2026 Global Cyberattacks Disrupt Public Services and Critical Infrastructure
In June 2026 a wave of distributed‑denial‑of‑service (DDoS) attacks hit a range of public‑interest targets. India’s Central Board of Secondary Education’s re‑evaluation portal was flooded with over 100,000 unauthorized requests, while a sports‑betting platform serving the World Cup opening match endured a flash attack of 786,000 requests in 87 seconds. Russian‑based hosting provider Biterika Group LLC was linked to the latter incident. Russian authorities were also accused of launching DDoS attacks against popular VPN services, crippling tools used to bypass internet restrictions.
In the United States, the emergency‑notification system AlertDC (operated by Everbridge) experienced a nationwide outage on June 26, and the National Weather Service’s website faced a similar disruption on June 27, with the hacking group 313 Team claiming responsibility for both incidents, though attribution remains unverified.
Separately, a review of the year’s most severe data breaches highlighted a purported leak of the Social Security Administration’s database after the Department of Government Efficiency (DOGE) allegedly uploaded a copy to an insecure third‑party server, potentially exposing the personal information of most living Americans. Europe saw ransomware‑style attacks on civilian energy and water infrastructure, including Poland’s power grid, a Swedish thermal plant and a Norwegian dam, with Russian actors suspected. Iranian hackers targeted U.S. water utilities and caused a disruptive wipe of tens of thousands of devices at medical‑technology firm Stryker.
These incidents illustrate a growing trend of cyber aggression that crosses national borders and threatens essential services, from education and emergency alerts to energy, water and personal data.