2026's Worst Hacks: DOGE to ShinyHunters
A look at the year's most significant cyber breaches.
Model Diplomat7 min readNorth America

2026's Worst Hacks: From DOGE Insiders to ShinyHunters
The DOGE data grab, Iran's Stryker wiper, China's Volt Typhoon and ShinyHunters' Canvas extortion have converged into one regulatory question — and Washington is losing the race.
On January 16, 2026, Justice Department lawyers filed a correction admitting the Social Security Administration could not verify what its own Department of Government Efficiency team had done with the personal data of roughly 300 million Americans. That single filing — not any foreign intrusion — is the most consequential cyber event of the year, because it turned the United States' most valuable citizen database into a policy hostage at precisely the moment Iran-linked wipers, People's Liberation Army pre-positioning inside a Massachusetts water utility, and ShinyHunters' extortion of 9,000 schools were all peaking. The 2026 breach lineup did not just get worse. It collapsed the wall between insider misuse, state sabotage, and criminal extortion — and the regulatory scaffolding built for the last decade of ransomware is now visibly a decade behind the threat.
The DOGE breach is a policy breach, not a hack
The DOGE incident is technically not an "intrusion." It is worse. According to a Supreme Court order granting the government's stay, the 6–3 majority in SSA v. AFSCME on June 6, 2025 lifted a preliminary injunction that had blocked DOGE staffers from bulk SSA data — over a 145-page opinion in which Judge Ellen Hollander called their access "tantamount to hitting a fly with a sledgehammer," per
NPR's reporting.
Days after that ruling, SSA whistleblower Charles Borges alleges, DOGE-affiliated officials copied the NUMIDENT master file — the identity backbone of every American with a Social Security number — into a private AWS environment with sub-standard controls, an action career SSA cybersecurity staff had flagged as "very high risk," according to NPR's review of the whistleblower complaint. By March 2026, NPR reported, a second whistleblower alleged a former DOGE engineer had retained NUMIDENT and Death Master File copies on a personal thumb drive with "God-level" access, prompting an
SSA inspector-general probe.
Borges' own written warning is the line the story turns on: loss of this data "would not be 'just another data breach,' but could represent a structural failure of our identity system." That is the framing every regulator now has to answer to.
Iran went destructive. China went patient.
While DOGE was consuming Washington's oxygen, two state-linked campaigns rewrote the risk model.
On March 11, 2026, orthopedics giant Stryker — a $134 billion company employing more than 50,000 people — was hit by a wiper that reached its internal Microsoft environment and took four days to recover from. Share price fell roughly 9%, an estimated $6–8 billion in market cap, according to the Manohar Parrikar Institute for Defence Studies and Analyses. The pro-Iran Handala Hack Team, which the U.S. Justice Department
publicly links to Iran's Ministry of Intelligence and Security, claimed to have wiped over 200,000 systems and exfiltrated 50 terabytes as retaliation for a February Israeli strike on an Iranian school. Two weeks later, the same group published purported personal emails belonging to FBI Director Kash Patel; the BBC reported the domain was registered the day DOJ seized Handala's previous infrastructure.
The message is the shift itself: Iranian operators are no longer content with espionage. They are targeting privately held, publicly traded, life-safety-adjacent U.S. firms with destructive payloads timed to kinetic events.
China's method is opposite and, per U.S. officials, more dangerous. In testimony before the House Science Committee on May 21, 2026, Idaho National Laboratory's Virginia Wright and the Institute for Security and Technology's Joshua Corman warned that PLA-linked Volt Typhoon has "pre-positioned" inside civilian water utilities with no military value — the point is chaos on demand. CSIS confirmed the same pattern in its
March 2026 assessment: Volt Typhoon sat inside Littleton, Massachusetts's electric and water utility for nearly a year, mapping operational technology. A
CRS backgrounder on Salt Typhoon frames the doctrine plainly — the Intelligence Community assesses Volt Typhoon's targeting "carries limited espionage potential, and is instead part of an effort to prepare to disrupt U.S. infrastructure."
ShinyHunters industrialised extortion — and taught schools to pay
If the state campaigns rewrote doctrine, ShinyHunters rewrote the criminal business model. On April 29, 2026 the group breached Instructure, the maker of the Canvas learning platform used by roughly half of North American higher education. NPR reported that the intrusion involved data from 275 million students, teachers and staff at nearly 9,000 institutions. Penn State, Baylor, University of Illinois and Georgetown postponed finals mid-attack.
Within ten days Instructure had, per BBC reporting, "reached an agreement" with the hackers, who claimed the data was deleted. Neither side confirmed a payment. Law enforcement across the Five Eyes advises against exactly this outcome — the National Crime Agency found that even the vaunted LockBit gang kept stolen data after taking ransoms — but Instructure's calculus was rational for its customers and terrible for the market. It signalled that a mid-sized SaaS vendor holding hundreds of millions of student records will pay to make problems disappear.
ShinyHunters is not slowing. In June the group breached the University of Nottingham, taking approximately 40GB including passport numbers, and then
Rockstar Games via a third-party cloud provider. The pattern — identity federation and cloud CRM as the soft underbelly — echoes the group's Snowflake-vector attacks on Ticketmaster and Santander in 2024, which
Mandiant traced to credential theft from client companies, not from the platform itself. It is a supply-chain crime spree that no single victim's security budget can fix.
The regulatory scaffolding is a decade late
Here is where policy meets the ledger. The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), signed in 2022, was meant to be the U.S. answer to exactly this year. It requires covered entities to report substantial cyber incidents to CISA within 72 hours and ransom payments within 24. According to GAO's assessment, DHS's plan was to publish the final rule by October 2025. It did not. On February 13, 2026, CISA
announced new town halls to "refine the scope and burden" of the still-unfinalised rule — a de facto reopening after 300 comments and heavy industry pushback.
Meanwhile the sectoral standards that do exist are visibly outdated. On March 24, 2026, FERC approved Reliability Standard CIP-003-11, belatedly adding remote-user authentication and malicious-communications detection for so-called low-impact bulk electric system cyber assets — the exact category Volt Typhoon exploited in Littleton. The
GAO's April 2026 water-sector report documents CISA and EPA warning utilities that Iran was actively targeting programmable logic controllers used in water treatment. Congressional testimony that same day pointed out the obvious: the Safe Drinking Water Act framework requires resilience assessments but not effectiveness standards, and the EPA lacks authority to enforce.
The AI overlay makes the timing worse. On June 23, 2026 the Five Eyes intelligence alliance issued a joint statement — reported by Al Jazeera — warning that "frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities." CISA on the same day shortened its known-exploited-vulnerability patch deadlines for federal agencies from three weeks to three days. That is a defensive posture built for an offensive tempo none of these breaches yet reflect — but that Anthropic's Mythos and OpenAI's GPT-5.5-Cyber, both cited by the alliance, will produce.
Who benefits, who loses
The winners of 2026's breach cycle are not obvious. Palantir, CrowdStrike and Dragos — the latter running Project Franklin to donate tooling to rural water utilities, per NPR — pick up mandates as CISA's staffing and rule-writing lag. Cyber-insurance carriers get pricing power: Allianz Life, itself the victim of a July 2025 CRM breach affecting most of its 1.4 million U.S. customers per
BBC reporting, will raise premiums across the sector it insures. The clear losers are mid-market SaaS platforms like Instructure that hold federated identity data for critical sectors and cannot afford either the security spend or the reputational hit of not paying.
The strategic loser is Washington's own leverage. When the U.S. government cannot verify what its own political staff did with 300 million Social Security records, its position lecturing Beijing about civilian infrastructure norms weakens. And when a sitting FBI Director's personal inbox turns up on an Iranian propaganda site, deterrence signalling is priced accordingly.
Diplomat View
The falsifiable call: Congress will not pass a coherent cyber-hardening statute before the 2026 midterms, but CIRCIA's final rule will ship by Q1 2027 with materially narrower "covered entity" scope than the April 2024 NPRM proposed — because the same industry lobbying that forced February's town halls now has a friendlier White House and a DOGE-adjacent SSA precedent that discourages aggressive federal data mandates. The Volt Typhoon dwell time in Littleton, combined with Corman's warning that Chinese leadership has set 2027 as the year for a Taiwan-conflict-ready posture, means the U.S. hardening window is roughly 18 months. If CIRCIA lands narrower than the NPRM and the EPA's water authority remains toothless, the next Stryker-scale incident hits a lifeline utility rather than a medical-devices vendor, and hits it during a Taiwan crisis. What would change this forecast: a bipartisan cyber-water bill emerging from the House Science Committee's May 21 hearings with SRMA-level EPA enforcement authority, or a Volt Typhoon incident that produces a civilian casualty and forces emergency legislation — either would compress the timeline the current regulatory posture assumes.
Catalysts to watch:
- Q4 2026: CISA's next CIRCIA rulemaking action after the February 2026 town halls; watch for narrowed "substantial cyber incident" thresholds.
- FY2027 appropriations: Whether the Drinking Water System Infrastructure Resilience program's requested $10 million for cybersecurity survives, per
Corman's testimony.
- SSA OIG report: Findings on the March 2026 whistleblower complaint over NUMIDENT and Death Master File retention will determine whether DOGE-era data handling triggers legislative response or fades into litigation.
The through-line of 2026's worst hacks is not that criminals got better, states got bolder, or insiders got sloppier — all three did, in the same year. It is that the U.S. regulatory scaffolding assumes those three threat classes are separate problems handled by separate agencies. They are not, and the calendar is not on Washington's side. Explore related coverage on tech policy and global politics.
Discover more

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.
US Politics
Congress Targets AI Chatbot Access for Terror
The House passed the Generative AI Terrorism Risk Assessment Act, focusing on AI's role in terrorism and potential surveillance implications.

US Politics
House Ethics Committee Pushes Sexual Miscond.
The House Ethics Committee has shifted responsibility for sexual harassment settlement records to the Office of Congressional Workplace Rights, complicating disclosure efforts.

Conflict & Security
West Africa Food Crisis: Three Shocks in 2026
Conflict, climate extremes, and the Strait of Hormuz closure drive a severe food crisis in West and Central Africa, with fertilizer prices surging 80% and millions displaced.