Index live· 1,284 files · 148 editions
ForensicPost

Search the index

39 results
Try
Results for “Intrusion”Newest first
26-0731
File

Conduent Breach Affected More Than 62 Million People, Final Count Shows

The final count on the Conduent intrusion landed above 62 million people — third-largest in US healthcare history, at a processor most of them have never heard of.

SafePayRansomwareHealthcareThird party
Sev 5TargetConduent Business SolutionsActorSafePayUSA
26-0721b
File

Patients Learned About an October 2025 Intrusion in July 2026

The remedy is 24 months of monitoring. The scanned passport stays valid for ten years.

UnattributedHealthcareThird party
Sev 4TargetUnlimited SystemsActorUnattributedUSA
26-0703
File

Seventy-three per Cent of Intrusions Came Through the Remote-Access Box

Legacy remote access at the entry point in 73% of intrusions, up from 38% in two years. The box keeps working, which is why it is still there.

MultipleLegacy VPNMultipleAnalysis
Sev 4TargetEnterprise remote accessActorMultiple
26-0701
File

DHS Information-Sharing Environment Intrusion Involved Deleted Logs

Unpatched vulnerability, persistent tooling, deleted logs. The deletion is a finding in itself — nobody spends that effort on a boring record.

UnattributedUnpatched vulnerabilityPublic sectorPublic sector
Sev 4TargetDHS information-sharing environmentActorUnattributed
26-0614
File

The Laundering Service Is the Part That Has to Touch a Bank

Two arrests at a laundering service. Intrusion capability is replaceable; banking relationships that move criminal proceeds are not.

MultipleEnforcement actionFinanceEnforcement
Sev 3TargetAudiA6 laundering serviceActorMultiple
26-0516
File

Finals Week Was Cancelled at a University That Was Never Attacked

No intrusion of its own — a dependency with a deadline, hitting the one week in the academic year with no slack in it.

ShinyHuntersVendor incidentEducationEducation
Sev 3TargetIdaho State UniversityActorShinyHunters
26-0515
File

Breached in 2024, Found in 2025, Disclosed in 2026

Two years between the intrusion and the notification, on identity documents. Small organisations produce long intervals, and mostly go unrecorded.

UnattributedRetailDetection
Sev 3TargetVacation Myrtle BeachActorUnattributed
26-0507
File

West Pharmaceutical Took Global Systems Offline After Intrusion

A global shutdown days after detection. From outside it reads as catastrophe; inside an incident it is often the correct call.

UnattributedRansomwareManufacturingManufacturing
Sev 4TargetWest Pharmaceutical ServicesActorUnattributed
26-0505
File

Mediaworks Hungary Intrusion Reportedly Took 15 Million Files

A reported 15 million files from a publishing group. In a newsroom the sensitive material usually belongs to somebody who was promised anonymity.

UnattributedIntrusionMultipleMedia
Sev 3TargetMediaworks HungaryActorUnattributed
26-0502
File

FTC Bars Kochava From Selling Sensitive Location Data Without Consent

No intrusion, no misconfiguration — a functioning business selling movement traces. From the traced person’s position the distinction is thin.

None — commercial saleData brokerageMultipleData brokers
Sev 4TargetKochavaActorNone — commercial saleUSA
26-0428
File

Not a Breach: Half a Million Lines Published by Mistake

No attacker, no intrusion, and half a million lines public anyway. Registry publication is a one-way door.

Internal errorMisconfigured publicationCloudMethod
Sev 2TargetAnthropicActorInternal error
26-0411
File

M&S and Co-op Intrusions Assessed as a Single Event Costing up to £440 Million

A phone call to an outsourced service desk, a password reset, and £270–440 million across two retailers assessed as one event.

Scattered SpiderHelp-desk social engineeringRetailRetail
Sev 5TargetMarks & Spencer and Co-opActorScattered Spider
26-0324
File

NYC Health + Hospitals Intrusion Touched 1.8 Million People Over Three Months

A three-month intrusion at the largest US public health system took biometric records among the 1.8 million affected. Credit monitoring does not cover a palm print.

UnattributedNetwork intrusionHealthcareHealthcare
Sev 4TargetNYC Health + HospitalsActorUnattributedUSA
26-0219
File

Three Billion Identity Records, and No Attacker Required

Around three billion records in an unsecured database, including a billion KYC entries. No intrusion, no actor, and no way to say who read it.

ExposureUnsecured databaseFinanceExposure
Sev 4TargetIDMeritActorExposure
26-0215
File

South Korea's National Diplomatic Academy Intrusion Ran Ten Months

Ten months in a diplomatic academy’s education platform, touching 360 serving diplomats. The coursework was never the point; the roster was.

UnattributedUnder reviewPublic sectorEspionage
Sev 3TargetNational Diplomatic Academy (KR)ActorUnattributedSouth Korea
26-0211
File

Conduent Intrusion Affected 17,000 Volvo Group North America Staff

Employees of a customer of a processor. Three steps from the incident, with no point at which they could have exercised judgement.

SafePaySupplier intrusionManufacturingThird party
Sev 3TargetVolvo Group North AmericaActorSafePay
26-0119
File

Jaguar Land Rover Intrusion Halted Production and Cost £1.9 Billion

Plants on four continents stopped, most of them never attacked. Assessed at £1.9 billion — the UK’s costliest cyber incident.

UnattributedManufacturingManufacturing
Sev 5TargetJaguar Land RoverActorUnattributedUnited Kingdom
25-1103
File

Two Security Vendors in Two Months, by State Actors

Neither actor wanted the vendor. Both wanted what the vendor holds about everyone else — the same reach as a thousand intrusions, from one operation.

State-sponsoredSupply chain positioningCloudAnalysis
Sev 5TargetSecurity vendorsActorState-sponsored
25-0928
File

UK Government Guarantee Unlocked £1.5 Billion for JLR's Supply Chain

An intrusion at one company produced a sovereign commitment in four weeks. Banks too large to fail got capital requirements in exchange; there is no equivalent here.

Scattered Lapsus$ HuntersManufacturingPolicy
Sev 5TargetJaguar Land Rover supply chainActorScattered Lapsus$ HuntersUnited Kingdom
25-0820
File

Salesloft Intrusion Began in March and Stayed Dormant Until August

Five months quiet, ten days of theft. A single dwell-time figure conflates the two, and organisations optimise against the wrong phase.

UNC6395Delayed exploitationCloudMethod
Sev 4TargetIncident response practiceActorUNC6395
25-0807
File

Pakistan Petroleum Isolated IT Services After Ransomware Intrusion

A corpus assembled from disclosures records failures in detail and successes almost never.

UnattributedRansomwareEnergyEnergy
Sev 2TargetPakistan Petroleum LimitedActorUnattributedPakistan
25-0724
File

Four Arrested Over M&S, Co-op and Harrods Intrusions

An unsophisticated technique that works is not a lesser threat than a sophisticated one. It is a worse one.

Scattered SpiderSocial engineeringRetailEnforcement
Sev 3TargetUK retail campaignActorScattered SpiderUnited Kingdom
25-0616
File

The Most Expensive Sector to Be Breached In

A retailer and a bank suffering identical intrusions produce very different invoices, and the difference is regulation rather than damage.

MultipleVariousFinanceAnalysis
Sev 3TargetFinancial sectorActorMultiple
25-0611
File

Network Diagrams, Location Maps, and the People Who Work There

Personnel data decays. A network diagram does not — it converts the next intrusion from exploration into navigation, silently.

UnattributedDefenceDefence
Sev 4TargetUS Army National GuardActorUnattributedUSA
25-0518
File

Nevada Intrusion Began With a Poisoned Search Result for an Admin Tool

The employee did go looking for the official site. The search platform put something else first.

UnattributedSearch engine poisoningPublic sectorMethod
Sev 4TargetIT personnelActorUnattributedUSA
25-0516
File

Nevada Intrusion Started When an Employee Downloaded a Spoofed Admin Tool

The employee was doing their job. The action was correct in every previous instance.

UnattributedTrojanised software downloadPublic sectorPublic sector
Sev 5TargetNevada state governmentActorUnattributedUSA
25-0430
File

Co-op Put Its Revenue Loss From the April Intrusion at £206 Million

£206 million in revenue that never arrived. Groceries are perishable and demand is not deferred — the loss is permanent in a way a car maker’s is not.

Scattered SpiderHelp-desk social engineeringRetailRetail
Sev 4TargetCo-opActorScattered Spider
25-0423
File

System Intrusions Behind 80% of Asia-Pacific Breaches, up From 38%

A number that moves faster than the world does is measuring the instrument.

MultipleVariousMultipleAnalysis
Sev 3TargetAsia-Pacific organisationsActorMultiple
24-0808
File

Sellafield Pleaded Guilty to Nuclear Site IT Security Failings

The regulator did not need an intrusion. The offence was the posture itself.

EnergyAccountability
Sev 3TargetSellafield LtdActorUnattributedUnited Kingdom
24-0702
File

Wise and Affirm Customers Exposed by a Breach at a Firm They Never Chose

The partnership had ended the year before the intrusion. The records had not.

LockBitFinanceConcentration
Sev 4TargetFintech customersActorLockBitUSA
24-0620
File

Change Healthcare Affected-Person Count Took Eleven Months to Settle

It did not grow because the intrusion grew. It grew because working out whose records sit in four terabytes takes eleven months.

ALPHVValid credentials, no MFAHealthcareVerification
Sev 5TargetChange HealthcareActorALPHVUSA
24-0509
File

Ascension Traced Its Intrusion to an Employee Downloading a Malicious File

A hundred and forty hospitals losing their record system is not a proportionate consequence of one download. What sits between is everything it was allowed to reach.

Black BastaMalicious file downloadHealthcareIdentity
Sev 5TargetAscensionActorBlack BastaUSA
23-1218
File

Comcast Says Citrix Bleed Reached Xfinity Data on 35.8 Million Customers

Six days between patch and intrusion. Faster than most manage, and longer than the window now exists.

UnattributedMemory disclosureTelecomTelecom
Sev 4TargetComcast XfinityActorUnattributedUSA
23-0808b
File

UK Electoral Commission Disclosed a 2021 Intrusion Two Years Later

The people who asked to be left off the public register were in the breach anyway.

UnattributedImpersonated account, known weaknessesGovernmentPublic sector
Sev 4TargetUK Electoral CommissionActorUnattributedUnited Kingdom
23-0715
File

ALPHV and Cl0p Both Listed Estee Lauder From Separate Intrusions

An organisation dealing with an incident should not assume it is dealing with an incident.

ALPHV, Cl0pMOVEit (Cl0p); not established (ALPHV)RetailAftermath
Sev 4TargetThe Estée Lauder CompaniesActorALPHV, Cl0pUSA
23-0512b
File

PharMerica Notified 5.8 Million People After a Two-Day Intrusion in March

Every remedy this database records requires a living person to take an action.

Money MessageHealthcareHealthcare
Sev 4TargetPharMericaActorMoney MessageUSA
23-0402
File

Western Digital Took My Cloud Offline for Eleven Days After Network Intrusion

Personal cloud storage is sold on one promise. For eleven days the product did not exist.

UnattributedTechnologyAvailability
Sev 4TargetWestern DigitalActorUnattributedUSA
22-0617
File

Flagstar Bank Told 1,547,169 Customers Six Months After a Two-Day Intrusion

The count is exact to the person. The explanation is a two-day window and nothing else.

UnattributedFinancial servicesFinance
Sev 4TargetFlagstar BankActorUnattributedUSA
22-0324
File

City of London Police Arrested Seven People Aged 16 to 21 Over Lapsus$ Intrusions

"Sophisticated" describes the attacker’s resources. It says nothing about the size of the gap.

Accountability
Sev 2TargetLapsus$ActorUnattributedUnited Kingdom
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging