Updated August 2026: This article has been updated with major cyber incidents disclosed since its original publication in June, including attacks affecting software supply chains, government systems and communications platforms.
As 2026 approaches its halfway point, cyber attackers have caused major disruption, exposed sensitive data and targeted some of the systems organisations depend on most. This year has seen high-profile attacks affecting government data, critical infrastructure, healthcare technology, education platforms and software supply chains. From destructive cyber activity and cloud-based breaches to attacks on OT and open source tools, the trend is clear: cyber risk is here to stay and is constantly evolving.
In this blog, we highlight five of the biggest cyber attacks and breaches of 2026 so far, what made them so significant, and what businesses can learn from these high-profile incidents.
What are the biggest cyber attacks of 2026 so far?
The biggest cyber attacks of 2026 so far include incidents involving Canvas, Telus, Stryker, Nike, Charter Communications and Match Group. These attacks show that cyber criminals are increasingly targeting SaaS platforms, third-party suppliers, sensitive internal data, customer records and operational systems. For businesses, the key lesson is clear: cyber resilience now depends on visibility, identity security, supplier risk management, data protection, continuous monitoring and tested incident response.
ChainDrop: Software Supply Chain Attack Hits More Than 1,300 npm Package Versions
The software supply chain became the focus of another major cyber incident in August when a new variant of the Shai-Hulud malware, dubbed ChainDrop, spread across the npm ecosystem. More than 1,300 package versions were reportedly compromised, affecting at least 868 distinct packages, including widely used JavaScript libraries Keyv and Cacheable.
The attack began with the compromise of a developer's GitHub account before malicious updates were pushed into affected projects and new package versions containing credential-stealing malware were published. Researchers reported that the affected packages collectively received around two billion downloads per month, demonstrating how quickly the compromise of a trusted developer or software component can create downstream risk for thousands of organisations.
ChainDrop also targeted API keys, tokens and developer and cloud credentials, potentially providing attackers with further opportunities to move from compromised development environments into other systems.
What can businesses learn from the ChainDrop attack?
Software supply chain security cannot stop at checking applications for known vulnerabilities. Organisations also need to protect the identities, credentials and infrastructure used to develop and deploy software.
Developer accounts should be protected with strong authentication and least-privilege access, while API keys, tokens and other secrets should be carefully managed and monitored. Organisations should also maintain visibility of open-source dependencies and have processes for quickly identifying and responding when trusted packages are compromised.
The incident also demonstrates why development environments and CI/CD infrastructure should be considered part of the organisation's wider attack surface rather than treated solely as engineering tools.
RingCentral: 1.6 Million Accounts Exposed Following Cyberattack
Business communications provider RingCentral became another major cyberattack victim in July 2026, with data associated with approximately 1.6 million unique email addresses subsequently appearing in data published by the ShinyHunters extortion group.
The exposed information reportedly included names, email addresses, telephone numbers and physical addresses. RingCentral said the incident affected a limited portion of its customer base and contacted those affected directly.
While passwords were not listed among the exposed information reported by Have I Been Pwned, the combination of contact and identity information could still provide criminals with valuable material for phishing, impersonation and other social engineering attacks.
What can businesses learn from the RingCentral attack?
The RingCentral incident highlights the continued importance of protecting identity and resisting social engineering attacks.
Cybercriminals do not always need to exploit a technical vulnerability to gain access to valuable information. By manipulating users, abusing trusted accounts or stealing legitimate credentials, attackers can potentially bypass security controls designed to stop more conventional attacks.
Organisations should combine strong access controls and phishing-resistant Multi-Factor Authentication (MFA) with identity monitoring and security awareness programmes that prepare employees for modern social engineering techniques across email, telephone calls and other communication channels.
Businesses should also consider the secondary risk created by breached data. Information stolen from one organisation can be used to make attacks against customers, employees and suppliers more convincing.
Latvia's CSDD: Historical Data of 1.2 Million People Accessed
In August, Latvia's Road Traffic Safety Directorate, CSDD, disclosed a significant cyberattack in which threat actors gained unauthorised access to historical payment receipt data.
According to CSDD and CERT.LV, the attackers accessed data between 8 and 10 August relating to approximately 1.2 million individuals and 200,000 legal entities. The compromised information dated back as far as 2008 and included names, personal or company identification details, payments, payment dates, vehicle registration numbers and historical addresses.
Customer usernames and passwords were not affected, and CSDD said its physical and online services continued operating normally. However, CERT.LV warned that the stolen information could potentially be used in subsequent targeted fraud attempts.
What can businesses learn from the CSDD cyberattack?
The CSDD incident raises an important cybersecurity question that is sometimes overlooked: does your organisation still need all the data it holds?
Businesses can spend considerable resources securing current systems while retaining years of historical customer, employee or transaction data. If that information no longer serves a legitimate business, regulatory or legal requirement, retaining it can increase the potential impact of a future breach.
Effective data security therefore needs to include retention and minimisation as well as access controls and encryption. Organisations should understand what information they hold, where it resides, who can access it and how long it genuinely needs to be retained.
The attack also demonstrates how breached historical information can create risks long after it was originally collected. Even without passwords or banking credentials, personal information can be combined with other data to create highly convincing phishing, impersonation and fraud attempts.
Canvas breach: education disruption on a massive scale
The Canvas breach was one of the most significant education-sector cyber incidents reported so far in 2026. Instructure, the company behind the widely used Canvas learning management system, confirmed that student information had been accessed after a breach linked to the ShinyHunters extortion group.
Reports claimed that the stolen data affected millions of users across thousands of educational institutions across the globe. The compromised information reportedly included names, institutional email addresses, student ID numbers and Canvas inbox messages. The timing also made the incident particularly disruptive, as the breach came during a critical period for many schools and universities.
The incident highlights the risk facing education providers and technology platforms that support them. Learning management systems hold large volumes of personal information and are deeply embedded in day-to-day operations. If these platforms are disrupted or compromised, the impact can extend to students, staff, exams, coursework and institutional trust.
The business lesson is clear: SaaS platforms must be treated as critical infrastructure. Organisations need visibility into third-party applications, strong access controls, user monitoring, incident response plans and a clear understanding of what data is stored in each platform.
Telus: telecoms data and the risk of scale
In March, Canadian company Telus became the most high-profile telecoms cyber incident so far in 2026 after ShinyHunters claimed to have stolen a huge volume of data from the telecommunications and business services provider.
The scale of the incident made it especially concerning. Reports suggested the data samples may have included personally identifiable information, call data, recordings, background check details and source code, although the full type and quantity of data had not been confirmed publicly at the time.
Telecoms providers are attractive targets because they sit at the centre of communications, identity, customer records and business connectivity. Even when operations continue, the potential exposure of customer and internal data can create significant reputational, regulatory and fraud risks.
For businesses, the Telus incident underlines the need to protect high-value datasets and monitor access to sensitive systems. Data classification, encryption, privileged access controls, logging, threat detection and supplier risk management are all essential. The more data an organisation holds, the greater the need to understand where it is, who can access it and how it is protected.
Stryker: destructive attacks and operational disruption
The cyber attack on Stryker, one of the world’s largest medical technology companies in March, stood out because it involved operational disruption rather than a simple data theft claim. Reports linked the incident to an Iran-linked hacking group, with claims that remote devices had been wiped and large volumes of data had been taken.
Stryker confirmed disruption to its systems and said it was working to restore operations. The incident was especially significant because of the sector involved. Medical technology companies support hospitals, surgical centres, healthcare providers and supply chains. When their systems are disrupted, the potential consequences can extend beyond the business itself.
This type of attack shows why organisations must prepare for destructive cyber activity. Not every incident is about ransomware encryption or stolen customer data. Some attacks are designed to disrupt, damage, destroy or create geopolitical pressure.
Businesses should treat resilience as a board-level priority. That means tested backups, endpoint protection, identity controls, network segmentation, crisis communications, business continuity planning and rapid incident response. The ability to recover quickly is now as important as the ability to prevent an attack.
Nike: internal data and brand exposure
In January, Nike investigated a cybersecurity incident after the WorldLeaks group claimed to have published 1.4TB of company data. Reports suggested the exposed material included internal business data related to design and manufacturing processes, although Nike did not confirm the full details publicly.
This incident is important because it shows that not every major breach is focused on customer data. Internal documents, product designs, manufacturing information, supplier materials and operational files can be extremely valuable to attackers. For global brands, exposure of this kind can create commercial, competitive and reputational risk.
The Nike case also reflects a broader shift in cyber extortion. Some groups are moving away from traditional ransomware encryption and focusing instead on data theft, leakage and pressure campaigns. This can be faster, cheaper and harder for victims to contain once data has been exfiltrated.
Businesses should review how they protect intellectual property and sensitive internal information. This includes access controls, data loss prevention, monitoring of file repositories, supplier access reviews and clear policies around how confidential data is stored and shared.
Charter: customer records and identity compromise
In May 2026, Charter Communications, the parent company behind the consumer broadband and cable brand Spectrum, was named by the ShinyHunters group in a “pay or leak” extortion campaign. The group later published the stolen data, exposing 4.9 million unique email addresses along with names, phone numbers and physical addresses.
A subset of approximately 85,000 records, originating from an internal employee directory, also included job titles. Charter confirmed the incident, but stated that no sensitive personal information or customer proprietary network information, known as CPNI, had been exfiltrated.
The incident is significant because it shows how damaging even “non-sensitive” data exposure can be. Names, email addresses, phone numbers and physical addresses can still be used for phishing, impersonation, social engineering and follow-on fraud attempts. For a communications provider, that risk is particularly acute because attackers can use exposed contact data to craft convincing scams against customers and employees.
The Charter case also reflects the growing use of data theft as leverage. Instead of encrypting systems, attackers increasingly steal information and threaten to publish it unless payment is made. This puts organisations under public pressure quickly, especially when customer records are involved.
Businesses should treat customer contact data, employee directory data and enterprise application access as high-value assets. Strong identity controls, access monitoring, data loss prevention, phishing-resistant authentication and rapid incident response are essential for reducing the impact of extortion-led breaches.
Match Group: 10 million records, one analytics vendor
In January, ShinyHunters claimed to have breached Match Group, parent company of Tinder, Hinge and OkCupid. The reported entry point was not Match Group itself, but AppsFlyer, a third-party marketing analytics partner.
The compromised data included user records, internal documentation, transaction data and IP addresses. Match Group called it a security incident under investigation, while AppsFlyer denied involvement in the alleged incident.
The case is a clear example of third-party vendor risk. Even when an organisation’s own systems are not directly breached, data handled by analytics providers, marketing platforms, SaaS tools or other partners can still become exposed. This is especially sensitive for dating platforms, where even limited tracking or usage data can create privacy concerns for users.
Businesses should take this as a warning to reassess supplier access, data sharing and third-party monitoring. Vendor risk management cannot be a once-a-year questionnaire. It needs to include continuous assessment, contractual security requirements, breach notification obligations, access reviews and a clear understanding of what data each supplier processes.
What Do the Biggest Cyber Attacks of 2026 Have in Common?
The attacks seen throughout 2026 have affected very different organisations, from retailers and telecommunications companies to software developers, government bodies and healthcare technology providers. However, several recurring themes are becoming increasingly difficult to ignore.
Identity Remains a Critical Attack Surface
Attackers continue to target users, credentials and trusted identities because gaining legitimate access can allow them to bypass security controls that are effective against conventional malware.
Protecting identity therefore requires more than passwords and basic MFA. Organisations need strong access controls, phishing-resistant authentication, effective privilege management and continuous visibility of suspicious identity activity.
Trusted Technology Can Become an Attack Route
The ChainDrop incident shows how the compromise of trusted software can rapidly create risk for organisations far removed from the original victim.
The same principle applies to SaaS platforms, suppliers and technology partners. Every trusted connection can potentially expand the attack surface, making third-party and software supply chain risk an increasingly important part of cybersecurity strategy.
Data Theft Does Not Require Ransomware
Several major incidents this year have reinforced the growth of data theft and extortion without the widespread encryption traditionally associated with ransomware.
Attackers do not necessarily need to shut down an organisation to create leverage. Sensitive customer information, intellectual property, credentials and commercial data can all be stolen and used for extortion, fraud or subsequent attacks.
Historical Data Can Become Tomorrow's Breach
The CSDD attack demonstrates how information retained for many years can significantly increase the scale of a breach.
Data minimisation should therefore form part of an organisation's cyber risk strategy. Information that is no longer required can become a liability if attackers eventually gain access to the system holding it.
Cyber Resilience Matters as Much as Prevention
No organisation can guarantee that every cyberattack will be prevented. The ability to detect malicious activity, contain it quickly and recover safely is therefore becoming just as important as preventative security.
Organisations need tested Incident Response plans, effective monitoring, reliable recovery processes and clear responsibilities before an attack occurs. Trying to establish these arrangements while systems are already compromised introduces delays at exactly the point when time matters most.
How businesses can reduce their cyber risk in 2026
The biggest cyber attacks of 2026 so far show that organisations need a more proactive approach to cybersecurity. Traditional controls are no longer enough when attackers are moving through cloud platforms, identities, suppliers and enterprise applications.
Businesses should focus on continuous threat exposure management to identify and prioritise exploitable weaknesses before attackers find them. They should also invest in managed detection and response to monitor suspicious activity across endpoints, cloud environments, networks, identities and SaaS applications.
Incident response planning is equally important. Organisations need to know how they will respond if data is stolen, systems are wiped, suppliers are compromised or critical platforms are disrupted. Plans should be tested regularly and updated as the business changes.
Supplier security must also become a core part of cyber resilience. Organisations should understand what data third parties hold, how they protect it and how quickly they will notify customers if something goes wrong.
Want to protect your organisation from cyber threats. Get in contact with the experts at Integrity360.
FAQ: The biggest cyber attacks of 2026 so far
What are the biggest cyber attacks of 2026 so far?
Some of the biggest cyber attacks and breaches of 2026 so far include incidents involving Canvas, Telus, Stryker, Nike, Charter Communications and Match Group. These cases affected education, telecoms, medical technology, retail, communications and digital platform providers, showing how cyber risk now cuts across almost every sector.
What can businesses learn from the biggest cyber attacks of 2026?
The biggest lesson is that cyber risk is no longer limited to traditional IT systems. Attackers are targeting SaaS platforms, cloud services, third-party suppliers, employee directories, customer data, internal files and operational systems. Businesses need stronger visibility, better identity controls, continuous monitoring, supplier risk management and tested incident response plans.
Why are SaaS platforms becoming a major cyber security risk?
SaaS platforms often hold large amounts of sensitive data and are deeply embedded in everyday business operations. If a SaaS provider is breached, disrupted or abused by attackers, the impact can spread quickly across customers, employees and partners. Businesses should treat critical SaaS platforms as part of their core infrastructure, not just as external software tools.
Why is third-party cyber risk such a major issue in 2026?
Third-party risk is increasing because organisations rely on more suppliers, analytics platforms, cloud services, software providers and managed applications than ever before. A breach at one supplier can expose data or create operational disruption for many customers. Vendor risk management must include continuous assessment, contractual security requirements, access reviews and clear breach notification processes.
How are cyber extortion tactics changing in 2026?
Cyber extortion is increasingly focused on data theft, leakage and public pressure rather than only ransomware encryption. Attackers may steal sensitive information and threaten to publish it unless payment is made. This can create immediate reputational, regulatory and fraud risks, even if core systems remain operational.
Why does “non-sensitive” data still create cyber risk?
Names, email addresses, phone numbers, job titles and physical addresses can still be used for phishing, impersonation, social engineering and fraud. Even when highly sensitive personal information is not exposed, attackers can use basic contact details to target customers, employees and suppliers with convincing scams.
What does the Stryker incident show about operational disruption?
The Stryker incident highlights the risk of destructive cyber activity. Not every cyber attack is designed only to steal data or encrypt systems. Some attacks aim to disrupt operations, damage devices, interrupt supply chains or create pressure on critical sectors. Businesses need tested backups, segmentation, incident response planning and business continuity processes.
Why are telecoms providers attractive targets for cyber criminals?
Telecoms providers hold valuable customer data, communications records, identity information and business connectivity services. This makes them attractive targets for cyber criminals and extortion groups. A breach in this sector can create privacy, fraud, regulatory and reputational risks for both the provider and its customers.
How should businesses protect sensitive internal data?
Businesses should identify and classify sensitive internal data, including product designs, financial records, manufacturing information, supplier documents and intellectual property. They should apply strong access controls, data loss prevention, file monitoring, encryption and clear policies for storing and sharing confidential information.
What is the role of identity security in preventing cyber attacks?
Identity security is critical because many attacks involve stolen credentials, excessive privileges or poor access controls. Businesses should use multi-factor authentication, privileged access management, conditional access policies, regular access reviews and monitoring for suspicious login behaviour.
Is MDR enough to reduce cyber risk in 2026?
Managed detection and response is essential, but it should not operate in isolation. MDR helps detect and respond to suspicious activity, but businesses also need exposure management, vulnerability prioritisation, identity security, supplier risk management, incident response planning and data protection controls.
How can businesses reduce cyber risk in 2026?
Businesses can reduce cyber risk by improving asset visibility, strengthening identity controls, monitoring cloud and SaaS environments, managing supplier risk, protecting sensitive data, testing incident response plans and adopting continuous threat exposure management. The aim should be to reduce exploitable weaknesses before attackers find them.
What is continuous threat exposure management?
Continuous threat exposure management, or CTEM, is a proactive approach to identifying, validating and prioritising cyber exposures across an organisation. It helps businesses understand which weaknesses are most likely to be exploited and where remediation will reduce the greatest amount of risk.
Why should incident response plans be tested regularly?
Incident response plans need to be tested because a plan that only exists on paper may fail during a real attack. Regular testing helps teams understand roles, escalation routes, communications processes, legal obligations, recovery steps and decision-making under pressure.
What should boards take from the biggest cyber attacks of 2026?
Boards should treat cyber resilience as a business priority, not just a technical issue. The biggest attacks of 2026 show that cyber incidents can disrupt operations, expose data, damage trust, trigger regulatory scrutiny and affect customers, suppliers and partners. Board-level oversight should include cyber risk, third-party exposure, incident readiness and recovery capability.





