CSIDB logo

Incidents

Date
Victim
Location
Sources
Updated
Summary
Sep 2026
United States of America
2026-09-22
Hackers claiming to be from ShinyHunters said they breached multiple FBI-related services using a zero‑day exploit in Oracle PeopleSoft, accessed AWS GovCloud servers and exfiltrated between two and three terabytes of data that includes names, addresses, phone numbers, dates of birth and spouse information for current and former employees and applicants. They also defaced the agency's jobs website, posting a seizure notice and asserting that all agency data was compromised. The group said the breach was not financially motivated and described their intended action as coercion rather than extortion.
Jul 2025
Singapore
2026-09-22
Singapore Telecommunications Limited, together with StarHub, M1 and Simba Telecom, was targeted by the cyber espionage group UNC3886, which gained access to portions of their telecom networks without disrupting services or obtaining personal data. The attackers exfiltrated a limited amount of technical, network‑related information to support their operational objectives. Mandiant has identified UNC3886 as a China‑linked espionage group that has previously struck defense, technology and telecommunications entities in the United States and Asia. Singapore authorities stated that this was the first disclosure of the specific infrastructure targeted by the group and noted that the incident prompted a coordinated multi‑agency response involving the Cyber Security Agency, IMDA, CSIT, the Digital and Intelligence Service, the Internal Security Department and GovTech. The telecom companies confirmed they employ defense‑in‑depth measures, conduct prompt remediation and collaborate with government and industry partners to enhance network resilience.
Feb 2026
United States of America
2026-09-22
The University of Mississippi Medical Center suffered a ransomware attack that disrupted its IT infrastructure, including its Epic electronic health records system and phone networks. In response, the organization shut down all 35 of its clinics statewide, canceling elective procedures and appointments, while hospitals and emergency departments remained open using manual paper-based processes. Staff reverted to pen-and-paper documentation to maintain patient care. The medical center activated its Emergency Operations Plan, took all network systems offline as a precaution, and is collaborating with the FBI and Department of Homeland Security to investigate and recover. Attackers have reportedly made contact, but it remains unclear whether any patient data was exfiltrated. The incident has caused significant disruption to clinical services, with ongoing efforts to restore systems and resume normal operations.
Dec 2021
United States of America
2026-09-22
Shutterfly experienced a ransomware attack by the Conti gang, which encrypted thousands of devices and servers while exfiltrating corporate data. The attackers employed double extortion tactics, threatening to leak stolen information—including legal agreements, bank account details, corporate credentials, spreadsheets, and customer data with partial credit card digits—unless a ransom was paid. Services for Lifetouch, BorrowLenses, and Groovebook were disrupted, though consumer-facing platforms like Shutterfly.com remained operational. While the company asserted no financial data was compromised, evidence suggested otherwise with screenshots of credit card fragments in the stolen cache. Conti, a Russia-linked group operating ransomware-as-a-service, conducted the breach after infiltrating the network.
May 2026
France
2026-09-22
CrowdSec confirmed that attackers stole source code from roughly 300 public and private GitHub repositories, including about 170 private repositories. The private material included source code for its SaaS console, AWS cloud routines, connectors, and automations. The company reported no leaked customer credentials or other customer-related data and said its investigation had found no token or credential that could enable lateral movement. It rotated potentially affected tokens and credentials and characterized the impact as limited to its own organization while monitoring for abnormal activity.
Sep 2026
Lithuania
2026-09-22
Revolut customers were targeted by smishing messages that appeared to come from the bank and urged recipients to follow links to confirm their identity or risk restricted account access. Some links led to pages mimicking a live-video identity check, requesting camera access before prompting users for passwords. The broader breach involved fraudulent requests for KYC information sent to the bank’s Lithuanian-regulated entity under European Investigation Orders. Threat actors impersonated Italian law enforcement after compromising Italian Ministry of the Interior email accounts with infostealer logs, reportedly maintaining access for around six months. Several hundred accounts were thought to be impacted, with high-net-worth crypto users singled out after blockchain records were analyzed.
Sep 2026
-
2026-09-22
Employees of Archer-Daniels-Midland filed a class action alleging that cybercriminals stole and posted personal identifying information to the dark web after gaining access to the company’s network. The cybercriminal group Qilin claimed responsibility for stealing names, dates of birth, addresses, Social Security numbers and driver’s license details, which the plaintiffs said could be used for fraud and identity theft. The complaint alleges the company lacked effective prevention, detection and mitigation controls, including employee training, strong passwords, multilayer security, encryption, multifactor authentication, backups and access restrictions. Plaintiffs also alleged they had not been promptly notified and sought injunctive relief, compensatory damages and punitive damages.
Sep 2026
United States of America
2026-09-22
The Alabama Board of Nursing experienced a cyberattack that took its online licensing system offline, leaving approximately eighty thousand nurses unable to renew their credentials and delaying licensure for recent graduates. The board has kept the system offline while it investigates the incident, works with external cybersecurity experts and state resources, and focuses on protecting licensee data. In the meantime, paper applications are being accepted and processed at designated community college sites, though renewals still lack an online option. Officials have not disclosed the attacker’s identity, the scope of any data breach, or a timeline for full service restoration, noting that recovery will proceed in phases as systems are validated.
Jun 2025
United States of America
2026-09-22
Columbia University experienced a suspected cyberattack that caused an IT outage affecting systems on its Morningside campus, including email and the CourseWorks portal used for assignments. Officials described the incident as a low‑level access control breach that triggered bizarre images on campus screens, with one dorm TV showing a picture of President Trump. The university notified law enforcement and warned the community to stay logged into accounts while services were restored, noting that no clinical operations at CUIMC were impacted. Claims of responsibility posted online were later debunked by the institution.
Sep 2026
United States of America
2026-09-22
Liquid Network reported that a white hat hacker exploited a bug to withdraw thousands of bitcoins worth about $340 million from its wallet, prompting the platform to pause operations. The hacker said they would return the funds if the vulnerability was fixed, and after Blockstream patched the flaw, roughly 3,400 of the approximately 4,000 stolen bitcoins were returned, leaving about 600 bitcoins valued at around $47 million still under the hacker’s control. Operations remain halted while additional fixes and security improvements are implemented before restarting.
Jul 2025
France
2026-09-21
Wibaie, a subsidiary of Groupe Liébot and a major producer of windows and entry doors located in Cholet, suffered a cyberattack that halted its factory operations. The attack left approximately 600 employees idle and the plant's parking lot nearly empty as officials confirmed they were dealing with a cybercriminal group and experts were engaged to resolve the incident.
Sep 2026
United States of America
2026-09-21
A reported cyberattack on AECOM remains unconfirmed, with the hacker group Metaencryptor claiming responsibility for an intrusion involving about 1.22 TB of data. A separate dark web monitoring service listed a roughly 670GB leak attributed to BrainCipher and indexed thousands of company-linked credentials, while cautioning that the credentials may not be connected to the claimed attack. The incident may affect current and former employees, clients, and others whose information the company maintained, but the scope, data types, and number of affected people have not been publicly established.
Jul 2025
Germany
2026-09-21
The city administration's website suffered a distributed denial‑of‑service attack that rendered it inaccessible for several hours and caused lingering loading problems afterward. The attack targeted the central infrastructure of the service provider brain‑SCC Merseburg GmbH, which hosts the city's data and also serves other municipalities, prompting the provider to deploy dynamic filtering to block suspicious traffic and restore service. The provider confirmed that no data security risk occurred during the incident.
Aug 2025
Canada
2026-09-21
The Canadian Investment Regulatory Organization said hackers compromised personal information of 750,000 individuals through a sophisticated phishing attack that forced some systems offline while leaving critical functions unaffected. The exposed data included annual income, dates of birth, government‑issued ID numbers, phone numbers, investment account numbers, social insurance numbers and account statements, though no passwords, PINs or security questions were stored or affected. The organization stated there is no evidence of misuse and is providing affected individuals with free credit monitoring and identity theft protection, sending notification letters and publishing an FAQ. As a pan‑Canadian self‑regulatory body overseeing investment and mutual fund dealers, it continues to monitor for malicious activity.
Aug 2025
United States of America
2026-09-21
The Cybersecurity and Infrastructure Security Agency's acting director uploaded sensitive government contracting documents marked for official use only to a public version of ChatGPT despite the tool being blocked for most Department of Homeland Security employees. Security sensors detected the uploads, generating alerts that prompted an internal assessment involving department officials and agency leaders, and a spokesperson later said the use had been approved as a short‑term limited exception under existing safeguards.
Aug 2025
United States of America
2026-09-21
Hypertherm, Inc. discovered a data breach affecting its computer network after an unauthorized actor accessed tables from its Oracle E-Business Suite database. The company launched an investigation with third‑party cybersecurity professionals and subsequently began sending notice letters to individuals whose personal data may have been compromised. Edelson Lechtzin LLP is investigating potential class action claims on behalf of those affected by the incident.
Aug 2025
United Kingdom
2026-09-21
Jaguar Land Rover experienced a ransomware attack that halted vehicle production and exposed employee and contractor data. The disruption led to multi‑billion‑pound financial losses, prompted regulatory scrutiny and the risk of legal action, and caused reputational harm to the parent group while the company provided credit monitoring and a helpline for affected individuals. Investigations traced the entry point to a third‑party IT vendor, and the incident prompted the vendor’s client to pilot enhanced AI‑driven cybersecurity measures across its services.
Sep 2026
Italy
2026-09-20
The Vivit Africa LNG carrier experienced a systems failure that the crew reported as a suspected cyber attack while sailing from the United States toward Europe, leaving the vessel unable to access some internal control systems. After idling off the Italian coast and abandoning its planned discharge at Rovigo, the ship reversed course toward Algeciras. The Italian Coast Guard assisted following a master‑reported malfunction in cargo‑monitoring systems, and Korean Register, the technical adviser for the South Korean‑owned vessel owned by H-Line Shipping Co. Ltd., was notified. The vessel uses Kongsberg Maritime equipment for positioning, navigation and propulsion, and Vitol Group holds the ship under a time charter. Authorities are monitoring nearly 20 ships worldwide for similar threats, and two oil and gas tankers off the US coast were previously boarded by the Coast Guard and FBI due to potential cyber incidents.
Sep 2026
Japan
2026-09-20
Helpfeel disclosed that attackers exploited a vulnerability in the Gyazo image upload server to gain unauthorized access, remaining inside until they were removed shortly thereafter. The breach exposed approximately 23.6 million user records containing names, email addresses, password hashes, user and device IDs, X integration tokens, profile details, usage statistics and billing information, while payment card data was not compromised. In addition, the intruders accessed roughly 490 million image metadata records and a set of private images, though the volume of the latter was not disclosed.
Sep 2026
United States of America
2026-09-20
ShinyHunters asserted they infiltrated the Florida Department of Highway Safety and Motor Vehicles Driver and Vehicle Information Database by exploiting a password‑reset flaw that allowed them to compromise accounts of agency employees and an FBI agent. They then downloaded roughly two hundred thousand driver records containing personal details such as Social Security numbers and licence information, providing a screenshot of a Jeffrey Epstein record as proof while stating the vulnerability has since been patched.
CSIDB