Significant cyberattacks frequent in 2026, affecting governments and AI platforms
TechCrunch
1h ago
Ai Focus
TechCrunch Review of Major Cyber Attacks in 2026, Involving Government Data, Critical Infrastructure, Meta AI Vulnerabilities, and Open Source Supply Chain Security.
Helpful
No.Help

Since 2026, cyberattacks have expanded from being a corporate security issue to targeting government data, public facilities, and AI platforms. According to a TechCrunch overview, this year's incidents have not only resulted in large-scale data breaches but also put water supply, energy, and law enforcement systems at even greater risk.

US government data risks are still evolving

The disputes over data management surrounding U.S. federal agencies have not yet come to an end. Reports mention that during the progress of related lawsuits involving the U.S. Social Security Administration, it is still not possible for the outside world to fully confirm the flow of sensitive data.

The most concerning claim comes from a federal whistleblower. According to this whistleblower, a copy of a real-time database containing the social security numbers and personal information of a large number of American residents was uploaded to a third-party server that lacked proper security measures. This claim is still under the purview of legal proceedings and investigations, but it has already sparked ongoing doubts about the federal government's ability to protect data.

Energy and water supply facilities have become targets of attacks.

This year, energy and water supply facilities in multiple European countries have successively suffered cyberattacks, with targets including power plants, dams, and water treatment systems. Reports mention that the Polish power grid, a thermal power facility in Sweden, and a dam in Norway have all been attacked, with some of these incidents attributed to Russia or related to Russia.

Since the beginning of this year, water treatment plants in Poland have also become targets. At the same time, following the military actions launched by the United States and Israel against Iran, critical infrastructure in the United States has faced more cyberattacks from Iran.

The US Cybersecurity and Infrastructure Security Agency (CISA) stated that Iranian hackers targeted hundreds of water supply service organizations during the summer, including private utility companies. Such organizations typically have limited budgets and weaker cyber defense capabilities, making them more vulnerable to attacks.

Enterprises and the AI platform expose vulnerabilities simultaneously

Data breaches on the corporate side are also severe. After the market research company Klue was compromised, nearly 200 clients were affected, including several cybersecurity firms. Reports indicate that the attackers utilized credentials that were issued in earlier years but not promptly deactivated to gain access to the system. They further obtained the clients' cloud service keys and then stole data to carry out ransom demands.

Klue informed customers that an arrangement has been reached with the hackers not to disclose the data, but another hacker group still holds some of the customer information. This means that even if the affected parties reach an agreement with a group of attackers, the risk of data leakage has not truly disappeared.

AI The product has also exposed new security vulnerabilities. Meta One of its subsidiaries, Instagram, experienced a large-scale account hijacking incident at the beginning of the year. The reason was that someone exploited Meta AI chatbots to reset others' passwords. Attackers impersonated account holders and directed the bots to send reset verification codes to designated emails, thereby gaining control of the accounts. It is reported that tens of thousands of accounts were affected.

Open-source supply chains and law enforcement systems are under impact

The Federal Bureau of Investigation (FBI) and the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) of the United States have successively identified major cyber incidents this year and reported them to Congress. The former incident involved an intrusion into a monitoring system, which may have exposed sensitive information such as phone numbers of those under surveillance; the latter stated that an information system related to the subjects of investigation was attacked by a ransomware organization.

Another risk comes from the software supply chain. Multiple ongoing attacks targeting open-source developers have spread this year, affecting projects such as Trivy, Bitwarden, and Checkmarx. Attackers steal passwords, credentials, and access tokens through software versions that have been implanted with backdoors, and then further penetrate large technology companies that rely on these tools, as well as their customers.

It was reported that OpenAI and Vercel also appeared on subsequent lists of affected individuals. By August, two hackers suspected of being involved in these large-scale theft incidents had been arrested in Australia.

Additional information:It is also mentioned in the text that a data breach by the authentication service provider IDScan may have involved approximately 150 million driver's licenses and identification photos from the United States and Canada, and that the relevant data has been used in dark web search tools.

Tip
$0
Like
0
Save
0
Views 17
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: Loomis says the "Clarity Act" has entered a critical voting phase
The U.S. Senate will vote on the advancement process of the "Clarity Act." Loomis stated that if it does not pass, the act may have difficulty moving forward again within 2026.
Coinpaper
·2026-09-16 01:58:22
22
AI Intelligent Entity Launches a "Report Hotline" to Target Similar Abnormal Behaviors
Two new tools have been launched, allowing AI agents to report similar abnormal behaviors, reflecting the growing concern in the industry regarding the security risks of multiple agents.
TechCrunch
·2026-09-16 01:58:19
14
Ethereum: Ethereum MEV Bot Launches a $7.8 Million rsETH Attack
An attack attempt on Ethereum worth approximately $7.8 million rsETH was preempted by a MEV bot, exposing authorization verification issues with the executor related to the Safe module.
Cryptonews
·2026-09-16 01:09:12
14
The Trump administration claims that the risks associated with AI can be managed by companies on their own.
The Trump administration claims that the risks associated with AI can mainly be managed by companies, while Democratic lawmakers are calling for more regulatory constraints.
CNBC
·2026-09-16 01:09:09
13
View More