2026 Cybersecurity Annual Breach Summary
Read more about the top cybersecurity breaches from July 2025 to June 2026, with a focus on the magnitude, type of credentials stolen, increases or decreases over prior years, and affected markets.
The global average cost of a data breach dropped to USD 4.44 million in 2025—a 9% decline and the first drop in five years, according to the IBM Cost of a Data Breach Report.
The catch: that improvement was almost entirely driven by faster, AI-assisted detection and containment. In the United States specifically, the average breach cost climbed to an all-time high of USD 10.22 million, and IBM found that supply-chain compromises were the second most common attack vector, behind only credential-based intrusions.
That tension— better detection tools on one side, AI-armed and increasingly state-linked attackers on the other—defines the past twelve months.
NCC Group’s threat intelligence researchers described 2025 as the year “AI moved from experiment to production, and with it came a sharp rise in security-critical issues,” while identity-crime data from the Identity Theft Resource Center (ITRC) shows unauthorized device access overtaking scams as the leading way personal information gets compromised. This is up 78% year-over-year and now accounting for 27.2% of all reported identity compromises.
Between July 2025 and June 2026, breaches escalated in both scale and consequence: a possible nation-scale government data exposure, destructive nation-state attacks on hospitals and manufacturers, a wave of supply-chain compromises that quietly infected some of the biggest names in tech and continued targeting of critical infrastructure across Europe and the U.S. Below is a summary table followed by details on each incident.
Note: Several of the largest incidents this year (DOGE/SSA, Hasbro, the FBI system, and the open-source supply-chain campaigns) do not have officially confirmed record counts, which is itself a notable shift — organizations and agencies are increasingly slow, or unwilling, to disclose exact scope.
The Details
- DOGE’s Social Security Data Exposure (ongoing disclosures, 2025–2026): More than a year after operatives from the Musk-led Department of Government Efficiency swept through the Social Security Administration, litigation and whistleblower claims are still surfacing about what happened to the agency’s data. A whistleblower alleged DOGE uploaded a live copy of the SSA database containing Social Security numbers and personal information for most living Americans to an unsecured third-party cloud server. Two senior House Democrats investigating the matter said the exposure “could very well be the largest data breach in our nation’s history.”
- Instructure/Canvas (May 2026): The ShinyHunters extortion group breached the learning management system used by over 30 million students and staff, stealing personal data. When Instructure didn’t pay, the group broke back in and defaced Canvas login pages during student finals, disrupting exams nationwide. Instructure ultimately paid the ransom despite FBI efforts to dissuade it.
- Charter Communications & Carnival Cruise Line: ShinyHunters’ campaign extended well beyond education, hitting internet provider Charter for roughly 40 million records and cruise line Carnival for at least 6 million customer records, along with additional victims spanning higher education, fintech, and government agencies across Europe.
- Klue Supply-Chain Breach (June 2026): Market research provider Klue was breached using a credential the company issued back in 2022 for a limited pilot and never decommissioned. The extortion gang “Icarus” used it to access the cloud-service keys of nearly 200 downstream Klue customers— including Jamf, HackerOne, and LastPass—to steal and extort their data. Klue reportedly paid the attackers, only to learn a second hacking group also held a copy of the stolen data and made its own ransom demands.
- Stryker (March 2026): Iranian government-linked hackers remotely wiped tens of thousands of employee devices at the medical technology company in a single, coordinated strike. The U.S. government attributed the attack to an arm of Iranian intelligence—a marked escalation from Iran’s historical focus on espionage and hack-and-leak operations toward outright destructive attacks, and one that had a material impact on the company’s Q1 earnings.
- FBI Surveillance System (April 2026): The FBI declared a “major cyber incident” after a surveillance system was compromised, potentially exposing the phone numbers of active wiretap and pen-register targets. Chinese state-linked actors were blamed for the intrusion.
- Meta/Instagram AI Chatbot Exploit (early 2026): Attackers discovered they could hijack high-profile Instagram accounts simply by asking Meta’s AI support chatbot to send a password-reset code to an email address of their choosing. The technique circulated in hacker Telegram groups for months before discovery, ultimately affecting tens of thousands of accounts.
- Hasbro (March–April 2026): The 103-year-old toy company was knocked largely offline for weeks after discovering hackers in its systems in late March. Hasbro has disclosed little about what data, if any, was taken, or whether a ransom was paid, but was forced to delay an SEC filing as it worked through recovery.
- Foxconn, West Pharmaceutical Services, and Grafana (May 2026): A busy month for ransomware and extortion. The Nitrogen ransomware group claimed to have stolen 8 TB of Foxconn’s North American data, including project files tied to Apple, Nvidia, and Intel. West Pharmaceutical Services suffered exfiltration ahead of encryption, disrupting global operations. Grafana disclosed a breach via a compromised token that exposed its GitHub source code, though it said no customer data was affected and it refused to pay. (Source: NCC Group’s May 2026 Cyber Threat Intelligence Report.)
- Bybit Crypto Exchange (February 2025): Attackers stole over $1.4 billion from Bybit’s cold wallet by compromising the Safe Wallet multisig interface and tricking authorized signers into approving a malicious contract change— the largest cryptocurrency heist on record, and a reminder that “blind signing” of opaque transactions remains a critical weakness even with multisig protections in place. (Source: NCC Group’s May 2026 Cyber Threat Intelligence Report.)
- Open-Source Supply Chain Attacks (ongoing, 2026): A wave of concurrent campaigns compromised widely used open-source tools and packages— including Aqua Security’s Trivy scanner, Bitwarden’s CLI, Checkmarx, and a backdoored top npm package—to steal developer credentials and tokens. The stolen credentials were then used to reach downstream victims, including OpenAI and hosting provider Vercel.
- Critical Infrastructure Attacks Across Europe: A pattern of attacks attributed at least in part to Russia hit civilian energy and water systems, including a wiper attack on Poland’s energy grid, a Swedish thermal plant, a Norwegian dam that spilled large volumes of water after being hijacked, and, more recently, Poland’s water treatment plants. U.S. officials have separately warned that Iranian hackers are now targeting privately owned water utilities in the wake of the U.S.–Israel–Iran conflict.
- Millions of Passports and Driver’s Licenses Exposed (spring 2026): A cluster of unrelated but similar security lapses left government ID documents publicly accessible online, including a hotel check-in system exposing roughly a million passports and licenses, a Canadian money-transfer app, a prison payphone provider exposing over 300,000 callers’ documents, and a UK visa applicant portal—over two million exposed identity documents in total, mostly due to basic misconfigurations.
Why the Trendlines Matter
Two shifts stand out across this year’s data:
- Device access has overtaken scams as the top way personal data gets compromised. ITRC’s 2026 Trends in Identity Report found unauthorized device/account access rose from 15.3% to 2% of reported compromises year-over-year (a 78% jump), while scam-driven compromise fell from 43.1% to 36.1%. For adults aged 35–64, device access is now the single most common compromise method.
- Ransomware and nation-state activity are converging. NCC Group’s May 2026 threat intelligence noted Iranian state-linked actors disguising espionage operations as ransomware (and vice versa), making attribution—and appropriate response—increasingly difficult for defenders. Meanwhile, ransomware volume has plateaued at an elevated baseline, with 749 victim listings recorded in May 2026 alone and the Industrials sector remaining the most frequently targeted.
These incidents continue to highlight the evolving and persistent nature of cybersecurity threats across nearly every sector, from government and healthcare to education, retail, and critical infrastructure—emphasizing the need for robust security measures, faster detection, and timely, transparent responses to breaches.
What to Do If You’re a Data Breach Victim
For more information about recent data breaches, or the increase in identity compromises discussed in the latest trend analysis, visit the ITRC’s data breach tracking tool, notified.
For more information about how to prevent identity theft, recover after a breach, or protect your business, visit the Identity Theft Resource Center’s website.
Businesses who would like an analysis of their security vulnerabilities can contact Cyber Solutions Technologies today to set up an expert consultation.


