Index live· 1,284 files · 148 editions
ForensicPost

Search the index

85 results
Try
Results for “Analysis”Newest first
26-0719
File

Research Puts Three Quarters of Insider Incidents Down to Negligence, Not Sabotage

About 75% of insider incidents involve nobody acting maliciously. Programmes built to detect grievance address a quarter of the problem.

InsiderNegligence & credential theftMultipleAnalysis
Sev 3TargetEnterprise organisationsActorInsider
26-0718
File

Vendor Analysis Maps Three ShinyHunters Attack Paths Into Salesforce Tenants

Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.

ShinyHuntersMultiple pathsCloudMethod
Sev 3TargetSalesforce tenantsActorShinyHunters
26-0703
File

Seventy-three per Cent of Intrusions Came Through the Remote-Access Box

Legacy remote access at the entry point in 73% of intrusions, up from 38% in two years. The box keeps working, which is why it is still there.

MultipleLegacy VPNMultipleAnalysis
Sev 4TargetEnterprise remote accessActorMultiple
26-0426
File

Healthcare Ransomware Rose 14% in Early 2026, Concentrated on Suppliers

Hospitals flat, their suppliers up ~35%. Hardening one class of victim redistributes attacks rather than preventing them.

MultipleRansomwareHealthcareAnalysis
Sev 4TargetHealthcare sector suppliersActorMultiple
26-0405
File

Federal Audit Found National Vulnerability Database Backlog Past 27,000 Entries

27,000 entries with no analysis attached. Your scanner matches on metadata that, for these, does not exist.

UnattributedProcess capacityMultipleVulnerabilities
Sev 4TargetNational Vulnerability DatabaseActorUnattributed
26-0330
File

Government Ransomware Rose 65%, and the Target Profile Explains Why

The calculation is not that a city has money. It is that a city has visible pain and a decision-maker accountable to the people feeling it.

MultipleRansomwarePublic sectorAnalysis
Sev 4TargetState and local governmentActorMultiple
26-0325
File

One Botnet Was Removed and Twenty Took Its Place

Twenty successors, and daily endpoints up from one million to nine. Enforcement removed operators; the device pool never changed.

MultipleIoT compromiseMultipleAnalysis
Sev 4TargetGlobal botnet ecosystemActorMultiple
26-0301
File

Education Ransomware Closed Schools and Universities Across Several Countries

Education fails closed while other sectors degrade. The fix is not detection — it is an offline copy of the data needed to open safely.

MultipleRansomwareEducationAnalysis
Sev 4TargetEducation institutionsActorMultiple
26-0121
File

Attacks on Automotive and Smart Mobility Organisations More Than Doubled in 2025

Three technology estates in one company. The research attention is on the vehicles; the billion-pound losses are in enterprise IT.

MultipleVariousManufacturingAnalysis
Sev 4TargetAutomotive manufacturersActorMultiple
26-0107
File

Ten Significant Attacks on Aviation in a Year, and Counting

The industry that invented blameless incident analysis handles cyber incidents with commercial confidentiality instead.

MultipleVariousLogisticsAviation
Sev 4TargetAviation and aerospace sectorActorMultiple
25-1231
File

A Fragmented Extortion Ecosystem Changes What Paying a Ransom Buys

The case for paying depended on a repeat player with a reputation to protect. Seventy-three new entrants in a year removes exactly that.

MultipleVariousMultipleAnalysis
Sev 4TargetExtortion negotiationActorMultiple
25-1227
File

Compensation to Affected Individuals Appears Twice in 587 Files

Every file that ends with credit monitoring should be read as ending with nothing.

MultipleAnalysis
Sev 4TargetAffected individualsActorUnattributed
25-1227b
File

Australia's Eight Years of Breach Statistics Show What a Register Is Worth

A universal register with cause classification is achievable — one country has run it for eight years.

RegulatorMultipleAnalysis
Sev 2TargetBreach measurementActorRegulatorAustralia
25-1225
File

An Accounting of What This Database Is Not

A corpus that spends its time discounting other people’s figures owes the same treatment to itself.

MultipleAnalysis
Sev 3TargetThis databaseActorUnattributed
25-1224
File

Promptware Research Traces a Shift to Multi-Stage Campaigns

Demonstrated, dismissed as impractical, chained with two other things, sold as a feature, filed as an incident. Every technique here took that route.

MultiplePrompt injectionCloudAnalysis
Sev 4TargetAI agent deploymentsActorMultiple
25-1224b
File

Fifty-two per Cent Found It Themselves

A five-day difference in median dwell, attributable to who noticed. It is the strongest available case for spending on detection.

MultipleMultipleAnalysis
Sev 3TargetDetection capabilityActorMultiple
25-1223
File

2025 Regulatory Reforms Leave Gaps No Instrument in This Corpus Addresses

A rule cannot make a help-desk conversation resistant to a plausible caller. Compliant organisations appear in this database as often as non-compliant ones.

RegulatorMultipleAnalysis
Sev 3TargetRegulatory coverageActorRegulator
25-1222
File

A Record Year for Enforcement and a Record Year for Attacks

“Attacks rose despite enforcement” is equally compatible with enforcement having prevented a much larger rise. There is no counterfactual.

MultipleVariousMultipleAnalysis
Sev 4TargetRansomware ecosystemActorMultiple
25-1221
File

What the Structural Findings Look Like From Outside the West

The corpus has treated the measured cases as the anomaly. They may be the only honest data in the set.

MultipleAnalysis
Sev 3TargetCorpus findingsActorUnattributed
25-1220b
File

Four Properties Combine in Healthcare That Combine Nowhere Else

A hospital carries the operational-technology problem of a utility alongside the data-protection problem of a bank.

MultipleRansomwareHealthcareAnalysis
Sev 4TargetHealthcare sectorActorMultiple
25-1219b
File

Seventeen Million Patients Depended on One Supplier Most Had Never Heard Of

A consumer-facing organisation is bounded by the customers it can serve. A supplier is bounded only by how many of them it can sell to.

MultipleVariousMultipleAnalysis
Sev 4TargetSupplier concentrationActorMultiple
25-1218
File

When One Breach Covers Most of a Country

Enhanced verification for everyone is just verification. An alert triggered by a population is not a signal.

MultipleVariousMultipleAnalysis
Sev 4TargetNational populationsActorMultiple
25-1217b
File

Ransomware Encryption Rate Fell to 50% in 2025 From 70%

A shift from the transaction that sometimes works to the one this corpus has never seen work.

MultipleData extortionMultipleAnalysis
Sev 4TargetRansomware victimsActorMultiple
25-1216
File

Newly Disclosed Vulnerabilities Weaponised Within Hours Through 2025

The head start was the entire point of coordinated disclosure. At an interval measured in hours, publication is a starting gun heard equally by both sides.

MultipleVariousCloudAnalysis
Sev 4TargetEnterprise software estatesActorMultiple
25-1216b
File

47% of Ransomware Attacks Were Halted Before Encryption in 2025, Vendor Research Says

This figure measures the category every disclosure-based count excludes by construction: the attacks that were stopped.

MultipleVariousMultipleAnalysis
Sev 3TargetRansomware defenceActorMultiple
25-1210
File

Crypto Losses Reached $3.4 Billion Across More Than 300 Incidents in 2025

The signature schemes held. The hash functions held. The losses came from signing workflows and outsourced support.

MultipleVariousFinanceAnalysis
Sev 4TargetDigital asset platformsActorMultiple
25-1210b
File

A Fourth 2025 Ransomware Total Puts Publicly Disclosed Attacks at 1,174

The corpus should be as suspicious of numbers that agree for no visible reason as of numbers that disagree.

MultipleVariousMultipleAnalysis
Sev 3TargetRansomware measurementActorMultiple
25-1204
File

Manufacturing Absorbed 56% of Ransomware Activity Across 1,929 Industrial Attacks

Blocking more attempts and losing more data are the same finding. A manufacturer can lose its entire engineering position with no duty to tell anyone.

MultipleVariousManufacturingAnalysis
Sev 3TargetIndustrial sectorActorMultiple
25-1203
File

Data Breaches Made up 39.9% of Incidents Across Asia and the South Pacific

Three categories within 3% of each other, with entirely different dynamics. Categories that overlap in reality produce counts that converge.

MultipleVariousMultipleAnalysis
Sev 3TargetAsia and South PacificActorMultiple
25-1202
File

INTERPOL Found Cybercrime Is 30% of Recorded Crime in Half of Surveyed Countries

At 30% of recorded crime, this stops being a specialist function and becomes ordinary policing.

MultipleVariousMultipleAnalysis
Sev 4TargetAsia and South PacificActorMultiple
25-1201
File

44% of 2025 Breaches Involved Ransomware and 30% a Third-Party Failure

Around 30% of 2025 breaches originated with a third party. The boundary an organisation defends stopped being the boundary that determines its exposure.

MultipleVariousMultipleAnalysis
Sev 4TargetGlobal breach landscapeActorMultiple
25-1127
File

Nevada Published a $1.5 Million Incident Response Bill

The only reliable incident costs in this corpus come from organisations that had no choice but to publish them.

UnattributedRansomwarePublic sectorAnalysis
Sev 3TargetNevada state governmentActorUnattributedUSA
25-1125
File

A Hundred and Two Days Inside a State Government

Prevention will fail. Detection is what determines whether that becomes a state government offline for 28 days.

UnattributedTrojanised software downloadPublic sectorAnalysis
Sev 5TargetNevada state governmentActorUnattributedUSA
25-1123
File

African Data Protection Regimes Made 2025 Incidents Harder to Conceal

Jurisdictions are penalised in insurance and procurement for the act of becoming transparent.

RegulatorMultipleAnalysis
Sev 3TargetAfrican disclosure regimesActorRegulator
25-1120
File

Automotive Ransomware More Than Doubled, and the Cars Are Next

Corporate IT, a production line, and a connected product you can still reach after sale. Few industries carry all three.

MultipleVariousManufacturingAnalysis
Sev 3TargetAutomotive sectorActorMultiple
25-1116
File

Three Countries Account for Most Latin American Ransomware Victims

Where disclosure is not mandatory, the regional picture is assembled almost entirely from what attackers chose to publish.

MultipleRansomwareMultipleAnalysis
Sev 3TargetLatin American organisationsActorMultipleUSA
25-1115
File

Latin American Organisations Faced 2,640 Attacks per Week in 2025

15% reads as a measurement somebody made. 2,640 a week reads as a headline somebody wanted.

MultipleVariousMultipleAnalysis
Sev 3TargetLatin American organisationsActorMultipleUSA
25-1112
File

A Million Users’ Metadata Is Not a Lesser Breach

Content tells you what a known person said. Metadata tells you who the people are — and it is the one that scales.

Salt TyphoonLawful-intercept infrastructureTelecomAnalysis
Sev 4TargetTelecom subscribersActorSalt Typhoon
25-1112c
File

The Provider Is How Small Firms Enter the Record

Only five of the seven routes are mechanisms anyone designed. The two reaching small firms are accidents of how research works.

MultipleAnalysis
Sev 3TargetSmall organisationsActorUnattributed
25-1107b
File

Two Ways an Edge Device Fails, and Only One Is Forgivable

The structural argument covers only the zero-day case. The corpus weakened itself by folding the two together.

MultipleVariousMultipleAnalysis
Sev 4TargetEdge appliance estatesActorMultiple
25-1106
File

Saint Paul Still Recovering Long After the Attack

Cities do not recover differently. They simply cannot stop describing it.

UnattributedPublic sectorAnalysis
Sev 3TargetCity of Saint PaulActorUnattributed
25-1103
File

Two Security Vendors in Two Months, by State Actors

Neither actor wanted the vendor. Both wanted what the vendor holds about everyone else — the same reach as a thousand intrusions, from one operation.

State-sponsoredSupply chain positioningCloudAnalysis
Sev 5TargetSecurity vendorsActorState-sponsored
25-1030
File

UK Car Production Fell 27% After the Jaguar Land Rover Halt

Worse than any September through oil shocks, three-day weeks and a pandemic. Output statistics may be a better instrument than any breach register.

MultipleVariousManufacturingAnalysis
Sev 4TargetUK automotive sectorActorMultipleUnited Kingdom
25-1024
File

The Fundraising Office Is the Softest Part of a University

The reached system is almost never the one the security programme was built around.

MultipleVoice phishingEducationAnalysis
Sev 3TargetUniversity advancement officesActorMultiple
25-1021
File

Extortion Drove More Than Half of Middle East Cyberattacks in 2025

Geopolitical exposure is additive, not substitutive. It does not displace ordinary criminal risk — it sits on top of it.

MultipleVariousMultipleAnalysis
Sev 3TargetMiddle East organisationsActorMultiple
25-1015
File

F5 Says Nation-State Actor Held Long-Term Access and Took BIG-IP Source Code

Source code is not a signing key. A vendor’s list of known-but-unpatched flaws is a queue of working zero-days with the analysis done.

Nation-stateLong-term compromiseCloudVendors
Sev 5TargetF5ActorNation-state
25-1015b
File

The Pharmaceutical Year, and What the Corpus Cannot See in It

The unrecorded categories include a medicine arriving later than it would have.

MultipleVariousPharmaAnalysis
Sev 4TargetPharmaceutical sectorActorMultiple
25-1010
File

Two Hundred and Seventy-Five Million Patient Records in Two Years

One episode of care generates records in six organisations — six independent breach exposures for the same history.

MultipleVariousHealthcareAnalysis
Sev 4TargetHealthcare sector recordsActorMultiple
25-1006
File

A CRM Holds the Commercial Position of Every Account in One Place

An organisation can lose its entire commercial position and notify only on the contact fields.

MultipleVariousCloudAnalysis
Sev 3TargetCRM tenantsActorMultiple
25-1005b
File

The Only Time This Database Saw the Small End

Four accidents in 454 files is not coverage of a population reportedly targeted by 43% of attacks.

MultipleAnalysis
Sev 3TargetSmall organisationsActorUnattributed
25-1004
File

Ten Groups Accounted for 71% of Leak-Site Postings in Q1 2025

Concentration is dangerous on the side holding the data and useful on the side attacking it. Both moved the wrong way at once.

MultipleVariousMultipleAnalysis
Sev 3TargetRansomware ecosystemActorMultiple
25-1004b
File

Customer Support Was the Route Into Four Separate 2025 Incidents

The properties are not defects. They are the function — which is why a vulnerability there is worth more.

MultipleVariousMultipleAnalysis
Sev 4TargetCustomer support estatesActorMultiple
25-0927
File

Every Remediation Mechanism in This Corpus Assumes an Adult

For a child the loss is maximally unquantifiable: real, permanent, and not yet manifest.

MultipleVariousEducationAnalysis
Sev 4TargetChildren as data subjectsActorMultiple
25-0923c
File

Stopping Research Is a Harm With No Victim to Notify

Real, distributed across people who will never know, and deferred by years. No instrument here can see it.

MultipleRansomwarePharmaAnalysis
Sev 3TargetPharmaceutical researchActorMultiple
25-0922b
File

Two Biopharma Breaches Were Called a Trend Without a Denominator

Two incidents among four operators is a strong signal. Two among several thousand is close to nothing.

MultipleVariousPharmaAnalysis
Sev 2TargetLife sciences sectorActorMultiple
25-0918
File

US Government Ransomware Incidents Rose 65% in the First Half of 2025

A company can raise prices. A county cannot — more security means visibly less of something a resident can see.

MultipleVariousPublic sectorAnalysis
Sev 4TargetUS public sectorActorMultipleUSA
25-0915b
File

Attackers Targeted Drug Formulations Alongside Patient Data

On every register in this corpus, the incident that mattered most did not happen.

MultipleVariousPharmaAnalysis
Sev 4TargetPharmaceutical researchActorMultiple
25-0913b
File

What Clinical Trial Data Is, Exactly

The other fields require expertise to read. Participation in a trial for a named condition does not.

MultipleVariousPharmaAnalysis
Sev 4TargetClinical trial participantsActorMultiple
25-0903
File

Managed File Transfer Appears Four Times in the 2025 Corpus

A transfer product is transitional by design. In practice the files persist, because deletion is a configuration nobody set.

MultipleVariousMultipleAnalysis
Sev 4TargetFile transfer estatesActorMultiple
25-0830
File

Nine ShinyHunters Victims Notified Separately With No Connecting Statement

A regulator receiving a dozen filings describing the same technique could warn the market. That is not a new obligation — it is a use of filings that already exist.

ShinyHuntersSocial engineeringMultipleAnalysis
Sev 4TargetMultiple sectorsActorShinyHunters
25-0828
File

Credit Monitoring Is Supplied by Bureaux That Are Themselves Breached

The standard response to data being held insecurely is to give it to another organisation that holds it.

MultipleAnalysis
Sev 3TargetBreach remediationActorUnattributed
25-0819
File

Municipalities Hold Records Residents Never Chose to Provide

The most sensitive records in this corpus, held by the least resourced organisations, under the thinnest supervision.

MultipleVariousPublic sectorAnalysis
Sev 4TargetMunicipal governmentsActorMultiple
25-0815b
File

Workday Says Core Platform and Customer Tenants Were Not Affected

A boundary between corporate systems and customer tenants held under live attack. This corpus rarely gets to observe that.

ShinyHuntersSocial engineeringCloudAnalysis
Sev 2TargetWorkdayActorShinyHunters
25-0808
File

Retail Recorded 837 Incidents and 419 Confirmed Breaches in a Quarter

837 incidents, 419 confirmed breaches. The 418 that never became a disclosure are the sector’s real attack volume.

MultipleVariousRetailAnalysis
Sev 3TargetRetail sectorActorMultiple
25-0807b
File

HR Platforms Assemble the Data an Employee Cannot Refuse to Hand Over

An HR record exceeds a bank’s, and includes categories no commercial relationship generates.

MultipleVariousCloudAnalysis
Sev 4TargetHR platformsActorMultiple
25-0805
File

Every Device on This List Was Sold as a Security Product

Internet-facing, parsing untrusted input, trusted by everything behind it. All three by design — and the customer has no hardening available.

MultipleVariousCloudAnalysis
Sev 4TargetSecurity appliance estatesActorMultiple
25-0729
File

The Utility Estate Nobody Can Take Offline to Fix

The equipment is not unpatched through neglect. It is unpatchable — commissioned to run continuously for thirty years, by a vendor that may no longer exist.

MultipleVariousUtilitiesAnalysis
Sev 4TargetUtility sectorActorMultiple
25-0728
File

A Seventy-Five Million Dollar Payment, and What It Tells the Market

Payments become known; refusals do not. The observable signal is biased towards paying, and it is the observable signal that sets expectations.

MultipleRansomwareFinanceAnalysis
Sev 4TargetFinancial sectorActorMultiple
25-0725
File

Nobody Is Collecting Hotel Records for the Hotel Records

A hotel record is the join key that turns location-adjacent data into confirmed physical presence. No DPIA has a field for that.

Salt TyphoonVariousTelecomAnalysis
Sev 4TargetMultiple sectorsActorSalt Typhoon
25-0725b
File

What the Hospitality Files Establish That 25-0725 Assumed

Evidence arriving later does not upgrade an inference. It removes one objection and leaves the rest where it was.

MultipleVariousHospitalityAnalysis
Sev 3TargetHospitality platformsActorMultiple
25-0720
File

Telecom Operators Hold Payment and Identity Data Without Financial Regulation

The data followed the obligation and the supervision did not follow the data.

MultipleVariousTelecomAnalysis
Sev 3TargetTelecom subscribersActorMultiple
25-0715
File

One Hospital in Three Says It Affected Patient Care

A third of hospitals say incidents affected care. It measures disruption, not harm — and it still moves the funding argument.

MultipleVariousHealthcareAnalysis
Sev 4TargetUS hospitalsActorMultipleUSA
25-0708
File

Insurance Is the Only Party Measuring Availability

The largest incidents in this database are measured only as a byproduct of a commercial risk-transfer market.

MultipleVariousMultipleAnalysis
Sev 3TargetAvailability incidentsActorMultiple
25-0704
File

Breach Notification Law Was Written for Consumers, Not the Workforce

A customer can stop being a customer. An employee cannot decline to give their employer a national identifier and a bank account.

MultipleVariousMultipleAnalysis
Sev 3TargetWorkforce dataActorMultiple
25-0702
File

One Scattered Spider Campaign Moved Through Four Sectors in Eight Months

By the final phase there was no peer sector to watch, because the target was defined by a product rather than an industry.

Scattered SpiderSocial engineeringMultipleAnalysis
Sev 5TargetMultiple sectorsActorScattered Spider
25-0630
File

US Healthcare Reported 343 Breaches Covering 57 Million Records in Six Months

343 mandatory filings in six months. Healthcare tops breach tables partly because it is the only sector compelled to count.

MultipleVariousHealthcareAnalysis
Sev 3TargetUS healthcare sectorActorMultipleUSA
25-0628
File

WestJet and Hawaiian Said Flight Operations Were Not Affected

A safety regime, built for other purposes, produced the segmentation that a security argument has repeatedly failed to fund elsewhere.

Scattered SpiderSocial engineeringAviationAnalysis
Sev 3TargetAirline operational systemsActorScattered Spider
25-0616
File

The Most Expensive Sector to Be Breached In

A retailer and a bank suffering identical intrusions produce very different invoices, and the difference is regulation rather than damage.

MultipleVariousFinanceAnalysis
Sev 3TargetFinancial sectorActorMultiple
25-0603b
File

Outsourcing IT Is Sound Advice and the Route to Twenty Compromises at Once

Telling small organisations to outsource is not a compromise position. It is the only realistic path to any capability at all.

MultipleVariousCloudAnalysis
Sev 4TargetManaged service modelActorMultiple
25-0506
File

Israel Accounted for 33% of Middle East Targeting in 2025

A distribution that departs from economic size is evidence of deliberate selection. It is the one regional file where the geopolitical framing is supported rather than assumed.

MultipleVariousMultipleAnalysis
Sev 3TargetMiddle East organisationsActorMultiple
25-0426
File

Breaches Involving a Third Party Rose Sharply in 2025

The finding is about the structure of the economy rather than the threat landscape — more durable and less urgent than reported.

MultipleThird partyMultipleAnalysis
Sev 3TargetMultiple sectorsActorMultiple
25-0423
File

System Intrusions Behind 80% of Asia-Pacific Breaches, up From 38%

A number that moves faster than the world does is measuring the instrument.

MultipleVariousMultipleAnalysis
Sev 3TargetAsia-Pacific organisationsActorMultiple
25-0402
File

Akira, PLAY and RansomHub Absorbed the Disrupted Leader's Affiliates

In a lawful market, removing the dominant supplier reduces volume because capacity is expensive to replace. Here the capacity is software.

MultipleRansomware-as-a-serviceMultipleAnalysis
Sev 4TargetRansomware ecosystemActorMultiple
25-0227
File

Blockchain Analysis Put Black Basta Receipts Above $107 Million

A floor from a public ledger and a ceiling from an interested party are not the same kind of object. This corpus has not always said which it was holding.

Black BastaExtortionMultipleVerification
Sev 4TargetNot applicableActorBlack Basta
25-0225
File

Black Basta Chats Show Shift Complaints and a Business-Data Subscription

An operation that runs on rotas, subscriptions and payment disputes does not require exceptional people. That is what makes it reproducible.

Black BastaCriminalAnalysis
Sev 3TargetNot applicableActorBlack Basta
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging