Six months into 2026 and the breach scoreboard is brutal: 22 million Aflac records, 30 million students locked out during finals, the FBI's own surveillance system breached, four banks knocked offline in an afternoon. But almost none of it was clever. No genius zero-days. Just a phone call, a stolen token, and an open door.
This is the 2026 Breach Hall of Shame — we name names, correct the hype, and show you the five failures connecting all of it.
What you'll hear:
• The vishing wave — Aflac, Carnival, Canvas, Charter — how Scattered Spider & ShinyHunters just called the help desk
• Two corrections: OnlyFans was NOT breached (recycled old data), and Charter was ~4.9M, not the 40M claimed
• The nation-state lane — Salt Typhoon in the FBI's network, Russia-linked sabotage in Europe, Volt Typhoon pre-positioned in US utilities
• The supply-chain wave — poisoned dev tools stealing API keys, OAuth grants, and CI/CD secrets
• The common thread: social engineering, missing MFA, non-human identities, exposed services, flat networks
• A 4-move Monday playbook to defend the new perimeter
Sources: TechCrunch "worst hacks of 2026 so far" (June 7) · CISA/NSA/FBI assessments · public breach disclosures. Nation-state attributions are linked/suspected, not court-proven.
— Andrés Sarmiento
#cybersecurity #databreach #infosec #SecurityPlus #identitysecurity #TechUpdates