Incidents
Filtering is available with a free account.
Create a free account to filter
Jan 1994
Germany
2026-01-24
The provided article describes M1-Sporttechnik as a bicycle manufacturer specializing in carbon e-bikes, highlighting its history of innovation since its founding and its active social media presence across platforms like Facebook and Instagram. No cybersecurity incident details are mentioned in the source material—the content focuses exclusively on promotional information about the company's products, community engagement, and website cookie usage. The article contains no references to data breaches, system compromises, or malicious activity affecting the organization or its customers.
Jan 1995
United Kingdom
2026-01-24
A cyberattack targeted unreleased music sessions from an alternative rock band's archived mini discs, with hackers demanding a ransom to prevent public release. The group refused payment and instead independently published the stolen 18 hours of material under the title MINIDISCS [HACKED], making it available for purchase with all proceeds directed to an environmental activism organization. The compromised content consisted of recordings not originally intended for public distribution. By proactively releasing the material, the band neutralized the attackers' leverage while converting the incident into a charitable initiative supporting ecological causes.
Sep 1996
Canada
2026-08-29
Canoe.ca disclosed that a breach exposed personal information of roughly one million users, including names, email addresses, mailing addresses and telephone numbers, collected through contests, forums, comment sections and personal pages. The investigation found no financial data or social insurance numbers among the compromised records. After discovering the incident, the organization launched an investigation, enlisted security experts, and informed the RCMP, the Office of the Privacy Commissioner and relevant provincial privacy authorities. It also provided a contact number for affected users seeking assistance.
Sep 1996
Canada
2026-08-29
Canoe.ca, a free news and entertainment portal operated by MediaQMI Inc. and previously owned by Sun Media Corp., disclosed that databases holding user records were accessed without authorization. The investigation revealed that the compromised data included names, email addresses, mailing addresses and telephone numbers of roughly one million Anglophone and Francophone users, but contained no financial or social insurance information. Data gathered after the affected period remained secure, and the organization notified law enforcement and privacy authorities while working with security experts to address the breach. It apologized to users and stated it is attempting to contact those potentially affected, providing a telephone line for inquiries.
Sep 1996
Canada
2026-01-24
Canoe.ca experienced a data breach compromising personal information of approximately one million users, including names, email and mailing addresses, and phone numbers collected through site interactions such as contests and forums. The company confirmed no financial data was affected, initiated an investigation with security experts, notified law enforcement and privacy authorities, and established a dedicated contact line for impacted individuals.
Jan 2000
Japan
2026-01-24
Porsche Japan experienced a data breach compromising customer information through unauthorized access, exposing over 28,000 email addresses primarily linked to online brochure requests. Potentially affected data included names, physical addresses, telephone numbers, and income details stored during customer interactions. The incident involved historical records of consumer engagements, resulting in significant exposure of personal identifiers and sensitive financial attributes.
Dec 2004
Israel
2026-01-24
A sophisticated cyber espionage campaign, attributed to Iranian actors and named Infy, targeted Israeli entities and a U.S. government organization through spear phishing emails containing malicious documents. The malware, delivered via compromised Israeli email accounts, employed evasion techniques such as delayed activation until system reboot, then harvested sensitive data including keystrokes, browser credentials, and cookies for exfiltration to command-and-control infrastructure. The operation demonstrated sustained refinement over years, incorporating regional targeting tactics and adapting to new technologies like the Microsoft Edge browser. Evidence from infrastructure analysis, including domain naming patterns and server locations, pointed to Iranian involvement, with the campaign focusing on governmental, commercial, and even domestic targets for intelligence collection while maintaining a low profile to avoid detection.
Jan 2006
United States of America
2026-01-24
Chinese state-sponsored hackers associated with the APT10 group conducted a decade-long cyber espionage campaign targeting managed service providers, technology firms, and government entities to steal intellectual property and sensitive business data. The attackers compromised IT infrastructure to access victim networks globally, exfiltrating hundreds of gigabytes of proprietary information across diverse sectors including aviation, satellite technology, healthcare, telecommunications, and energy exploration. The operation involved leveraging MSP access to infiltrate client systems and systematically harvest confidential technological and commercial data.
Jan 2006
United States of America
2026-01-24
Two Chinese nationals associated with the APT10 hacking group, operating in conjunction with China's Ministry of State Security, conducted a global cyber espionage campaign targeting intellectual property and confidential business data. The group compromised managed service providers to access client networks and infiltrated technology companies and government agencies, stealing sensitive information across sectors including aviation, healthcare, biotechnology, telecommunications, and energy. Their operations involved unauthorized access to hundreds of gigabytes of proprietary data, leveraging stolen credentials and infrastructure to sustain intrusions over multiple years. The campaign impacted numerous U.S. entities through coordinated theft of technological and commercial secrets.
Jan 2006
China
2026-01-24
Chinese state-sponsored hackers associated with the APT10 group infiltrated a U.S. space research center and numerous technology firms through sustained cyber espionage campaigns. Operating under China's Ministry of State Security, the attackers compromised managed service providers to access sensitive networks, stealing intellectual property and confidential data across critical sectors including satellite technology, aviation, healthcare, and energy. The breach at the NASA facility formed part of broader operations targeting over 45 companies and government agencies, resulting in the theft of hundreds of gigabytes of proprietary information spanning industrial automation, telecommunications, and biotechnology over more than a decade.
Jan 2008
United States of America
2026-01-24
Hackers affiliated with @TheFamilyMethod, operating under the alias @hackinyolife ("Fear"), publicly claimed responsibility for compromising the Bank of North Dakota and released transaction logs containing 124 records. The exposed data included cardholder postal addresses, payment card types, the last four digits of card numbers, transaction authorization codes, and merchant details, though consumer names were not present in the logs. The financial institution did not respond to inquiries from a cybersecurity outlet seeking confirmation of the breach's authenticity after being notified of the data disclosure.
Mar 2008
United States of America
2026-01-24
Yale University disclosed a past data breach impacting approximately 119,000 individuals, including members, alumni, faculty, and staff, stemming from unauthorized access to a database over a decade ago. Compromised information included names, Social Security numbers, and dates of birth for most victims, with some also experiencing exposure of email and physical addresses; no financial data was accessed. The intrusion remained undetected until a recent server review, despite prior database maintenance activities that deleted personal information without uncovering the breach.
Jan 2009
United States of America
2026-01-24
A Chinese businessman collaborating with unidentified individuals in China orchestrated cyber intrusions targeting Boeing and other aerospace firms, stealing sensitive military aircraft data including details on fighter jets and cargo planes to advance Chinese aviation capabilities. The defendant, arrested in cooperation with international law enforcement, allegedly facilitated the theft to enable technological gains, as evidenced by communications stating the intent to rapidly catch up with US defense industry standards.
Jan 2009
United States of America
2026-01-24
A Chinese aerospace executive was charged with conspiring to hack major US defense contractors, including Lockheed Martin, to steal sensitive military aircraft data such as designs for the F-22, F-35, and C-17 programs. Working with China-based hackers, the individual facilitated unauthorized access to corporate networks over several years, intending to transfer proprietary information to benefit Chinese aviation development. The suspect was arrested overseas through international law enforcement cooperation and allegedly described the stolen data as enabling China to rapidly advance its aerospace capabilities by building upon US technology.
Oct 2009
United States of America
2026-01-24
The University of Alabama disclosed a historical unauthorized access incident involving a server at its Brewer-Porch Children’s Center, discovered during preparations to decommission outdated equipment. The breach exposed personal and medical information of former clients, alongside Social Security numbers and employment-related data of employees and medical providers associated with the center over a multi-year period. Approximately 1,400 individuals were impacted, with foreign-origin login activity identified as the intrusion vector. The institution provided notifications to affected parties in compliance with regulatory obligations.
Jan 2010
China
2026-01-24
APT17, a cyber-espionage group linked to China's Ministry of State Security via its Jinan bureau, was exposed by Intrusion Truth, an anonymous cybersecurity collective. The group identified three individuals operating as contractors for the ministry, alleging they conducted on-demand hacking operations from Jinan. This revelation followed Intrusion Truth's prior successful doxing of Chinese state-linked APT groups APT3 and APT10, which led to U.S. Department of Justice indictments. The exposure reinforced established patterns of Chinese state-sponsored cyber operations, though Chinese hacking activities reportedly continued despite previous indictments and naming efforts.
Jan 2010
China
2026-01-24
A suspected Chinese state-sponsored hacking group, APT10, conducted a multi-year cyber espionage campaign targeting major technology service providers, including NTT Data, by compromising their cloud computing infrastructures to gain unauthorized access to client networks. The attackers exploited cloud service vulnerabilities to steal sensitive corporate and government data, aiming to advance Chinese economic interests, while victim organizations faced challenges in detecting and responding due to service providers withholding critical breach information over liability and reputational concerns. Persistent intrusions continued despite countermeasures and international agreements, highlighting systemic risks in third-party cloud dependencies and gaps in coordinated threat response.
Jan 2010
China
2026-01-24
A group of Chinese state-sponsored hackers known as APT10 conducted a prolonged cyber espionage campaign targeting multiple global technology service providers, including Dimension Data, by compromising their cloud infrastructure to access client networks. The attackers exploited vulnerabilities in outsourced IT services to steal sensitive corporate and government data, aiming to advance Chinese economic interests. Despite security efforts and a diplomatic agreement against economic espionage, the hackers persisted, leveraging compromised providers as launchpads for further intrusions. The incident revealed systemic challenges in cloud security and information sharing, as service providers often withheld breach details from affected clients due to legal and reputational concerns, potentially leaving many victims unaware of compromises.
Jan 2010
China
2026-08-23
Tata Consultancy Services was among multiple technology firms compromised in a sustained cyber espionage campaign attributed to Chinese state-linked actors, specifically APT10. The attackers infiltrated cloud service providers to access client networks, exfiltrating sensitive corporate and government data to advance Chinese economic interests. The incident exposed systemic vulnerabilities in cloud computing ecosystems and highlighted challenges in coordinated defense, as service providers reportedly withheld breach details from affected clients due to liability and reputational concerns. Despite security countermeasures and international agreements prohibiting economic espionage, the perpetrators maintained persistent access, underscoring difficulties in detecting and mitigating sophisticated state-sponsored intrusions targeting supply chain intermediaries.
Jan 2010
China
2026-01-24
A technology firm was compromised as part of a sustained cyber espionage campaign attributed to Chinese state-sponsored actors, specifically the APT10 group, which targeted multiple IT service providers to access client networks. The attackers exploited cloud computing infrastructure to steal corporate and government secrets, aiming to advance Chinese economic interests. The incident revealed systemic vulnerabilities in third-party cloud services and highlighted challenges in threat response, as service providers often withheld breach details from affected clients due to legal and reputational concerns. Despite countermeasures and international agreements prohibiting economic espionage, the campaign persisted, underscoring difficulties in defending against sophisticated state-aligned cyber intrusions and information-sharing gaps among Western institutions.