If anything, 2026 has made clear that cybersecurity is no longer a background concern.
After DOGE entered the Social Security Administration, it’s not yet known what happened with some of the nation’s most sensitive data, as lawsuits are still going on in federal courts.
In court filings, the Social Security Administration isn’t sure what was on the server but said that DOGE signed an agreement with an outside political advocacy group under the guise of finding evidence of voter fraud, which President Trump continues to claim without any evidence.
Two of the top House Democrats investigating some of DOGE’s activities at the Social Security Administration said the exposure “could very well be the largest data breach in our nation’s history.”
The Cybersecurity and Infrastructure Security Agency said Iranian hackers targeted over a hundred water providers over the summer, including privately owned water utilities, which remain a soft target as they often lack basic funding and cybersecurity protections.
Market research provider Klue was at the center of a large data breach that affected close to 200 companies, several of which were cybersecurity giants such as Jamf, HackerOne, and LastPass.
Klue said that an extortion gang, dubbed Icarus, broke into its systems using a credential that it issued in 2022 for a limited pilot.
The U.S. Federal Bureau of Investigation was forced to declare a “major cyber incident” in April, prompting a legally needed disclosure to Congress, after it found that one of its surveillance systems was compromised.
Months later in August, the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed its own “major incident” that prompted a separate disclosure to Congress.