This year's hacking timeline is insane
Key point
A roundup of the major cyberattack wave that unfolded over 100 days in early 2026.
Details
Over about 100 days in early 2026, a chain of large-scale cyberattacks involving nation-states and criminal organizations occurred, and the security industry frames this sequence of events as a turning point.
The attacks are organized into 4 clusters: Iran, SLH (Scattered LAPSUS$ Hunters), North Korea, and Russia, with a common pattern of exploiting supply chains and trust relationships.
Notable examples mentioned include:
- Stryker: 200,000 systems wiped worldwide
- Lockheed Martin: claims of 375TB leaked and 28 engineers' personal information exposed
- FBI Director's email leaked and breach of FBI wiretap network
- Axios npm infection, breaches of Oracle, Cisco, Rockstar, Mercor
- AI-generated phishing up 1,265%, voice phishing up 442%, and other AI-driven attack automation
In particular, the attack patterns evolved beyond simple breaches to include OAuth token theft, phone-based MFA manipulation, social engineering using fake companies and Slack/Teams environments, and open-source package infection.
While public discourse has been quiet, this period is described as one where nation-state attacks, SaaS takeovers, supply chain breaches, and healthcare, defense, and AI infrastructure were all shaken simultaneously.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.