Close Menu
New York Examiner News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    6 Best Tattoo Cover Up Makeup For Everyone in 2026

    September 16, 2026

    Drake Premieres His Not-So-Short Film FOMO

    September 16, 2026

    The CEO of Capgemini has a warning: You might be thinking about AI all wrong 

    September 16, 2026
    Facebook X (Twitter) Instagram
    New York Examiner News
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    New York Examiner News
    Home»Technology»Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
    Technology

    Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

    By AdminSeptember 15, 2026
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far


    If anything, 2026 has made clear that cybersecurity is no longer a background concern. Today, security is at the front and center of many conversations, woven into almost every major story of the year. 

    Inequalities are still common, the climate is worsening, and we’re seemingly one dodgy sneeze away from the next global pandemic. But running beneath all of it is a digital current that touches everything: Wars are fought on digital fronts as well as physical ones; governments are weaponizing citizens’ own data against them; botnets are quietly undermining democratic institutions; nation-state hackers are targeting civilian infrastructure, from power grids to water systems; and ransomware gangs are holding companies and institutions hostage for massive payouts. The attacks are getting bolder, more destructive, and harder to contain.

    As we cross into the closing quarter of this already horrendous year of digital attacks and hybrid warfare, here is a look at some of the worst hacks and breaches so far, and how they might affect us going forward.

    Questions of DOGE’s massive swipe of Social Security data linger

    More than a year after operatives with the Elon Musk-led band of government destroyers known as the Department of Government Efficiency (or DOGE) swept through and dismantled federal agencies from the inside out, we’re still learning about the data lapses that happened under their watch.

    After DOGE entered the Social Security Administration, it’s not yet known what happened with some of the nation’s most sensitive data, as lawsuits are still going on in federal courts. The most alarming claim by a federal whistleblower is that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server, which led to a scramble to understand what was stored on the server. This database allegedly contained the Social Security numbers and associated personal information of most living Americans.

    In court filings, the Social Security Administration isn’t sure what was on the server but said that DOGE signed an agreement with an outside political advocacy group under the guise of finding evidence of voter fraud, which President Trump continues to claim without any evidence. The fears are that the database could be misused to target Americans for spurious reasons. 

    Two of the top House Democrats investigating some of DOGE’s activities at the Social Security Administration said the exposure “could very well be the largest data breach in our nation’s history.”

    Hackers are increasingly targeting U.S. water systems and European energy grids to sow chaos

    A rash of cyberattacks across Europe targeting civilian energy and water supplies, like power plants and water dams, has set a troubling trend. 

    Several hacks attributed to (or partly blamed on) Russia have risked real-world harm to communities and populations. Poland’s energy grid was targeted with computer-destroying malware late last year, as was a Swedish thermal plant and a Norwegian dam that spilled entire swimming pools’ worth of water. 

    Then earlier this year, Russian hackers targeted Poland’s water treatment plants, showing that Moscow’s hybrid war antagonism continues to extend beyond the digital realm.

    Now, thanks to the recent war waged by the U.S. and Israel against Iran, hackers working for the Iranian regime are actively hacking critical infrastructure across the United States in opportunistic attempts to disrupt neighborhoods and communities. The Cybersecurity and Infrastructure Security Agency (CISA) said Iranian hackers targeted over a hundred water providers over the summer, including privately owned water utilities, which remain a soft target as they often lack basic funding and cybersecurity protections.

    a photo of a dam in Spain seen spilling water.
    Image Credits:Gabri Solera/Europa Press / Getty Images

    Klue reached a deal with its hackers but still lost control of its customers’ data

    Market research provider Klue was at the center of a huge data breach that affected close to 200 companies, several of which were cybersecurity giants such as Jamf, HackerOne, and LastPass. It was one of the broadest data breaches of the year, affecting a multitude of Klue’s customers, less than a year after the company laid off half of its staff in favor of doubling down on AI.

    Klue admitted that an extortion gang, dubbed Icarus, broke into its systems using a credential that it issued in 2022 for a limited pilot. So it appears the company had around four years to decommission the credential before it was stolen and used to break into its systems. In the data breach, Klue exposed the keys to its customers’ cloud services, allowing the hackers to break in and steal those stores of data to extort those companies for a ransom.

    While governments and researchers often urge victims not to pay ransoms to prevent hackers from profiting from cybercrime, Klue told its customers that it had reached an agreement with the hackers not to publish the stolen data — strongly suggesting that it had paid them.

    But as part of the deal, the hackers conceded that another hacking group also had a portion of Klue’s customers’ data and urged those victim companies not to pay them.

    Thousands had their Instagram accounts hijacked thanks to Meta’s AI chatbot

    When is a hack not quite a hack? When you’re granted access simply by asking for it. That’s what happened when thousands of Instagram accounts were hijacked in early 2026 as people abused Meta’s AI chatbot to reset others’ account passwords.

    The hijackings, first reported by 404 Media, happened over the course of several months and were only noticed after news of the exploit began to leak online. The attack was simple in execution: Impersonating a target, people opened a chat with Meta’s AI chatbot and pretended that they had been locked out of the account. By requesting the chatbot to send a password reset code to an email address of the attacker’s choosing, the attacker gained access to their victim’s account.

    The incident affected tens of thousands of accounts before the improper access was discovered and cut off. It was an embarrassing and high-profile lapse in security — and trust — for one of the world’s largest tech companies.

    A screenshot that shows a successful takeover, posted in a Telegram group where hackers were sharing the technique, as well as bragged about their hacks.
    Image Credits:TechCrunch / screenshot

    FBI and ATF surveillance systems were breached, sparking two “major cyber incidents”

    The U.S. Federal Bureau of Investigation was forced to declare a “major cyber incident” in April, prompting a legally required disclosure to Congress, after it found that one of its surveillance systems was compromised. According to reports, the breach potentially exposed phone numbers of targets under surveillance by federal agents. 

    Chinese spies were accused of the breach of the unclassified network, which held sensitive information about the surveillance targets of wiretaps and other communication intercepts, such as pen register returns. Because lawmakers were notified, the breach is likely to have met a high bar: causing “demonstrable harm” to U.S. national security.

    Months later in August, the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed its own “major incident” that prompted a separate disclosure to Congress. A ransomware gang took credit for the breach of a system that the enforcement agency said contained “targets of ATF investigations.”

    The software supply chain is under attack, targeting open source projects and Big Tech companies

    A series of ongoing, concurrent and occasionally overlapping attacks on open-source developers has resulted in massive hacks targeting Big Tech companies and their customers. 

    Some of the biggest names in security, including Aqua Security’s Trivy tool, Bitwarden and Checkmarx, alongside other major open-source projects, were compromised this year. The hacks allowed attackers to steal passwords, credentials and other sensitive tokens from the computers of anyone who installed a backdoored copy of the software, or their pre-installed software auto-updated to download the malware. 

    These attacks used stolen credentials to spread further, and opened the door to downstream compromises of big companies that rely on the targeted software, including AI giant OpenAI and web hosting company Vercel. The EU’s top cyber agency later confirmed a major data heist following the theft of its cloud keys by the hackers. 

    By August, two hackers blamed for these major heists were arrested in Australia.

    Hundreds of millions of passports and driver’s licenses are now exposed online

    An immense data breach at an identity document checking company called IDScan threatens to affect almost every driver in North America: Hackers touted a search engine on the dark web capable of listing the photos of 150 million drivers in the U.S. and Canada, including the reporter who broke the story.

    The company confirmed a data breach soon after, but details are still emerging. The hackers appear to be holding the vast cache of data, stolen over the course of a year, hostage in return for a ransom.

    This breach adds to an already extensive list of data spills involving people’s passports and driver’s licenses: From a hotel check-in system and a money transfer app to a prison payphone provider and a U.K. visa service, services exposed over 2 million people’s personal documents. Many of these were caused by simple security lapses that would have been easily prevented if basic cybersecurity practices had been followed.

    The massive data breaches come as closed-community apps and websites are increasingly leaning on “know your customer” checks to force users to verify their identity before being allowed in. Meanwhile, governments are pushing age-verification laws, demanding similar identity checks from adults to access a vast swath of the internet. 

    The logic goes that the greater the spills, the less effective these identity-checking systems are, as they can be easily misused with a stolen or leaked passport or driver license. The further rollout of these ID-collecting systems will inevitably lead to more data breaches and security lapses.

    a photo of the driver's license of Pete Hegseth, the DOD secretary, whose photo can be seen here on this identity theft website called Nexus on the dark web
    Image Credits:Screenshot via Krebs On Security

    Healthcare hacks spill medical records belonging to tens of millions of people

    A scattering of healthcare-related data breaches have hit tens of millions of people across the U.S. this year. The largest known breach of 2026 hit insurance company DentaQuest, which resulted in the theft of health data of 15 million people. Another major data breach at CareCloud, a company that hosts electronic patient records, allowed hackers to steal the sensitive medical information of at least 3.7 million people. 

    And, a breach at healthcare data and billing giant Aesto Health at the end of last year was later confirmed to affect at least 9.5 million patients at dozens of providers and practices that use its software. 

    Hasbro’s hack led to weeks of downtime

    Toymaker giant Hasbro is the latest example of what happens when a large corporation isn’t prepared to manage a security incident. Weeks after discovering hackers in its systems in late March, the 103-year-old company remained largely offline, its website was unavailable, and unable to serve its customers.

    The company, which owns big name brands such as Transformers, Peppa Pig and Dungeons & Dragons, has said little about the incident itself, what data was taken (if any), and whether it paid the hackers. But the disruption alone was likely to affect the company’s financials, and it was forced to delay filing its quarterly report with the SEC, as it scrambled to handle the incident. 

    Hasbro said in May that the hackers were no longer in its systems, and that its recovery was underway. While the data breach affected a few hundred employees, the financial costs of the breach and the knock-on effects to its business are likely to be realized in the coming months.

    Instructure falls victim to ShinyHunters’ disruptive hacking campaigns

    The ShinyHunters gang continued its hacking campaign, targeting dozens of companies with simple but highly effective voice-phishing techniques. The English-speaking hackers are adept at tricking companies into turning over access to their internal systems by pretending to be IT support, or conversely, an employee who forgot their password.

    Few companies know better the toll a ShinyHunters campaign can exact than education tech giant Instructure. The hackers breached the company’s flagship learning management system, Canvas, to steal private data and personal information of over 30 million students and staff. 

    When the company didn’t pay the hackers’ ransom, the hackers broke in again, and defaced the login screens for Canvas, used by students to access their exam and coursework material. This second hack happened during school finals, disrupting exams across the United States. 

    Instructure eventually paid the ransom, despite efforts by the FBI to dissuade the company from paying.

    This wasn’t the only company targeted by the ShinyHunters hackers. The gang has been behind some of the largest breaches by the number of records stolen: They’ve stolen some 40 million records from internet provider Charter and at least 6 million customer records from cruise liner Carnival, as well as other victims in higher education, finance, and government.

    A redacted screenshot of the message ShinyHunters left on the hacked login pages of Instructure's platform Canvas.
    Image Credits:TechCrunch

    Medical device makers Stryker and Boston Scientific struck with destructive attacks

    A cyberattack on a U.S. medical tech company, Stryker, in March saw Iranian hackers break in and remotely wipe tens of thousands of employee devices in one fell swoop, widely disrupting the company’s operations for several days. 

    The breach represented a marked shift in Iran’s hacking tactics at a time of ongoing war: the country moved from its typical focus on espionage and hack-and-leak operations in aid of political gains, toward active, destructive hacks in apparent retaliation for the war. 

    The U.S. government connected the hacking group behind the breach to an arm of Iranian intelligence. The breach ended up having a material impact on Stryker’s first-quarter earnings.

    In August, a similar fate befell medical device maker Boston Scientific, after a cyberattack cut off the company’s global network, causing a “global disruption” to its operations. The Massachusetts-based company, which makes heart implants like pacemakers, said some patients were affected by the outages, which also prevented it from shipping and creating new orders. 

    Boston Scientific took two weeks to recover from its immediate outage, though its ongoing recovery has stretched into September. 

    First published on June 8, and updated on July 7 and again on September 15.

    When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleThose Viral Bodega Peptides Aren’t Actually Peptides
    Next Article Dustin Moskovitz’s ‘effective altruism’ tied to AI doomerism claims

    RELATED POSTS

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 16, 2026

    The Supreme Court Just Blocked Trump’s Efforts to Control Mail-In Voting for the Midterms

    September 15, 2026

    Microsoft’s new AI ‘code of conduct’ tells models not to hack systems or trick humans

    September 14, 2026

    The Smart Bird Feeders Everyone’s Talking About (and Actually Buying) (2026)

    September 14, 2026

    Obama urges Democrats to have a ‘clear plan’ for AI safeguards

    September 13, 2026

    10 Best Standing Desks Worth Buying in 2026

    September 13, 2026
    latest posts

    6 Best Tattoo Cover Up Makeup For Everyone in 2026

    We independently evaluate all recommended products and services. Any products or services put forward appear…

    Drake Premieres His Not-So-Short Film FOMO

    September 16, 2026

    The CEO of Capgemini has a warning: You might be thinking about AI all wrong 

    September 16, 2026

    Iran-Backed Houthis Attempt Strike on Mecca in Saudi Arabia – Islam’s Holiest City! * The Gateway Pundit * by Jim Hoft

    September 16, 2026

    House Republicans back war powers resolution to limit Trump on Iran

    September 16, 2026

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 16, 2026

    The hole in the ozone layer is healing, but extreme weather may be slowing progress down

    September 16, 2026
    Categories
    • Books (1,493)
    • Business (6,397)
    • Events (76)
    • Film (6,331)
    • Lifestyle (4,402)
    • Music (6,461)
    • Politics (6,384)
    • Science (5,748)
    • Technology (6,329)
    • Television (6,020)
    • Uncategorized (9)
    • US News (6,384)
    popular posts

    50, 100 & 150: April 2023

    1973 Catalytic Conversion “Among the most troublesome air pollutants produced by automobiles are the chemically…

    ‘Bachelor in Paradise’ Season 8 Reveals First Cast Members & Teaser (VIDEO)

    August 26, 2022

    DJ Haram Announces Handplay EP, Shares New Song: Listen

    November 1, 2023

    ‘Grey’s Anatomy’ Season 19: Alexis Floyd Joins Cast as Simone

    July 20, 2022
    Archives
    Browse By Category
    • Books (1,493)
    • Business (6,397)
    • Events (76)
    • Film (6,331)
    • Lifestyle (4,402)
    • Music (6,461)
    • Politics (6,384)
    • Science (5,748)
    • Technology (6,329)
    • Television (6,020)
    • Uncategorized (9)
    • US News (6,384)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 16, 2026

    The hole in the ozone layer is healing, but extreme weather may be slowing progress down

    September 16, 2026

    Majora’s Mask Remake Quietly Confirmed

    September 16, 2026
    © 2026 New York Examiner News. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT