breaches – Gaming Master https://gaming.vmondeika.com Get daily gaming updates with us Sun, 07 Jun 2026 19:54:31 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 Hacked, leaked, and held for ransom: the worst breaches of 2026 so far https://gaming.vmondeika.com/hacked-leaked-and-held-for-ransom-the-worst-breaches-of-2026-so-far/ https://gaming.vmondeika.com/hacked-leaked-and-held-for-ransom-the-worst-breaches-of-2026-so-far/#respond Sun, 07 Jun 2026 19:54:31 +0000 https://gaming.vmondeika.com/hacked-leaked-and-held-for-ransom-the-worst-breaches-of-2026-so-far/

If anything, 2026 has made clear that cybersecurity is no longer a background concern — it’s front and center, woven into almost every major story of the year. Yes, wars are still raging, the climate keeps worsening, and we’re seemingly one dodgy sneeze away from the next global pandemic.

But running beneath all of it is a digital current that touches everything: wars being fought on digital fronts as well as physical ones, governments weaponizing citizens’ own data against them, botnets quietly undermining democratic institutions, nation-state hackers targeting civilian infrastructure from power grids to water systems, and ransomware gangs holding companies and institutions hostage for massive payouts. The attacks are getting bolder, more destructive, and harder to contain.

As we’re halfway through this already horrendous year of digital attacks and hybrid warfare, we look at some of the worst hacks and breaches so far, and how they might affect us going forward.

Questions remain over DOGE’s massive swipe of Social Security data

A year on, after operatives with the Elon Musk-led band of government destroyers known as the Department of Government Efficiency (or DOGE) swept through and dismantled federal agencies from the inside out, we’re still learning about the data lapses that happened under their watch.

After DOGE entered the Social Security Administration, it remains unclear as to what happened with some of the nation’s most sensitive data, as lawsuits battle on in federal court. The most alarming whistleblower’s claim is that DOGE uploaded a live copy of the Social Security database to an unsecured third-party server, leading to a scramble to understand what was stored in it. This database allegedly contained the Social Security numbers and associated personal information of most living Americans.

In court filings, the Social Security Administration doesn’t know for sure what was on the server, but said that the DOGE signed an agreement with an outside political advocacy group under the guise of finding evidence of voter fraud, something that President Trump continues to claim without any evidence. The fears are that the database could be misused to target Americans for spurious reasons. 

Two of the top House Democrats investigating some of DOGE’s activities at the Social Security Administration said that the exposure of the government’s Social Security database “could very well be the largest data breach in our nation’s history.”

Demonstrators gather outside of the Office of Personnel Management in Washington, D.C. on February 7, 2025 to protest federal layoffs and demand the termination of Elon Musk from the Department of Government Efficiency (DOGE). (Photo by Bryan Dozier / Middle East Images / Middle East Images via AFP)
Image Credits:Bryan Dozier/Middle East Images via AFP / Getty Images

Hackers are increasingly targeting water systems and energy grids

A rash of cyberattacks across Europe targeting civilian energy and water supplies, like power plants and water dams, has set a troubling trend of late. Several hacks attributed to (or at least in part blamed on) Russia have risked real-world harm to communities and populations. 

Poland’s energy grid was targeted with computer-destroying malware at the tail end of last year, as well as a Swedish thermal plant and a Norwegian dam that spilled swimming pools’ worth of water. Hackers targeted Poland again earlier this year, this time its water treatment plants, showing that Russia’s hybrid war antagonism continues to extend beyond the digital realm.

Now, thanks to the recent war between the U.S. and Israel against Iran, there are warnings that Iranian hackers are targeting critical infrastructure in the United States. This includes privately owned water utilities, which remain a soft target for hackers, often lacking basic cybersecurity protections.

Iranian government hackers struck Stryker with a destructive device hack

Speaking of Iran, a cyberattack on a U.S. medical tech company, Stryker, in March saw Iranian hackers break in and remotely wipe tens of thousands of employee devices in one fell swoop, causing widespread disruption to the company’s operations for several days. 

The breach was a marked shift in Iranian hacking tactics at a time of ongoing war in the Middle East, with Iran moving from its typical focus of espionage and hack-and-leak operations in aid of the country’s political gains, toward actively causing destructive hacks in apparent retaliation for the war. The U.S. government attributed the hacking group behind the breach to an arm of Iranian intelligence. The breach ended up having a material impact on Stryker’s first-quarter earnings after regaining control of its systems.

Instructure among ShinyHunters’ disruptive hacking campaigns

The ShinyHunters continued their hacking campaigns, targeting dozens of companies with simple but highly effective voice phishing techniques. The English-speaking hackers are adept at tricking companies into turning over access to their internal systems by pretending to be IT support, or conversely, an employee who forgot their password.

Few know better than the toll a hack from the ShinyHunters can have than education tech giant Instructure. The hackers breached the company’s flagship learning management system Canvas to steal private data and personal information belonging to over 30 million students and staff. When the company didn’t pay the hackers’ ransom, the hackers broke in — again — and defaced the school’s login screens for Canvas, used by students to access their exam and coursework material. This second hack happened during school finals, disrupting exams for students across the United States. Instructure eventually paid the ransom, despite efforts by the FBI to dissuade the company from paying.

Instructure wasn’t the only company targeted by the ShinyHunters hackers by far. The gang has been behind some of the largest breaches by the number of records stolen, including some 40 million records from internet provider Charter and at least 6 million customer records from cruiseliner Carnival, among other victims in higher education, finance, and government.

A redacted screenshot of the message ShinyHunters left on the hacked login pages of Instructure's platform Canvas.
Image Credits:TechCrunch

The supply chain is under attack, targeting open source projects and big tech companies

A series of ongoing, concurrent, and occasionally overlapping attacks on open source developers have resulted in massive hacks targeting big tech companies and their customers. 

Some of the biggest names in security, including Aqua Security’s Trivy tool, Bitwarden, and Checkmarx, alongside other major open source projects, were compromised this year, allowing the hackers to steal passwords, credentials, and other sensitive tokens from the computers of anyone who installed a backdoored copy of the software, or their pre-installed software auto-updated to download the malware. 

These attacks used the stolen credentials to spread further, and opened the door to downstream compromises of big companies that rely on the targeted software, including AI giant OpenAI and web hosting company Vercel. With a new hack almost every week, the open source world remains a vulnerable target in the broader tech ecosystem. 

FBI’s surveillance system was breached, sparking a “major cyber incident

The U.S. Federal Bureau of Investigation was forced to declare a “major cyber incident” in April, prompting a legally required disclosure with Congress, after identifying that one of its surveillance systems was compromised. According to reports, the breach potentially exposed phone numbers of targets under surveillance by federal agents. 

Chinese spies were accused of the breach of the unclassified network, which held sensitive information about the surveillance targets of wiretaps and other communication intercepts, such as pen register returns. By notifying lawmakers, the breach is likely to have met a bar of causing “demonstrable harm” to U.S. national security.

Hasbro’s hack has led to weeks of downtime

Toymaker giant Hasbro is the latest example of what happens when a large corporation is hit by a security incident and isn’t prepared for it. Weeks after discovering hackers in its systems in late March, the 103-year-old company remained largely offline, its website unavailable, and unable to serve its customers.

The company, which owns big name brands such as Transformers, Peppa Pig, and Dungeons & Dragons, has said little about the incident itself, what data was taken (if any), and whether it paid the hackers. But the disruption alone is likely to affect the company’s financials, which it was forced to delay, as the company scrambled to handle the incident. 

Hasbro said as of mid-May that the hackers are no longer in its systems and that its recovery was underway. But the financial costs of the breach and the knock-on effect to its business are likely to be realized in the coming months, and are expected to be substantial.

Millions of passports and driver licenses have been exposed galore

Over the past few months alone, there has been an uptick in major data exposures involving people’s sensitive government-issued identity documents, including passport and driver license scans left exposed to the web. From a hotel check-in system and a money transfer app to a prison payphone provider and a U.K. visa service, these services exposed over two million people’s personal documents that can be easily misused. Many were caused by simple security lapses that were easily avoidable with basic cybersecurity practices.

These massive data spills come at a time when closed-community apps and websites are increasingly leaning on “know your customer” checks to force users to verify their identity before being allowed in, and governments are pushing age-verification laws demanding similar identity checks from adults to access a vast swath of the internet. 

The logic goes that the greater the spills, the less effective these identity checking systems are, as they can be easily misused with a stolen or leaked passport or driver license. The further rollout of these ID-collecting systems will inevitably lead to more data breaches and security lapses.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

]]>
https://gaming.vmondeika.com/hacked-leaked-and-held-for-ransom-the-worst-breaches-of-2026-so-far/feed/ 0
Former cyber executive turned whistleblower accuses IBM of covering up several data breaches https://gaming.vmondeika.com/former-cyber-executive-turned-whistleblower-accuses-ibm-of-covering-up-several-data-breaches/ https://gaming.vmondeika.com/former-cyber-executive-turned-whistleblower-accuses-ibm-of-covering-up-several-data-breaches/#respond Sat, 06 Jun 2026 00:55:43 +0000 https://gaming.vmondeika.com/former-cyber-executive-turned-whistleblower-accuses-ibm-of-covering-up-several-data-breaches/

A former IBM cybersecurity executive accused the company of getting hacked three times in the previous decade by foreign governments and then covering up the breaches. 

In a lawsuit unsealed this week but filed in 2020, William Barlow, who was IBM’s vice president of threat intelligence until August 2019, said IBM concluded Chinese hackers breached its core network between 2013 and 2016 but that the company then covered up the breaches and never disclosed them. Barlow also said at least two IBM subsidiaries were also breached, and that IBM covered up those breaches as well.

Barlow alleged in his complaint that IBM’s core network was “routinely hacked by foreign state actors and others,” adding that data was frequently stolen and government agencies were “never notified.” 

While the alleged breaches date back more than a decade, the news shows that cyberattacks, even those affecting large public tech companies such as IBM, sometimes never get disclosed, either to the public or to relevant government authorities. IBM is a major cybersecurity vendor to the U.S. federal government, which makes the alleged concealment especially significant. In the last few years, several data breach notification laws have been passed to counter this problem.   

Bloomberg first reported on the lawsuit.

IBM spokesperson Miki Carver declined to answer specific questions about the lawsuit and the underlying accusations. Instead, Carver told TechCrunch, “This complaint was filed six years ago, and the U.S. Department of Justice declined to intervene. IBM is confident that our actions followed the letter of the law.”

In particular, Barlow said IBM was among several victims of a hacking campaign carried out by APT 10, a Chinese government-linked group that then-FBI Director Christopher Wray said had targeted a “Who’s Who” of the global economy when its members were indicted in 2018. The hackers broke into both the company’s network and the data it maintained there in partnership with AT&T. 

Barlow alleged that in March 2017, intelligence officials from Australia, Canada, New Zealand, United States, and the United Kingdom — the so-called Five Eyes alliance — warned IBM of the breach, which prompted an internal investigation.

According to the complaint, the investigation concluded that APT 10 potentially breached IBM’s network more than 56,000 times between 2013 and 2016. Crucially, the company said it could not investigate further because it had not kept logs of who accessed its network and when — a basic security practice.

IBM then allegedly failed to alert any authorities or the U.S. government, one of its main customers. 

“As IBM and AT&T’s Core Networks’ infrastructure is archaic, hackers have been able to gain access to the system on numerous occasions and can roam almost anywhere undetected,” read the complaint, which explained that IBM’s internal investigation concluded four servers were compromised in the APT 10 hacking campaign.

“The attackers have compromised and/or accessed nearly 400 compromised accounts and almost 200 total systems and servers across every IBM business unit, eighteen countries, and multiple IBM products,” said an internal IBM report about the investigation into the breach, according to the complaint.

Jason Brown, a lawyer representing Barlow, told TechCrunch that his firm is “looking forward to aggressively litigating the matter.” 

“You can’t sell cybersecurity to the federal government while allegedly having these security problems within your own company,” said Brown. 

According to Barlow, other breaches he was aware of affected Trusteer, a cybersecurity startup acquired by IBM in 2013, which he says was breached in 2018; and Truven, a healthcare data startup IBM acquired in 2016, which he says was breached multiple times after the acquisition.

In both cases, Barlow accused IBM of failing to properly investigate and disclose these breaches. 

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

]]>
https://gaming.vmondeika.com/former-cyber-executive-turned-whistleblower-accuses-ibm-of-covering-up-several-data-breaches/feed/ 0