RackTop Systems
Sector Spotlight

Government data breaches in 2026: a running list, and the patterns underneath it

A running list of notable 2026 government data breaches, from county networks to the FBI and the Pentagon, updated monthly, with the patterns that repeat across them.

RackTop Systems•October 1, 2026•6 min read

Key takeaways

  • Comparitech counted 187 ransomware attacks on government organizations in the first half of 2026, 89 of them confirmed by the victims, up from 165 in the second half of 2025.
  • Several of 2026’s largest government incidents ran through systems built to share documents, according to public reporting: a Defense Manpower Data Center file-sharing system, a third-party discovery-transfer tool at the Los Angeles City Attorney’s Office, and a SharePoint system connected to DHS’s Homeland Security Information Network.
  • Valid or borrowed credentials were a recurring way in, including a staff account and a contractor account at France’s tax administration, a police department user’s credentials at Florida’s DAVID driver database, and a maintenance staff account at Japan’s Digital Agency.
  • Scope was the recurring gap. The City of Suffolk, Virginia notified everyone potentially affected because investigators could not determine what personal information was accessed, and the Pentagon’s notification letters give no count of people affected.

Government bodies disclosed breaches at every level in 2026, from county networks to an FBI system holding surveillance data. Comparitech counted 187 ransomware attacks on government organizations in the first half of the year, 89 of them confirmed by the victims, up from 165 in the second half of 2025. Ransomware is only part of the picture, though. Several of the year’s most consequential government incidents involved no encryption at all.

This page tracks notable government data breaches made public in 2026, in the United States and among allied governments. An incident is listed when the affected government body confirmed it or at least two reputable outlets reported it, and any figure that comes only from an attacker is labeled as a claim. The list is updated monthly and was last updated on October 1, 2026.

The 2026 list, newest first

Dates reflect when each incident became public, which is often months after the intrusion began.

DisclosedGovernment bodyWhat happenedData at risk
Sep 2026U.S. Department of Defense, Defense Manpower Data CenterA vulnerability in a file-sharing system, discovered July 16, had allowed unauthorized users to access files since October 2025. Notification letters went out beginning in September.Unencrypted personal data including Social Security numbers; approximately four million personnel may be affected, per Military Times sources
Sep 2026FBI (FBIJobs.gov)ShinyHunters claims it entered through the recruiting portal and reached HR and medical systems. The FBI says it is investigating and that the point of breach is undetermined.Personnel and applicant records; the group claims 2 to 3 TB, and Reuters reviewed sample medical and mental health evaluation documents
Sep 2026Japan, Digital Agency (Government Solution Service)An attacker got in through a VPN appliance flaw. The agency detected the intrusion on June 25, when a large volume of files was accessed with a maintenance staff member’s account, and disclosed it September 11.About 246,000 records on government staff and contractors, mainly names, email addresses, and phone numbers
Sep 2026Florida Department of Highway Safety and Motor Vehicles (DAVID)Discovered September 4. The agency says a Plant City Police Department user’s credentials, stored on a personal device, were used to access the law-enforcement driver database. ShinyHunters later published files, TechCrunch reported.Driver and vehicle records; the group claims more than 200,000 (unconfirmed)
Aug 2026U.S. Bureau of Alcohol, Tobacco, Firearms and ExplosivesA standalone system holding information on investigation targets was compromised and shut down. The Justice Department designated it a major incident, and the Qilin group listed ATF on its leak site.Case information on investigation targets; Qilin claims it published about 6.3 GB
Aug 2026Berlin, Senate Department for Mobility, Transport, Climate Protection and the EnvironmentIntrusion discovered August 14, with exfiltration reported between August 7 and 12. Berlin refused a 30-bitcoin extortion demand.Rhysida claims 5.7 TB across about 1.44 million files (unconfirmed)
Aug 2026France, Direction générale des Finances publiques (DGFiP)A tax office employee account and a contractor account, combined with a technique that got past multi-factor authentication, were used to consult and extract records.Tax and property data on 678,000 individuals and businesses
Jul 2026Kootenai County, IdahoRansomware was detected March 30, and the county says data was extracted. Its review finished July 2, and notification letters went out beginning July 22.Names, Social Security numbers, driver’s license, medical, and financial data; fingerprints for some residents
Jul 2026U.S. Department of Homeland Security (HSIN)Intruders reached Homeland Security Information Network servers and a SharePoint system used for inter-agency collaboration sometime between late May and early June.Sensitive but unclassified information shared among agencies; whether documents were stolen remains unclear
Apr 2026City of Suffolk, VirginiaCISA told the city on February 25 that data may have been exfiltrated. An attempted ransomware deployment was stopped, but investigators could not determine what personal information, if any, was accessed.All potentially affected people were notified: 157,725, per Comparitech; the Cloak group claims 2.5 TB (unconfirmed)
Apr 2026Los Angeles City Attorney’s OfficeA third-party tool used to transfer discovery to opposing counsel was breached. The office learned of it March 20, and the files were posted for download.More than 337,000 files totaling 7.7 TB, per Los Angeles Times reporting, including LAPD personnel files, witness names, and medical information
Apr 2026FBI (unclassified surveillance system)Anomalous activity was found February 17 on a system holding pen register and trap-and-trace data. It was declared a major incident and reported to Congress in April, and a China-linked actor is suspected.Phone numbers of surveillance targets

File-sharing systems keep showing up

Several of the year’s largest incidents ran through systems built to move documents between people. The Los Angeles City Attorney’s Office lost more than 337,000 files from a third-party tool used to send discovery to opposing counsel, and GovTech reported that the tool was not password-protected so outside attorneys could reach it. The Defense Manpower Data Center’s breach came through a file-sharing system. Intruders in DHS’s Homeland Security Information Network reached a SharePoint system used for collaboration, and Japan’s Digital Agency found its intrusion through file access on a shared government server.

A file-sharing system hands documents to whoever its front end lets in, which makes that front end the entire security model. When it fails, through a flaw, a missing password, or a stolen login, everything behind it becomes readable. Access policy that travels with the data, evaluated on every operation against how each file is labeled, is what keeps one failed front end from exposing a whole repository.

Most of the damage came from reading and copying

In most incidents on the list, the harm came from data being read and copied rather than locked. The City of Suffolk stopped an attempted ransomware deployment and still had to notify everyone whose data might have been taken. France’s tax administration saw 678,000 records consulted and extracted through accounts that were allowed to log in. In the Florida and FBIJobs.gov incidents, the extortion was over stolen records, and no encryption was reported in either.

That changes which controls matter. Backups and immutable snapshots restore files that were encrypted or destroyed, and they do nothing about copies an attacker already holds. Against theft, the defense has to act while the reads are happening.

Borrowed credentials did much of the work

Valid accounts were a common way in. France’s tax data left through a staff account and a contractor account, with multi-factor authentication bypassed. Florida says its driver database was reached with a police department user’s credentials kept on a personal device. Japan’s intruder entered through a VPN flaw and then read files with a maintenance staff member’s account. Each of those sessions authenticated, so each was trusted by every control that checks only who is logged in.

A session that authenticates correctly can still behave in ways no job requires: reading a department’s entire file share, walking a database record by record, or pulling files at night from a source address with no history. Japan’s case shows that signal is real. The agency found its intrusion on June 25 because a large volume of files was accessed with a single maintenance account, which is exactly the kind of pattern behavioral analysis at the storage layer is built to catch while it is happening.

Scope arrives late, or as a range

The hardest question in most of these incidents came after containment: what, exactly, was taken? Suffolk’s investigators could not determine what personal information, if any, the intruder accessed, so the city notified all potentially affected people, 157,725 of them according to Comparitech. The Pentagon’s letters give no count, and approximately four million personnel may be affected according to Military Times’ sources. DHS has not said whether documents left HSIN. Kootenai County detected ransomware on March 30 and finished its review on July 2. In Berlin, the most detailed inventory of the stolen data is still the attacker’s leak-site listing.

Each of those answers depends on a record of which files were read, by whom, and when. When that record is incomplete, organizations notify broadly, pay for monitoring for everyone on the list, and have no evidence with which to test an attacker’s numbers. An immutable, per-operation audit kept by the storage itself turns scoping into a query.

What would shorten next year’s list

The controls that address these patterns belong in the storage layer, where the files are. RackTop BrickStor SP evaluates every SMB, NFS, S3, and Web Drive operation inline. Its Active Defense engine profiles normal activity for each user, host, and dataset and ends an anomalous session in under a second, attribute-based access control (ABAC) decides each request on the user’s attributes and the data’s labels, and every operation is written to an immutable audit record. Data at rest is encrypted with a FIPS 140-3 Level 1 validated cryptographic module in version 23.8 and later.

None of this replaces patching the flaw or hardening the login. It limits what happens after those fail, which is where this year’s government breaches did their damage. RackTop’s analysis of the Pentagon DMDC breach walks through how those controls map onto a single incident.

Frequently asked questions

By people or data potentially affected, the largest disclosed so far include the Pentagon’s Defense Manpower Data Center breach (approximately four million personnel may be affected, according to Military Times’ sources), France’s tax administration breach (678,000 individuals and businesses), the Los Angeles City Attorney’s Office breach (more than 337,000 files totaling 7.7 TB), Japan’s Digital Agency breach (about 246,000 records), and the City of Suffolk, Virginia (157,725 people notified). ShinyHunters claims 2 to 3 TB from the FBI, which the bureau has not confirmed.
Comparitech counted 187 ransomware attacks on government organizations in the first half of 2026, 89 of them confirmed by the victims, up from 165 in the second half of 2025. It found 179,000 records known to have been breached in the confirmed attacks and a median ransom demand of $100,000, down from $500,000 in the second half of 2025.
Under the Federal Information Security Modernization Act, the Office of Management and Budget defines what counts as a major incident, and federal agencies must report major incidents to Congress within seven days of identifying them, according to CISA’s federal incident notification guidelines. In 2026, both the FBI’s surveillance-system breach and the ATF breach were designated major incidents.
Scoping depends on a record of which files and records were actually read, by whom, and when, and many systems keep only partial logs of reads. Without that record, investigators reconstruct activity after the fact and agencies often notify everyone whose data was reachable. The City of Suffolk, Virginia, for example, notified all potentially affected people because investigators could not determine what personal information was accessed.
Put the controls on the data itself: behavioral detection that evaluates every file read and stops anomalous sessions, attribute-based access control that decides each request on user attributes and data labels, and an immutable per-operation audit for scoping. RackTop BrickStor SP provides all three inline across SMB, NFS, S3, and Web Drive.How storage-layer controls map to the Pentagon DMDC breach

Keep your agency’s files off next year’s list

Talk with a RackTop engineer about storage that detects anomalous reads, enforces ABAC on every file operation, and keeps the immutable record that answers what was taken.

Government Data Breaches 2026: The Running List | RackTop