Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

泄露、数据泄露与勒索信:2026年迄今为止最严重的黑客攻击

If anything, 2026 has made clear that cybersecurity is no longer a background concern. Today, security is at the front and center of many conversations, woven into almost every major story of the year. Inequalities are still common, the climate is worsening, and we’re seemingly one dodgy sneeze away from the next global pandemic. But running beneath all of it is a digital current that touches everything: Wars are fought on digital fronts as well as physical ones; governments are weaponizing citizens’ own data against them; botnets are quietly undermining democratic institutions; nation-state hackers are targeting civilian infrastructure, from power grids to water systems; and ransomware gangs are holding companies and institutions hostage for massive payouts. The attacks are getting bolder, more destructive, and harder to contain. As we cross into the closing quarter of this already horrendous year of digital attacks and hybrid warfare, here is a look at some of the worst hacks and breaches so far, and how they might affect us going forward.

如果说2026年证明了什么,那就是网络安全已不再是一个次要问题。如今,安全已成为许多对话的核心,并贯穿于今年几乎所有重大事件之中。不平等现象依然普遍,气候状况持续恶化,我们似乎距离下一场全球大流行病仅一步之遥。但在这一切之下,一股数字暗流触及了方方面面:战争不仅在物理前线进行,也在数字前线展开;政府正将公民自身的数据作为武器来对付他们;僵尸网络正悄然破坏民主制度;国家级黑客正瞄准民用基础设施,从电网到供水系统;勒索软件团伙则将企业和机构扣为人质,索要巨额赎金。攻击正变得越来越大胆、更具破坏性,也更难遏制。随着我们进入这个数字攻击与混合战争频发的糟糕年份的最后一个季度,以下是迄今为止一些最严重的黑客攻击和数据泄露事件,以及它们未来可能对我们产生的影响。

Questions of DOGE’s massive swipe of Social Security data linger

关于DOGE大规模窃取社会保障数据的质疑依然存在

More than a year after operatives with the Elon Musk-led band of government destroyers known as the Department of Government Efficiency (or DOGE) swept through and dismantled federal agencies from the inside out, we’re still learning about the data lapses that happened under their watch. After DOGE entered the Social Security Administration, it’s not yet known what happened with some of the nation’s most sensitive data, as lawsuits are still going on in federal courts. The most alarming claim by a federal whistleblower is that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server, which led to a scramble to understand what was stored on the server. This database allegedly contained the Social Security numbers and associated personal information of most living Americans. In court filings, the Social Security Administration isn’t sure what was on the server but said that DOGE signed an agreement with an outside political advocacy group under the guise of finding evidence of voter fraud, which President Trump continues to claim without any evidence. The fears are that the database could be misused to target Americans for spurious reasons. Two of the top House Democrats investigating some of DOGE’s activities at the Social Security Administration said the exposure “could very well be the largest data breach in our nation’s history.”

在埃隆·马斯克领导的“政府效率部”(简称DOGE)——这群以摧毁政府机构著称的组织——横扫并从内部瓦解联邦机构一年多后,我们仍在了解其监管下发生的数据泄露事件。在DOGE进入社会保障局(SSA)后,由于联邦法院的诉讼仍在进行,该国一些最敏感的数据究竟发生了什么尚不得而知。一位联邦举报人最令人震惊的说法是,DOGE将社会保障数据库的实时副本上传到了一个不安全的第三方服务器上,这引发了人们对服务器存储内容的恐慌。据称,该数据库包含了大多数在世美国人的社会保障号码及相关个人信息。在法庭文件中,社会保障局表示不确定服务器上存储了什么,但称DOGE曾以寻找选民欺诈证据为幌子,与一个外部政治倡导团体签署了协议(特朗普总统在没有任何证据的情况下持续声称存在选民欺诈)。人们担心该数据库可能被滥用,从而以虚假理由针对美国公民。两名调查DOGE在社会保障局活动的众议院民主党高层表示,此次泄露“很可能是我们国家历史上最大的数据泄露事件”。

Hackers are increasingly targeting U.S. water systems and European energy grids to sow chaos

黑客日益频繁地攻击美国供水系统和欧洲电网以制造混乱

A rash of cyberattacks across Europe targeting civilian energy and water supplies, like power plants and water dams, has set a troubling trend. Several hacks attributed to (or partly blamed on) Russia have risked real-world harm to communities and populations. Poland’s energy grid was targeted with computer-destroying malware late last year, as was a Swedish thermal plant and a Norwegian dam that spilled entire swimming pools’ worth of water. Then earlier this year, Russian hackers targeted Poland’s water treatment plants, showing that Moscow’s hybrid war antagonism continues to extend beyond the digital realm. Now, thanks to the recent war waged by the U.S. and Israel against Iran, hackers working for the Iranian regime are actively hacking critical infrastructure across the United States in opportunistic attempts to disrupt neighborhoods and communities. The Cybersecurity and Infrastructure Security Agency (CISA) said Iranian hackers targeted over a hundred water providers over the summer, including privately owned water utilities, which remain a soft target as they often lack basic funding and cybersecurity protections.

欧洲各地针对民用能源和供水设施(如发电厂和水坝)的一系列网络攻击,引发了一种令人不安的趋势。几起归咎于(或部分归咎于)俄罗斯的黑客攻击,已对社区和民众造成了现实世界的危害。去年年底,波兰电网遭到破坏性恶意软件攻击,瑞典的一家热电厂和挪威的一座水坝也未能幸免,导致相当于多个游泳池容量的水量外泄。今年早些时候,俄罗斯黑客又瞄准了波兰的水处理厂,这表明莫斯科的混合战争对抗正持续延伸至数字领域之外。如今,由于美国和以色列近期对伊朗发动的战争,为伊朗政权工作的黑客正积极攻击美国各地的关键基础设施,试图趁机扰乱社区生活。美国网络安全与基础设施安全局(CISA)表示,伊朗黑客在夏季针对了一百多家供水商,其中包括私营水务公司,由于这些公司往往缺乏基本资金和网络安全防护,它们依然是脆弱的目标。

Klue reached a deal with its hackers but still lost control of its customers’ data

Klue与黑客达成协议,但仍失去了对其客户数据的控制

Market research provider Klue was at the center of a huge data breach that affected close to 200 companies, several of which were cybersecurity giants such as Jamf, HackerOne, and LastPass. It was one of the broadest data breaches of the year, affecting a multitude of Klue’s customers, less than a year after the company laid off half of its staff in favor of doubling down on AI. Klue admitted that an extortion gang, dubbed Icarus, broke into its systems using a credential that it issued in 2022 for a limited pilot. So it appears the company had around four years to decommission the credential before it was stolen and used to break into its systems. In the data breach, Klue exposed the keys to its customers’ cloud services, allowing the hackers to break in and steal those stores of data to extort those companies for a ransom. While governments and researchers often urge victims not to pay ransoms to prevent hackers from profiting from cybercrime, Klue told its customers that it had reached an agreement with the hackers not to publish the stolen data — strongly suggesting that it had paid them. But as part of the deal, the hackers conceded that another hacking group also had a portion of Klue’s customers’ data and urged those victim companies not to pay them.

市场研究提供商Klue卷入了一起巨大的数据泄露事件,影响了近200家公司,其中包括Jamf、HackerOne和LastPass等网络安全巨头。这是今年波及范围最广的数据泄露事件之一,影响了Klue的大量客户。而就在不到一年前,该公司刚刚裁掉了一半员工,转而全力投入人工智能领域。Klue承认,一个名为“伊卡洛斯”(Icarus)的勒索团伙利用其在2022年为有限试点项目颁发的凭证侵入了其系统。因此,该公司似乎有大约四年的时间在凭证被盗并用于入侵系统之前将其停用。在这次数据泄露中,Klue泄露了其客户云服务的密钥,使黑客得以入侵并窃取这些数据存储,从而勒索这些公司。尽管政府和研究人员经常敦促受害者不要支付赎金,以防止黑客从网络犯罪中获利,但Klue告诉客户,它已与黑客达成协议,不公开被盗数据——这强烈暗示该公司已经支付了赎金。但作为协议的一部分,黑客承认另一个黑客组织也掌握了Klue部分客户的数据,并敦促那些受害公司不要向对方支付赎金。

Thousands had their Instagram accounts hijacked thanks to Meta’s AI chatbot

数千人的Instagram账户因Meta的AI聊天机器人而被劫持

When is a hack not quite a hack? When you’re granted access simply by asking for it. That’s what happened when thousands of Instagram accounts were hijacked in early 2026 as people abused Meta’s AI chatbot to reset others’ account passwords. The hijackings, first reported by 404 Media, happened over the course of several months and were only noticed after news of the exploit began to leak online. The attack was simple in execution: Impersonating a target, people opened a chat with Meta’s AI chatbot and pretended that they had been locked out of the account. By requesting the chatbot to send a password reset code to an email address of the attacker’s choosing, the attacker gained access to their victim’s account. The incident affected tens of thousands.

什么时候黑客攻击算不上真正的“黑客攻击”?当你仅仅通过请求就能获得访问权限时。2026年初,数千个Instagram账户被劫持,原因正是人们滥用了Meta的AI聊天机器人来重置他人的账户密码。据404 Media首次报道,这些劫持事件发生在几个月内,直到有关该漏洞的消息开始在网上流传才被发现。攻击执行起来很简单:攻击者冒充目标用户,与Meta的AI聊天机器人开启对话,并谎称自己无法登录账户。通过要求聊天机器人将密码重置代码发送到攻击者指定的电子邮件地址,攻击者便获得了受害者的账户访问权限。该事件影响了数万人。