2026

Hackers are exploiting a recently patched WordPress bug, putting millions of websites at risk

July 20, 2026

Hackers steal 'vast amounts' of data from technology company used by thousands of US hospitals and pharmacies

July 20, 2026

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

How human error in OpenAI led to the AI-powered Hugging Face hack

July 22, 2026

Travis Kalanick's robotics company raises $1.7 billion led by a16z

July 22, 2026

If you pay the hackers a ransom, they're likely to come back for more money.

July 22, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2026 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.