Home Cybersecurity Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
CYBERSECURITY

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far. 25% off tickets now Back by popular demand: Save up to $300 on Disrupt Close Image Credits:Bryan Dozier/Middle East Images via AFP / Getty Images Security Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far Zack Whittaker 9:00 AM PDT · September 15, 2026 If anything, 2026 has made clear that cybersecurity is no longer a background concern.

What happened

From the massive DOGE data breach and the compromise of critical infrastructure to the hack of federal surveillance systems, here are the most damaging security incidents and data breaches of 2026 so far. As we cross into the closing quarter of this already horrendous year of digital attacks and hybrid warfare, here is a look at some of the worst hacks and breaches so far, and how they might affect us going forward. Image Credits:Screenshot via Krebs On Security Healthcare hacks spill medical records belonging to tens of millions of people A scattering of healthcare-related data breaches have hit tens of millions of people across the U.

But running beneath all of it is a digital current that touches everything: Wars are fought on digital fronts as well as physical ones; governments are weaponizing citizens’ own data against them; botnets are quietly undermining democratic institutions; nation-state hackers are targeting civilian infrastructure, from power grids to water systems; and ransomware gangs are holding companies and institutions hostage for massive payouts. It was one of the broadest data breaches of the year, affecting a multitude of Klue’s customers, less than a year after the company laid off half of its staff in favor of doubling down on AI.

In the data breach, Klue exposed the keys to its customers’ cloud services, allowing the hackers to break in and steal those stores of data to extort those companies for a ransom. While governments and researchers often urge victims not to pay ransoms to prevent hackers from profiting from cybercrime, Klue told its customers that it had reached an agreement with the hackers not to publish the stolen data — strongly suggesting that it had paid them.

The wider picture

A ransomware gang took credit for the breach of a system that the enforcement agency said contained “targets of ATF investigations. ” The software supply chain is under attack, targeting open source projects and Big Tech companies A series of ongoing, concurrent, and occasionally overlapping attacks on open source developers has resulted in massive hacks targeting Big Tech companies and their customers. The hackers appear to be holding the vast cache of data, stolen over the course of a year, hostage in return for a ransom.

The massive data breaches come as closed-community apps and websites are increasingly leaning on “know your customer” checks to force users to verify their identity before being allowed in. The further rollout of these ID-collecting systems will inevitably lead to more data breaches and security lapses. The largest known breach of 2026 hit insurance company DentaQuest, which resulted in the theft of health data of 15 million people. Topics cyberattack, cybersecurity, data breach, hacks, Security When you purchase through links in our articles, we may earn a small commission.

Disrupt 2026: OpenAI, Anthropic, Replit, and more take over 6 industry stages. Questions of DOGE’s massive swipe of Social Security data linger More than a year after operatives with the Elon Musk-led band of government destroyers known as the Department of Government Efficiency (or DOGE) swept through and dismantled federal agencies from the inside out, we’re still learning about the data lapses that happened under their watch.

What has been reported

After DOGE entered the Social Security Administration, it’s not yet known what happened with some of the nation’s most sensitive data, as lawsuits are still going on in federal courts. The most alarming claim by a federal whistleblower is that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server, which led to a scramble to understand what was stored on the server. This database allegedly contained the Social Security numbers and associated personal information of most living Americans.

The fears are that the database could be misused to target Americans for spurious reasons. Two of the top House Democrats investigating some of DOGE’s activities at the Social Security Administration said the exposure “could very well be the largest data breach in our nation’s history. ” Hackers are increasingly targeting U. Several hacks attributed to (or partly blamed on) Russia have risked real-world harm to communities and populations. Image Credits:Gabri Solera/Europa Press / Getty Images Klue reached a deal with its hackers but still lost control of its customers’ data Market research provider Klue was at the center of a huge data breach that affected close to 200 companies, several of which were cybersecurity giants such as Jamf, HackerOne, and LastPass.

But as part of the deal, the hackers conceded that another hacking group also had a portion of Klue’s customers’ data and urged those victim companies not to pay them.

What happens next

That’s what happened when thousands of Instagram accounts were hijacked in early 2026 as people abused Meta’s AI chatbot to reset others’ account passwords. The hacks allowed attackers to steal passwords, credentials, and other sensitive tokens from the computers of anyone who installed a backdoored copy of the software, or their pre-installed software auto-updated to download the malware. The EU’s top cyber agency later confirmed a major data heist following the theft of its cloud keys by the hackers.

Hundreds of millions of passports and driver’s licenses are now exposed online An immense data breach at an identity document checking company called IDScan threatens to affect almost every driver in North America: Hackers touted a search engine on the dark web capable of listing the photos of 150 million drivers in the U. The company confirmed a data breach soon after, but details are still emerging. This breach adds to an already extensive list of data spills involving people’s passports and driver’s licenses: From a hotel check-in system and a money-transfer app to a prison payphone provider and a U.

Another major data breach at CareCloud, a company that hosts electronic patient records, allowed hackers to steal the sensitive medical information of at least 3.

Was this article useful?