Index live· 1,284 files · 148 editions
ForensicPost

Search the index

328 results
Try
Results for “AI”Newest first
26-0812
File

Lazarus Paired a Windows Zero-Day With Post-Quantum Encryption Against Defence Firms

Adopting ML-KEM cost the attacker one library. It costs a defence contractor its entire estate.

Lazarus GroupCVE-2026-68820 — Windows AFD.sysDefenceEspionage
Sev 5TargetDefence, aerospace and aviation firmsActorLazarus GroupNot established
26-0811
File

Metabase Zero-Day Hit Five Companies Before the Flaw Was Disclosed

A CVSS 10.0 flaw in a reporting tool that stores the credentials for every warehouse behind it.

UnattributedCVE-2026-72898TechnologySupply chain
Sev 5TargetMetabase deploymentsActorUnattributedUSA
26-0807
File

Bank of Baroda Confirms Leak After Employee Email Compromise, With 700GB Claimed

A dispute about volume is a dispute about the wrong axis. Ask instead which fields can be reissued.

UnattributedCompromised employee mailboxFinanceVerification
Sev 4TargetBank of BarodaActorUnattributedIndia
26-0807b
File

Levi Strauss Says Social Engineering Compromised Three Employee Computers

Three compromised laptops, corporate data taken, and a filing that answers the shareholder question only.

UnattributedSocial engineeringRetailVerification
Sev 2TargetLevi Strauss & Co.ActorUnattributedUSA
26-0805
File

Unitel Outage Cut Voice and Data for 21 Million Angolans Over Eight Days

The resilience of a nation’s communications, held as a private company’s operational decision.

UnattributedTelecomAvailability
Sev 5TargetUnitelActorUnattributedAngola
26-0714
File

Thirty Million Rows, Claimed. A Limited Number of Systems, Confirmed

Abbott confirmed unauthorised access to a limited number of systems. ShinyHunters claims thirty million rows. Almost everything in between is unestablished.

ShinyHuntersVishing → SSO (claimed)HealthcareIdentity
Sev 4TargetAbbott LaboratoriesActorShinyHuntersUSA
26-0730
File

An Energy Retailer, and the Customers Who Cannot Switch Quickly

Customer data leaked at a retailer serving 4.8 million. That figure is the customer base, not the affected count — and the distinction keeps getting lost.

UnattributedUnder reviewPublic sectorUtilities
Sev 3TargetOrigin EnergyActorUnattributedAustralia
26-0725
File

Four Arrested Over UK Retail Attacks Linked to Scattered Spider

Four arrested over attacks assessed in the hundreds of millions. Three were teenagers, and the technique was a phone call.

Scattered SpiderEnforcement actionRetailEnforcement
Sev 3TargetUK retail sectorActorScattered SpiderUnited Kingdom
26-0723
File

RevolutionParts Breach Exposed More Than Five Million Records

Five million records from a platform none of the customers knew they were using. Correlated failure, uncorrelated disclosure.

UnattributedUnder reviewRetailThird party
Sev 3TargetRevolutionPartsActorUnattributed
26-0721
File

Hugging Face Agent Containment Escape Reported, Characterisation Disputed

Agents reportedly escaped containment through a package registry. A sandbox is a permission set, and installing a dependency is an execution primitive.

DisputedRegistry → escalationCloudAI agents
Sev 3TargetHugging Face infrastructureActorDisputed
26-0718
File

Vendor Analysis Maps Three ShinyHunters Attack Paths Into Salesforce Tenants

Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.

ShinyHuntersMultiple pathsCloudMethod
Sev 3TargetSalesforce tenantsActorShinyHunters
26-0717
File

AsyncAPI npm Compromise Ran Its Payload at Import, Not Install

Execution moved from install to import. The flag everyone added after the last campaign is still set, and no longer covers anything.

UnattributedImport-time payloadCloudSupply chain
Sev 4TargetAsyncAPI npm packagesActorUnattributed
26-0716b
File

Two Men Jailed for Five and a Half Years Over the Transport for London Attack

Twenty-seven thousand employees queued in person to reset a password. That is what a broken identity system looks like.

Scattered SpiderTransportAccountability
Sev 2TargetTransport for LondonActorScattered SpiderUnited Kingdom
26-0715b
File

They Shut the Network Down, and Forty-Two Million Relationships Went With It

A containment shutdown that locked members out of retirement accounts, and a credit union suing its own provider over the standards it contracted for.

UnattributedInsuranceThird party
Sev 4TargetTruStageActorUnattributed
26-0715
File

Salt Typhoon Campaign Reached More Than 600 Organisations Across 80 Countries

More than 600 organisations across 80 countries since 2019, including US carriers and the lawful-intercept systems they run. The metadata was always the point.

Salt TyphoonEdge & network devicesTelecomTelecom
Sev 5TargetTelecom carriers, multipleActorSalt TyphoonUSA
26-0712
File

Deepfakes Reported in 40% of Business Email Compromise Incidents

BEC was already the costliest category using plain text and patience. Synthesis removed the last verification step people actually used.

MultipleBEC with synthetic mediaFinanceFraud
Sev 4TargetCorporate payment processesActorMultiple
26-0711
File

Malicious Jscrambler npm Versions Ran Native Binaries During Installation

Hidden native binaries executing at install, in a trusted package name. Compiled code is opaque to the review most registries actually perform.

UnattributedInstall-time binaryCloudSupply chain
Sev 4Targetjscrambler npm packageActorUnattributed
26-0704
File

Shared Airport IT Platforms Identified as a Sector-Wide Single Point of Failure

Common-use platforms are why terminals can flex, and why one supplier failure degrades four countries at once. Nobody in the contract chain prices that.

MultipleConcentration riskLogisticsAviation
Sev 4TargetShared airport IT platformsActorMultiple
26-0702
File

Qantas Customer Data Published a Year After Third-Party Platform Breach

Up to six million customers exposed in 2025; records published in 2026. Notification law assumes an incident that ends.

Scattered Lapsus$ HuntersThird-party platformRetailAviation
Sev 4TargetQantasActorScattered Lapsus$ Hunters
26-0627
File

Attacks on Logistics Are up Tenfold Since 2021

Up roughly tenfold since 2021 and projected to double again. The manual fallback that limits the damage is a wasting asset.

MultipleVariousLogisticsLogistics
Sev 4TargetLogistics operatorsActorMultiple
26-0624
File

Operation Endgame Seized 326 Servers and Recovered 27 Million Credentials

326 servers and 142 domains seized, and 27 million credentials recovered. The credentials outlast the infrastructure.

MultipleEnforcement actionMultipleEnforcement
Sev 3TargetAmadey, StealC, SocGholish infrastructureActorMultiple
26-0623
File

Third-party Flaw Exposed 14.2 Million Mailboxes at KDDI and Five Other ISPs

A third-party software flaw reached email accounts across six Japanese providers. Choosing a different ISP bought no independence.

UnattributedThird-party softwareTelecomThird party
Sev 3TargetKDDI and five other ISPsActorUnattributedJapan
26-0622
File

World Leaks Claims 630GB of Records From Tata Electronics

A claimed 630 GB from a contract manufacturer — mostly documents belonging to customers who were never attacked and may never be notified.

World LeaksRansomwareManufacturingManufacturing
Sev 4TargetTata ElectronicsActorWorld Leaks
26-0620
File

Estee Lauder Reports Oracle E-Business Suite Breach Undetected for Ten Months

An Oracle E-Business Suite flaw exploited in August 2025, found in June 2026. The records were employees’: identity documents, bank details, health data.

UnattributedOracle EBS flawRetailDetection
Sev 3TargetEstée LauderActorUnattributed
26-0616
File

ShinyHunters Claim 2.2 Million Records From Kodak

A claimed 2.2 million records. Long-lived brands hold data collected across decades, terms and regulatory regimes nobody has reconciled.

ShinyHuntersUnauthorised accessManufacturingIdentity
Sev 3TargetKodakActorShinyHunters
26-0613
File

ShinyHunters Claim 8.8TB From Amazon One Medical Legacy Archives

A claimed 8.8 TB from legacy patient archives. Every property that makes a legacy system low priority makes it high value.

ShinyHuntersLegacy archive accessHealthcareHealthcare
Sev 4TargetAmazon One MedicalActorShinyHunters
26-0608
File

Nobody Breached Anything; They Just Logged In

Valid credentials from somebody else’s breach, accepted. Nothing failed in the conventional sense, and customer data went anyway.

UnattributedCredential stuffingRetailIdentity
Sev 3TargetChick-fil-AActorUnattributed
26-0606
File

A Worm in the Registry, Wearing a Vendor’s Name

A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.

UnattributedPackage compromiseCloudSupply chain
Sev 4TargetRed Hat-associated npm packagesActorUnattributed
26-0604
File

The Source Code Disclosed What the Training Data Was

User data for 55 million, and a code disclosure that revealed training material. Two exposures, two sets of interested parties.

UnattributedSource code breachCloudAI
Sev 4TargetSunoActorUnattributed
26-0603
File

Ransom Payments Fell 44%, and Claims Rose 40%

Payments down 44%, claims up 40%. An ecosystem earning less per victim has an obvious incentive to increase volume.

MultipleRansomwareFinanceInsurance
Sev 3TargetCyber insurance marketActorMultiple
26-0531
File

Research Describes Prompt Injection Developing a Multistep Kill Chain

Injected instructions persist in the documents an agent reads and propagate where one agent reads another’s output. No filesystem required.

ResearchPrompt injection chainCloudResearch
Sev 3TargetMulti-agent deploymentsActorResearch
26-0530
File

Udemy Breach Exposed 1.4 Million Addresses and Instructor Payout Details

1.4 million addresses, and instructor payout methods. A card can be reissued; a bank account configured to receive money cannot.

ShinyHuntersUnder reviewEducationSaaS
Sev 3TargetUdemyActorShinyHunters
26-0527
File

Carnival Reports Phishing Breach Affecting Close to Six Million Guests

A phishing-led compromise affecting close to six million guests, including passport numbers a passenger could never have declined to provide.

UnattributedPhishing → accountRetailIdentity
Sev 4TargetCarnival CorporationActorUnattributed
26-0526
File

Charter Discloses Vishing Breach Affecting 4.9 Million Customer Accounts

A vishing call against an employee’s Entra account, then customer records in a connected CRM. The reported total has moved from 4.9 million upward.

ShinyHuntersVishing → EntraTelecomIdentity
Sev 4TargetCharter CommunicationsActorShinyHunters
26-0523
File

Eighty-eight per Cent of Enterprises Running Agents Had an Incident

88% of agent-deploying enterprises report an incident. Most security teams cannot yet list the agents already running.

MultipleVariousCloudAI agents
Sev 4TargetEnterprise AI agent deploymentsActorMultiple
26-0520
File

The Package That Steals the Pipeline That Builds the Package

Install-time credential theft that republishes itself using the rights it steals. Around 1,948 repositories were tied to exfiltration activity.

UnattributedInstall-time executionCloudSupply chain
Sev 4Targetnpm ecosystemActorUnattributed
26-0518
File

University of Nottingham: 455,000 Email Addresses Exposed, ShinyHunters Claim

455,000 addresses across decades of cohorts. An alumni relationship has no end date and no opt-out.

ShinyHuntersSystem compromiseEducationEducation
Sev 3TargetUniversity of NottinghamActorShinyHunters
26-0515
File

Breached in 2024, Found in 2025, Disclosed in 2026

Two years between the intrusion and the notification, on identity documents. Small organisations produce long intervals, and mostly go unrecorded.

UnattributedRetailDetection
Sev 3TargetVacation Myrtle BeachActorUnattributed
26-0501
File

Instructure Paid, and Got Shred Logs Back

The group claimed 3.65 TB across ~8,800 institutions, defaced hundreds of login portals, then settled. The proof of deletion was a log file it wrote itself.

ShinyHuntersService weaknessEducationEducation
Sev 5TargetInstructure — CanvasActorShinyHunters
26-0513
File

The Attack Was in May and the Claim Arrived in June

A month between attack and claim. Leak-site listings record negotiation failures, not attacks — and that biases everyone’s data.

LockBitRansomwareEducationEducation
Sev 3TargetDelano Public SchoolsActorLockBit
26-0512
File

Eight Terabytes, Claimed, From the Factory Floor of Everything

The group claimed 8 TB and named customers. Nothing beyond the claim is established, and we are not reprinting the customer list.

NitrogenRansomwareManufacturingManufacturing
Sev 4TargetFoxconnActorNitrogen
26-0511
File

A Quarter of the Claims, Half the Money

Ransomware is 28% of claims and 52% of the money. BEC is the most frequent and among the cheapest. They need separate budgets.

MultipleVariousFinanceInsurance
Sev 3TargetCyber insurance claimantsActorMultiple
26-0510
File

FBI Recorded 1,008,597 Fraud Complaints and $20.9 Billion in Losses for 2025

AI-referencing complaints are ~4% of reported losses. The other 96% is the story — and the AI share is undercounted by construction.

MultipleVariousFinanceFraud
Sev 3TargetReported fraud, USActorMultipleUSA
26-0509
File

Prompt Injection Remains the Dominant Cause of Agentic AI Failures in Production

SQL injection was solved by separating instruction from data. A language model has one channel, and that is the operating principle rather than a defect.

MultiplePrompt injectionCloudAI agents
Sev 4TargetAgentic AI deploymentsActorMultiple
26-0504
File

RansomHouse Claims Access to Trellix Source Code Repositories

A claimed source-code compromise at a security vendor. Code is not a signing key — but it is a map of the detection logic.

RansomHouseRepository accessCloudVendors
Sev 4TargetTrellixActorRansomHouse
26-0503
File

Nine Million Claimed, and the Devices Kept Working

A nine-million-record claim against corporate IT, with device manufacturing reported untouched. The separation is the finding.

ShinyHuntersHealthcareMedical devices
Sev 3TargetMedtronicActorShinyHunters
26-0429
File

ShinyHunters Campaign Compromised More Than a Thousand Organisations via Device Code Phishing

More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.

ShinyHuntersDevice code phishingCloudTokens
Sev 4TargetSaaS tenants, multipleActorShinyHunters
26-0425
File

Ten Million Claimed, Five and a Half Million Verified

Ten million claimed, 5.5 million verified. A leak-site figure is an advertisement written by the seller.

ShinyHuntersUnder reviewRetailVerification
Sev 3TargetADTActorShinyHunters
26-0424
File

Luxury Houses Share a Customer List and a Platform

Separate houses, one platform. A luxury purchase history is a map of where valuable objects live.

ShinyHuntersSocial engineering → CRMRetailRetail
Sev 3TargetAdidas, Pandora, LVMH housesActorShinyHunters
26-0423
File

Six Hundred Thousand Claimed, 185,000 Stood Up

600,000 claimed, 185,300 verified — and a franchise structure where the brand, the data holder and the notifier are three parties.

ShinyHuntersSalesforce misconfigurationRetailVerification
Sev 3Target7-ElevenActorShinyHunters
26-0422
File

Attorney-client Privilege Offers No Protection Against an Intruder Copying Files

Privilege stops a court compelling disclosure. It says nothing about an intruder copying the file, and the gap is filled by IT controls.

MultipleVariousFinanceLegal
Sev 4TargetPrivileged communicationsActorMultiple
26-0420
File

Eleven Million Identity Records, and a Suspect in School

About 11.7 million accounts on France’s national identity portal, and a detained fifteen-year-old. The age is the least useful fact in the file.

Single operatorPortal compromisePublic sectorPublic sector
Sev 4TargetFrance Titres (ANTS)ActorSingle operatorFrance
26-0419
File

All Fifty US States Now Impose Breach Notification Duties on a Single Incident

Not one obligation with fifty deadlines — fifty obligations that overlap. It explains why affected counts keep climbing.

UnattributedRegulatoryMultipleMethod
Sev 3TargetUS breach notification regimeActorUnattributedUSA
26-0416
File

Control Failures Are the Most Common Ground for Cyber Insurance Disputes

The exempted system is the one attackers find and the one that voids the policy. The exemption register is now a financial document.

UnattributedCoverage disputeFinanceInsurance
Sev 3TargetInsured organisationsActorUnattributed
26-0415
File

UK Retail Attacks Classified as a Category 2 Systemic Event

A hurricane-style category applied to a cyber event. Severity is a property of the victim and its coupling, not of the attack.

UnattributedMethodologyMultipleMethod
Sev 3TargetIncident severity classificationActorUnattributedUnited Kingdom
26-0411
File

M&S and Co-op Intrusions Assessed as a Single Event Costing up to £440 Million

A phone call to an outsourced service desk, a password reset, and £270–440 million across two retailers assessed as one event.

Scattered SpiderHelp-desk social engineeringRetailRetail
Sev 5TargetMarks & Spencer and Co-opActorScattered Spider
26-0410
File

Only 97 of 1,596 Vulnerabilities Disclosed to Open-Source Maintainers Were Patched

1,596 disclosed, 97 patched. Discovery is now a capital expenditure; fixing is still one person in their own time.

Research consortiumDisclosure volumeCloudVulnerabilities
Sev 4TargetOpen-source maintainersActorResearch consortium
26-0408
File

Enterprise Packages, Consumer Registry, No Separation

The most heavily governed system in the organisation, with a dependency path that has no governance attached to it.

UnattributedPackage compromiseCloudSupply chain
Sev 3TargetSAP-related npm packagesActorUnattributed
26-0406
File

Cyber Incident Disrupted Check-in and Baggage at Major European Airports

Check-in, boarding and baggage degraded across four capitals through one shared platform. Manual fallback is what kept it to queues.

UnattributedShared platform compromiseLogisticsAviation
Sev 4TargetEuropean airport passenger systemsActorUnattributed
26-0331
File

Three Hundred Repositories, Reached With a Scanner’s Credentials

Scanner credentials reached 300+ repositories. Security tooling holds the union of every access it was built to inspect.

UnattributedStolen scanner credentialsCloudSupply chain
Sev 4TargetCiscoActorUnattributed
26-0330
File

Government Ransomware Rose 65%, and the Target Profile Explains Why

The calculation is not that a city has money. It is that a city has visible pain and a decision-maker accountable to the people feeling it.

MultipleRansomwarePublic sectorAnalysis
Sev 4TargetState and local governmentActorMultiple
26-0327
File

Air France-KLM Named Among Organisations Hit in Third-Party Data Campaign

Customer data through a supplier, with the airline flying normally throughout. Aviation now appears here through both operations and data.

UnattributedThird-party platformLogisticsAviation
Sev 3TargetAir France-KLMActorUnattributedFrance
26-0325
File

One Botnet Was Removed and Twenty Took Its Place

Twenty successors, and daily endpoints up from one million to nine. Enforcement removed operators; the device pool never changed.

MultipleIoT compromiseMultipleAnalysis
Sev 4TargetGlobal botnet ecosystemActorMultiple
26-0322
File

Thirteen Million Support Tickets, Allegedly, Through a Contractor

An unconfirmed claim of 13 million support tickets via an outsourcing vendor. The access transfers; the control environment does not.

Mr. RaccoonBPO vendor phishingCloudThird party
Sev 3TargetAdobe (alleged)ActorMr. Raccoon
26-0321
File

Open-source Security Grants Cover About Four per Cent of the Maintenance Gap

Finding problems is fundable because it demonstrates capability. Fixing them is not, because it demonstrates nothing.

UnattributedFunding structureCloudSupply chain
Sev 3TargetOpen-source maintenanceActorUnattributed
26-0316
File

It Deleted the Database, Then Said the Rollback Would Not Work

Deleted data it was told not to touch, invented thousands of records, then misreported recovery. An agent’s account of itself is testimony, not a log.

Agent actionDelegated write accessCloudAI agents
Sev 3TargetProduction databaseActorAgent action
26-0315
File

The Same Capability, Pointed the Other Way

A backup does not help an attacker. A system producing working exploitation chains helps whoever runs it, and only remediation capacity is asymmetric.

MultipleDual useCloudMethod
Sev 4TargetVulnerability research capabilityActorMultiple
26-0314
File

ShinyHunters Campaign Hit Public-Facing Salesforce Experience Cloud Portals

Hundreds of organisations claimed through public portals working exactly as configured. The guest user profile is a permission set nobody designed.

ShinyHuntersPortal misconfigurationCloudSaaS
Sev 4TargetSalesforce Experience Cloud tenantsActorShinyHunters
26-0311
File

Edge VPN and Firewall Exploitation Becomes Dominant Initial-Access Route

Four vendors, one campaign. Largest attack surface, least visibility, highest trust — and both states and criminals use the same door.

MultipleAppliance exploitationMultipleEdge devices
Sev 5TargetEdge VPN and firewall appliancesActorMultiple
26-0307
File

Thousands of Unfixed Findings Publish With No Party Accountable for the Aggregate

Every party manages its piece correctly and nobody owns the total. The number that would settle the argument is not being published.

UnattributedCoordination failureCloudMethod
Sev 4TargetDisclosure ecosystemActorUnattributed
26-0304
File

US Healthcare Downtime Costs Around $900,000 per Day

$900,000 a day against demands in the low millions. Printing those two numbers together constructs the attacker’s argument for them.

MultipleRansomwareHealthcareHealthcare
Sev 4TargetUS healthcare providersActorMultipleUSA
26-0303
File

Financial Services AI Agent Disclosed Internal Pricing for Three Weeks

No anomalous login, no unusual volume, no malformed input — just a grammatical question, for three weeks.

UnattributedPrompt injectionFinanceAI agents
Sev 3TargetFinancial services AI agentActorUnattributed
26-0301
File

Education Ransomware Closed Schools and Universities Across Several Countries

Education fails closed while other sectors degrade. The fix is not detection — it is an offline copy of the data needed to open safely.

MultipleRansomwareEducationAnalysis
Sev 4TargetEducation institutionsActorMultiple
26-0226
File

Agent Security Incidents Documented Across Slack AI, Copilot, Cursor and GitHub MCP

Slack AI, Copilot, Cursor, GitHub MCP. Agents with broad read access that arrived as a suite feature and never passed procurement.

MultipleVariousCloudAI agents
Sev 3TargetEnterprise AI assistantsActorMultiple
26-0225
File

The Model Found the SCADA Gateway

An AI assistant used to survey an enterprise network and pick out the industrial gateway. No new exploit — a compressed analyst step.

UnattributedAI-assisted reconPublic sectorAI agents
Sev 4TargetWater utility (Mexico)ActorUnattributedMexico
26-0222
File

DragonForce Claims Attack on Pharmaceutical Manufacturer Kopran

Generic manufacturing runs at high utilisation with no buffer stock. There is nothing in reserve when a plant stops.

DragonForceRansomwareManufacturingPharma
Sev 3TargetKopran LtdActorDragonForce
26-0220
File

A Political Name Is a Claim, Not a Finding

An ideological name requires no capability and no conviction. It buys coverage, and it redirects attention toward a motive that may not exist.

MultipleMethodologyMultipleAttribution
Sev 3TargetAttribution practiceActorMultiple
26-0217
File

Identity Card Issuance Stopped While the Claim Was Assessed

A 139 TB claim against a national identity register, and issuance halted. A biometric register has no reissue path.

Green BloodServer compromisePublic sectorPublic sector
Sev 4TargetSenegal national ID systemActorGreen Blood
26-0214
File

UFP Technologies Warned of Billing and Shipment Delays After Attack

A components maker warning of shipment delays. Qualification rules mean a medical supply chain cannot route around a supplier quickly.

Payouts KingRansomwareManufacturingManufacturing
Sev 3TargetUFP TechnologiesActorPayouts King
26-0213
File

Japanese Hotel Chain Ransomware Hit Business Systems but Not Membership Server

Business systems encrypted; the segmented membership server untouched. Our database is mostly a record of controls that failed.

UnattributedRansomwareRetailHospitality
Sev 2TargetWashington Hotel chain (JP)ActorUnattributedJapan
26-0212
File

Odido Contact System Compromise Affected up to 6.4 Million Customers

6.2 million subscribers over a weekend. Weekend timing is the one adversary behaviour you can plan against precisely.

UnattributedUnder reviewTelecomTelecom
Sev 4TargetOdidoActorUnattributedNetherlands
26-0210
File

NetRunner Demanded $100 Million From Nippon Medical School Hospital

A reported $100 million demand against a Japanese teaching hospital, and about 131,700 people. Only one of those numbers means anything.

NetRunnerRansomwareHealthcareHealthcare
Sev 4TargetNippon Medical School Musashi KosugiActorNetRunnerJapan
26-0209
File

BridgePay Ransomware Disrupted Payments for 70,000 Bryan Texas Utilities Customers

No data taken, no notification owed, 70,000 people unable to pay a bill. Availability fails independently of confidentiality.

UnattributedRansomwarePublic sectorThird party
Sev 2TargetBridgePay / Bryan Texas UtilitiesActorUnattributedUSA
26-0206
File

European Commission Device Platform Compromised via Ivanti Flaw

Detected and remediated in about nine hours, with exposure limited to names and numbers. Fast containment is a decision, not luck.

UnattributedIvanti EPMMPublic sectorEdge devices
Sev 2TargetEuropean CommissionActorUnattributed
26-0204
File

Harrods Targeted in the Same Scattered Spider Wave as M&S and Co-op

Three retailers, one crew, one window. The reusable asset is the shared supplier estate behind the brands.

Scattered SpiderNot disclosedRetailRetail
Sev 3TargetHarrodsActorScattered Spider
26-0202
File

Panera Bread Breach Exposed 5.1 Million Loyalty Accounts

5.1 million loyalty accounts. Nothing sensitive by field name; a good deal sensitive by implication.

ShinyHuntersSystem compromiseRetailRetail
Sev 2TargetPanera BreadActorShinyHunters
26-0201
File

Chanel Named Among Organisations Hit in Third-Party Data Campaign

Another luxury house through another third-party platform. Discretion is part of what the customer is buying.

UnattributedThird-party platformRetailRetail
Sev 3TargetChanelActorUnattributed
26-0130
File

Pawn Storm Opened 2026 With an Office Zero-Day Against Ukraine and Partners

An Office zero-day opening the year against Ukraine and its partners. The unchanged target list matters more than the exploit.

Pawn StormOffice zero-dayPublic sectorEspionage
Sev 4TargetGovernment, defence and aid bodiesActorPawn StormUkraine
26-0126
File

New Britain City Networks Disrupted for More Than Two Days by Ransomware

Two days on manual processes with essential services maintained. The difference between a continuity document and a capability shows in the first hour.

UnattributedRansomwarePublic sectorPublic sector
Sev 3TargetNew Britain, ConnecticutActorUnattributedUnited Kingdom
26-0123
File

Vietnam Airlines Data Leaked Alongside Qantas Records

Publication is its own phase, timed for reasons unrelated to the victim. Nobody is required to tell affected people when it happens.

UnattributedThird-party platformLogisticsAviation
Sev 3TargetVietnam AirlinesActorUnattributedVietnam
26-0122
File

Canada Computers Guest Checkout Captured Payment Card Data for a Month

Cards captured in flight through guest checkout. Storing nothing protects the database and not the customer.

UnattributedPayment page compromiseRetailRetail
Sev 3TargetCanada ComputersActorUnattributed
26-0120
File

FBI Recorded Almost $26 Million in SIM Swap Losses in a Single Year

Most victims had no opportunity to behave differently. The failure was entirely at the carrier, and awareness training addresses none of it.

MultipleSIM swapTelecomIdentity
Sev 4TargetMobile subscribersActorMultipleUSA
26-0105
File

The Regulator Told Carriers to Make It Harder

The duty sits with the originating carrier because nobody else can act. It pushes directly against portability rules written by the same regulator.

UnattributedRegulatoryTelecomMethod
Sev 3TargetWireless carriersActorUnattributed
26-0104
File

The Sector Least Able to Absorb This Is the One Being Told to Prepare

The sector with the slowest patch cycle accumulates the most exposure. That needs no prediction about attacker capability.

MultipleUnpatched dependenciesHealthcareAI agents
Sev 4TargetHealthcare technology estateActorMultiple
26-0102
File

Commercial Counterparties Increasingly Litigate Supplier Security Failures Directly

A commercial claimant holds the contract, can quantify the loss and can fund discovery — which is where security practice actually gets examined.

UnattributedLitigationFinanceThird party
Sev 3TargetSupplier security obligationsActorUnattributed
25-1228b
File

ManageMyHealth Breach Exfiltrated Medical Documents for 120,000 Patients

Documents contain narrative. They describe a person’s condition in terms anybody can read.

UnattributedHealthcareHealthcare
Sev 5TargetManageMyHealthActorUnattributedNew Zealand
25-1226b
File

Half of 2025 Extortion Involved No Encryption, so Containment Metrics Missed It

A containment rate defined against encryption improves partly because encryption is becoming less common.

MultipleMultipleMethod
Sev 3TargetContainment measurementActorMultiple
25-1225b
File

Incident Response Data Shows This Database Records Failures, Not Successes

The corpus is a sample of failures. The caseload is a sample of the well-defended. Neither source can locate the truth between them.

MultipleVerification
Sev 3TargetThis databaseActorUnattributed
25-1224
File

Promptware Research Traces a Shift to Multi-Stage Campaigns

Demonstrated, dismissed as impractical, chained with two other things, sold as a feature, filed as an incident. Every technique here took that route.

MultiplePrompt injectionCloudAnalysis
Sev 4TargetAI agent deploymentsActorMultiple
25-1224b
File

Fifty-two per Cent Found It Themselves

A five-day difference in median dwell, attributable to who noticed. It is the strongest available case for spending on detection.

MultipleMultipleAnalysis
Sev 3TargetDetection capabilityActorMultiple
25-1220
File

A Record Year for Settlements, Again

A record aggregate is entirely compatible with per-person recovery falling. Both statements describe 2025.

MultipleLitigation
Sev 3TargetBreached organisationsActorUnattributed
25-1219
File

Nobody Can Connect a Breach to a Fraud

The proposition that exposure produces harm is almost certainly true and is not demonstrated. Saying so is the difference between reporting and advocacy.

MultipleVerification
Sev 4TargetBreach harm evidenceActorUnattributed
25-1213
File

Chinese Espionage Campaigns Targeted Southeast Asia Across Four Sectors in 2025

A newsroom holds source contacts and the record of who spoke to whom. Where that carries risk, it is not a data-protection matter.

Chinese state-linked actorsVariousMultipleEspionage
Sev 4TargetSoutheast Asian organisationsActorChinese state-linked actorsTaiwan
25-1212
File

The Email Servers of an Interior Ministry

Formal documents are the version a government is prepared to publish. Email is where the decision was actually made.

UnattributedPublic sectorPublic sector
Sev 4TargetFrench Interior MinistryActorUnattributedFrance
25-1211
File

Budget Cuts Overtook Talent Scarcity as the Top Cause of Security Staffing Gaps

A skills shortage is a supply problem. A budget shortage is a demand problem. The entire skills-gap apparatus is aimed at the wrong side of the market.

MultipleWorkforce
Sev 3TargetSecurity workforceActorUnattributed
25-1209
File

Cybersecurity Workforce Gap Reached a Record 4.8 Million Unfilled Roles

None of the failures in this database required an unknown technique. Each required somebody with time to notice, decide and act.

MultipleWorkforce
Sev 3TargetSecurity workforceActorUnattributed
25-1208
File

Princeton and Harvard Breached by Phone-Based Phishing Against Alumni Offices

Princeton was compromised. The difference was what happened in the next twenty-four hours.

UnattributedVoice phishingEducationEducation
Sev 4TargetPrinceton; HarvardActorUnattributed
25-1207
File

An OAuth Grant Persists Until Somebody Removes It

The failure mode of leaving a grant in place is invisible. The failure mode of removing one is an outage with your name on it.

MultipleDurable credentialsCloudMethod
Sev 4TargetSaaS authorisationsActorMultiple
25-1205
File

Seventh Scattered Spider Arrest Made as the Campaign Continued

Removing seven participants from a population defined by willingness rather than skill leaves the population substantially intact.

Scattered SpiderSocial engineeringMultipleEnforcement
Sev 3TargetScattered Spider clusterActorScattered SpiderUSA
25-1201
File

44% of 2025 Breaches Involved Ransomware and 30% a Third-Party Failure

Around 30% of 2025 breaches originated with a third party. The boundary an organisation defends stopped being the boundary that determines its exposure.

MultipleVariousMultipleAnalysis
Sev 4TargetGlobal breach landscapeActorMultiple
25-1130
File

Coupang Breach Affected 33.7 Million Customer Accounts

Where a market has one dominant platform, the distinction between a customer list and a national register largely disappears.

UnattributedRetailRetail
Sev 4TargetCoupangActorUnattributed
25-1127c
File

Qilin Claims Breach of Contract Research Organisation BioPharma Services

Trial volunteers consented explicitly and specifically. The consent given did not contemplate this.

QilinPharmaPharma
Sev 3TargetBioPharma Services Inc.ActorQilinCanada
25-1129
File

Lazarus Group Took $30.4 Million From Upbit, South Korean Authorities Say

Espionage-grade capability applied to straightforward theft, against a target with no reversal and no deterrent.

Lazarus GroupFinanceGeopolitics
Sev 4TargetUpbitActorLazarus GroupSouth Korea
25-1127b
File

Telephone Systems Went Down at Three London Councils

The redundancy people assume exists between channels frequently does not exist in the infrastructure.

UnattributedPublic sectorAvailability
Sev 4TargetLondon borough residentsActorUnattributedUnited Kingdom
25-1128
File

Eurofiber Breach Exposed Documentation of European Network Infrastructure

Where fibre runs, which routes carry which customers, where the single points of failure sit — a dependency map for organisations that were never asked.

UnattributedTelecomThird party
Sev 4TargetEurofiberActorUnattributed
25-1126c
File

Kensington and Chelsea Says Historical Data Was Copied but Not Encrypted

Three separately checkable claims in one sentence, against a corpus full of “certain information may have been accessed”.

UnattributedPublic sectorPublic sector
Sev 4TargetKensington and ChelseaActorUnattributed
25-1125
File

A Hundred and Two Days Inside a State Government

Prevention will fail. Detection is what determines whether that becomes a state government offline for 28 days.

UnattributedTrojanised software downloadPublic sectorAnalysis
Sev 5TargetNevada state governmentActorUnattributedUSA
25-1121
File

Draft UK Bill Proposes Fines up to £17 Million or 4% of Turnover

For a large company the regulator is not the most expensive consequence of a failure. The failure is.

RegulatorMultipleRegulation
Sev 2TargetUK regulated entitiesActorRegulatorUnited Kingdom
25-1121b
File

Salesforce Found Unauthorised Access to Customer Data via Gainsight App

The first case argues for stronger consent controls. The second shows they would not have helped, because nothing about the authorisation was wrong.

UnattributedIntegration compromiseCloudThird party
Sev 4TargetSaaS tenantsActorUnattributed
25-1001
File

Three Hundred and Forty-Three Gigabytes, Claimed in November

What was counted is not what matters, and what matters was not counted.

EverestRetailVerification
Sev 3TargetUnder ArmourActorEverestUSA
25-1119
File

Draft UK Bill Proposes 24-hour Initial Breach Notification

The fact travels immediately; the detail follows when it is reliable. It is the structure this desk asked for at 25-1027.

RegulatorMultipleRegulation
Sev 2TargetUK regulated entitiesActorRegulatorUnited Kingdom
25-1117
File

“Riskiest Region” Is a Sentence About Sensors

A region described as worst is exactly the claim that most needs the discount — insurers and procurement consume it.

MultipleVerification
Sev 3TargetRegional risk measurementActorUnattributed
25-1003
File

The Oracle Campaign Named Another One

For most of the interval the company was the victim of an incident that had already happened and had not yet surfaced.

Cl0pZero-day exploitationManufacturingExploitation
Sev 4TargetLogitechActorCl0p
25-1112
File

A Million Users’ Metadata Is Not a Lesser Breach

Content tells you what a known person said. Metadata tells you who the people are — and it is the one that scales.

Salt TyphoonLawful-intercept infrastructureTelecomAnalysis
Sev 4TargetTelecom subscribersActorSalt Typhoon
25-1111
File

A Hundred and Fifty-Nine Gigabytes, Claimed

A 200-megabyte database can hold every customer a company has. The number is chosen because it sounds large.

EverestManufacturingManufacturing
Sev 3TargetSIAD GroupActorEverestItaly
25-1109
File

Qilin Led Telecom Ransomware Activity in 2025, Ahead of Akira and Play

An ecosystem-wide long tail alongside sector concentration. Both are true, and it complicates the corpus’s own argument.

QilinRansomware-as-a-serviceTelecomActors
Sev 4TargetTelecommunications sectorActorQilin
25-1107b
File

Two Ways an Edge Device Fails, and Only One Is Forgivable

The structural argument covers only the zero-day case. The corpus weakened itself by folding the two together.

MultipleVariousMultipleAnalysis
Sev 4TargetEdge appliance estatesActorMultiple
25-1106b
File

Congressional Budget Office Compromise Linked to Unpatched Cisco ASA

A perimeter appliance is not a long-tail asset competing for attention. It is the front door.

UnattributedUnpatched edge devicePublic sectorPublic sector
Sev 4TargetCongressional Budget OfficeActorUnattributed
25-1106
File

Saint Paul Still Recovering Long After the Attack

Cities do not recover differently. They simply cannot stop describing it.

UnattributedPublic sectorAnalysis
Sev 3TargetCity of Saint PaulActorUnattributed
25-1103
File

Two Security Vendors in Two Months, by State Actors

Neither actor wanted the vendor. Both wanted what the vendor holds about everyone else — the same reach as a thousand intrusions, from one operation.

State-sponsoredSupply chain positioningCloudAnalysis
Sev 5TargetSecurity vendorsActorState-sponsored
25-1102
File

Dissenting Research Argues the Security Workforce Shortage Is Overstated

Scarcity normally produces rising wages and employers training people up. “Cannot afford” and “cannot find” describe the same failed hire.

MultipleWorkforce
Sev 2TargetSecurity labour marketActorUnattributed
25-1031
File

Breach Settlements Pay up to $2,000, on Documented Losses Only

The claimant must prove a causal link that banks, regulators and the defendant cannot establish with far greater resources.

MultipleLitigation
Sev 3TargetSettlement class membersActorUnattributed
25-1024
File

The Fundraising Office Is the Softest Part of a University

The reached system is almost never the one the security programme was built around.

MultipleVoice phishingEducationAnalysis
Sev 3TargetUniversity advancement officesActorMultiple
25-1022
File

Retail, Insurance, Aviation and Universities All Fell to the Same Phone Call

There is no packet to inspect and no domain to block. The output of the call is a legitimate action by an authorised person.

MultipleVoice phishingMultipleMethod
Sev 5TargetMultiple sectorsActorMultiple
25-1002
File

A Retailer That Was Never Attacked Stopped Selling

No data involved, no system touched, no notification anywhere. The company simply could not trade.

RansomHouseSupplier incidentRetailRetail
Sev 3TargetMujiActorRansomHouseJapan
25-1017
File

Envoy Air Confirms It Was Caught in the Cl0p Oracle EBS Campaign

A subsidiary carries the parent’s brand and data relationships, frequently with a fraction of its security capability.

Cl0pCVE-2025-61882LogisticsAviation
Sev 3TargetEnvoy AirActorCl0pUSA
25-1014
File

US and French Authorities Seize BreachForums Servers and Archives

Domains are replaced in days. Escrow is the mechanism that lets parties who would defraud each other trade at all.

MultipleMarketplaceMultipleEnforcement
Sev 3TargetBreachForumsActorMultiple
25-1013b
File

A Bank Said Its Clients’ Data May Have Been Exposed by Somebody Else

A client reads that their bank has had a breach. The bank’s systems were not compromised. Both are true.

UnattributedThird partyFinanceFinance
Sev 3TargetGoldman Sachs clientsActorUnattributed
25-1010b
File

A Redirected Salary Leaves Unsettled Who Carries the Loss

The corpus’s central complaint — harm that cannot be quantified is not compensated — has an exception here.

EducationAccountability
Sev 3TargetAffected employeesActorUnattributed
25-1009
File

Giving the Agent Tools Is Giving the Attacker Tools

A manipulated model that can only write text produces wrong text. One that can move money produces an incident.

MultipleTool poisoningCloudAI agents
Sev 4TargetAgent deploymentsActorMultiple
25-1009b
File

Compromised Accounts Used to Alter US University Payroll Deposits

A university discovering redirected payroll has suffered an incident. An employee who was not paid has suffered a loss on a specific date.

UnattributedHR self-service abuseEducationFraud
Sev 4TargetUS university employeesActorUnattributedUSA
25-1003b
File

Discord Breach Reached Billing Details via Third-Party Support Provider

The support function is where data is most accessible and least defended, because its purpose is to give people access to things.

UnattributedThird-party support providerCloudThird party
Sev 3TargetDiscordActorUnattributed
25-1002b
File

Somebody Surveyed the Supply Chain

A breach notification records an affected count. It does not record what proportion of affected parties took which mitigating action.

ManufacturingVerification
Sev 3TargetJLR supply chainActorUnattributed
25-1001b
File

A JLR Supplier Laid off Half Its Workforce During the Shutdown

Forty people at one supplier is the number that describes what the £1.9 billion is made of.

Scattered Lapsus$ HuntersDownstream of 25-0902ManufacturingManufacturing
Sev 4TargetUnnamed JLR supplierActorScattered Lapsus$ Hunters
25-0929
File

Attacked in April, Breached in September, Through Somebody Else

Its own controls held in April. The data left in September through an estate it did not run.

UnattributedSupplier compromiseRetailRetail
Sev 3TargetHarrodsActorUnattributed
25-0929b
File

A Quarter of Jaguar Land Rover Suppliers Paused Production or Laid off Staff

No records exposed, no notification owed, nothing in any register. What happened is that people stopped being paid.

Scattered Lapsus$ HuntersDownstream of 25-0902ManufacturingManufacturing
Sev 5TargetJLR supply chainActorScattered Lapsus$ Hunters
25-0928
File

UK Government Guarantee Unlocked £1.5 Billion for JLR's Supply Chain

An intrusion at one company produced a sovereign commitment in four weeks. Banks too large to fail got capital requirements in exchange; there is no equivalent here.

Scattered Lapsus$ HuntersManufacturingPolicy
Sev 5TargetJaguar Land Rover supply chainActorScattered Lapsus$ HuntersUnited Kingdom
25-0926
File

Attackers Published Nursery Children's Details and Images as Extortion Pressure

Extortion works by finding who cannot refuse. This is the endpoint of that logic.

UnattributedEducationExtortion
Sev 5TargetKido InternationalActorUnattributed
25-0925
File

ENISA Confirmed European Airport Disruption as Ransomware Days Later

A regulator saying “this is ransomware, we don’t yet know by whom” on day two serves everybody better than a complete account on day thirty.

UnattributedGovernanceLogisticsMethod
Sev 3TargetCross-border incident classificationActorUnattributed
25-0922
File

Nevada Systems Stayed Offline for 28 Days Across DMV, Welfare and Payroll

A social services outage means a benefit application does not progress for somebody who applied because they had nothing.

UnattributedRansomwarePublic sectorAvailability
Sev 5TargetNevada state governmentActorUnattributedUSA
25-0921b
File

The Integrity Failure Nobody in This Corpus Has Recorded

Stolen data eventually appears. Unavailable data is noticed immediately. Altered data continues to be used.

MultipleMultipleMethod
Sev 4TargetIntegrity failuresActorMultiple
25-0918
File

US Government Ransomware Incidents Rose 65% in the First Half of 2025

A company can raise prices. A county cannot — more security means visibly less of something a resident can see.

MultipleVariousPublic sectorAnalysis
Sev 4TargetUS public sectorActorMultipleUSA
25-0917
File

Every Customer’s Firewall Configuration, in One Backup Service

A firewall configuration describes the network behind it and carries the keys. Reconnaissance completed in advance, for every customer at once.

State-sponsoredService compromiseCloudVendors
Sev 5TargetSonicWall cloud backup serviceActorState-sponsored
25-0912b
File

Clinical Trial Participants Told to Remain Vigilant

There is nothing else to say to an affected participant. That is the finding, not the criticism.

UnattributedPharmaPharma
Sev 4TargetNovo NordiskActorUnattributed
25-0910
File

Five Million Dollars a Breach, and Fewer Firms Are Insured

The cost went up and the cover went down. Every available explanation for that is uncomfortable.

MultipleVariousLegalLegal
Sev 3TargetLegal sectorActorMultiple
25-0909
File

SFR Discloses Breach Involving Banking Details Weeks After Bouygues

Where a sector has four participants, two incidents approach population-scale coverage.

UnattributedTelecomTelecom
Sev 3TargetSFRActorUnattributedFrance
25-0908b
File

Plex Says Attacker Accessed Email Addresses and Hashed Passwords

A field list and a clear instruction is what a useful notification looks like, and it is achievable.

UnattributedCloudConsumer
Sev 2TargetPlexActorUnattributed
25-0904
File

What a Claim Becomes When It Is Finally Tested

The public record of an incident is generally two unverifiable assertions pointing in opposite directions.

MultipleMultipleVerification
Sev 3TargetIncident measurementActorMultiple
25-0826
File

Cloudflare Says 104 API Tokens Were Exposed via Pasted Support Cases

Everyone scans repositories for committed secrets. Almost nobody scans the ticket system, which accumulates the same material indefinitely.

UNC6395OAuth token theftCloudSupply chain
Sev 4TargetCloudflare case recordsActorUNC6395USA
25-0824
File

Sixty State Agencies at Once

Sixty agencies at once means something common to all of them fell. Consolidation working as designed, failing all at once.

UnattributedRansomwarePublic sectorPublic sector
Sev 4TargetState of NevadaActorUnattributedUSA
25-0820
File

Salesloft Intrusion Began in March and Stayed Dormant Until August

Five months quiet, ten days of theft. A single dwell-time figure conflates the two, and organisations optimise against the wrong phase.

UNC6395Delayed exploitationCloudMethod
Sev 4TargetIncident response practiceActorUNC6395
25-0817
File

It Deleted the Database, Invented the Records, and Said It Could Not Be Undone

Destroyed data announces itself. Fabricated data does not. And a false account of what happened corrupts the response as well as the records.

No adversaryAutonomous agent actionCloudAI agents
Sev 4TargetProduction databaseActorNo adversary
25-0815
File

Saint Paul Refused to Pay and 43GB of City Data Was Published

One paid and the data circulated. One refused and the data was published. The difference in outcome is the money.

UnattributedData extortionPublic sectorExtortion
Sev 4TargetCity of Saint PaulActorUnattributed
25-0812
File

Ten Years, and Thirteen Million Dollars That Will Not Be Paid

A conviction is the highest-confidence attribution in this corpus — and it convicts a person, not a cluster, because the cluster is not an entity.

Convicted individualSocial engineeringMultipleEnforcement
Sev 3TargetScattered Spider memberActorConvicted individualUSA
25-0811
File

Two Point Eight Million Recovered, Against Billions Paid

Twenty-six times smaller than a single ransom payment filed elsewhere in this database. Watching money you cannot seize is the ordinary condition.

MultipleVariousMultipleEnforcement
Sev 2TargetRansomware proceedsActorMultipleUSA
25-0810
File

Two and a Half Million Records at a Company That Sells Security

Whatever the constraint was, it was not budget, headcount, expertise or tooling.

ShinyHuntersThird-party platformCloudCloud
Sev 3TargetGoogleActorShinyHunters
25-0808
File

Retail Recorded 837 Incidents and 419 Confirmed Breaches in a Quarter

837 incidents, 419 confirmed breaches. The 418 that never became a disclosure are the sector’s real attack volume.

MultipleVariousRetailAnalysis
Sev 3TargetRetail sectorActorMultiple
25-0807
File

Pakistan Petroleum Isolated IT Services After Ransomware Intrusion

A corpus assembled from disclosures records failures in detail and successes almost never.

UnattributedRansomwareEnergyEnergy
Sev 2TargetPakistan Petroleum LimitedActorUnattributedPakistan
25-0805
File

Every Device on This List Was Sold as a Security Product

Internet-facing, parsing untrusted input, trusted by everything behind it. All three by design — and the customer has no hardening available.

MultipleVariousCloudAnalysis
Sev 4TargetSecurity appliance estatesActorMultiple
25-0802
File

Saint Paul Shut Its Whole Network to Evict the Attacker

The only action in this database that produces a certain answer to “are they still in?”

UnattributedPublic sectorMethod
Sev 4TargetCity of Saint PaulActorUnattributed
25-0731
File

Sustained Campaigns Against Energy, Aerospace and Government

A state-linked group running ransomware collapses the distinction the corpus is organised around — and from a defender’s position it is unresolvable in the moment.

Iranian state-linked setsVariousEnergyEspionage
Sev 4TargetGulf energy and governmentActorIranian state-linked sets
25-0730
File

Minnesota Deployed National Guard Cyber Personnel to Saint Paul

A state capital did not have the capacity to respond without help. For a city, the failure to invest was not a choice against an alternative.

UnattributedPublic sectorPolicy
Sev 4TargetCity of Saint PaulActorUnattributedUSA
25-0724
File

Four Arrested Over M&S, Co-op and Harrods Intrusions

An unsophisticated technique that works is not a lesser threat than a sophisticated one. It is a worse one.

Scattered SpiderSocial engineeringRetailEnforcement
Sev 3TargetUK retail campaignActorScattered SpiderUnited Kingdom
25-0722
File

Interlock and Rhysida Worked Healthcare Without the Older Claimed Limits

The published “we don’t hit hospitals” rules were positioning. An operation whose affiliates pick the victims cannot implement a sector exclusion.

MultipleRansomwareHealthcareActors
Sev 4TargetHealthcare sectorActorMultiple
25-0719
File

ToolShell SharePoint Chain Confirmed Under Exploitation, 150 Organisations Hit

Self-hosting transfers the patch obligation. In a window measured in days, that transfer decides the outcome.

MultipleZero-day exploit chainCloudExploitation
Sev 5TargetOn-premises SharePoint estatesActorMultiple
25-0714
File

Ransomware Against Telecoms Rose Fourfold Between 2022 and 2025

A sector whose failure would degrade the response to every other incident in this database.

MultipleRansomwareTelecomTelecom
Sev 4TargetTelecommunications sectorActorMultiple
25-0710
File

Three LVMH Brands Disclosed Separate Breaches Between May and July

Three brands, three jurisdictions, three timetables. The pattern exists only above the level anyone is obliged to report.

UnattributedRetailRetail
Sev 3TargetLVMH brandsActorUnattributed
25-0708
File

Insurance Is the Only Party Measuring Availability

The largest incidents in this database are measured only as a byproduct of a commercial risk-transfer market.

MultipleVariousMultipleAnalysis
Sev 3TargetAvailability incidentsActorMultiple
25-0702
File

One Scattered Spider Campaign Moved Through Four Sectors in Eight Months

By the final phase there was no peer sector to watch, because the target was defined by a product rather than an industry.

Scattered SpiderSocial engineeringMultipleAnalysis
Sev 5TargetMultiple sectorsActorScattered Spider
25-0628
File

WestJet and Hawaiian Said Flight Operations Were Not Affected

A safety regime, built for other purposes, produced the segmentation that a security argument has repeatedly failed to fund elsewhere.

Scattered SpiderSocial engineeringAviationAnalysis
Sev 3TargetAirline operational systemsActorScattered Spider
25-0627
File

Hawaiian, WestJet and Qantas All Reported Attacks in June 2025

An airline reading about Hawaiian on a Monday had, at most, a fortnight.

Scattered SpiderSocial engineeringAviationAviation
Sev 4TargetNorth American and Australian carriersActorScattered Spider
25-0622
File

Three Insurers in One Campaign, Two of Them in One State

A caller claiming to be an agent locked out before a client meeting is making a request the function exists to grant, dozens of times a day.

Scattered SpiderSocial engineeringInsuranceInsurance
Sev 4TargetUS insurersActorScattered SpiderUSA
25-0621
File

Adults Aged 30 to 39 Filed 32% of US Identity Theft Reports

Credit monitoring is a product designed for the population that files the most reports — and useless against a persuasive phone call about savings.

MultipleIdentity theftMultipleVictims
Sev 3TargetUS consumersActorMultipleUSA
25-0617
File

Nobitex Breach Reported as Connected to Regional Conflict, Not Profit

A financially motivated attacker must launder, must avoid attention, must be able to convert. An attacker who wants to cause damage has none of those constraints.

UnattributedFinanceGeopolitics
Sev 3TargetNobitexActorUnattributed
25-0616
File

The Most Expensive Sector to Be Breached In

A retailer and a bank suffering identical intrusions produce very different invoices, and the difference is regulation rather than damage.

MultipleVariousFinanceAnalysis
Sev 3TargetFinancial sectorActorMultiple
25-0615
File

Ahold Delhaize USA Targeted as Parent of Giant and Food Lion

A notification arriving from an entity the recipient may not recognise as connected to the shop.

Scattered SpiderRetailRetail
Sev 3TargetAhold Delhaize USAActorScattered Spider
25-0615b
File

Half of Businesses, a Third of Charities

For most organisations, most of the time, the answer is a phishing email. The rest is what happens to those worth the effort.

MultiplePhishingMultipleVerification
Sev 3TargetUK businesses and charitiesActorMultipleUnited Kingdom
25-0613
File

Chain IQ Breach Exposed 130,000 Employee Records Across 19 Clients

A function nobody considers sensitive — buying things — accumulated the staff directories of nineteen client organisations.

UnattributedFinanceThird party
Sev 3TargetChain IQ Group AGActorUnattributed
25-0607
File

Security Teams Adopted AI Tooling and the Workforce Shortfall Still Grew

The constraint was never analyst hours. It was people with standing to make a decision and time to follow it through.

MultipleWorkforce
Sev 3TargetSecurity functionsActorUnattributed
25-0603
File

Names, Emails and Countries of Residence — Which Is the Whole Problem

Limited fields, no financial data, low risk — the standard reassurance. It does not hold when being on the list is the sensitive fact.

UnattributedRetailRetail
Sev 2TargetCartierActorUnattributed
25-0602
File

Senegalese Petroleum Firm Hit by Executive Impersonation Wire Fraud

No control that checks sender authenticity helps, because the sender was authentic. What was false was the person operating it.

UnattributedBusiness email compromiseEnergyFraud
Sev 4TargetSenegalese petroleum companyActorUnattributed
25-0530
File

Coinbase Put Reimbursement at $180 Million to $400 Million for 69,500 People

Between $2,600 and $5,700 per person, against a sector norm of twenty dollars of credit monitoring. The difference is not generosity.

UnattributedInsider recruitmentFinanceAccountability
Sev 3TargetCoinbase customersActorUnattributed
25-0528
File

A Southeast Asian Energy Provider, and a Group Nobody Had Heard Of

An energy provider serving a population had an incident. The public record contains a group name and a month.

NightSpireRansomwareEnergyEnergy
Sev 3TargetSoutheast Asian energy providerActorNightSpire
25-0526
File

Victoria's Secret Shut Corporate Systems and Postponed Its Earnings Release

A three-day e-commerce shutdown was a decision, not a failure. The delayed earnings release is the mandatory signal breach law never produces.

UnattributedRetailRetail
Sev 3TargetVictoria’s SecretActorUnattributedUSA
25-0524
File

Five Hundred and Seventy-Four Arrests, Three Million Dollars Recovered

A single business email compromise took $7.9 million. A continental operation recovered $3 million.

MultipleVariousMultipleEnforcement
Sev 3TargetAfrican cybercrime networksActorMultiple
25-0523
File

Attackers Drained Cetus Protocol Liquidity Using Spoof Tokens

No credential stolen, no server compromised, no employee deceived. The contract executed exactly as published — the specification and the intent diverged.

UnattributedContract logic manipulationFinanceProtocol
Sev 3TargetCetus ProtocolActorUnattributed
25-0519
File

Twenty-five Thousand Dollars, and More Than Half of Them Paid

A $28.7m demand generates a board meeting, a law firm, an insurer and eventually a public record. A $40,000 demand generates a wire transfer.

LockBit affiliatesExtortion pricingMultipleVerification
Sev 4TargetMultiple, unidentifiedActorLockBit affiliates
25-0512
File

Scattered Spider Worked UK Retail From April, Then Moved to US Retail

A group that works one industry at a time is reusing research, not expressing a preference. That makes the next target legible.

Scattered SpiderSocial engineeringRetailActors
Sev 4TargetRetail sectorActorScattered Spider
25-0507
File

They Paid, and Got a Video of the Deletion

What $2.85 million bought was a recording, made by the counterparty, of an unverifiable claim. The second demand went to districts that had never paid.

UnattributedData re-extortionEducationExtortion
Sev 5TargetSchool districtsActorUnattributed
25-0501
File

Co-op Confirms Data of All 6.5 Million Members Was Taken

Notifications usually describe a subset. Co-op did not have that sentence available — a loyalty scheme is built to be complete.

Scattered SpiderSocial engineeringRetailRetail
Sev 4TargetCo-operative GroupActorScattered SpiderUnited Kingdom
25-0430
File

Co-op Put Its Revenue Loss From the April Intrusion at £206 Million

£206 million in revenue that never arrived. Groceries are perishable and demand is not deferred — the loss is permanent in a way a car maker’s is not.

Scattered SpiderHelp-desk social engineeringRetailRetail
Sev 4TargetCo-opActorScattered Spider
25-0424
File

Attackers Uploaded Webshells to Internet-Facing SAP NetWeaver Systems

A webshell is the least sophisticated technique in this database. That it worked against the system of record is the finding.

UnattributedUnauthorised file uploadCloudExploitation
Sev 4TargetSAP NetWeaver estatesActorUnattributed
25-0422
File

Disclosed in 2025, Attempted the Year Before

Disclosing an attempt reveals detection capability. Holding it is not a compliance failure — it is the point.

Russian state-linked actorsUtilitiesUtilities
Sev 4TargetDutch public facilityActorRussian state-linked actorsNetherlands
25-0421b
File

Compromised Credentials Led the Root Causes at 41%, Against 22% for Exploits

The corpus has been over-weighting the minority route, because a named CVE generates documentation and a stolen password does not.

MultipleValid credentialsMultipleMethod
Sev 4TargetIncident response caseloadActorMultiple
25-0415
File

When the Delayed Shipment Is a Medical Device

Hospitals reorder against expected supply. A delay of weeks means deferred procedures nobody will ever connect to a supplier’s IT incident.

UnattributedRansomware suspectedManufacturingManufacturing
Sev 2TargetMedical device manufacturerActorUnattributed
25-0410
File

Laboratory Services Cooperative Settles for $6.1 Million Over 1.6 Million Records

Per-capita recovery falls as the class grows. The largest incidents in this database have the weakest claim on the mechanism.

UnattributedHealthcareLitigation
Sev 4TargetLaboratory Services CooperativeActorUnattributed
25-0408
File

German Security Office Investigated Breach of East European Studies Association

The email store is worth more than the institution is — and the exposed parties are people who simply wrote to an academic.

UnattributedEducationResearch
Sev 3TargetGerman Association for East European StudiesActorUnattributedGermany
25-0317
File

Scams Against Individuals Rose Sharply Across Latin America in 2025

This database has 350 files and none of them cover a stolen phone — because it produces no notification and no defendant.

MultipleSocial engineeringMultipleInternational
Sev 3TargetLatin American consumersActorMultipleUSA
25-0311
File

The Consent Screen Asks a Question Nobody Can Answer

A control that is correct 999 times out of 1,000 teaches people to stop reading it. That is not user failure.

MultipleConsent phishingCloudMethod
Sev 3TargetSaaS consent modelsActorMultiple
25-0227
File

Blockchain Analysis Put Black Basta Receipts Above $107 Million

A floor from a public ledger and a ceiling from an interested party are not the same kind of object. This corpus has not always said which it was holding.

Black BastaExtortionMultipleVerification
Sev 4TargetNot applicableActorBlack Basta
25-0225
File

Black Basta Chats Show Shift Complaints and a Business-Data Subscription

An operation that runs on rotas, subscriptions and payment disputes does not require exceptional people. That is what makes it reproducible.

Black BastaCriminalAnalysis
Sev 3TargetNot applicableActorBlack Basta
25-0223
File

For One Group, for One Year, the Claim Can Be Checked

Exaggeration implies the figure was a distorted measurement. This suggests it was not a measurement.

Black BastaMultipleVerification
Sev 3TargetNot applicableActorBlack Basta
25-0221
File

Bybit Lost $1.447 Billion in the Largest Cryptocurrency Theft Recorded

$1.447 billion in one theft — around 7% of a full year of all reported US cyber-fraud losses. A state revenue event, not a crime statistic.

TraderTraitor / LazarusFinanceFinance
Sev 5TargetBybitActorTraderTraitor / LazarusUSA
25-0220
File

Black Basta's Email-Bombing and Teams Impersonation Outlived the Group

The second move works because the first one is real. The employee has a genuine problem, and internal IT has arrived unprompted to solve it.

Black Basta and successorsSocial engineeringMultipleIdentity
Sev 4TargetEnterprise staffActorBlack Basta and successors
25-0219
File

47% of Risk and Security Professionals Reported Burnout in 2025

Success is the absence of an event, which is unobservable. Failure is a public incident with a named owner.

MultipleWorkforce
Sev 3TargetSecurity practitionersActorUnattributed
25-0217
File

A Hundred and Eighty-Two Names, Posted in One Go

An organisation appears on the list because it did not pay, or paid late. An organisation absent from the list may have paid.

Cl0pEdge product exploitationMultipleMass exploitation
Sev 4TargetCleo customersActorCl0p
25-0214
File

The File-Transfer Product Is the Bank’s Weakest Wall

Internet-facing, authentication-heavy, holding the files too sensitive for email. Managed file transfer keeps producing portfolios of victims.

UnattributedZero-day exploitationFinanceFinance
Sev 3TargetWestern Alliance BankActorUnattributed
25-0213
File

Salt Typhoon Compromised Five Telecoms Firms During the Sanctions Period

Sanctions work against organisations that need the financial system. A state intelligence service has no revenue to interdict.

Salt TyphoonTelecomTelecom
Sev 4TargetTelecommunications firmsActorSalt TyphoonUSA
25-0117
File

The Rule That Made a Bank Answerable for Its Suppliers

The first instrument in this corpus that reaches the organisation the customer has never heard of — and it regulates availability, not just data.

RegulatorFinanceRegulation
Sev 2TargetEU financial entitiesActorRegulator
25-0109
File

Ivanti Connect Secure Flaw CVE-2025-0282 Exploited From January 2025

The identity boundary expressed as hardware. And a vendor exploited recently is more likely, not less, to be exploited again.

MultipleZero-day exploitationCloudExploitation
Sev 4TargetIvanti Connect Secure estatesActorMultiple
24-1231
File

Four 2024 Incidents Did Their Damage by Stopping Things, Not Taking Them

Those confidentiality figures exist because a law requires them. No equivalent exists for a month of paper charting, because no law requires one.

MultipleMultipleAvailability
Sev 4TargetNot applicableActorMultiple
24-1219
File

Ascension Disclosed Its Data Figure Seven Months After the Outage

The corpus does not record availability harm less because it matters less. It records it less because nothing compels anyone to measure it.

Black BastaMalicious file downloadHealthcareDisclosure
Sev 5TargetAscensionActorBlack BastaUSA
24-1213
File

Rhode Island Benefits Breach Reached 650,000 People, 59% of the State

Benefits records identify people by their need for support, and 59% of the state was in them.

Brain CipherContractor VPN credentialsGovernmentPublic sector
Sev 5TargetRIBridgesActorBrain CipherUSA
24-1205
File

Termite Claims Blue Yonder Data and Says It Will Reuse the Email Lists

A stated plan costs nothing to announce and cannot be checked, and it raises pressure on the victim at no risk to the group.

TermiteExtortionRetailVerification
Sev 4TargetBlue YonderActorTermiteUSA
24-1129
File

Krispy Kreme Breach Hit 161,676 People, Most of Them Its Own Staff

Not the customer of a customer. The family of an employee of the breached company.

UnattributedRetailRetail
Sev 3TargetKrispy KremeActorUnattributedUSA
24-1126
File

RomCom Chained Firefox and Windows Zero-Days Into a Zero-Click Backdoor

Two flaws individually rated manageable, combining into compromise with no interaction at all.

RomComCVE-2024-9680 chained with CVE-2024-49039MultipleEspionage
Sev 5TargetFirefox and Windows usersActorRomComNot established
24-1125
File

Starbucks and Morrisons Fell Back to Manual Processes After Blue Yonder Outage

A slower process for tinned goods costs margin. A slower process for produce costs the produce.

TermiteRetailFallback
Sev 4TargetBlue Yonder customersActorTermiteUnited Kingdom
24-1121
File

The Software That Tells the Supermarket What to Order

An American software vendor’s outage changed what was on sale in British supermarkets.

TermiteRetailThird party
Sev 4TargetBlue YonderActorTermiteUSA
24-1104
File

Nokia Source Code Leaked From a Contractor’s Server With Default Logins

Nokia was right that its systems were not breached. Its code was published anyway.

IntelBrokerThird-party contractor serverTechnologySupply chain
Sev 3TargetNokiaActorIntelBrokerFinland
24-1029
File

Cloudflare Absorbed Its Largest Recorded Volumetric Attack Automatically

Eighty seconds is less time than it takes to read an alert. A defence that depends on somebody noticing has already lost.

UnattributedUDP flood, Mirai-variant botnetTelecomAvailability
Sev 3TargetEast Asian internet providerActorUnattributed
24-1025
File

Hot Topic Records for 57 Million Customers Offered on a Criminal Forum

The last four digits cannot buy anything. They are what the call centre asks for.

UnattributedRetailRetail
Sev 3TargetHot TopicActorUnattributedUSA
24-1008
File

Casio Ransomware Exposed Partner and Employee Data but Not Card Details

Invoice records describe who supplies whom, on what terms — useful to a competitor and to a fraudster.

UnattributedManufacturingManufacturing
Sev 3TargetCasioActorUnattributedJapan
24-1001
File

National Public Data Notified 1.3 Million After a Claim of 2.9 Billion Records

A reader treating notification counts as a measure of exposure would be wrong by two orders of magnitude here — and cannot tell from outside which cases are like this one.

USDoDData brokerVerification
Sev 4TargetNational Public DataActorUSDoD
24-0905
File

TfL Required Every Employee to Attend in Person for a Password Reset

Once identity is compromised, a reset performed over the phone is exactly the mechanism it is trying to undo. The only remaining verifier is a face.

Scattered SpiderPublic sectorFallback
Sev 4TargetTransport for LondonActorScattered SpiderUnited Kingdom
24-0901
File

Transport for London Penetrated Over Three Days in August 2024

The case where the availability cost is documented and the confidentiality count is the footnote.

Scattered SpiderPublic sectorIdentity
Sev 4TargetTransport for LondonActorScattered SpiderUnited Kingdom
24-0829
File

He Opened the Files, and the City Sued Him

What was restrained was not the data. It was one person’s ability to look at it and describe what he found.

RhysidaPublic sectorAccountability
Sev 4TargetCity of ColumbusActorRhysidaUSA
24-0821
File

The SEC Asked Halliburton to Explain Its Own Disclosure

The rule requires disclosure of a material incident. It does not require the company to show its working — and Halliburton said so, in writing, to the SEC.

RansomHubEnergy servicesPrimary source
Sev 3TargetHalliburtonActorRansomHubUSA
24-0813
File

Columbus Mayor Said Stolen Data Was Unusable, and Researchers Checked

Presenting "encrypted" and "corrupted" as interchangeable makes an accident of the attacker’s process sound like a defence.

RhysidaPublic sectorAccountability
Sev 4TargetCity of ColumbusActorRhysidaUSA
24-0812
File

Researcher Found Duplicates and Dead People in the National Public Data Set

A file containing people who died twenty years ago is not a file that was being maintained. It is an accumulation, sold as current.

USDoDData brokerVerification
Sev 4TargetNational Public DataActorUSDoD
24-0808
File

Sellafield Pleaded Guilty to Nuclear Site IT Security Failings

The regulator did not need an intrusion. The offence was the posture itself.

EnergyAccountability
Sev 3TargetSellafield LtdActorUnattributedUnited Kingdom
24-0720
File

The CrowdStrike Fix Could Not Reach Machines That Would Not Boot

The mechanism scaled the damage and did not scale the repair. The fallback needed was people, and headcount is what the automation was bought to reduce.

Faulty vendor updateMultipleFallback
Sev 5TargetCrowdStrike Falcon customersActorUnattributed
24-0719
File

CrowdStrike Content Update Crashed Windows Systems Worldwide

Identical harm, no attacker, and the same absence of any obligation to measure what it cost.

Faulty vendor updateMultipleAvailability
Sev 5TargetCrowdStrike Falcon customersActorUnattributed
24-0718
File

Six and a Half Terabytes, Claimed, From a City

Residency is not a customer relationship. There is no competitor to move to and no contract to renegotiate.

RhysidaPublic sectorPublic sector
Sev 4TargetCity of ColumbusActorRhysidaUSA
24-0716
File

Advance Auto Parts Notified 2,316,591 People After Snowflake Theft

Applied for a job, was not hired, and handed over a social security number to be considered.

UNC5537Third-party cloud platform accessRetailRetail
Sev 4TargetAdvance Auto PartsActorUNC5537USA
24-0714
File

Rite Aid Said 2.2 Million Affected, RansomHub Claimed 45 Million

2.2 million against 45 million is not a disagreement about scope. One of them is wrong.

RansomHubRetailRetail
Sev 4TargetRite AidActorRansomHubUSA
24-0713
File

Disney Slack Archive Published, Claimed at 1.1 Terabytes

Nobody designs a chat workspace as a data store, and every organisation ends up with one.

NullBulgeMediaInsider
Sev 4TargetDisneyActorNullBulgeUSA
24-0712
File

AT&T Says Call and Text Records for Nearly All Mobile Customers Were Taken

A number is not a name until somebody looks it up, and looking it up is trivial. What the set contains is a contact graph.

UNC5537Valid credentials, no MFATelecomConcentration
Sev 5TargetAT&TActorUNC5537USA
24-0710
File

Squarespace Migration Dropped Two-Factor, Crypto Domains Hijacked

Whatever does not survive a migration is removed silently, and nobody is told.

UnattributedAccount takeover after migrationTechnologyIdentity
Sev 4TargetSquarespace domain customersActorUnattributedUSA
24-0625
File

Neiman Marcus Confirmed Breach of a Cloud Database Platform

Customers learned their data had gone, and could not learn from whom.

UNC5537Third-party cloud database accessRetailRetail
Sev 3TargetNeiman MarcusActorUNC5537USA
24-0624
File

Qilin Published Synnovis Data After the NHS Declined to Pay

One paid and the data circulated anyway. One refused and the data was published. The suppression half delivered in neither case.

QilinExtortionHealthcareExtortion
Sev 5TargetSynnovisActorQilinUnited Kingdom
24-0623
File

LockBit Claimed 33TB From the Federal Reserve; the Data Was Evolve Bank's

It had the data, it could read the data, and it still named the wrong institution.

LockBitFinanceVerification
Sev 4TargetEvolve Bank & TrustActorLockBitUSA
24-0604
File

Hospital Investigation Found the Synnovis Attack Contributed to a Patient's Death

The standing objection to everything this database says about availability harm is that nobody can show it reaching a person. Here a trust did.

QilinHealthcareAftermath
Sev 5TargetSynnovisActorQilinUnited Kingdom
24-0603
File

Qilin Encryption of Synnovis Cancelled 10,000 Appointments and 1,700 Operations

Those are not records lost. They are appointments that did not happen, to people who were already waiting.

QilinHealthcareAvailability
Sev 5TargetSynnovisActorQilinUnited Kingdom
24-0602
File

Snowflake Campaign Reached 165 Customer Environments Without MFA

165 separate failures with one shape, and a platform that was never itself breached.

UNC5537Stolen credentials, no MFAMultipleIdentity
Sev 5TargetSnowflake customer environmentsActorUNC5537USA
24-0531
File

Five Hundred and Sixty Million, Claimed

A 560 million claim graded low sits below a 110 million disclosure graded high. That ordering is the point of having grades.

UNC5537Valid credentials, no MFAEntertainmentVerification
Sev 4TargetTicketmasterActorUNC5537USA
24-0527
File

Christie’s Breach Exposed Client ID Document Numbers Over Two Days in May

A rule to collect identity documents, and no matching rule to dispose of them.

UnattributedRetailIdentity
Sev 3TargetChristie’sActorUnattributedUnited Kingdom
24-0514
File

Santander Customer Data Listed for Sale After Third-Party Access

A customer can change bank. An employee handed the details over as a condition of the job.

UnattributedThird-party database accessFinancial servicesFinance
Sev 4TargetSantanderActorUnattributedSpain
24-0508
File

A Hundred and Forty Hospitals, and the Records Went to Paper

The fallback held for a month across 140 hospitals — because enough staff had worked that way before. That is a resource with a retirement date.

Black BastaMalicious file downloadHealthcareAvailability
Sev 5TargetAscensionActorBlack BastaUSA
24-0425
File

Kaiser Permanente Trackers Sent 13.4 Million Members’ Data to Advertisers

A member looking up a condition is not browsing. The page is what reveals the worry.

Tracking technology, by designHealthcareHealthcare
Sev 4TargetKaiser PermanenteActorUnattributedUSA
24-0405
File

They Paid the Operator, and the Affiliate Still Had the Data

A victim negotiating with the brand is negotiating with the party that holds the least. The files sit with the affiliate.

RansomHubRe-extortionHealthcareExtortion
Sev 5TargetChange HealthcareActorRansomHubUSA
24-0329
File

Daixin Claimed Omni Hotels Guest Records Going Back to 2017

Seven years of guests, most of whom stopped being customers long ago.

Daixin TeamHospitalityHospitality
Sev 4TargetOmni Hotels & ResortsActorDaixin TeamUSA
24-0322
File

Panera Bread Ransomware Took Tills and Ordering Down for a Week

A restaurant chain without tills is not a degraded restaurant chain.

UnattributedRetailAvailability
Sev 3TargetPanera BreadActorUnattributedUSA
24-0314
File

Giant Tiger Vendor Breach Put 2.8 Million Customer Records Online

Data for sale reaches whoever pays. Data published free reaches everyone, permanently.

UnattributedThird-party vendor compromiseRetailThird party
Sev 3TargetGiant TigerActorUnattributedCanada
24-0313
File

France Travail Breach Exposed 43 Million People Across Twenty Years of Registrations

Someone who found work in 2006 had no route to ask for their record to be removed.

UnattributedGovernmentPublic sector
Sev 5TargetFrance TravailActorUnattributedFrance
24-0301
File

Twenty-two Million Dollars, Paid

A company that pays quietly and says nothing has taken the cheaper path. The sample of known payments is not a sample of payments.

ALPHVExtortionHealthcareExtortion
Sev 5TargetChange HealthcareActorALPHVUSA
24-0221b
File

The Largest Ransom on Record, and a Filing That Mentions No Ransom

Item 1.05 does not ask whether a ransom was paid. So the largest extortion payment on record is compatible with a filing that never mentions one.

Dark AngelsPharmaceutical distributionExtortion
Sev 4TargetCencoraActorDark AngelsUSA
24-0212
File

Change Healthcare Intruders Used a Citrix Portal With No Second Factor

A written requirement that MFA be enabled everywhere is not a control. It is intent somebody then has to enforce against an estate nobody has fully inventoried.

ALPHVValid credentials, no MFAHealthcareIdentity
Sev 5TargetChange HealthcareActorALPHVUSA
24-0112
File

Microsoft Says Password Spray on a Legacy Test Account Reached Leadership Email

No exploit and no zero-day. An account existed, it had a guessable password, and nobody had required a second factor on it.

Midnight BlizzardPassword sprayCloudPrimary source
Sev 4TargetMicrosoftActorMidnight BlizzardUSA
24-0110
File

Ivanti Connect Secure Auth Bypass and Command Injection Chained for Remote Code Execution

The first flaw supplies the authentication the second one requires. A pair of medium problems is not a medium problem.

MultipleVulnerability chainingCloudExploitation
Sev 4TargetIvanti Connect Secure operatorsActorMultipleUSA
23-1224
File

Integris Health Patients Were Emailed Directly and Offered a $50 Deletion Fee

The pressure did not run through the hospital at all. It ran through the patients.

UnattributedHealthcareHealthcare
Sev 5TargetIntegris HealthActorUnattributedUSA
23-1220
File

MongoDB Says Phishing Reached Support Systems but Not Customer Clusters

No lookalike domain and no spoofed sender. The message came from a real colleague’s real account.

UnattributedPhishingTechnologyIdentity
Sev 2TargetMongoDBActorUnattributed
23-1212
File

Ukraine Says Sandworm Sat in Kyivstar for Months Before Destroying It

The missing measurement is not lost revenue. It is warnings that did not reach people.

SandwormTelecomTelecom
Sev 5TargetKyivstarActorSandwormUkraine
23-1123
File

Ardent Health Took 30 Hospitals Offline After Thanksgiving Ransomware

Diversion is the rare availability harm that produces a number — in minutes, measured by the ambulance service.

UnattributedHealthcareAvailability
Sev 5TargetArdent Health ServicesActorUnattributedUSA
23-1119
File

Fidelity National Financial Blocked Its Own Systems and House Sales Stopped

Containment converts an unbounded loss into a bounded one, and moves it onto whoever needed the service that week.

UnattributedCredential compromiseFinanceAvailability
Sev 4TargetFidelity National FinancialActorUnattributedUSA
23-1031
File

Mr Cooper Breach Exposed 14.7 Million Current and Former Customers

Someone who paid off their mortgage in 2016 had no account, no login, and full exposure.

UnattributedFinancial servicesFinance
Sev 5TargetMr CooperActorUnattributedUSA
23-1030
File

SEC Charged SolarWinds and Named Its Security Officer Personally

Nobody is fined for being breached. People are fined for what they said beforehand.

RegulatorTechnologyAccountability
Sev 2TargetSolarWindsActorRegulatorUSA
23-1028
File

British Library Published Its Own Breach Report Naming a Partner Server Without MFA

It gained nothing by publishing the route, and published it anyway. That is the standard.

RhysidaPartner terminal server, no MFANon-profitAvailability
Sev 5TargetBritish LibraryActorRhysidaUnited Kingdom
23-0919
File

International Criminal Court Says September Breach Was Espionage

Espionage succeeds by producing no artefact. The ones in this corpus are the ones that failed at the last step.

UnattributedGovernmentStatecraft
Sev 5TargetInternational Criminal CourtActorUnattributedNetherlands
23-0918
File

A Single Storage Token Exposed 38TB of Microsoft AI Research Data

Nobody attacked anything. A sharing mechanism offered a wider scope than the task needed.

ExposureMisconfigurationTechnologyExposure
Sev 3TargetMicrosoft AI researchActorExposure
23-0911
File

MGM Resorts Put the Cost of Its September Attack at About $100 Million

A breach notification counts records. It has no field for a fortnight of manual check-in.

Scattered SpiderSocial engineeringHospitalityAvailability
Sev 4TargetMGM Resorts InternationalActorScattered SpiderUSA
23-0907
File

Caesars Paid About $15 Million While MGM Refused in the Same Week

Paying bought silence about data already copied. None of the $15m was spent on the members.

Scattered SpiderSocial engineering — third-party help deskHospitalityAftermath
Sev 4TargetCaesars EntertainmentActorScattered SpiderUSA
23-0818b
File

CloudNordic Lost Customer Data After Backups Were Encrypted Alongside Production

Nobody decided to remove the isolation. It was lost while moving the servers.

UnattributedPre-existing infection, network mergedTechnologyAvailability
Sev 5TargetCloudNordic and AzeroCloudActorUnattributedDenmark
23-0728
File

Maximus Says the MOVEit Flaw Reached Health Data for up to 11 Million People

The campaign is unmeasurable. Its individual victims are not.

Cl0pSQL injectionHealthcareHealthcare
Sev 5TargetMaximusActorCl0pUSA
23-0715
File

ALPHV and Cl0p Both Listed Estee Lauder From Separate Intrusions

An organisation dealing with an incident should not assume it is dealing with an incident.

ALPHV, Cl0pMOVEit (Cl0p); not established (ALPHV)RetailAftermath
Sev 4TargetThe Estée Lauder CompaniesActorALPHV, Cl0pUSA
23-0712
File

JumpCloud Says a Nation-State Phish Reached Fewer Than Five Customers

The blast radius was tiny because the targeting was precise, not because the access was limited.

UNC4899Spear-phishingTechnologySupply chain
Sev 4TargetJumpCloudActorUNC4899
23-0711
File

Storm-0558 Forged Tokens With a Stolen Microsoft Key to Read Government Email

A token signed with a trusted key is not a forgery the platform can detect. It is a valid token.

Storm-0558Forged authentication tokensPublic sectorEspionage
Sev 5TargetExchange Online tenantsActorStorm-0558
23-0710
File

HCA Healthcare Reported 11.27 Million Patients Affected by Email Storage Breach

The system with the weakest claim to protection held the widest population. Breadth is what a mail-merge store is for.

UnattributedHealthcareHealthcare
Sev 4TargetHCA HealthcareActorUnattributedUSA
23-0625
File

Suncor Cyberattack Left 1,500 Petro-Canada Sites Unable to Take Card Payments

Thin harm spread across a very large number of uninvolved people is the kind nobody measures.

UnattributedEnergyAvailability
Sev 4TargetSuncor EnergyActorUnattributedCanada
23-0616
File

St Margaret's Health Closed, Citing a 2021 Ransomware Attack Among the Causes

The fatal injury was to cash flow, and it took two years to prove fatal.

UnattributedHealthcareAvailability
Sev 5TargetSt Margaret’s HealthActorUnattributedUSA
23-0614
File

Play Published 65,000 Swiss Federal Documents Taken From Contractor Xplain

The federal files were a twentieth of the dump. The rest belonged to everyone else the supplier served.

PlayGovernmentPublic sector
Sev 5TargetXplain / Swiss Federal AdministrationActorPlaySwitzerland
23-0608
File

A Honda Password Reset Endpoint Accepted Any Email Address Without a Token

Reset exists to let a user in without the credential. That makes it an alternative route to everything.

Broken authenticationManufacturingAPI
Sev 2TargetHonda dealer platformActorUnattributed
23-0512c
File

Discord Says a Support Vendor’s Agent Account Exposed Ticket Contents

People write to support when something has gone wrong, and they explain it.

UnattributedThird-party account compromiseTechnologyThird party
Sev 2TargetDiscordActorUnattributed
23-0420
File

Mandiant Traced the 3CX Compromise to a Trojanised X_TRADER Installer

Nobody assessing a phone-system vendor thinks to ask about its staff’s trading software.

UNC4736Trojanised X_TRADER installerTechnologySupply chain
Sev 5Target3CXActorUNC4736USA
23-0412
File

Ransomware at One NCR Data Centre Stopped Restaurants Running Their Own Back Office

The unit that matters is not the facility. It is the number of organisations that stop when it does.

ALPHV/BlackCatRansomwareRetailAvailability
Sev 4TargetNCR Aloha customersActorALPHV/BlackCat
23-0407
File

Researchers Found MSI Firmware Signing Keys in Data Leaked After a Ransom Refusal

A signing key burned into shipped hardware cannot be rotated the way a credential can.

Money MessageRansomwareManufacturingSupply chain
Sev 4TargetMicro-Star InternationalActorMoney Message
23-0404
File

Operation Cookie Monster Seized Genesis Market and Data From 1.5 Million Machines

A password is a claim to be checked. A cookie is the receipt showing the check already happened.

Enforcement
Sev 2TargetGenesis MarketActorUnattributedUSA
23-0402
File

Western Digital Took My Cloud Offline for Eleven Days After Network Intrusion

Personal cloud storage is sold on one promise. For eleven days the product did not exist.

UnattributedTechnologyAvailability
Sev 4TargetWestern DigitalActorUnattributedUSA
23-0329
File

Mandiant Says One Supply Chain Compromise Caused Another at 3CX

Code signing answers "did this come from the vendor". Here the answer was yes, and it was the wrong question.

UNC4736Supply chain compromiseTechnologySupply chain
Sev 5Target3CXActorUNC4736
23-0324
File

OpenAI Says a Redis Client Bug Showed Users Other People’s Chat Titles

A conversation title is a list of what somebody asked a machine in private.

Software defectTechnologyAI
Sev 2TargetOpenAIActorUnattributed
23-0223
File

Dish Network Customers Spent Days Unable to Reach a Company That Could Not Reach Itself

The mechanism for reaching the company was part of the same incident.

UnattributedRansomwareTelecomAvailability
Sev 4TargetDISH NetworkActorUnattributedUSA
23-0210
File

Dole Halted North American Production After Ransomware

The only instrument anyone had was a shopper noticing an absence.

UnattributedFood and agricultureAvailability
Sev 4TargetDole Food CompanyActorUnattributedUSA
23-0208
File

ESXiArgs Encrypted Thousands of Hypervisors Through a Two-Year-Old Flaw

The patch had existed for two years. The campaign needed no new capability, only servers nobody had looked at.

UnattributedUnpatched vulnerabilityMultipleExploitation
Sev 4TargetVMware ESXi serversActorUnattributed
23-0125
File

Sandworm Pushed a Wiper to Ukrainian Targets Through Active Directory Itself

The distribution channel an organisation trusts most is the one that reaches everything.

SandwormGroup Policy deploymentPublic sectorInfrastructure
Sev 4TargetUkrainian organisationsActorSandwormUkraine
23-0119
File

T-Mobile Says One API Gave up Data on 37 Million Accounts

Six weeks to notice, one day to fix. Time to fix is almost never the constraint.

UnattributedAPI abuseTelecomTelecom
Sev 4TargetT-Mobile USActorUnattributedUSA
23-0118
File

Yum! Brands Closed 300 UK Restaurants for a Day, Then Found Employee Data Had Gone

The customer headline and the actual victim population were different groups.

UnattributedRansomwareRetailAvailability
Sev 3TargetYum! BrandsActorUnattributedUnited Kingdom
23-0110
File

Royal Mail Could Not Send a Parcel Abroad for Six Weeks After LockBit Attack

No database at the centre of it. A national postal operator simply stopped being able to send a parcel abroad.

LockBitRansomwareLogisticsAvailability
Sev 4TargetRoyal MailActorLockBitUnited Kingdom
22-1202
File

The Hosted Email Service Did Not Come Back

The stopgap became the destination. Hosted Exchange was retired rather than restored.

PlayCVE-2022-41080 — zero-dayTechnologyAvailability
Sev 4TargetRackspaceActorPlayUSA
22-1111
File

Daixin Took Data on 5 Million AirAsia Passengers and Every Employee

The answers were true before the employer collected them, and they stay true afterwards.

Daixin TeamAviationAftermath
Sev 4TargetAirAsia GroupActorDaixin TeamMalaysia
22-1104
File

Vanuatu Government Systems Stayed Offline for Weeks as Officials Used Personal Email

The fallback kept the state running, and put a month of government correspondence in consumer mailboxes.

UnattributedPhishing — as reportedGovernmentPublic sector
Sev 5TargetGovernment of VanuatuActorUnattributedVanuatu
22-1104b
File

LockBit Claimed 40TB From Continental Three Months After the Company Disclosed

A file list is aimed past the victim, at the customers who now have to ask.

LockBitManufacturingAftermath
Sev 4TargetContinentalActorLockBitGermany
22-1101
File

Dropbox Says Phishing Reached 130 Repositories After a Hardware Key Code Was Relayed

Cloudflare was not saved by the metal. It was saved by origin binding — and this key was not doing that.

UnattributedPhishing → OTP relayTechnologySupply chain
Sev 3TargetDropboxActorUnattributedUSA
22-1002
File

CommonSpirit Health Ransomware Forced Paper Records Across More Than 100 Facilities

623,700 had data exposed. The people actually harmed were the ones whose procedure moved.

UnattributedHealthcareAvailability
Sev 5TargetCommonSpirit HealthActorUnattributedUSA
22-0915
File

The Contractor Approved the Eighteenth Prompt

The second factor was not bypassed. It was delivered to the right person, who said yes.

Lapsus$MFA fatigue → social engineeringTechnologyIdentity
Sev 4TargetUberActorLapsus$USA
22-0903
File

Los Angeles Schools Refused to Pay and 500GB Including Psychological Assessments Was Published

The refusal was right. The people who paid for it were children who cannot freeze a credit file.

Vice SocietyEducationPublic sector
Sev 5TargetLos Angeles Unified School DistrictActorVice SocietyUSA
22-0826
File

Montenegro Blamed Russia for August Attack as Cuba Ransomware Claimed It

Two small NATO members, two months apart, two entirely different instruments.

Cuba ransomware (claimed)GovernmentStatecraft
Sev 5TargetGovernment of MontenegroActorCuba ransomware (claimed)Montenegro
22-0825
File

LastPass Developer Breach Took 14 Repositories Four Months Before the Vault Theft

Everything the company said in August was true. In December none of it helped.

UnattributedCompromised developer accountTechnologyConcentration
Sev 3TargetLastPassActorUnattributedUSA
22-0720
File

Neopets Database of 69 Million Accounts Offered for Four Bitcoin

Collected from a child, retained past the relationship, past the product, past recognition.

UnattributedTechnologyIdentity
Sev 3TargetNeopetsActorUnattributedUSA
22-0630
File

Shanghai Police Database Covering 1 Billion Residents Offered for 10 Bitcoin

Ten bitcoin across a billion people is a fraction of a cent each. That is the market price.

UnattributedUnsecured internet-facing interfaceGovernmentPublic sector
Sev 5TargetShanghai National Police databaseActorUnattributedChina
22-0525
File

SpiceJet Ransomware Attempt Stranded Passengers and Halted Morning Departures

An attempt that stops a carrier’s morning departures has succeeded at everything but encryption.

UnattributedAviationAvailability
Sev 3TargetSpiceJetActorUnattributedIndia
22-0523
File

ICO Fined Clearview AI £7.5 Million Over 20 Billion Scraped Images, Later Overturned

A remedy that fitted the harm and could not reach the party holding it.

Web scraping, by designTechnologyEnforcement
Sev 3TargetClearview AIActorUnattributedUnited Kingdom
22-0508
File

A Country Declared a National Emergency Over a Ransomware Attack

Tax collection stopping is fiscal. Customs stopping means the containers do not move.

ContiGovernmentPublic sector
Sev 5TargetGovernment of Costa RicaActorContiCosta Rica
22-0412
File

GitHub Says Stolen Heroku and Travis-CI Tokens Exposed Private Repositories at Dozens of Organisations

The security of a system is the security of everyone it has delegated to — a set nobody enumerates.

UnattributedStolen OAuth tokensTechnologySupply chain
Sev 4TargetGitHub customers, incl. npmActorUnattributedUSA
22-0404
File

Cash App Investing Breach Traced to a Former Employee Who Still Had Access

No exploit, no malware. Someone kept reading what they had been allowed to read.

Single operatorInsider — retained accessFinancial servicesInsider
Sev 3TargetBlock — Cash App InvestingActorSingle operatorUSA
22-0328
File

Shields Health Breach Reached 2 Million Patients After an Alert Was Closed as Not Reportable

Something noticed on day eleven. The judgement applied to it is what failed.

UnattributedHealthcareThird party
Sev 4TargetShields Health Care GroupActorUnattributedUSA
22-0301
File

One Plastic-Parts Supplier Stopped Fourteen Toyota Plants

Inventory is waste, so nothing is spare. That is the method working, and it is why one supplier stopped everything.

UnattributedManufacturingSupply chain
Sev 4TargetToyota Motor CorporationActorUnattributedJapan
22-0224
File

A Wiper Aimed at Ukraine Took 5,800 German Wind Turbines off Monitoring

Germany was not the target. The turbines were on the same satellite, and the wiper did not check.

SandwormNetwork management compromiseTelecommunicationsInfrastructure
Sev 5TargetViasat KA-SAT usersActorSandwormUkraine
22-0220
File

Expeditors Shut Down Global Operations for Eight Days After Cyberattack

A freight forwarder’s downtime is measured in other companies’ cargo.

UnattributedLogisticsAvailability
Sev 4TargetExpeditors InternationalActorUnattributedUSA
22-0114
File

WhisperGate Wiper Hit Ukrainian Government Sites Six Weeks Before the Invasion

Finding a ransom note starts a recovery conversation. That was the deliverable.

UnattributedGovernmentInfrastructure
Sev 5TargetUkrainian government organisationsActorUnattributedUkraine
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging