2026 did not ease itself in. As the year opened, Poland was working through a coordinated cyberattack — begun in the last days of December — against roughly thirty sites connected to its energy grid. Thirty is not a number that happens by accident; it is a number that speaks of reconnaissance, patience, and a target list drawn up long before the first alarm. Against the backdrop of a Europe already treating its power infrastructure as contested space, the operation read less like crime than like signalling — a reminder, in the coldest month, of who can reach what.
Energy grids occupy a special place in the defender's imagination because they are the layer everything else stands on: hospitals, water, payments, heat. The Polish operation didn't produce blackouts of the kind that make history books, and that, in a way, was the message received by every grid operator on the continent — this time. January's grid story wasn't about outage; it was about access, and about how many of those thirty doors had been quietly open for how long.
The month around it set 2026's tempo: global breach counts ticked up 3% over December, and the ledger filled with names from every aisle of modern life. If December had been the reckoning, January was the reload.
Target's source code, Under Armour's customers
On January 13, Target confirmed the theft of roughly 860 GB of internal code and developer documentation — not customer cards this time, but the blueprints of the retailer's own systems, the kind of haul that funds future attacks rather than immediate fraud. A week later, a customer dataset from Under Armour surfaced on a hacking forum: names, birthdays, purchase histories, locations. Two retail giants, two different kinds of loss — one selling the map, the other the territory.
The doors left open
Some of January's biggest exposures required no attacker at all. Researchers found a misconfigured cloud database sitting on the public internet with 149 million records — nearly 100 GB of sensitive information, free to anyone who looked. State systems in Illinois and Minnesota suffered a failure that exposed personal data of close to a million people. The month's quiet lesson: in the league table of threats, human configuration error remains a perennial title contender.
The MSP problem arrives home
January's India entry cut at the country's crown-jewel sector: the Sinobi ransomware group claimed an attack on an India-based IT services company, saying it had reached Hyper-V servers, virtual machines, and — most dangerously — customer backups, with an alleged 150 GB or more of contracts, financial information, and client data. The claim mattered beyond one firm: India's IT services industry is the back office of the global economy, and a compromised service provider is a skeleton key to every customer it manages. With ransomware activity that month surging more than 31% above the prior nine-month average, it was an uncomfortable way for the sector's year to begin.
ChatGPT takes ads and medical records
Two announcements nine days apart shaped the assistant's year. On 7 January 2026 OpenAI introduced ChatGPT Health, a walled-off space where people could connect patient portals and wellness apps and ask questions grounded in their own lab results; the company said those conversations would stay separate from the rest of ChatGPT, would not train its foundation models and were not meant for diagnosis. On 16 January it said it would test advertising in the United States on the free and Go tiers, as labelled placements beneath the answer, insisting ads would not influence replies and that user data would not be sold to advertisers. The notice went out late on the Friday of a holiday weekend, and scepticism followed; Sam Altman had once called advertising a last resort. The test opened in February and, on reported accounts, reached Canada, Australia and New Zealand by late March. At month's end Anthropic's Dario Amodei published a long essay on the risks of powerful AI, an odd counterpoint to a fortnight that made the assistant both more commercial and more intimate.
CrowdStrike buys identity and the browser
CrowdStrike spent the first fortnight of the year buying the parts of the endpoint its own agent no longer sees. On 8 January 2026 it signed a definitive agreement for SGNL, whose technology sits between identity providers and cloud resources and grants, denies or revokes access continuously on live risk signals; George Kurtz framed the logic around machines rather than staff, arguing that agents operating at superhuman speed and access make every agent a privileged identity. Five days later came Seraphic Security, whose browser runtime protection is meant to turn any browser into an enterprise one without asking anybody to switch. Neither announcement named a price; SecurityWeek and CNBC reported roughly $740 million for SGNL, and SecurityWeek about $420 million for Seraphic. Both were expected to close in CrowdStrike's fiscal first quarter of 2027. The reasoning was plain: work had moved into the browser and into non-human identities, and the agent on the laptop had stopped seeing all of it. Zscaler closed its own browser purchase, SquareX, on 5 February.
⏳ Time capsule — January 2026
- The Crimson Collective claimed data on more than a million customers of US telecom Brightspeed — telecoms would keep that theme running all quarter.
- Monroe University notified 320,000 people about a breach that had happened in December 2024 — disclosure lag, the industry's other epidemic.
- Prediction-season hangover: every 2026 forecast said "agentic AI," and January obligingly began proving them right.
- The first full month of Windows 10's afterlife: the unpatched cohort grew, quietly, exactly as October promised.
The year of systems begins
With the whole runway now visible, January reads as the opening move of a quarter with a theme: attackers heading for the machinery societies run on. The grid in January, an island's entire telecom core in February, wipers destroying workstations in March, the FBI's own surveillance systems in April. Data theft never paused — Target and Under Armour made sure of that — but the direction of travel was unmistakable, and it's the lens our current editions still use. The thirty Polish sites were the year's first entry in a ledger that kept asking the same question: not "what did they take?" but "what can they reach?"