Incidents
Filtering is available with a free account.
Create a free account to filter
Sep 2026
United States of America
2026-09-22
Hackers claiming to be from ShinyHunters said they breached multiple FBI-related services using a zero‑day exploit in Oracle PeopleSoft, accessed AWS GovCloud servers and exfiltrated between two and three terabytes of data that includes names, addresses, phone numbers, dates of birth and spouse information for current and former employees and applicants. They also defaced the agency's jobs website, posting a seizure notice and asserting that all agency data was compromised. The group said the breach was not financially motivated and described their intended action as coercion rather than extortion.
Sep 2026
United States of America
2026-09-21
A reported cyberattack on AECOM remains unconfirmed, with the hacker group Metaencryptor claiming responsibility for an intrusion involving about 1.22 TB of data. A separate dark web monitoring service listed a roughly 670GB leak attributed to BrainCipher and indexed thousands of company-linked credentials, while cautioning that the credentials may not be connected to the claimed attack. The incident may affect current and former employees, clients, and others whose information the company maintained, but the scope, data types, and number of affected people have not been publicly established.
Sep 2026
-
2026-09-22
Employees of Archer-Daniels-Midland filed a class action alleging that cybercriminals stole and posted personal identifying information to the dark web after gaining access to the company’s network. The cybercriminal group Qilin claimed responsibility for stealing names, dates of birth, addresses, Social Security numbers and driver’s license details, which the plaintiffs said could be used for fraud and identity theft. The complaint alleges the company lacked effective prevention, detection and mitigation controls, including employee training, strong passwords, multilayer security, encryption, multifactor authentication, backups and access restrictions. Plaintiffs also alleged they had not been promptly notified and sought injunctive relief, compensatory damages and punitive damages.
Sep 2026
Lithuania
2026-09-22
Revolut customers were targeted by smishing messages that appeared to come from the bank and urged recipients to follow links to confirm their identity or risk restricted account access. Some links led to pages mimicking a live-video identity check, requesting camera access before prompting users for passwords. The broader breach involved fraudulent requests for KYC information sent to the bank’s Lithuanian-regulated entity under European Investigation Orders. Threat actors impersonated Italian law enforcement after compromising Italian Ministry of the Interior email accounts with infostealer logs, reportedly maintaining access for around six months. Several hundred accounts were thought to be impacted, with high-net-worth crypto users singled out after blockchain records were analyzed.
Sep 2026
Japan
2026-09-20
Helpfeel disclosed that attackers exploited a vulnerability in the Gyazo image upload server to gain unauthorized access, remaining inside until they were removed shortly thereafter. The breach exposed approximately 23.6 million user records containing names, email addresses, password hashes, user and device IDs, X integration tokens, profile details, usage statistics and billing information, while payment card data was not compromised. In addition, the intruders accessed roughly 490 million image metadata records and a set of private images, though the volume of the latter was not disclosed.
Sep 2026
United States of America
2026-09-17
Hilltop Bank experienced a cybersecurity incident that forced it to take its primary and backup systems offline, disrupting online and mobile banking for approximately a week. The bank limited debit‑card transactions to $1,000 per day, suspended scheduled outgoing payments such as mortgages and credit‑card bills, and pledged to reimburse customers for any late fees incurred. While seven of its eight branches reopened for limited in‑person services and ATMs remained operational, the core digital channels stayed unavailable and the institution provided no detailed timeline for full restoration. Officials said they disconnected systems as a precaution, worked with federal agencies and cybersecurity experts, and notified regulators, but have not disclosed whether malware, stolen credentials or data exfiltration was involved. Scammers have also attempted to spoof the bank’s call‑center number, prompting warnings to customers to rely only on official communications.
Sep 2026
United States of America
2026-09-09
Everett City Hall was closed to the public after a cyber incident disrupted its internal network and systems, with the attack detected over the weekend and only essential staff permitted to work the next day while police, fire, public works and the local school district continued normal operations. The city’s IT department and the local police department are investigating the scope of the breach and working to restore full functionality, though it remains uncertain when the building will reopen to visitors.
Sep 2026
United States of America
2026-09-22
Liquid Network reported that a white hat hacker exploited a bug to withdraw thousands of bitcoins worth about $340 million from its wallet, prompting the platform to pause operations. The hacker said they would return the funds if the vulnerability was fixed, and after Blockstream patched the flaw, roughly 3,400 of the approximately 4,000 stolen bitcoins were returned, leaving about 600 bitcoins valued at around $47 million still under the hacker’s control. Operations remain halted while additional fixes and security improvements are implemented before restarting.
Sep 2026
United States of America
2026-09-17
Veradigm disclosed that compromised credentials from a third-party vendor allowed an attacker to access a limited customer-services API and copy patient data. The incident affected a small number of customers but caused no operational disruptions, and the compromised interface did not provide access to the company’s broader network, servers, databases, or other systems. Stolen information included personal details and, for some patients, Social Security numbers, while clinical and medical information remained unaffected. The Gentlemen ransomware group claimed responsibility, alleging possession of millions of records containing names, addresses, contact details, Social Security numbers, and guarantor information, and threatened to publish the data unless ransom negotiations began. Veradigm activated incident-response procedures, notified law enforcement, began notifying affected customers and individuals, and is offering credit monitoring where applicable.
Sep 2026
United States of America
2026-09-20
ShinyHunters asserted they infiltrated the Florida Department of Highway Safety and Motor Vehicles Driver and Vehicle Information Database by exploiting a password‑reset flaw that allowed them to compromise accounts of agency employees and an FBI agent. They then downloaded roughly two hundred thousand driver records containing personal details such as Social Security numbers and licence information, providing a screenshot of a Jeffrey Epstein record as proof while stating the vulnerability has since been patched.
Sep 2026
United States of America
2026-09-11
A cybersecurity incident has disrupted certain systems at Luminis Health, a health system operating facilities primarily in central Maryland and on the Eastern Shore. The incident, announced via a Facebook post, affected the organization's online patient portal, which was down shortly after the announcement. Despite the disruption, the health system stated that its priority remains providing safe, high-quality care to patients and expressed appreciation for the community's patience and understanding.
Sep 2026
Italy
2026-09-20
The Vivit Africa LNG carrier experienced a systems failure that the crew reported as a suspected cyber attack while sailing from the United States toward Europe, leaving the vessel unable to access some internal control systems. After idling off the Italian coast and abandoning its planned discharge at Rovigo, the ship reversed course toward Algeciras. The Italian Coast Guard assisted following a master‑reported malfunction in cargo‑monitoring systems, and Korean Register, the technical adviser for the South Korean‑owned vessel owned by H-Line Shipping Co. Ltd., was notified. The vessel uses Kongsberg Maritime equipment for positioning, navigation and propulsion, and Vitol Group holds the ship under a time charter. Authorities are monitoring nearly 20 ships worldwide for similar threats, and two oil and gas tankers off the US coast were previously boarded by the Coast Guard and FBI due to potential cyber incidents.
Sep 2026
United States of America
2026-09-14
IDScan confirmed that hackers stole driver’s licenses from its cloud systems, including full names, license numbers, photos, and identity numbers from other government-issued documents such as passports. The exposed database reportedly contained records for more than 150 million people in the United States and Canada and was accessible through a dark web search site, with full access allegedly requiring payment. The Louisiana-based identity verification company said its investigation was ongoing, while the FBI said it was investigating and the Pentagon said it was aware of the suspected breach.
Sep 2026
United States of America
2026-09-14
Springfield Public Schools experienced a cyber intrusion in which an outside group gained access to the network and blocked access to third‑party systems for student medical records, transportation, food services and educational tools. The incident was classified as a Level 4 event, prompting involvement of the FBI, state and local police alongside district IT staff. Schools were closed as a precaution while officials worked to contain and eradicate the threat, and students and families were advised not to use district‑issued devices to limit malware spread. Instruction continued using non‑digital methods such as books and paper while restoration efforts proceeded. Investigators have not confirmed a ransom demand nor identified the responsible actors, and the city government was reported to be unaffected.
Sep 2026
-
2026-09-14
The FBI is investigating an alleged data breach in which digital scans of millions of driver’s licenses from the United States and Canada were offered for sale on a dark web service called Nexus. Independent journalist Brian Krebs first disclosed the leak, noting that the scans included his own license and that of U.S. Defense Secretary Pete Hegseth, and that many of the documents had recently been processed by businesses using equipment tied to the New Orleans‑based ID verification firm IDScan.net. The firm said an unauthorized third party may have accessed or copied certain customer information stored in its cloud, such as full names and driver’s license or other government‑issued identification numbers, and that it is notifying affected individuals, providing free credit monitoring, and cooperating with federal investigators.
Sep 2026
United States of America
2026-09-16
CenterPoint Energy, a Houston-based public utility providing electric and natural gas services to about seven million customers across several states, disclosed that an unauthorized third party accessed personal information through one of its external-facing systems. The breach involved the exfiltration of millions of customer records via a public API lacking rate limiting and web application firewall protections, with leaked data including names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. Although the company confirmed the incident in an SEC filing, it did not disclose the threat actor’s identity, the exact number of affected customers, or the full scope of compromised data, and stated that its utility services remained uninterrupted. The company has engaged third‑party cybersecurity experts, strengthened system protections, reported the incident to law enforcement and regulators, and faces multiple class‑action lawsuits alleging the breach occurred over a recent period.
Sep 2026
United States of America
2026-09-22
The Alabama Board of Nursing experienced a cyberattack that took its online licensing system offline, leaving approximately eighty thousand nurses unable to renew their credentials and delaying licensure for recent graduates. The board has kept the system offline while it investigates the incident, works with external cybersecurity experts and state resources, and focuses on protecting licensee data. In the meantime, paper applications are being accepted and processed at designated community college sites, though renewals still lack an online option. Officials have not disclosed the attacker’s identity, the scope of any data breach, or a timeline for full service restoration, noting that recovery will proceed in phases as systems are validated.
Aug 2026
Canada
2026-08-31
A Canadian telecommunications provider operating across seven provinces and Bermuda notified customers of a potential data breach affecting accounts that may have been compromised between late Wednesday and early Thursday morning. The company sent initial email notifications to affected customers before the weekend and stated that exposed information may include customer names, contact details, account numbers, and PINs, though it does not believe credit card or banking information was involved. After learning of the breach, the company shut down affected platforms on its website and mobile app and committed to using additional communication channels, including letters and further web updates, to reach potentially impacted individuals, including those with historical accounts. The exact number of affected customers remains unclear, and the company indicated it is still gathering details about the incident.
Aug 2026
United States of America
2026-09-07
The Bureau of Alcohol, Tobacco, Firearms and Explosives reported a cybersecurity incident affecting a standalone system that is not connected to its enterprise network, eForms platform or other core systems. The agency said the compromised machine contained information about investigation targets and that there is no indication gun owner records were exposed. The Department of Justice classified the event as a major incident, triggering mandatory congressional notification. A Russian‑speaking ransomware group claimed responsibility on its leak site, though the agency has not confirmed the group’s involvement or disclosed any ransom demand. Investigators have not published proof of data exfiltration, and the case remains under active forensic review.
Aug 2026
United Kingdom
2026-08-31
Manchester Airports Group confirmed a cyberattack in which an unauthorised third party accessed the personal data of approximately 8.7 million customers. The compromised information related to car park, lounge and Fast Track bookings as well as sign‑ups for the airports’ free Wi‑Fi networks, exposing email addresses, phone numbers, vehicle registration numbers and postcodes; for most affected individuals only an email address obtained via Wi‑Fi sign‑in was involved. No bank details or payment card data were stored on the affected system, and flight operations, security and day‑to‑day activities remained uninterrupted. The group temporarily suspended its online Manage My Booking service while it worked with specialist advisers and relevant authorities to contain the breach and began contacting customers to warn them of possible phishing attempts using the exposed data.