A new tally of 2026's major cybersecurity incidents, compiled by TechCrunch, shows a year marked by breaches touching government systems, healthcare providers and consumer identity records. The list includes an alleged exposure of Social Security Administration data linked to the Department of Government Efficiency, and a breach at data broker Klue that reportedly affected roughly 200 companies, including Jamf, HackerOne and LastPass.
Other notable incidents include a wave of Instagram and Meta AI chatbot account hijackings, an FBI surveillance-system breach in April tied to Chinese-linked hackers, and a ransomware attack on the ATF in August. Identity verification firm IDScan disclosed a breach exposing roughly 150 million driver's license records, while healthcare-adjacent companies DentaQuest, CareCloud and Aesto Health each reported separate incidents.
The education sector was not spared either: Instructure, the company behind the Canvas learning platform, disclosed a breach affecting more than 30 million records. Medical device security also drew renewed attention after Iranian-linked hackers targeted Stryker in March and a separate breach hit Boston Scientific in August, underscoring how deeply connected hardware has expanded the attack surface for critical health infrastructure.
Source: TechCrunch

