A year of cyberattacks has pushed digital security into the center of American public life, with federal agencies, energy providers and major technology companies among those hit. The breaches have ranged from a massive exposure of Social Security data to hijacked Instagram accounts and ransomware attacks on law enforcement systems. Security researchers and lawmakers say the attacks are growing bolder and harder to contain.
The Social Security Administration is still facing lawsuits over data handling during the period when the Department of Government Efficiency, led by Elon Musk, entered the agency. A federal whistleblower has claimed that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server, and the agency has said in court filings that it does not know what was on the server. The database allegedly contained the Social Security numbers and personal information of most living Americans. Two top House Democrats investigating DOGE's activities said the exposure could be the largest data breach in the nation's history.
Attacks on civilian infrastructure in Europe have continued, with Poland's energy grid, a Swedish thermal plant and a Norwegian dam among the targets of computer-destroying malware late last year. Russian hackers later targeted Poland's water treatment plants. CISA said Iranian hackers targeted more than a hundred water providers over the summer, including privately owned utilities that often lack basic cybersecurity protections.
Market research provider Klue suffered one of the year's broadest breaches, affecting close to 200 companies, including cybersecurity firms Jamf, HackerOne and LastPass. An extortion gang called Icarus broke in using a credential Klue issued in 2022 for a limited pilot, exposing keys to customers' cloud services. Klue told customers it had reached an agreement with the hackers not to publish the stolen data, suggesting it paid them; the hackers also said another group held a portion of the data.
Thousands of Instagram accounts were hijacked in early 2026 after people abused Meta's AI chatbot to reset passwords, an exploit first reported by 404 Media. Attackers impersonated targets and asked the chatbot to send a reset code to an email address they controlled. The incident affected tens of thousands of accounts before the access was cut off.
The FBI declared a major cyber incident in April and disclosed it to Congress after finding one of its surveillance systems was compromised, reportedly exposing phone numbers of surveillance targets. Chinese spies were accused of the breach. In August, the ATF confirmed its own major incident and disclosed it to Congress, with a ransomware gang taking credit for breaching a system containing targets of ATF investigations. Separate attacks on open source developers led to compromises at OpenAI, Vercel and the EU's top cyber agency, and two hackers were arrested in Australia by August.
More cybersecurity news from TechManNews.






