Stuxnet: the USB-spread cyberweapon that hit Iran's nuclear programme
What is confirmed, what is only reported, and what it means for your own USB habits.
October 9, 2026 ROUND-UP · 2023–2026The biggest scams and hacks of the last 3 years
Ten big cases by type of attack: how each was done, what was stolen and who was behind it.
October 9, 2026 HISTORY · USBAgent.btz: how one USB drive breached the US military
The 2008 incident that led to a Pentagon-wide ban on USB drives.
October 9, 2026 CRYPTOCrypto hacks explained: Bybit, Ronin and who is behind them
The biggest thefts, how they happened and how to protect yourself.
October 9, 2026 ROUND-UP · 2026The 10 biggest cyber hacks of 2026
The year's most significant confirmed breaches, now with Stryker and IDScan added.
Updated October 9, 2026 EXPLAINERHow data breaches actually happen
The five routes attackers really use, with new 2026 examples.
Updated October 9, 2026 ANALYSISScam trends in 2026: what has actually changed
Cheap fluent writing, copied voices and industrial operations, plus crypto and extortion trends.
Updated October 9, 2026 EXPLAINERInside a modern phishing operation
Phishing is a supply chain. Why the old warning signs stopped working.
Updated October 9, 2026 SCAMSThe ClickFix scam explained
How fake fix-it prompts trick people into infecting themselves.
ROUND-UPCyber fraud news and analysis
Longer pieces on how online fraud is actually working right now.
Updated October 9, 2026The full stories
The four biggest stories on this page, told in full. Each one says what is confirmed, what is only reported, and what it means for you, with dated sources.
Stuxnet: the USB-spread cyberweapon that hit Iran's nuclear programme
What happened
Stuxnet was discovered in June 2010. It was a computer worm aimed at Siemens industrial control software and the controllers it programs, and it was built to damage the centrifuges at Iran's Natanz uranium enrichment plant.
Researchers at the security company Symantec reported that it only acted on specific equipment running at specific speeds. That suggests it was made for one particular target rather than for general damage. About 60% of the infected computers Symantec found were in Iran.
How it got into a plant with no internet
Natanz's control computers were kept off the internet on purpose. Stuxnet was built around that. Industrial systems are often programmed from standalone Windows computers, and staff move files between them on removable drives. Stuxnet copied itself onto any USB drive that was plugged in.
Symantec also reported that Stuxnet first hit five Iranian organisations between June 2009 and May 2010, before it reached the plant. Those organisations were not named, but their business ties to the plant appear to have given the worm a route in. Symantec traced about 12,000 infections back to them. The worm also used several previously unknown Windows flaws, including one that could run code just by showing a shortcut icon in a folder.
What it did to the centrifuges
Stuxnet is reported to have targeted motor-speed controllers connected to the centrifuges and damaged them. The Institute for Science and International Security estimated in December 2010 that up to about 1,000 centrifuges, around 10%, were destroyed between November 2009 and late January 2010. That is an estimate, not a verified figure.
On November 29, 2010 Iran's president at the time, Mahmoud Ahmadinejad, said a computer virus had caused problems for "a limited number" of centrifuges. Iran later replaced the damaged equipment.
Who was behind it
Nobody has officially taken responsibility. The New York Times reported on June 1, 2012 that Stuxnet was part of a joint US and Israeli operation. Neither government has confirmed it. Kaspersky concluded an attack this advanced needed the backing of a nation state. A 2019 report that an engineer recruited by Dutch intelligence carried it in relies on unnamed sources and is unconfirmed.
What this means for you
- Never plug in a USB drive you found, or one handed to you by a stranger.
- Turn off AutoPlay so a drive cannot launch anything by itself. In Windows, search Settings for "AutoPlay" and set it to take no action.
- Keep your computer updated. Stuxnet relied on flaws that updates close.
- At work, hand found drives to IT instead of checking what is on them.
- Wikipedia: Stuxnet (summarises Symantec, Kaspersky, ISIS and New York Times reporting) (page checked October 9, 2026)
- NBC News: Stuxnet malware hit five sites before target (Symantec findings) (publication date not shown on the page)
- Dark Reading: Report says an Iranian mole carried Stuxnet to the nuclear facility (September 3, 2019)
Agent.btz: how one USB drive breached the US military
What happened
In 2008 a USB flash drive carrying malware was inserted into a laptop at a US military base in the Middle East. From that one laptop, a worm called Agent.btz spread onto a network run by US Central Command, across both classified and unclassified systems, without being noticed.
US Deputy Defense Secretary William Lynn confirmed the incident publicly in an article for Foreign Affairs, reported on August 25, 2010. He said the malicious code on the drive had been placed there by a foreign intelligence agency. A senior US defence official later called it the most significant breach of US military computers. Some retellings say the drive was left in a car park for someone to find. The sources we checked do not confirm that.
How it worked
Agent.btz is reported to be a variant of an older worm called SillyFDC, which spread whenever an infected removable drive was plugged into a computer. It could scan an infected computer for certain data and open a backdoor to a remote server. Lynn described the result as a "digital beachhead" from which information could be sent out.
The sources disagree on whether data was actually stolen. One report says classified and unclassified data was sent to servers under foreign control. Another says Lynn did not say whether any data was taken.
The response
The Pentagon banned removable drives and switched off the Windows AutoPlay feature to slow the spread. Wired reported this on November 19, 2008. The ban was later lifted. The clean-up, named Operation Buckshot Yankee, took more than a year, and reports link the incident to the later creation of US Cyber Command.
Who was behind it
Lynn did not name the agency in 2010. In December 2016 a joint FBI and Department of Homeland Security report attributed Agent.btz to "one or more" Russian civilian and military intelligence services. Wired reported in 2010 that some insiders doubted it was a foreign spy operation, so treat the attribution as reported, not settled.
What this means for you
- The US military has strong security and still lost control of its networks because one person plugged in one drive.
- Never plug in a drive you found or were given by a stranger. A "lost" drive left where you will find it is a classic trap.
- Turn off AutoPlay, and keep your computer and apps updated.
- In public, use your own charger and cable, or a USB data blocker.
- Computerworld: Infected USB drive blamed for 2008 military cyber breach (August 25, 2010)
- Threatpost: Buckshot Yankee (June 30, 2011)
- Wikipedia: 2008 malware infection of the US Department of Defense (cites Wired November 19, 2008 and the FBI/DHS report of December 29, 2016) (page checked October 9, 2026)
Bybit: the biggest crypto theft on record
What happened
On or about February 21, 2025 attackers stole about US$1.5 billion from the crypto exchange Bybit. It was described as the largest crypto theft recorded at that time.
How it happened
Security reviews by Sygnia and Verichains, reported by BleepingComputer, found the attackers did not break into Bybit's own systems directly. They first compromised a developer's computer at Safe{Wallet}, a wallet service Bybit used. That gave them access to Bybit's wallet account.
They then intercepted a routine transfer from Bybit's offline storage and redirected the money to wallets they controlled. The FBI said the stolen funds were being converted to bitcoin and other assets and spread across thousands of addresses, and it published a list of 51 Ethereum addresses holding stolen funds.
Who was behind it
On February 26, 2025 the FBI issued a public notice naming North Korea, specifically the groups known as TraderTraitor, Lazarus Group and APT38. The same groups were blamed by the FBI for the US$620 million Ronin Network theft in March 2022.
The bigger picture
Chainalysis, a firm that tracks crypto crime, estimates more than US$3.4 billion was stolen across the crypto world in 2025, and that North Korea-linked hackers took at least US$2.02 billion of it, up 51% on the year before. It also counted about 158,000 personal wallet compromises, with roughly US$713 million taken from individuals. Figures are in US dollars, as reported.
What this means for you
- Never share your recovery phrase. Nobody legitimate will ever ask for it, including "support staff".
- Use a hardware wallet for any amount you cannot afford to lose, and keep the recovery phrase offline.
- Do not leave everything on one exchange.
- Use an authenticator app, not text messages, for two-factor sign-in, and double-check wallet addresses before sending.
- BleepingComputer: FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist (February 27, 2025)
- Wikipedia: Ronin Network (cites the FBI statement of April 14, 2022) (page checked October 9, 2026)
- Payment Expert: Chainalysis Crypto Crime Report 2026 (December 19, 2025)
Stryker: tens of thousands of work devices wiped
What happened
On about March 11, 2026 attackers got into the internal Microsoft environment of Stryker, a US medical technology company, and remotely wiped employee devices. Stryker confirmed "tens of thousands" of devices were affected. It said this was not ransomware, that no malware was deployed, and that its medical products and connected devices were not affected.
How it happened
BleepingComputer, citing a source, reported that the attacker compromised an administrator account and then used a device management tool's built-in wipe command. In other words, the attackers did not need to write or plant any malicious software. They used a normal admin tool against the company.
Who was behind it
A group called Handala claimed the attack. Security researchers widely link Handala to Iran, but that link is not officially confirmed. Device counts vary: Stryker confirmed "tens of thousands", one report says nearly 80,000, and Handala claims more than 200,000. Treat the larger figures as claims.
What this means for you
- One stolen admin login can do more damage than malware.
- Protect every admin and email account with two-factor authentication.
- Keep backups that a single account cannot delete.
- At home, the same rule applies to your main email: it is the admin account for your whole digital life.
How we cover the news
We link every claim to a source and show its date. When something is reported but not confirmed, we say so, and we leave out what we cannot verify. Dollar amounts are given in US dollars, as reported. Our editorial policy explains how we work, and you can tell us about a mistake through Contact Us.
What to do with any of it
Most stories lead to the same short list: strong, different passwords, two-factor sign-in, automatic updates and verifying anything urgent through a channel you chose. Our stay safe online guide puts it all in one place.