2026 did not ease itself in. As the year opened, Poland was working through a coordinated cyberattack — begun in the last days of December — against roughly thirty sites connected to its energy grid. Thirty is not a number that happens by accident; it is a number that speaks of reconnaissance, patience, and a target list drawn up long before the first alarm. Against the backdrop of a Europe already treating its power infrastructure as contested space, the operation read less like crime than like signalling — a reminder, in the coldest month, of who can reach what.
Energy grids occupy a special place in the defender's imagination because they are the layer everything else stands on: hospitals, water, payments, heat. The Polish operation didn't produce blackouts of the kind that make history books, and that, in a way, was the message received by every grid operator on the continent — this time. January's grid story wasn't about outage; it was about access, and about how many of those thirty doors had been quietly open for how long.
The month around it set 2026's tempo: global breach counts ticked up 3% over December, and the ledger filled with names from every aisle of modern life. If December had been the reckoning, January was the reload.
Target's source code, Under Armour's customers
On January 13, Target confirmed the theft of roughly 860 GB of internal code and developer documentation — not customer cards this time, but the blueprints of the retailer's own systems, the kind of haul that funds future attacks rather than immediate fraud. A week later, a customer dataset from Under Armour surfaced on a hacking forum: names, birthdays, purchase histories, locations. Two retail giants, two different kinds of loss — one selling the map, the other the territory.
The doors left open
Some of January's biggest exposures required no attacker at all. Researchers found a misconfigured cloud database sitting on the public internet with 149 million records — nearly 100 GB of sensitive information, free to anyone who looked. State systems in Illinois and Minnesota suffered a failure that exposed personal data of close to a million people. The month's quiet lesson: in the league table of threats, human configuration error remains a perennial title contender.
The MSP problem arrives home
January's India entry cut at the country's crown-jewel sector: the Sinobi ransomware group claimed an attack on an India-based IT services company, saying it had reached Hyper-V servers, virtual machines, and — most dangerously — customer backups, with an alleged 150 GB or more of contracts, financial information, and client data. The claim mattered beyond one firm: India's IT services industry is the back office of the global economy, and a compromised service provider is a skeleton key to every customer it manages. With ransomware activity that month surging more than 31% above the prior nine-month average, it was an uncomfortable way for the sector's year to begin.
⏳ Time capsule — January 2026
- The Crimson Collective claimed data on more than a million customers of US telecom Brightspeed — telecoms would keep that theme running all quarter.
- Monroe University notified 320,000 people about a breach that had happened in December 2024 — disclosure lag, the industry's other epidemic.
- Prediction-season hangover: every 2026 forecast said "agentic AI," and January obligingly began proving them right.
- The first full month of Windows 10's afterlife: the unpatched cohort grew, quietly, exactly as October promised.
The year of systems begins
With the whole runway now visible, January reads as the opening move of a quarter with a theme: attackers heading for the machinery societies run on. The grid in January, an island's entire telecom core in February, wipers destroying workstations in March, the FBI's own surveillance systems in April. Data theft never paused — Target and Under Armour made sure of that — but the direction of travel was unmistakable, and it's the lens our current editions still use. The thirty Polish sites were the year's first entry in a ledger that kept asking the same question: not "what did they take?" but "what can they reach?"