Worst Cyberattacks of 2026: DOGE, IDScan, Meta and Critical Infrastructure Breaches
Cyberattacks in 2026 exposed IDs, medical records and critical systems, hitting Meta, Hasbro, Instructure, medical firms and U.S. agencies across the world.
Summary
Through September 15, 2026, a whistleblower alleged Elon Musk-led DOGE copied Social Security’s live database, with most living Americans’ Social Security numbers and personal data, to an unsecured third-party server. The agency could not establish its contents and had agreed with an outside advocacy group to seek voter fraud evidence. CISA said Iranian hackers targeted more than 100 U.S. water providers over summer amid war with Iran, while Russia-linked attacks struck Polish water plants after attacks on Poland’s grid, a Swedish thermal plant and a Norwegian dam. April’s FBI and August’s ATF breaches triggered major incident disclosures to Congress, potentially exposing surveillance phone numbers and ATF targets.
Klue said Icarus used a credential issued in 2022 to breach nearly 200 customers, including Jamf, HackerOne and LastPass, exposing cloud keys. Klue reached a nonpublication deal, but another gang held data. Backdoored Trivy, Bitwarden, Checkmarx and other open source software stole credentials and reached OpenAI, Vercel and the EU’s top cyber agency; two accused hackers were arrested in Australia by August. Meta’s AI chatbot enabled tens of thousands of Instagram takeovers. IDScan hackers advertised 150 million U.S. and Canadian driver photos, while separate spills exposed more than 2 million identity documents.
DentaQuest lost data on 15 million people, CareCloud at least 3.7 million and Aesto Health at least 9.5 million. ShinyHunters stole Canvas data from over 30 million Instructure users, disrupted U.S. finals and was paid; it also took about 40 million Charter and at least 6 million Carnival records. Hasbro suffered weeks offline, delayed an SEC filing and affected hundreds of employees. Iranian hackers wiped tens of thousands of Stryker devices in March, hurting first-quarter earnings. Boston Scientific’s August attack disrupted global operations and patients, blocked orders and shipments, and required two weeks for immediate recovery, which continued into September.
Positives
- Two accused software supply-chain hackers were arrested in Australia by August after attacks reached major technology companies and an EU cyber agency.
- Meta cut off the chatbot access method after attackers hijacked tens of thousands of Instagram accounts using fraudulent password resets.
- Hasbro said in May that hackers had left its systems and recovery was underway after weeks of disruption.
- Boston Scientific recovered from its immediate global outage within two weeks, although broader restoration continued into September.
Risks & concerns
- DOGE allegedly placed Social Security data covering most living Americans on an unsecured third-party server whose contents remain uncertain.
- Iranian hackers targeted more than 100 U.S. water providers over summer, exploiting utilities that often lack funding and basic cybersecurity controls.
- IDScan hackers advertised 150 million U.S. and Canadian driver photos through a dark-web search engine and demanded ransom.
- Healthcare breaches exposed data belonging to 15 million DentaQuest members, at least 3.7 million CareCloud patients and at least 9.5 million Aesto Health patients.
- ShinyHunters breached Instructure twice, stole data from over 30 million Canvas users and disrupted exams during U.S. school finals.
- Iranian hackers remotely wiped tens of thousands of Stryker employee devices, disrupting operations and materially affecting first-quarter earnings.