Worst Hacks of 2026 So Far: DOGE Data Breach, Ransomware and Critical Infrastructure Attacks

TL;DR
- A whistleblower-reported DOGE copy of 300M+ Social Security records to an unsecured cloud and China's Salt Typhoon compromise of U.S. telecom wiretap systems turned 2026 into a crisis of federal trust.
- Scattered Spider, ShinyHunters and SafePay drove a record wave of Salesforce-targeted breaches and ransomware, hitting Qantas, Allianz Life, Ingram Micro, Coinbase and Jaguar Land Rover.
- Critical infrastructure is now the front line, with Iranian-linked attacks on water utilities and Chinese pre-positioning in power and telecom forcing a shift to zero-trust and mandatory disclosure.
The Year Trust Broke
2026 was supposed to be the year of AI defense. Instead, it became the year attackers went straight for the crown jewels: federal databases, wiretap systems, airlines, insurers, and the power and water systems keeping cities running. The worst hacks of the year so far share a pattern — not just stolen passwords, but wholesale copying of sensitive systems, followed by ransom notes, leak sites, and geopolitical fallout.
What makes 2026 different is scale combined with legitimacy. Some of the most damaging exposures didn't start with a masked hacker, but with insider access, third-party vendors, and state-backed groups already inside telecom and infrastructure providers for months before they were caught.
DOGE and the 300 Million-Record Federal Data Crisis
The biggest domestic story of 2026 is the Department of Government Efficiency data scandal. Throughout early 2026, DOGE engineers were granted sweeping access to Treasury, Office of Personnel Management, and Social Security Administration systems as part of a federal efficiency drive.
By August, a Social Security whistleblower disclosure alleged that DOGE staff had copied the SSA's Numident database — containing names, Social Security numbers, birth dates, addresses, and citizenship status for more than 300 million Americans — to an insecure commercial cloud environment outside federal oversight. Cybersecurity experts called it the largest federal privacy breach in U.S. history, not because of an external exploit, but because guardrails, logging, and access controls were bypassed from the inside.
Lawsuits, congressional hearings, and an emergency court order followed. The SSA said no evidence of external exfiltration had been found, but former NSA and CISA officials warned the damage was already done: once a dataset that complete leaves a hardened mainframe, you cannot put it back. Fraud monitoring firms reported a surge in Social Security-based identity theft attempts in July and August, which they linked to fears the data was circulating.
Salt Typhoon and the Compromise of U.S. Surveillance Systems
If DOGE was a self-inflicted wound, Salt Typhoon was a foreign intelligence coup. The Chinese-linked group that burrowed into AT&T, Verizon, Lumen and other telecoms in 2024-2025 was still being cleaned up in 2026, and investigators revealed how deep it went.
Attackers accessed lawful-intercept wiretap platforms, geolocation metadata, and call records for Washington targets, including senior government and campaign officials. In early 2026, the FBI and CISA confirmed the group maintained persistence in parts of telecom infrastructure for over a year, harvesting diplomatic and law enforcement communications.
The implications are staggering. Federal surveillance systems designed for court-ordered monitoring became a monitoring tool for Beijing. Telecoms have since begun a $500 million-plus rip-and-replace of routers and identity systems, while the government pushed new rules requiring end-to-end encryption for sensitive federal mobile communications and mandatory reporting of backbone compromises within 72 hours.
Ransomware Reigns: Ingram Micro, Jaguar Land Rover and the Supply Chain Domino
Ransomware in 2026 got louder, faster, and more public. In July, IT distribution giant Ingram Micro was hit by SafePay ransomware, forcing offline ordering systems and disrupting resellers worldwide for days. The company confirmed data theft and faced a multi-million dollar ransom demand posted to a leak site.
Weeks later, Jaguar Land Rover shut down global production after a cyberattack later linked to Scattered Spider affiliates. Factories in the UK, Slovakia and India were idled for weeks, costing an estimated hundreds of millions in lost output and making it one of the most expensive manufacturing cyberattacks ever.
Other victims included French retailer Auchan, U.S. toolmaker Snap-on, and multiple hospital systems. The FBI's 2026 Internet Crime Report data through mid-year shows ransomware complaints up nearly 40 percent year-over-year, with double and triple extortion — encrypt, leak, then harass customers directly — now standard.
The Salesforce Crime Wave: Qantas, Allianz Life, Coinbase and Lululemon
The most replicable attack playbook of 2026 targeted Salesforce. Groups tracked as Scattered Spider, ShinyHunters and Lapsus$ affiliates used vishing, help-desk impersonation and stolen OAuth tokens to break into corporate Salesforce instances, then demanded ransom with a familiar note threatening to publish on leak site BreachForums successor forums.
Victims piled up fast:
- Qantas confirmed 5.7 million customer records exposed in July after attackers hit a third-party contact center platform.
- Allianz Life USA disclosed theft of personal data for 1.1 million customers and employees the same month.
- Lululemon, Ahold Delhaize USA, Adidas, and Qantas' peers reported similar third-party breaches.
- Coinbase revealed in May that bribed overseas support agents leaked account data for about 69,000 users, leading to targeted phishing and a $20 million ransom demand the company refused to pay.
Google Threat Intelligence called it the largest sustained social-engineering spree against enterprise CRM systems ever seen, and Salesforce responded with emergency MFA and IP-allowlisting guidance adopted across the Fortune 500.
Critical Infrastructure Under Fire
Beyond data theft, 2026 brought alarming attacks on physical systems. U.S. officials warned in spring 2026 of renewed Iranian-linked probing and intrusions into municipal water utilities in Pennsylvania, Texas and California, exploiting default passwords on programmable logic controllers. While no city lost water, CISA issued emergency directives ordering utilities to disconnect exposed OT systems from the public internet.
Meanwhile, Chinese Volt Typhoon activity continued to haunt power, port and transportation networks. Federal briefings in 2026 said the group had pre-positioned access in critical infrastructure for potential disruption in a future Taiwan crisis, prompting joint U.S.-allied advisories and offensive takedowns of botnet infrastructure.
On the criminal side, the February 2026 ransomware attack on a major U.S. blood center network and spring attacks on Yale New Haven Health and other hospital chains showed healthcare remains ransomware's favorite target, with patient care diverted and 5.5 million-plus health records exposed in a single Yale incident.
The Rise of Ransom Notes and Leak Sites
One defining aesthetic of 2026 hacks is the ransom note itself. Attackers no longer just encrypt — they email executives, text patients, and tag victims on social media with links to searchable leak portals. SafePay, Clop, Qilin and World Leaks competed for headlines with polished victim blogs, countdown timers, and PR-style press releases.
Researchers say this shaming economy works. Median ransom demands in the first half of 2026 topped $2 million, and more than 60 percent of listed victims saw at least some data published, according to incident response firms. Stolen data is also being fed into AI-powered phishing kits that craft hyper-personalized lures from breach dumps within hours.
What This Means for Cybersecurity Going Forward
Three lessons stand out from the worst hacks of 2026 so far. First, identity is the perimeter. Almost every major breach — from DOGE's over-privileged access to Salesforce vishing to telecom backdoors — started with valid credentials, not zero-days. Zero-trust architecture, phishing-resistant passkeys, and strict third-party access are no longer optional.
Second, government data needs government-grade controls. The DOGE and Salt Typhoon sagas shattered assumptions that federal systems were too sensitive to fail. Expect new laws limiting bulk copying of citizen data, mandatory encryption of wiretap infrastructure, and personal liability for executives who ignore CISA directives.
Third, resilience beats prevention. Jaguar Land Rover, Ingram Micro and hospitals that recovered fastest had segmented backups, offline OT kill-switches, and practiced incident response plans. Those that didn't paid weeks of downtime.
With four months left in 2026, defenders are bracing for election-related disinformation tied to stolen voter data and AI-amplified extortion. If the first eight months proved anything, it's that no database is too big to copy and no infrastructure too critical to target.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!