IT-PUB NEWS

2026 hacks exposed hospitals, grids and personal data

16.09.2026 14:03 • Author: IT-PUB
2026 hacks exposed hospitals, grids and personal data

Major breaches this year hit Social Security records, water systems, schools and healthcare, showing how cyberattacks now disrupt daily life and business.

Cybersecurity did not stay in the background in 2026. A string of breaches, ransomware attacks and destructive intrusions pushed digital security to the center of public life, with consequences far beyond lost files or defaced websites. The incidents touched government databases, hospitals, schools, identity-checking services and critical infrastructure. In many cases, the damage was not limited to stolen data — it also meant outages, disrupted services and new fears about how exposed information could be used.

Social Security data raised fears of large-scale misuse

One of the most alarming cases centers on what happened to Social Security data after DOGE entered the Social Security Administration. More than a year later, lawsuits are still ongoing, and the full picture remains unclear.

A federal whistleblower claimed that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server. According to the source text, that database allegedly contained Social Security numbers and related personal information of most living Americans. Court filings also say the Social Security Administration does not know exactly what was on the server.

The concern is not just exposure of sensitive data, but how it could be used. The agency also said DOGE signed an agreement with an outside political advocacy group under the stated goal of finding evidence of voter fraud, a claim President Trump continues to make without evidence. Two House Democrats investigating the matter said the exposure “could very well be the largest data breach in our nation’s history.”

Energy and water systems came under pressure

Another major theme in 2026 was attacks on civilian infrastructure. Across Europe, hacks against energy and water systems raised fears of direct harm to communities, not just digital disruption.

The source text points to several incidents attributed to or partly blamed on Russia, including attacks on Poland’s energy grid, a Swedish thermal plant and a Norwegian dam. In one case, the dam spilled water equivalent to several swimming pools. Later, Russian hackers were also said to have targeted water treatment plants in Poland.

The pattern did not stop in Europe. After the war waged by the U.S. and Israel against Iran, hackers working for the Iranian regime began targeting critical infrastructure in the United States as well. CISA said Iranian hackers went after more than 100 water providers over the summer, including privately owned utilities. As IT-PUB News notes, those companies were described as soft targets because they often lack basic funding and cybersecurity protections.

Klue's breach reached nearly 200 companies

Market research provider Klue drew attention after a breach that affected close to 200 companies, including cybersecurity names such as Jamf, HackerOne and LastPass.

According to the source, the company said an extortion gang called Icarus broke in using a credential issued in 2022 for a limited pilot. That credential apparently was never fully decommissioned. The hackers then used that access to steal customer cloud-service keys, which let them break into those stores of data and pressure the companies for ransom.

Klue told customers it had reached an agreement with the hackers not to publish the stolen data, which strongly suggests payment was made. At the same time, the hackers said another group also had some of Klue’s customers’ data and urged those victims not to pay that other gang. The breach showed how one forgotten credential could open the door to a much wider compromise.

Meta's chatbot helped attackers seize Instagram accounts

In early 2026, thousands of Instagram accounts were hijacked in an unusual way: attackers abused Meta’s AI chatbot to reset other people’s passwords.

The method was simple. People impersonated a target, opened a chat with Meta’s AI chatbot and claimed they had been locked out of their account. By asking the chatbot to send a password reset code to an email address they controlled, they gained access to the victim’s account.

The issue was first reported by 404 Media and unfolded over several months before the abuse was noticed and stopped. The incident affected tens of thousands of accounts. What makes it stand out is that the attack did not depend on a traditional software exploit, but on tricking an automated system into helping the attacker. For users, it was a reminder that AI tools can become part of the security problem when they are asked to make trust decisions they were not meant to handle.

FBI and ATF breaches exposed sensitive investigations

The FBI was forced to disclose a “major cyber incident” in April after one of its surveillance systems was compromised. The breach allegedly exposed phone numbers of targets under surveillance by federal agents. The source says Chinese spies were accused of the attack on the unclassified network, which contained sensitive information tied to wiretaps and other communication intercepts.

Because lawmakers were notified, the breach likely met the threshold of causing “demonstrable harm” to U.S. national security. Then, in August, the ATF made another major incident disclosure after a ransomware gang took credit for breaching a system that contained “targets of ATF investigations.”

These incidents matter not only because they involved federal agencies. They also showed that even systems used for law enforcement and surveillance can be exposed, raising concerns about operational security as well as the privacy of people caught up in investigations.

Open-source compromises spread into larger companies

The software supply chain also came under heavy pressure this year. A series of overlapping attacks on open-source developers led to compromises involving major tools and projects, including Aqua Security’s Trivy, Bitwarden and Checkmarx.

The attacks used stolen credentials to spread further, stealing passwords, credentials and other sensitive tokens from the computers of people who installed backdoored software or received malicious auto-updates. The fallout reached beyond the original projects and into larger companies that depend on them, including OpenAI and Vercel. The EU’s top cyber agency later confirmed a major data theft after hackers stole its cloud keys.

By August, two hackers blamed for these heists had been arrested in Australia. Even so, the incidents underlined how a problem in one widely used piece of software can cascade through the broader digital ecosystem.

Identity and health data kept spilling out

Another troubling pattern in 2026 was the scale of data stolen from identity verification services. A breach at IDScan threatened to affect almost every driver in North America, with hackers advertising a dark-web search engine that could list photos of 150 million drivers in the U.S. and Canada.

The company confirmed the breach, though details are still emerging. The hackers appear to be holding the stolen data hostage for ransom. The source also notes that similar spills have hit other services handling passports and driver’s licenses, including a hotel check-in system, a money transfer app, a prison payphone provider and a U.K. visa service. In many of these cases, the failures were linked to basic security lapses.

That matters because more platforms now demand identity checks, while governments are pushing age-verification rules that require adults to hand over similar documents. As those systems expand, they become more attractive targets.

Healthcare saw a similar pattern. DentaQuest suffered the year’s largest known healthcare breach, with health data stolen from 15 million people. CareCloud said hackers took sensitive medical information from at least 3.7 million people, while a breach at Aesto Health was later confirmed to affect at least 9.5 million patients across dozens of providers.

Cyberattacks increasingly caused business shutdowns

Not every attack was defined by data theft alone. Hasbro’s breach showed how long a company can stay disrupted after hackers get in. Weeks after the toy giant discovered the intrusion in late March, its website was still unavailable and it was unable to serve customers normally.

Hasbro said little about what was taken, if anything, or whether it paid the hackers. But the outage was serious enough to delay its quarterly SEC filing. The company said in May that the attackers were no longer in its systems and recovery was underway. Even so, the incident affected a few hundred employees and is likely to have financial consequences.

Education tech company Instructure faced similar disruption after attacks linked to ShinyHunters. The group used voice phishing to trick companies into handing over access to internal systems. Instructure said the hackers stole private data and personal information belonging to more than 30 million students and staff from Canvas, its learning platform.

When the company did not pay the ransom, the hackers returned and defaced Canvas login screens during school finals, disrupting exams across the United States. Instructure later paid the ransom, despite FBI efforts to dissuade it.

Medical device companies faced destructive intrusions

The healthcare and medical device sector also faced destructive cyberattacks. In March, Stryker was hit by Iranian hackers who remotely wiped tens of thousands of employee devices, disrupting operations for several days. The U.S. government linked the group behind the breach to an arm of Iranian intelligence. The incident had a material impact on Stryker’s first-quarter earnings.

In August, Boston Scientific suffered a similar attack that cut off its global network and caused a “global disruption” to operations. The company, which makes devices such as pacemakers, said some patients were affected by the outage and that shipping and new orders were interrupted. Recovery took two weeks for the immediate outage and continued into September.

Taken together, these attacks show why 2026 drew so much attention in cybersecurity. They were not isolated technical failures. They affected salaries, school exams, patient records, public services and systems that keep cities and companies running. The cost of weak security was increasingly measured in everyday disruption, not just stolen data.


Improve SEO for a small/medium business website for $50