Tag: data-breach
All entries tagged data-breach.
- NCSC-CH advises its own constituency on the actively exploited Power Pages misconfiguration — anonymous web roles granted excessive Dataverse table permissions
- Liechtenstein VwbP breach: forensics identify a possible entry point, confirm the register was hit in isolation, and publish the exact field set — identity data, no contact details, no financial data
- ByteToBreach hits Hungary's State Treasury after Romania's land registry — the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle
- Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed
- PNLD confirms the police contact-data breach and names a second affected service; researchers trace the ExfilSquad campaign to anonymously readable Power Pages portals, but not PNLD's own root cause
- Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution
- ShinyHunters status: a sector ISAC formalised the helpdesk-vishing-to-SSO chain as a written advisory and told defenders to protect the identity provider like a domain controller, while deliberately declining to name victims
- Criminal claims outran confirmation in every direction this week — a victim list a vendor assesses is more likely fabricated than real, yet containing a confirmed government breach; a blast-radius claim on one outlet; an attribution the victim will not endorse
- In every confirmed European public-sector and critical-infrastructure incident this week the entry point was an already-valid credential, and the attacker's tool was the platform's own export or admin function
- CCI Nice Côte d'Azur: a compromised administrator account on the chamber's jobseeker platform was used to run the platform's own export function
- Adform: the shared tracking script every customer site embeds was trojanised with a clipboard-rewriting crypto-clipper, and no antivirus engine flagged it
- French Éducation nationale: a hijacked staff account reached the agent-training system, exposing identity and NIR data for everyone who has worked in an académie since 2001
- Health-ISAC tells the health sector to treat SSO as Tier 0 against ShinyHunters, and deliberately declines to name victims — the pattern, not the tally, is the advisory's point
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad — a five-day-old extortion brand whose other 14 claims look fabricated
- Stadler Rail: Everest moves from ransom demand to publication, and claims the released archive touches four other rail operators — Stadler's own channel has said nothing about it
- Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to it
- ShinyHunters claims the Ernst & Young ITSM breach and asserts the stolen third-party credentials reached Jira, GitHub and Azure
- Chat Control backlash turns operational: a hacktivist compiles targeting dossiers on French and EU officials out of old breach data, not a new intrusion
- Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet
- BaFin fined TeamViewer EUR 240,000 for how it disclosed its 2024 nation-state breach — a website notice did not satisfy the ad-hoc-disclosure duty, setting a breach-disclosure-mechanics precedent for any SIX/EU-listed software or CI supplier
- Swiss and European public-sector bodies carried the week's home-region incident load — and nearly every one was reached through a third party, a shared platform or a fiduciary, then followed by a disclosure that had to be walked back
- IFAGE Geneva — DragonForce publishes the stolen data, exposing student exam results the institute had said were unaffected
- ANCPI Romania — DNSC interim report confirms vCenter-to-ESXi ransomware and exfiltration of ~2 million ePayment user records
- Swiss autism-support foundation Stiftung Autismuslink confirms data-theft cyberattack; INC Ransom claims it
- BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file
- South Korea's Foreign Ministry: a ~10-month zero-day intrusion into the Diplomatic Academy's e-learning platform exposed records on nearly all diplomats
- Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million — the Swiss rail manufacturer refuses to pay
- ANCPI (Romania cadastre): agency says core databases were NOT compromised, contradicting ByteToBreach's destruction claim; Gov Cloud migration to complete 22 July
- Nearly every breach disclosed this week entered through someone else's infrastructure — a service provider, a data-centre host, an ITSM platform and a CI/CD pipeline, not the victim's own perimeter
- Swiss and European public-sector, utility and transport organisations carried the week's home-region incident load — a land registry offline for days, two Swiss utilities/foundations hit through third parties, an EU transit ransomware and a EUR 1.7M telco enforcement
- The week's identity intrusions all abused a trusted relationship rather than breaking authentication — OAuth consent and secret reuse, forged and unverified tokens, and helpdesk process abuse turned valid trust into valid-account access
- Ernst & Young discloses a breach of a third-party IT support-ticket platform used by its tax practice, exposing client tax and financial documents
- Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware
- TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD
- Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
- Garante fines Wind Tre EUR 1.7M over a vishing-enabled API-enumeration breach that exposed 365,048 telco customers
- Nayax refuses The Syndicate's extortion demand and narrows its disclosed breach scope
- World Leaks posts ~858,000 files tied to India's Kudankulam nuclear-plant contractor; Reliance confirms a third-party-hosting breach
- Basel utility IWB: ~40,000 customer records exfiltrated in a breach of a third-party service provider
- Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerability
- DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB — an attribution and volume IFAGE has not confirmed
- npm supply-chain wave status: jscrambler package compromised this week, extending the install-hook-evasion pattern seen in the injectivelabs SDK
- This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim
- Healthcare across Switzerland and the UK saw ransomware confirmation, mailbox compromise and an insider-access clampdown this week
- Government and public administration across Switzerland and Europe took a broad spread of attacks this week — ransomware, espionage watering-holes, AI-tooled APTs and credential-phishing
- Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking it
- NHS England issues insider-access controls after staff 'snooping' on high-profile patients' records
- 'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
- ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
- Nextcloud GmbH's own hosting infrastructure exposed 367K internal records via a misconfigured public Elasticsearch cluster, including client setup scripts with hardcoded credentials
- CERT.LV: ransomware crew breaches Latvia's state forestry operator LVM via a 2-year-unpatched system, hits essential-services provider Olpha, and is probing other EU/NATO institutions
- KDDI names the root cause of its ISP email-platform breach: a zero-day in third-party software the vendor had not recognized
- Deutsche Bank confirms a third-party vendor incident after 'Unsafe' ransomware group posts alleged employee data
- Groupe 3R confirms Akira attribution and darknet publication of stolen data in its own forensic update
- Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records — claim unverified and contradicted by the filing
- Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials
- FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim
- ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces
- Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recovered
- Government and public administration took three distinct hits this week — a Swiss cantonal leak-site claim, a Pegasus-infected MEP, and a US federal info-sharing breach
- Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaign
- Kairos data-theft-only extortion — a US county paid ~$1M with no ransomware encryptor ever recovered
- Navient discloses borrower SSN exposure from a ransomware hit on its outside law firm
- AdaptHealth breached via a social-engineered hijack of a third-party contractor's session
- Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach — 2.5 months after containment
- DHS confirms a breach of the Homeland Security Information Network (HSIN)
- MedusaLocker leak site lists the Canton of Zürich's Baudirektion — unconfirmed claim
- Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign
- Blackfield ransomware demands $2M from Nidec's Taiwanese subsidiary after a 22 June server compromise
- Aflac discloses a Japan-subsidiary breach — 4.38 million policyholders and agents, ~10-day dwell before detection
- KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs
- ShinyHunters / UNC6240 Oracle PeopleSoft campaign
- FortiBleed
- Mass third-party exposures: Xsolis, Texas Parks & Wildlife, Canvas
- Social engineering and SSO abuse opened the highest-profile intrusions
- Technology & SaaS supply chain — the week's busiest victim class
- Education
- Healthcare
- Public administration & government
- ShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one week
- Klue / Icarus Salesforce OAuth-integration breach — from nine named victims to ~24, then the attacker gets hacked
- ShapedPlugin's official update channel shipped backdoored WordPress Pro plugins — credential, 2FA-secret and web-shell theft
- NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall
- Island: "BadBlocker" — an 11M-user Chrome ad-blocker is one server config change away from arbitrary JavaScript on any site
- NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
- Klue/Icarus Salesforce breach widens to ~24 firms; the attacker is itself hacked and a second extortion actor emerges
- UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach — 160 universities, ShinyHunters extortion, ransom paid
- ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square Garden
- Ukrposhta digital services disrupted by an overnight attack; pro-Russian hacktivists claim a prior data theft
- Klue/Icarus Salesforce OAuth breach — BeyondTrust and LastPass added to the named-victim list
- 8x8 confirms Klue/Icarus Salesforce exfiltration in an SEC 8-K Item 1.05 filing
- Xsolis healthcare-AI vendor breach exposes 1.4M patients across seven US health systems — third-party processor pattern
- Klue/Icarus OAuth-token breach — named victim list expands to nine firms, mostly cybersecurity vendors
- FortiBleed — first full tool-chain disclosure (FortigateSniffer, SNIFTRAN, GPU cracking cluster); Fortinet confirms no new CVE
- ShapedPlugin build pipeline compromised — three Pro WordPress plugins backdoored to steal credentials, 2FA secrets and drop a web shell
- Brazil's national Cell Broadcast alert platform hijacked to push fake "Extreme Alert" messages to ~30M phones
- UK ICO left leaderless mid-restructure — Commissioner resigns with immediate effect
- EDPB adopts a harmonised GDPR Article 33 breach-notification template — consultation open to 5 August
- The third-party breach as the week's dominant entry vector
- Insider and process failures — Munich school data, a lost SSD, and an NHS records caution
- Technology & SaaS supply chain — the week's busiest victim class
- Energy, water & OT — perimeter and process failures, with an OT-adjacent halt
- Healthcare — third-party exposure and a 16-month notification gap
- Education — exposed CMS and forum software stack a structural risk
- Public administration — named European institutions and government data in the firing line
- ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure
- FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory
- Klue OAuth-token breach — victim list grows, CRM-API abuse chain detailed
- Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today
- Texas Parks & Wildlife: 3.08M licence holders exposed via an unnamed third-party vendor — with a public-vs-AG-filing SSN contradiction
- HCRG Care Group first notifies patients of a February 2025 Medusa breach — 16 months on
- UK Information Commissioner resigns with immediate effect — regulator left leaderless mid-restructure
- FortiBleed reaches 86,644 compromised FortiGate devices; CISA issues emergency hardening guidance
- Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication
- Nintendo employee data stolen from third-party HR-survey SaaS (TinyPulse), not Nintendo's own systems
- UK ICO issues criminal caution to London Clinic insider over Princess of Wales medical-record access
- FortiBleed — 73,932 internet-facing FortiGate devices exposed, Russian-speaking group cracking credentials into Active Directory
- Novo Nordisk — FulcrumSec claims authorship, $25M demand refused, data offered for private sale
- Munich: ~120,000 student records suspected on the darknet — terminated employee under investigation
- Novo Nordisk clarifies stolen-data scope — non-pseudonymised HCP data in play
- Council of Europe named as a victim of the Oracle PeopleSoft (CVE-2026-35273) campaign
- iRhythm discloses data theft via social engineering of a third-party-hosted application (SEC 8-K)
- WordPress supply-chain compromise via Awesome Motive's CDN backdoors ~1.2M sites
- Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform — billing PII for ~2M customers leaked, no OT access
- EDPB adopts a harmonised GDPR Article 33 breach-notification template
- South Korea fines Coupang a record ₩624.7 bn over an unrevoked signing key
- Novo Nordisk — theft of non-public data including personal data
- France's Tchap government messenger — account-takeover scrapes 73,467 civil servants' metadata
- Healthcare & energy — large-scale personal-data exposure from theft and from mishandling
- Education — ShinyHunters' PeopleSoft campaign lands disproportionately on universities
- Maine breach-notification portal hoax — fraudulent filings against VRChat and Discord, then the portal goes dark
- CVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardest
- Kyushu Electric subsidiary loses an unencrypted SSD with 10.9 million customer records — reportedly Japan's largest personal-data breach
- Maine AG takes its breach-notification portal offline after confirming the VRChat/Discord filings were a hoax
- Oracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardest
- South Korea fines Coupang a record ₩624.7 bn over an unrevoked signing key held by a former employee
- Novo Nordisk discloses theft of clinical-trial and healthcare-professional data
- ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records
- Maine's breach-notification portal abused for fraudulent filings against VRChat and Discord — both companies deny any breach
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
- EDPB adopts a harmonised GDPR Article 33 breach-notification template; consultation open to 5 August
- ServiceNow unauthenticated REST endpoint queried customer instance tables before a silent 5 June patch
- Meta discloses 20,225 Instagram account takeovers via an AI support-tool logic flaw; Maine AG notification filed 8 June
- France's Tchap government messenger breached via account takeover — 73,467 civil servants' metadata scraped, CNIL notified
- Oxford University CareerConnect (Group GTI) breach exposes students at multiple UK universities
- ICO secures Proceeds-of-Crime confiscation from former RAC employees who sold ~30,000 customer records
- Magecart family runs its skimmer out of Stripe — payload in customer metadata, stolen cards exfiltrated back through api.stripe.com
- Hijacked polyfill[.]io domain reactivates, surfacing native browser credential prompts on sites that never removed legacy script tags
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services
- ShinyHunters extortion campaign adds DentaQuest — 234 GB published after refusal to pay, 2.6 M dental-benefit records exposed
- UN World Food Programme breach exposes IDs and locations of ~600,000 Gaza households
- Shared booking-software breach exposes guests at 100+ Dutch, Belgian and Irish hotels; phishing wave already underway
- NCSC Switzerland: Booking.com breach feeds two-pronged WhatsApp hotel-booking phishing against Swiss travellers
- Dashlane discloses TOTP brute-force that downloaded encrypted vaults of fewer than 20 users
- ShinyHunters publishes the Charter Communications dataset after ransom refusal
- Spain arrests doxer who published personal data on INCIBE, prosecutorial and security-service staff
- Booking.com WhatsApp phishing + upstream hotel SaaS breach: real reservation data weaponised, 100+ properties affected, Dutch DPA opens investigation
- ShinyHunters — DentaQuest: 234 GB HIPAA claims data published after ransom refusal, 2.6 M Medicaid and dental-benefit records
- Luna Moth / UNC3753: vishing-to-physical-USB data-theft extortion reaches ~$20 M suppression payment and DNS fast-flux C2
- Finance / payments — Stripe-abusing Magecart and OFAC Iran sanctions
- Healthcare — HIPAA breach + healthcare supply-chain exposure
- California AG sues former 23andMe (Chrome Holding Co.) over the 2023 genetic-data breach — bulk-enumeration coding error plus absent credential-stuffing defences
- CNIL fines IQVIA Operations France €5M for health data warehouse security failures: no MFA, no log monitoring, no network segmentation
- TechCrunch finds 100 K passport scans and selfies on a public-read S3 bucket behind a UK Visa Portal lookalike
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brands
- Dutch National Police arrest 35-year-old over AFC Ajax fan-data breach — misconfigured API access-control and shared keys exposed 300,000+ accounts and 42,000 season-ticket records
- ShinyHunters Salesforce campaign — Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
- Lithuania's Centre of Registers loses ~600,000 state-register records to abused institutional credentials; foreign-state actor suspected
- Data-protection enforcement converges on a health-data controls floor — CNIL fines IQVIA €5M; California AG sues over 23andMe
- ShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seized
- UK Visa Portal — ~100,000 passport scans and selfies on a public-read S3 bucket behind a government-lookalike site
- AFC Ajax — 300,000+ fan accounts exposed via misconfigured API access control; Dutch suspect arrested
- Healthcare — administrative and imaging intermediaries remain the soft surface
- ShinyHunters lists Charter Communications (Spectrum) — telco victim in the Salesforce-credential campaign
- Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
- Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed
- Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident
- West Pharmaceutical Services — 8-K/A confirms full operational restoration, data investigation ongoing
- ICO secures £355,880 POCA confiscation against former Markerstudy Insurance employee for off-hours bulk record access and sale
- TeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root cause
- B1ack's Stash carding marketplace publicly releases 4.6M card records — SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks
- TheGentlemen RaaS lists Czech university and Swiss engineering firm on leak site
- Grafana Labs CoinbaseCartel breach — victim confirms source-code-only theft, no customer data, ransom rejected
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
- CISA contractor (Nightwing) exposed AWS GovCloud admin keys and internal credentials in public GitHub repo for ~6 months
- ARWINI (Lower Saxony statutory-prescription audit body) — investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87 TB; ~70,000 GDPR Art. 9 records in scope
- Rhysida claims Stuttgart municipal data — city denies a confirmed incident
- West Pharmaceutical Services — 8-K/A confirms full operational restoration
- Grafana Labs / CoinbaseCartel — source-code-only theft confirmed; ransom rejected; detected by canary token
- 7-Eleven — ShinyHunters Salesforce campaign claims another 600,000+ records
- ARWINI (Lower Saxony prescription-audit body) — exfiltration confirmed; Kairos claims 2.87 TB including ~70,000 GDPR Art. 9 records
- Six German university hospitals — patient records exfiltrated via billing processor Unimed
- Education — virtual-classroom platforms and EdTech SaaS exposure
- Public administration — web-CMS and identity estate under multi-vector pressure
- Healthcare (DACH) — the soft surface is the administrative intermediary, not the hospital
- FunnelKit "Funnel Builder for WooCommerce" actively exploited as Magecart skimmer on 40,000+ WordPress stores — no CVE assigned
- node-ipc npm package backdoored via expired-domain account takeover — 90+ credential categories exfiltrated, three malicious versions, ~3-minute window to detection
- GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
- TeamPCP / Mini Shai-Hulud — OpenAI named as victim; code-signing certificate rotation enforced for all macOS apps
- Sophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectors
- GemStuffer — RubyGems weaponised as a one-way exfiltration channel scraping UK local-authority ModernGov portals; new abuse pattern targets the asymmetric monitoring gap between package pull and push
- Dutch IGJ rules Clinical Diagnostics/NMDL failed NEN 7510 information-security standard at time of July 2025 ransomware breach; ~941,000 patients affected, cervical-cancer screening data exposed
- Instructure Canvas — US House Homeland Security Committee opens formal investigation; Instructure paid ransom
- BWH Hotels (Best Western, WorldHotels, Sure Hotels) — 181-day unauthorised access to a guest-reservation web application, six EU brands in scope
- Foxconn confirms Nitrogen ransomware crippled North-American manufacturing sites; 8 TB / 11M files claimed
- Instructure (Canvas LMS) — ransom paid to ShinyHunters with "shred logs"; second intrusion confirmed; per-institution leak deadline reset to today
- Škoda Auto Deutschland online-shop breach exposes customer PII and password hashes; logging gap prevents exfiltration confirmation
- West Pharmaceutical Services files SEC Form 8-K Item 1.05 — data exfiltrated, systems encrypted, global operations partially restarted
- BKA and ZIT dismantle relaunched Crimenetwork darknet marketplace; German operator arrested in Mallorca on European Arrest Warrant
- ICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record
- EDPB Coordinated Enforcement Framework 2026 — 25 DPAs investigating GDPR Articles 12–14 transparency
- Canvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigation
- Verizon DBIR 2026 (19th annual edition)
- node-ipc npm package — backdoored via expired-domain account takeover
- South Staffordshire Water — ICO £963,900 fine
- Škoda Auto Deutschland — online-shop breach exposes customer PII and password hashes
- West Pharmaceutical Services — SEC Form 8-K Item 1.05
- Clinical Diagnostics / NMDL — Dutch IGJ formal NEN 7510 non-conformity ruling
- BWH Hotels — 181-day unauthorised access to guest-reservation web application
- WordPress retail / e-commerce
- Hospitality
- Manufacturing
- Healthcare
- Canvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploited
- Canvas/Instructure — ShinyHunters claims a *second* intrusion despite May 8 patches; seven Dutch universities executed emergency disconnects on/before May 9
- Braintrust AI evaluation platform AWS account breach — multi-tenant LLM-provider keys and SaaS credentials at risk; mandatory key rotation across customer base
- Groupe 3R (Réseau Radiologique Romand) — Akira ransomware claims 48 GB; 20 imaging centres across seven Swiss cantons, second attack in twelve months
- Canvas/Instructure extortion — Oxford, Cambridge, Liverpool issue public statements; 44 Dutch universities confirmed; May 12 deadline active
- Inditex (Zara) — ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
- Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed
- Eurail breach: 308 777 travellers notified three months after December 2025 compromise; Dutch DPA and EDPS open reviews
- Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)
- Europol shadow-IT — LIBE committee MEPs call for mandate-expansion pause; EDPS sanctioning toolkit identified as binary
- Akira playbook quarterly context — Q1 2026 healthcare concentration; Qilin remains the dominant operator on German healthcare victims
- The Gentlemen RaaS — Europe-skewed operation surged approximately 448% QoQ; 32% of Q1 2026 victims in Europe; FortiGate CVE-2024-55591 initial-access funnel
- Qilin / Agenda RaaS — Die Linke confirms Q2 2026 German activity continuity
- ShinyHunters / WorldLeaks family (financial-data extortion, third-party-SaaS pivot)
- Google Threat Intelligence Group — Europe data-leak landscape 2025
- Trellix source code repository breach — vendor confirmed, scope undisclosed, supply-chain integrity question open
- DigiCert support portal compromise — Salesforce-based support-chat social engineering yielded 60 fraudulent EV code-signing certificates
- Media and political (HU, DE)
- Transport (NL/EU)
- Public-sector administration and digital identity (FR, EU, FI, CH)
- Education (NL, UK, DE)
- Healthcare (CH, NL)
- Canvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnects
- ShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / Canvas
- Akira ransomware on Groupe 3R — 20 Swiss medical-imaging centres across seven cantons; second cyberattack on the same operator within twelve months