Key takeaways
- Comparitech counted 187 ransomware attacks on government organizations in the first half of 2026, 89 of them confirmed by the victims, up from 165 in the second half of 2025.
- Several of 2026’s largest government incidents ran through systems built to share documents, according to public reporting: a Defense Manpower Data Center file-sharing system, a third-party discovery-transfer tool at the Los Angeles City Attorney’s Office, and a SharePoint system connected to DHS’s Homeland Security Information Network.
- Valid or borrowed credentials were a recurring way in, including a staff account and a contractor account at France’s tax administration, a police department user’s credentials at Florida’s DAVID driver database, and a maintenance staff account at Japan’s Digital Agency.
- Scope was the recurring gap. The City of Suffolk, Virginia notified everyone potentially affected because investigators could not determine what personal information was accessed, and the Pentagon’s notification letters give no count of people affected.
Government bodies disclosed breaches at every level in 2026, from county networks to an FBI system holding surveillance data. Comparitech counted 187 ransomware attacks on government organizations in the first half of the year, 89 of them confirmed by the victims, up from 165 in the second half of 2025. Ransomware is only part of the picture, though. Several of the year’s most consequential government incidents involved no encryption at all.
This page tracks notable government data breaches made public in 2026, in the United States and among allied governments. An incident is listed when the affected government body confirmed it or at least two reputable outlets reported it, and any figure that comes only from an attacker is labeled as a claim. The list is updated monthly and was last updated on October 1, 2026.
The 2026 list, newest first
Dates reflect when each incident became public, which is often months after the intrusion began.
| Disclosed | Government body | What happened | Data at risk |
|---|---|---|---|
| Sep 2026 | U.S. Department of Defense, Defense Manpower Data Center | A vulnerability in a file-sharing system, discovered July 16, had allowed unauthorized users to access files since October 2025. Notification letters went out beginning in September. | Unencrypted personal data including Social Security numbers; approximately four million personnel may be affected, per Military Times sources |
| Sep 2026 | FBI (FBIJobs.gov) | ShinyHunters claims it entered through the recruiting portal and reached HR and medical systems. The FBI says it is investigating and that the point of breach is undetermined. | Personnel and applicant records; the group claims 2 to 3 TB, and Reuters reviewed sample medical and mental health evaluation documents |
| Sep 2026 | Japan, Digital Agency (Government Solution Service) | An attacker got in through a VPN appliance flaw. The agency detected the intrusion on June 25, when a large volume of files was accessed with a maintenance staff member’s account, and disclosed it September 11. | About 246,000 records on government staff and contractors, mainly names, email addresses, and phone numbers |
| Sep 2026 | Florida Department of Highway Safety and Motor Vehicles (DAVID) | Discovered September 4. The agency says a Plant City Police Department user’s credentials, stored on a personal device, were used to access the law-enforcement driver database. ShinyHunters later published files, TechCrunch reported. | Driver and vehicle records; the group claims more than 200,000 (unconfirmed) |
| Aug 2026 | U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives | A standalone system holding information on investigation targets was compromised and shut down. The Justice Department designated it a major incident, and the Qilin group listed ATF on its leak site. | Case information on investigation targets; Qilin claims it published about 6.3 GB |
| Aug 2026 | Berlin, Senate Department for Mobility, Transport, Climate Protection and the Environment | Intrusion discovered August 14, with exfiltration reported between August 7 and 12. Berlin refused a 30-bitcoin extortion demand. | Rhysida claims 5.7 TB across about 1.44 million files (unconfirmed) |
| Aug 2026 | France, Direction générale des Finances publiques (DGFiP) | A tax office employee account and a contractor account, combined with a technique that got past multi-factor authentication, were used to consult and extract records. | Tax and property data on 678,000 individuals and businesses |
| Jul 2026 | Kootenai County, Idaho | Ransomware was detected March 30, and the county says data was extracted. Its review finished July 2, and notification letters went out beginning July 22. | Names, Social Security numbers, driver’s license, medical, and financial data; fingerprints for some residents |
| Jul 2026 | U.S. Department of Homeland Security (HSIN) | Intruders reached Homeland Security Information Network servers and a SharePoint system used for inter-agency collaboration sometime between late May and early June. | Sensitive but unclassified information shared among agencies; whether documents were stolen remains unclear |
| Apr 2026 | City of Suffolk, Virginia | CISA told the city on February 25 that data may have been exfiltrated. An attempted ransomware deployment was stopped, but investigators could not determine what personal information, if any, was accessed. | All potentially affected people were notified: 157,725, per Comparitech; the Cloak group claims 2.5 TB (unconfirmed) |
| Apr 2026 | Los Angeles City Attorney’s Office | A third-party tool used to transfer discovery to opposing counsel was breached. The office learned of it March 20, and the files were posted for download. | More than 337,000 files totaling 7.7 TB, per Los Angeles Times reporting, including LAPD personnel files, witness names, and medical information |
| Apr 2026 | FBI (unclassified surveillance system) | Anomalous activity was found February 17 on a system holding pen register and trap-and-trace data. It was declared a major incident and reported to Congress in April, and a China-linked actor is suspected. | Phone numbers of surveillance targets |
File-sharing systems keep showing up
Several of the year’s largest incidents ran through systems built to move documents between people. The Los Angeles City Attorney’s Office lost more than 337,000 files from a third-party tool used to send discovery to opposing counsel, and GovTech reported that the tool was not password-protected so outside attorneys could reach it. The Defense Manpower Data Center’s breach came through a file-sharing system. Intruders in DHS’s Homeland Security Information Network reached a SharePoint system used for collaboration, and Japan’s Digital Agency found its intrusion through file access on a shared government server.
A file-sharing system hands documents to whoever its front end lets in, which makes that front end the entire security model. When it fails, through a flaw, a missing password, or a stolen login, everything behind it becomes readable. Access policy that travels with the data, evaluated on every operation against how each file is labeled, is what keeps one failed front end from exposing a whole repository.
Most of the damage came from reading and copying
In most incidents on the list, the harm came from data being read and copied rather than locked. The City of Suffolk stopped an attempted ransomware deployment and still had to notify everyone whose data might have been taken. France’s tax administration saw 678,000 records consulted and extracted through accounts that were allowed to log in. In the Florida and FBIJobs.gov incidents, the extortion was over stolen records, and no encryption was reported in either.
That changes which controls matter. Backups and immutable snapshots restore files that were encrypted or destroyed, and they do nothing about copies an attacker already holds. Against theft, the defense has to act while the reads are happening.
Borrowed credentials did much of the work
Valid accounts were a common way in. France’s tax data left through a staff account and a contractor account, with multi-factor authentication bypassed. Florida says its driver database was reached with a police department user’s credentials kept on a personal device. Japan’s intruder entered through a VPN flaw and then read files with a maintenance staff member’s account. Each of those sessions authenticated, so each was trusted by every control that checks only who is logged in.
A session that authenticates correctly can still behave in ways no job requires: reading a department’s entire file share, walking a database record by record, or pulling files at night from a source address with no history. Japan’s case shows that signal is real. The agency found its intrusion on June 25 because a large volume of files was accessed with a single maintenance account, which is exactly the kind of pattern behavioral analysis at the storage layer is built to catch while it is happening.
Scope arrives late, or as a range
The hardest question in most of these incidents came after containment: what, exactly, was taken? Suffolk’s investigators could not determine what personal information, if any, the intruder accessed, so the city notified all potentially affected people, 157,725 of them according to Comparitech. The Pentagon’s letters give no count, and approximately four million personnel may be affected according to Military Times’ sources. DHS has not said whether documents left HSIN. Kootenai County detected ransomware on March 30 and finished its review on July 2. In Berlin, the most detailed inventory of the stolen data is still the attacker’s leak-site listing.
Each of those answers depends on a record of which files were read, by whom, and when. When that record is incomplete, organizations notify broadly, pay for monitoring for everyone on the list, and have no evidence with which to test an attacker’s numbers. An immutable, per-operation audit kept by the storage itself turns scoping into a query.
What would shorten next year’s list
The controls that address these patterns belong in the storage layer, where the files are. RackTop BrickStor SP evaluates every SMB, NFS, S3, and Web Drive operation inline. Its Active Defense engine profiles normal activity for each user, host, and dataset and ends an anomalous session in under a second, attribute-based access control (ABAC) decides each request on the user’s attributes and the data’s labels, and every operation is written to an immutable audit record. Data at rest is encrypted with a FIPS 140-3 Level 1 validated cryptographic module in version 23.8 and later.
None of this replaces patching the flaw or hardening the login. It limits what happens after those fail, which is where this year’s government breaches did their damage. RackTop’s analysis of the Pentagon DMDC breach walks through how those controls map onto a single incident.
Frequently asked questions
- By people or data potentially affected, the largest disclosed so far include the Pentagon’s Defense Manpower Data Center breach (approximately four million personnel may be affected, according to Military Times’ sources), France’s tax administration breach (678,000 individuals and businesses), the Los Angeles City Attorney’s Office breach (more than 337,000 files totaling 7.7 TB), Japan’s Digital Agency breach (about 246,000 records), and the City of Suffolk, Virginia (157,725 people notified). ShinyHunters claims 2 to 3 TB from the FBI, which the bureau has not confirmed.
- Comparitech counted 187 ransomware attacks on government organizations in the first half of 2026, 89 of them confirmed by the victims, up from 165 in the second half of 2025. It found 179,000 records known to have been breached in the confirmed attacks and a median ransom demand of $100,000, down from $500,000 in the second half of 2025.
- Under the Federal Information Security Modernization Act, the Office of Management and Budget defines what counts as a major incident, and federal agencies must report major incidents to Congress within seven days of identifying them, according to CISA’s federal incident notification guidelines. In 2026, both the FBI’s surveillance-system breach and the ATF breach were designated major incidents.
- Scoping depends on a record of which files and records were actually read, by whom, and when, and many systems keep only partial logs of reads. Without that record, investigators reconstruct activity after the fact and agencies often notify everyone whose data was reachable. The City of Suffolk, Virginia, for example, notified all potentially affected people because investigators could not determine what personal information was accessed.
- Put the controls on the data itself: behavioral detection that evaluates every file read and stops anomalous sessions, attribute-based access control that decides each request on user attributes and data labels, and an immutable per-operation audit for scoping. RackTop BrickStor SP provides all three inline across SMB, NFS, S3, and Web Drive.How storage-layer controls map to the Pentagon DMDC breach
Sources
- Comparitech (H1 2026 government ransomware roundup)
- Military Times (Defense Manpower Data Center)
- CNN (Defense Manpower Data Center)
- NBC News (FBIJobs.gov)
- CBS News (FBIJobs.gov)
- Reuters via GV Wire (FBIJobs.gov)
- BleepingComputer (Japan Digital Agency)
- Cybersecurity News (Japan Digital Agency)
- BleepingComputer (Florida DAVID)
- TechCrunch (Florida DAVID)
- CyberScoop (ATF)
- The Record (ATF)
- BleepingComputer (Berlin)
- SecurityWeek (Berlin)
- BleepingComputer (France DGFiP)
- Help Net Security (France DGFiP)
- Kootenai County notice
- KXLY (Kootenai County)
- BleepingComputer (DHS HSIN)
- TechCrunch (DHS HSIN)
- City of Suffolk news release
- Comparitech (City of Suffolk)
- The Record (Los Angeles City Attorney)
- GovTech (Los Angeles City Attorney)
- Nextgov/FCW (FBI surveillance system)
- TechCrunch (2026 roundup)
- CISA Federal Incident Notification Guidelines
Go deeper
