The incidents index.

Every incident catalogued, newest first. Stubs are added the day a breach becomes public. Deep-dives are filled in once post-incident reports are available — sometimes weeks or months later. Filter by sector, attack type, or severity.

132 of 132 shown

Grindr — alleged 15M+ user database listing

Forum seller listed an alleged 15-million-record Grindr database for $400 covering bcrypt hashes, geolocation and HIV-status field; Grindr has not commented.

Technology · Data Breach · nilojeda (forum alias) · // stub
Medium
15M+
Records claimed; unverified

Red Hat (@redhat-cloud-services npm) — Miasma supply-chain worm via compromised employee GitHub account

Wiz researchers found 32 trojanised releases under the @redhat-cloud-services npm scope, traced to a compromised Red Hat employee's GitHub account, deploying a credential-stealing self-propagating worm.

Technology · Supply Chain · Unattributed (Miasma — Mini Shai-Hulud derivative) · // stub
High
32
Red Hat npm releases trojanised

Palo Alto Networks PAN-OS GlobalProtect — CVE-2026-0257

Authentication-override flaw in PAN-OS GlobalProtect lets unauthenticated attackers forge cookies and establish VPN tunnels; CISA added it to KEV with a 1 June deadline.

Technology · Vulnerability Exploit · Unattributed (Vultr and Dromatics Systems infrastructure observed) · // stub
High
KEV
Federal mitigation deadline 1 June 2026

OpenAI — two employee devices compromised in TanStack npm supply-chain attack

Two OpenAI staff devices compromised by poisoned @tanstack npm packages; limited credentials exfiltrated and OpenAI is re-signing all desktop and mobile applications.

Technology · Supply Chain · TeamPCP (Mini Shai-Hulud campaign) · // stub
High
Re-sign
All OpenAI apps re-signed after breach

DentaQuest — ShinyHunters leak-site listing, US dental insurer

ShinyHunters listed US dental-insurance provider DentaQuest on its leak site, claiming 744 user records and threatening publication after the extortion deadline lapsed.

Healthcare · Data Breach · ShinyHunters · // stub
Medium
744
User records claimed

GS Yuasa Lithium Power — Akira leak-site listing, US aerospace battery supplier

Akira listed US aerospace battery supplier GS Yuasa Lithium Power on its leak site, naming Boeing satellite project data among the allegedly stolen material.

Defence · Ransomware · Akira · // stub
Medium
AKIRA
leak-site listing, aerospace supplier

7-Eleven — misconfigured Salesforce Experience Cloud, ShinyHunters dump

ShinyHunters dumped a 9.4 GB archive of 7-Eleven franchise applicant data after exploiting a misconfigured Salesforce Experience Cloud instance with the AuraInspector audit tool.

Retail · Data Breach · ShinyHunters · // stub
High
185K
Franchise applicants exposed

Charter Communications — vishing-led Salesforce CRM breach, ShinyHunters extortion

ShinyHunters claims 42 million Charter customer records exfiltrated from Salesforce after vishing an employee into surrendering their Microsoft Entra account.

Telecoms · Phishing · ShinyHunters · // stub
High
42M
Customer records claimed

Panasonic Avionics — CoinbaseCartel extortion claim, unverified

CoinbaseCartel listed in-flight entertainment supplier Panasonic Avionics on its data-leak site claiming corporate data theft; the company has not publicly confirmed an intrusion.

Transport · Data Breach · CoinbaseCartel · // stub
Medium
Claim
Leak-site listing; no confirmation yet

GitHub — internal repositories breached via poisoned Nx Console VS Code extension

A poisoned Nx Console VS Code extension on a GitHub employee's device harvested credentials; attackers cloned roughly 3,800 internal repositories and listed them for $50,000.

Technology · Supply Chain · TeamPCP / UNC6780 (Shai-Hulud campaign cluster) · // deep dive
Critical
3,800
Internal GitHub repos cloned by TeamPCP

Foxconn — Nitrogen ransomware attack on North American factories

Foxconn confirmed a ransomware attack on its US factories after Nitrogen claimed 8TB and 11 million files stolen referencing Apple, Nvidia and Intel projects.

Manufacturing · Ransomware · Nitrogen · // stub
High
8TB
Allegedly exfiltrated by Nitrogen

Vodafone — Lapsus$ source-code dump after failed extortion

Lapsus$ dumped 7.1 GB of Vodafone internal source code after failed extortion; leaked repos contained hardcoded database credentials. Vodafone says no customer data affected.

Telecoms · Data Breach · Lapsus$ · // stub
Medium
7.1 GB
Source code dumped, failed extortion

NVIDIA GeForce NOW (GFN.am) — Armenian regional-partner breach

NVIDIA confirmed personal data of GeForce NOW users in Armenia was exposed via a compromise of regional partner GFN.am; no passwords or payment data taken.

Technology · Data Breach · Unattributed (ShinyHunters-branded claim, NVIDIA assesses likely impersonator) · // stub
Medium
AM
Armenian regional partner; NVIDIA safe

SailPoint — GitHub repository breach via third-party app vulnerability

Identity-governance vendor SailPoint disclosed unauthorised access to a subset of its GitHub repositories via a third-party application vulnerability; no customer data accessed.

Technology · Supply Chain · Unattributed · // stub
Medium
0
customer records exposed

West Pharmaceutical Services — ransomware attack, Item 1.05 8-K

West Pharmaceutical filed an Item 1.05 8-K on 7 May confirming data exfiltration, file-encrypting ransomware and a global systems shutdown following a 4 May intrusion.

Healthcare · Ransomware · Unattributed · // stub
High
1.05
8-K Item filed; no leak-site claim

DAEMON Tools (Disc Soft) — trojanised signed installers

Official DAEMON Tools Lite installers signed with Disc Soft's certificate were trojanised for a month, deploying a backdoor and QUIC RAT to selective targets.

Technology · Supply Chain · Unattributed (Chinese-speaking artefacts per Kaspersky) · // deep dive
High
100+
Countries with infection telemetry

Vimeo — third-party Anodot compromise, ShinyHunters dump

Vimeo confirms 119,000 user emails exposed after attackers compromised analytics vendor Anodot's Snowflake and BigQuery instances; ShinyHunters dumps 106GB after failed extortion.

Technology · Supply Chain · ShinyHunters · // stub
Medium
119K
Email addresses exposed

Cushman & Wakefield — vishing-led Salesforce CRM breach, ShinyHunters dump

Real-estate services giant Cushman & Wakefield confirmed a vishing-driven Salesforce compromise; ShinyHunters published a 50GB archive of more than 500,000 records after a 6 May ransom deadline lapsed.

Professional Services · Phishing · ShinyHunters (separate Qilin leak-site claim, no confirmed coalition) · // stub
High
500K+
Salesforce records dumped

Trellix — source code repository breach, RansomHouse extortion claim

Security vendor Trellix confirmed attackers accessed a portion of its source code repository; RansomHouse later claimed the intrusion and leaked screenshots suggesting wider internal access.

Technology · Ransomware · RansomHouse · // stub
High
src
source code repository breach

Instructure (Canvas LMS) — ShinyHunters extortion, ~275M users claimed

Edtech vendor behind Canvas confirms attacker accessed user data; ShinyHunters claims 275 million records across roughly 8,800 schools and universities.

Education · Data Breach · ShinyHunters · // stub
High
275M
Records claimed by ShinyHunters

France Titres (ANTS) — 11.7 million citizen records via IDOR

French national ID-document portal exposed up to 19 million records via an IDOR flaw; 15-year-old hacker detained, charged by Paris prosecutors.

Government · Data Breach · breach3d (15-year-old French national, charged) · // deep dive
High
11.7M
Citizen accounts exposed

Citizens Financial Group and Frost Bank — shared-vendor Everest ransomware breach

Everest compromised a shared vendor handling statement printing for Citizens and tax-document fulfilment for Frost, claimed 3.65 million records; the vendor remains unnamed.

Financial Services · Supply Chain · Everest · // deep dive
High
3.65M
Records via shared vendor

Pitney Bowes — Salesforce CRM phishing breach, ShinyHunters dump

A phishing-compromised Pitney Bowes employee email account was the foothold for a Salesforce CRM exfiltration; ShinyHunters later dumped 8.2M email addresses publicly.

Technology · Phishing · ShinyHunters · // deep dive
High
8.2M
Email addresses confirmed by HIBP

Carnival Corporation — Holland America Mariner Society phishing breach

Carnival confirms a social-engineered employee account let attackers exfiltrate data on nearly six million Holland America Mariner Society members; ShinyHunters dumped it publicly.

Transport · Phishing · ShinyHunters · // deep dive
High
~6M
People notified (Maine AG filing)

Medtronic — corporate IT breach, ShinyHunters extortion claim

Medical-device giant filed Form 8-K confirming corporate IT breach; ShinyHunters subsequently published the dataset alongside ~40 other victims after Medtronic refused extortion.

Healthcare · Data Breach · ShinyHunters · // stub
High
9M
Records dumped by ShinyHunters

UK Biobank — 500,000-volunteer dataset listed on Alibaba

De-identified data on 500,000 UK Biobank volunteers listed on Alibaba; trail traced to three Chinese research institutions previously granted bulk access.

Healthcare · Data Breach · Unattributed · // stub
High
500K
Volunteer records on Alibaba

Bitwarden CLI — npm supply-chain compromise (downstream of Checkmarx)

Trojanised @bitwarden/cli 2026.4.0 lived on npm for 93 minutes; root cause was a compromised Checkmarx GitHub Action that altered Bitwarden's publish step without touching its source.

Technology · Supply Chain · TeamPCP (Shai-Hulud campaign cluster) · // deep dive
High
93 min
Trojanised CLI on npm; 334 installs

Itron — internal IT network breach

NASDAQ-listed utility-tech vendor disclosed via SEC 8-K that an unauthorised third party accessed internal systems; company says customer environments not affected, investigation ongoing.

Energy · Data Breach · Unattributed · // stub
Medium
112M
endpoints under management

University of Mississippi Medical Center — Medusa ransomware

Medusa ransomware took Mississippi's only Level I trauma centre offline for nine days, demanded $800,000, and claimed exfiltration of more than 1 TB.

Healthcare · Ransomware · Medusa · // stub
High
9 days
Hospital offline

Stryker — Handala wiper attack via Microsoft Intune

Iran-linked Handala compromised a Microsoft Intune admin account at Stryker and remotely wiped roughly 200,000 employee devices across 79 countries.

Healthcare · Nation State · Handala (Iran-linked, MOIS / Void Manticore) · // deep dive
High
200K
Devices wiped

Conduent — SafePay ransomware (govtech contractor)

SafePay sat inside govtech contractor Conduent for 84 days, exfiltrating 8 TB and exposing 25 million-plus Americans on state Medicaid and benefits programmes.

Government · Ransomware · SafePay · // deep dive
Critical
25M+
Americans exposed

Wynn Resorts — ShinyHunters Oracle PeopleSoft breach

ShinyHunters exploited an unpatched Oracle PeopleSoft flaw at Wynn Resorts in 2025, exfiltrating 800,000 employee records and demanding $1.5M — confirmed months later when the listing went public.

Consumer Goods · Vulnerability Exploit · ShinyHunters · // deep dive
Medium
800K
Employee records exposed

Singapore telecommunications — UNC3886 espionage

Singapore's Cyber Security Agency confirmed UNC3886 had persistent rootkit access across all four major Singapore telcos; the eviction operation took eleven months.

Telecoms · Nation State · UNC3886 (China-linked) · // deep dive
Critical
4 of 4
Telcos compromised

Coupang — South Korea customer data exposure

South Korea's largest e-commerce platform reported 33.7 million customer accounts exposed; Korean police identified a former IT employee as the principal suspect.

Retail · Insider · Former employee (alleged Chinese national) · // deep dive
High
33.7M
Accounts exposed

Red Hat Consulting — Crimson Collective repository theft

Crimson Collective claimed 570 GB exfiltrated from 28,000 internal Red Hat consulting repositories, including 800 customer engagement reports naming IBM, NSA, Cisco and the DoD.

Technology · Data Breach · Crimson Collective · // deep dive
Medium
570GB
Data exfiltrated

Jaguar Land Rover — production halt

Vishing calls and stale infostealer credentials gave attackers admin access to JLR's SAP systems; ransomware halted five-plant production for five weeks on the UK's busiest plate-change day.

Automotive · Ransomware · Scattered Lapsus$ Hunters (claimed) · // deep dive
High
£1.9B
Industry impact estimate

SalesLoft Drift OAuth supply-chain breach

Stolen OAuth tokens from the Drift conversational marketing platform let attackers query Salesforce environments at major enterprises and exfiltrate CRM data at scale.

Technology · Supply Chain · UNC6395 / ShinyHunters · // deep dive
High
4.46M
TransUnion records exposed

Microsoft SharePoint — ToolShell zero-days

Two chained zero-days in on-premises SharePoint enabled unauthenticated remote code execution; incomplete patches kept attackers in for months.

Technology · Vulnerability Exploit · Linen Typhoon, Violet Typhoon, Storm-2603 and others (China-linked) · // deep dive
High
396
Confirmed compromises

Qantas — Salesforce-connected CRM exfiltration

Around 5.7 million Qantas customer records exfiltrated via a third-party platform integrated with the airline's Salesforce environment.

Transport · Supply Chain · Scattered Lapsus$ Hunters (Scattered Spider / ShinyHunters / Lapsus$ alliance) · // deep dive
High
5.7M
Customer records

16-billion credential exposure

Researchers compiled roughly 16 billion login credentials from infostealer logs, phishing kits and prior breaches — the largest credential exposure ever disclosed.

Technology · Data Breach · Aggregated infostealer operators (multiple) · // deep dive
Critical
16B
Credentials exposed

Coinbase — overseas-contractor breach

Attackers bribed overseas Coinbase customer-support contractors to extract internal data on a subset of customers; Coinbase refused a $20M ransom and offered a counter-bounty.

Financial Services · Insider · Bribed overseas customer-support contractors · // deep dive
High
$400M
Estimated remediation cost

Marks & Spencer

A Scattered Spider operation pivoted through M&S's third-party IT helpdesk into the retailer's Active Directory, halting online ordering for six weeks and exposing customer data.

Retail · Ransomware · Scattered Spider (DragonForce affiliate) · // deep dive
Critical
£300M
Estimated impact

Bybit

Approximately $1.46B in Ethereum drained from Bybit cold-wallet infrastructure via a compromised Safe{Wallet} signing flow — the largest cryptocurrency theft on record.

Crypto · Wallet Compromise · Lazarus Group (DPRK / TraderTraitor) · // deep dive
Critical
$1.46B
USD stolen

US Treasury — BeyondTrust supply-chain breach

Silk Typhoon used a stolen BeyondTrust API key to access US Treasury workstations including those of the sanctions team at OFAC and the foreign-investment reviewers at CFIUS.

Government · Supply Chain · Silk Typhoon (Chinese state-sponsored) · // deep dive
High
OFAC
Sanctions agency workstations accessed

Radiant Capital — cross-chain lending exploit

DPRK's UNC4736 operators delivered macOS malware via a fake-contractor Telegram message, compromised three of eleven multi-signature key-holders, and drained $50M from Radiant Capital's cross-chain lending pools.

Crypto · Wallet Compromise · UNC4736 / TraderTraitor / Lazarus Group (DPRK, Mandiant attribution) · // deep dive
Medium
$50M
Lending pools drained

US telecoms — Salt Typhoon espionage campaign

Salt Typhoon, a Chinese state-sponsored group, compromised lawful-intercept systems at nine US telecom carriers, reading wiretap lists and senior officials' communications for months before detection.

Telecoms · Nation State · Salt Typhoon (Chinese state-sponsored) · // deep dive
Critical
9 telcos
Lawful-intercept systems compromised

WazirX — multi-signature wallet compromise

Attackers compromised four multi-signature co-signers protecting WazirX's Liminal Custody wallet and used a smart-contract upgrade to drain $235M, forcing India's largest crypto exchange into Singapore restructuring.

Crypto · Wallet Compromise · Lazarus Group (DPRK, suspected) · // deep dive
High
$235M
Drained from multi-sig wallet

CDK Global — auto-dealer SaaS ransomware

BlackSuit ransomware took CDK Global offline for two weeks, halting transactions at 15,000 North American auto dealerships; CDK reportedly paid a $25M ransom rather than rebuild from backup.

Technology · Ransomware · BlackSuit (linked to Royal ransomware lineage) · // deep dive
High
15,000
Dealerships affected

DMM Bitcoin — hot wallet compromise

North Korean TraderTraitor operatives compromised a Ginco wallet engineer via a fake LinkedIn job offer, then stole $305M from the DMM Bitcoin exchange.

Crypto · Wallet Compromise · TraderTraitor / Lazarus Group (DPRK, attributed by FBI, CISA and DC3) · // deep dive
High
$305M
BTC drained

Snowflake-customer mass credential-stuffing

Infostealer-harvested credentials with no MFA gave attackers access to roughly 165 Snowflake customer environments including Ticketmaster and Santander, exposing hundreds of millions of records.

Technology · Credential Stuffing · UNC5537 / ShinyHunters (Mandiant attribution) · // deep dive
Critical
165
Snowflake tenants compromised

Ascension Health — Black Basta ransomware

Black Basta ransomware hit Ascension Health's 140 hospitals after a contractor opened a malicious file, forcing paper-based clinical care and exposing 5.6 million patient records.

Healthcare · Ransomware · Black Basta · // deep dive
Critical
5.6M
Patient records exposed

Change Healthcare — ALPHV/BlackCat ransomware

ALPHV ransomware took US healthcare-claims clearinghouse Change Healthcare offline for weeks, blocked a third of US claims processing, and exposed 190M individuals' health records.

Healthcare · Ransomware · ALPHV / BlackCat · // deep dive
Critical
190M
Health records exposed

LoanDepot — ALPHV ransomware

ALPHV ransomware encrypted LoanDepot's systems in January 2024, forcing a multi-week portal outage and exposing full mortgage dossiers on 16.9 million customers.

Financial Services · Ransomware · ALPHV / BlackCat · // deep dive
High
16.9M
Mortgage customers' data exposed

KyberSwap — concentrated-liquidity exploit

An attacker exploited a tick-boundary rounding flaw in KyberSwap Elastic's concentrated-liquidity contracts to drain $54M across six chains, then demanded total governance control of the protocol.

Crypto · Vulnerability Exploit · Unattributed · // deep dive
Medium
$54M
Liquidity pools drained

ICBC Financial Services — LockBit ransomware

LockBit ransomware disabled ICBC's US broker-dealer arm via the Citrix Bleed vulnerability in November 2023, disrupting US Treasury market settlement and forcing manual trade processing.

Financial Services · Ransomware · LockBit · // deep dive
High
USB
Trades settled by hand

British Library — Rhysida ransomware

Rhysida ransomware encrypted the British Library's systems in October 2023; the Library refused to pay, lost 600GB of data to publication, and faced a £6–7M recovery bill.

Government · Ransomware · Rhysida · // deep dive
High
£6–7M
Recovery cost estimate

Boeing — LockBit ransomware leak

LockBit accessed Boeing via the Citrix Bleed vulnerability in October 2023, exfiltrated 43GB of data, and published it after Boeing declined to pay the ransom.

Defence · Ransomware · LockBit · // deep dive
Medium
43GB
Stolen data leaked

23andMe — credential-stuffing breach

Attackers credential-stuffed 14,000 23andMe accounts, then exploited the DNA Relatives feature to harvest profile data on 6.9 million users including ancestry and health predisposition records.

Technology · Credential Stuffing · Threat actor 'Golem' on BreachForums · // deep dive
High
6.9M
Users exposed

Mixin Network — cloud-provider key compromise

Attackers breached the third-party cloud database used by Mixin Network's deposit infrastructure, obtained the credentials it contained, and drained $200M — the single largest crypto loss of 2023.

Crypto · Wallet Compromise · Unattributed · // deep dive
High
$200M
Mainnet deposits drained

MGM Resorts — Scattered Spider ransomware

A LinkedIn search and a helpdesk phone call gave Scattered Spider domain-admin access to MGM Resorts; ransomware halted casino operations for ten days and cost over $100M.

Consumer Goods · Ransomware · Scattered Spider (ALPHV affiliate) · // deep dive
High
$100M
Estimated financial impact

Caesars Entertainment — Scattered Spider extortion

Scattered Spider socially engineered an IT support contractor, exfiltrated the Caesars Rewards loyalty database, and reportedly received a $15M ransom payment to prevent data publication.

Consumer Goods · Data Breach · Scattered Spider (ALPHV affiliate) · // deep dive
High
$15M
Reported extortion paid

Stake.com — hot wallet compromise

FBI-attributed Lazarus Group operators obtained Stake.com hot-wallet private keys and drained $41M in ETH, BTC and stablecoins across multiple networks in September 2023.

Crypto · Wallet Compromise · Lazarus Group (DPRK, FBI attribution) · // deep dive
Medium
$41M
Hot wallets drained

Curve Finance — Vyper compiler exploit

A reentrancy bug in specific Vyper compiler versions drained $70M from multiple Curve Finance pools; the attacker voluntarily returned a portion of the stolen funds.

Crypto · Vulnerability Exploit · Multiple opportunistic exploiters · // deep dive
High
$73M
Lost from Curve pools

Multichain — bridge collapse

Five days after Chinese police detained Multichain's CEO — sole custodian of the bridge keys — $130M drained from bridge contracts; the protocol shut down permanently.

Crypto · Wallet Compromise · Unattributed (suspected internal after CEO arrest) · // deep dive
High
$130M
Bridge drained

Atomic Wallet — multi-chain user theft

Lazarus Group operators drained approximately $100M from 5,500 Atomic Wallet user accounts across eight blockchains simultaneously — the largest known theft from a non-custodial wallet application to date.

Crypto · Wallet Compromise · Lazarus Group (DPRK, FBI / DOJ attribution) · // deep dive
High
$100M
Stolen across user wallets

MOVEit Transfer — Cl0p mass exploitation

Cl0p exploited a SQL-injection zero-day in MOVEit Transfer before it was patched, silently exfiltrating data from over 2,600 organisations including US government agencies and major corporations.

Technology · Vulnerability Exploit · Cl0p · // deep dive
Critical
2,700+
Organisations affected

US critical infrastructure — Volt Typhoon pre-positioning

Chinese state-sponsored Volt Typhoon silently pre-positioned inside US water, power and communications infrastructure for years, building persistent access for potential future use.

Energy · Nation State · Volt Typhoon (Chinese state-sponsored) · // deep dive
Critical
Standby
Pre-positioned for disruptive operations

Euler Finance — flash-loan exploit

A flash-loan attack exploited a flaw in Euler's liquidation logic to drain $197M across six tokens; the attacker later returned nearly all funds after on-chain negotiations.

Crypto · Vulnerability Exploit · Self-identified as 'Jacob' — funds fully returned · // deep dive
High
$197M
Drained, all returned

Royal Mail — LockBit ransomware

LockBit ransomware encrypted Royal Mail's international export systems in January 2023, suspending overseas deliveries for six weeks; Royal Mail refused to pay the $80M ransom demand.

Transport · Ransomware · LockBit · // deep dive
High
6 weeks
International posting suspended

LastPass — encrypted vault exfiltration

Attackers compromised a LastPass DevOps engineer's home computer to harvest credentials to the vault backup, then exfiltrated customer vault data including encrypted passwords.

Technology · Data Breach · Unattributed (linked by researchers to subsequent crypto-wallet drains) · // deep dive
Critical
Vaults
Customer vaults exfiltrated

Medibank Private — REvil-affiliated extortion

Russian-attributed actors stole the complete health-claims database of Australia's largest private health insurer and published sensitive records including abortion and addiction data after Medibank refused to pay.

Healthcare · Data Breach · REvil-linked actors (Aleksandr Ermakov, sanctioned) · // deep dive
Critical
9.7M
Customer health records

Mango Markets — oracle-manipulation drain

Avi Eisenberg manipulated Mango Markets' oracle to inflate collateral 13×, borrowed $114M against it, and publicly argued the theft was legal — until a federal jury disagreed.

Crypto · Vulnerability Exploit · Avi Eisenberg · // deep dive
High
$114M
Borrowed against manipulated collateral

BNB Chain Token Hub bridge exploit

An attacker forged IAVL proofs to mint $570M in BNB; validators paused the entire blockchain to freeze most of it, limiting unrecovered losses to approximately $100M.

Crypto · Vulnerability Exploit · Unattributed · // deep dive
High
$570M
Minted; $100M unrecoverable

Optus — Australian telco 9.8M-customer breach

An unauthenticated public API let an attacker enumerate 9.8 million Optus customer records — roughly 40% of Australia's population — including government identity document numbers.

Telecoms · Data Breach · Unattributed · // deep dive
High
9.8M
Customer records exposed

Uber — 2016 cover-up + 2022 social-engineering breach

Uber concealed a 2016 breach of 57M records by paying the attacker as a bug bounty; a 2022 Lapsus$ intrusion exposed internal systems and executive Slack messages.

Technology · Data Breach · Lapsus$ (2022); Brandon Glover and Vasile Mereacre (2016) · // deep dive
High
57M
Users exposed in 2016 breach

Nomad Bridge — open-door exploit

A routine upgrade accidentally set Nomad bridge's trusted root to zero, making every withdrawal message valid; opportunistic attackers drained $190M in a chaotic free-for-all within hours.

Crypto · Vulnerability Exploit · Distributed copy-paste exploitation by hundreds of addresses · // deep dive
High
$190M
Bridge drained

Harmony Horizon Bridge

Lazarus Group compromised two of the five multi-signature keys guarding the Harmony Horizon bridge and drained $100M in a single transaction.

Crypto · Wallet Compromise · Lazarus Group (DPRK) · // deep dive
High
$100M
Bridge drained

Beanstalk Farms — flash-loan governance exploit

An attacker used flash loans to acquire a temporary governance supermajority and voted to drain $182M from Beanstalk Farms in a single on-chain transaction.

Crypto · Vulnerability Exploit · Unattributed · // deep dive
High
$182M
Treasury drained

Ronin Network — Axie Infinity bridge theft

DPRK operators compromised Ronin Network validators and an Axie DAO key to authorise a $625M drain of ETH and USDC from the Axie Infinity bridge.

Crypto · Wallet Compromise · Lazarus Group (DPRK) · // deep dive
Critical
$625M
Bridge funds stolen

Okta — Lapsus$ support-engineer breach

Lapsus$ compromised a Sitel support engineer with Okta customer-tooling access and sat inside the environment for months; Okta's delayed public response compounded the reputational damage.

Technology · Supply Chain · Lapsus$ · // deep dive
High
366
Okta customer tenants affected

Wormhole — Solana bridge exploit

A signature-verification bypass in the Wormhole cross-chain bridge let an attacker mint 120,000 wrapped ETH from nothing and drain $320M — the second-largest DeFi exploit at the time.

Crypto · Vulnerability Exploit · Unattributed · // deep dive
Critical
$325M
Bridge funds stolen

BitMart — hot wallet compromise

Attackers stole BitMart's hot-wallet private keys and drained $196M across 20+ tokens — a breach first detected by an external researcher on Twitter, not BitMart's own monitoring.

Crypto · Wallet Compromise · Unattributed · // deep dive
High
$196M
Hot wallets drained

Robinhood — 2021 vishing breach

An attacker social-engineered a Robinhood customer-support agent into granting account access, exposing email addresses for 5 million and full personal data for 310 users.

Financial Services · Phishing · Unattributed extortionist · // deep dive
Medium
7M
Users' contact data exposed

Cream Finance — flash-loan exploit

An attacker exploited a price-oracle flaw in Cream's lending protocol via flash-loan-borrowed yUSDVault tokens, drained $130M across multiple assets, and exited through Tornado Cash.

Crypto · Vulnerability Exploit · Unattributed · // deep dive
High
$130M
Lending pool drained

Coinbase — SMS 2FA recovery bypass

Attackers combined stolen credentials with a Coinbase SMS recovery flaw to take over 6,000 accounts and drain balances; the 2020 breach wasn't disclosed to users until October 2021.

Financial Services · Phishing · Unattributed · // deep dive
Medium
6,000
Customer accounts drained

T-Mobile US — recurring data breaches 2018-2023

T-Mobile US disclosed at least eight data breaches between 2018 and 2023; the 2021 incident exposed 76.6 million records via an exposed gateway and produced a $350M settlement.

Telecoms · Data Breach · John Binns (2021); various others · // deep dive
High
76.6M
Customers exposed in 2021

Poly Network — cross-chain bridge exploit

A privilege-escalation flaw in the Poly Network bridge let an attacker appoint themselves contract administrator and drain $611M — then the attacker returned all funds over two weeks.

Crypto · Vulnerability Exploit · Pseudonymous 'Mr. White Hat' (returned all funds) · // deep dive
High
$611M
Drained, fully returned

Kaseya VSA — REvil supply-chain ransomware

REvil exploited a zero-day authentication bypass in Kaseya VSA to push ransomware through managed service providers to roughly 1,500 downstream businesses in July 2021.

Technology · Supply Chain · REvil / Sodinokibi · // deep dive
Critical
1,500
Downstream victims

JBS Foods — REvil ransomware

REvil ransomware took JBS Foods — the world's largest meat processor — offline globally; JBS paid an $11M ransom to restore operations within days, then disclosed it.

Manufacturing · Ransomware · REvil / Sodinokibi · // deep dive
High
$11M
Ransom paid

Ireland's HSE — Conti ransomware

Conti ransomware entered Ireland's Health Service Executive via a phishing email, encrypted core clinical systems, and forced hospitals to cancel tens of thousands of appointments.

Healthcare · Ransomware · Conti · // deep dive
Critical
€100M+
Estimated recovery cost

Colonial Pipeline — DarkSide ransomware

DarkSide ransomware encrypted Colonial Pipeline's billing, prompting a six-day shutdown of the largest US East Coast fuel pipeline; Colonial paid $4.4M, DOJ recovered $2.3M.

Energy · Ransomware · DarkSide · // deep dive
Critical
6 days
Pipeline shutdown

Microsoft Exchange — Hafnium ProxyLogon

Chinese state-sponsored Hafnium exploited four chained Exchange zero-days (ProxyLogon) before patches were available; over 250,000 servers were compromised by multiple actors within days of disclosure.

Technology · Nation State · Hafnium (Chinese state-sponsored, US/UK attribution) · // deep dive
Critical
60K+
Exchange servers compromised

SolarWinds — Sunburst supply-chain compromise

Russian SVR operators compromised SolarWinds' Orion build server and pushed the Sunburst backdoor via a signed software update to 18,000 customers including nine federal agencies.

Technology · Supply Chain · APT29 / Cozy Bear / Nobelium (Russian SVR) · // deep dive
Critical
18,000
Orion customers receiving the backdoor

KuCoin — hot wallet compromise

Attackers obtained KuCoin's hot-wallet private keys and drained $281M across BTC, ETH and dozens of tokens; on-chain freezes and project-team co-operation recovered most of the funds.

Crypto · Wallet Compromise · Lazarus Group (DPRK, attributed by Chainalysis) · // deep dive
High
$281M
Hot wallets drained

Garmin — WastedLocker ransomware

WastedLocker ransomware took Garmin's consumer, aviation and marine services offline for several days; Garmin reportedly paid the $10M ransom to restore operations.

Technology · Ransomware · Evil Corp (WastedLocker) · // deep dive
High
$10M
Reported ransom paid

Twitter — verified-account Bitcoin scam

A 17-year-old social-engineered Twitter employees into admin tool access, hijacked 130 high-profile accounts including Obama and Musk to run a Bitcoin scam, and collected $120,000.

Media · Phishing · Graham Ivan Clark (17, Florida) and co-conspirators · // deep dive
High
$118K
Bitcoin scammed

Travelex — Sodinokibi ransomware

A New Year's Eve ransomware deployment took Travelex's foreign-exchange systems offline for weeks, contributed to its August 2020 administration, and forced UK store closures.

Financial Services · Ransomware · Sodinokibi / REvil · // deep dive
High
$2.3M
Reported ransom paid

Pulse Secure VPN — mass exploitation of CVE-2019-11510

CVE-2019-11510 in Pulse Secure VPN went unpatched at thousands of enterprises; criminal and nation-state actors exploited it for years, breaching Travelex, US federal agencies and defence contractors.

Technology · Vulnerability Exploit · Multiple — nation-state APTs, REvil, Sodinokibi, Conti affiliates · // deep dive
Critical
1,000s
Enterprise networks compromised

Capital One — AWS misconfiguration breach

A misconfigured web application firewall let a former AWS employee exfiltrate personal data on 100 million US and 6 million Canadian Capital One credit-card applicants.

Financial Services · Data Breach · Paige Thompson (former AWS engineer) · // deep dive
High
106M
Card applicants exposed

First American Financial — 885M document exposure

An IDOR vulnerability in First American's document portal exposed 885 million mortgage and title records publicly online — no authentication required to access any document.

Financial Services · Data Breach · Unauthorised researcher access (sequential URL enumeration) · // deep dive
High
885M
Mortgage documents exposed

Norsk Hydro — LockerGoga ransomware

LockerGoga ransomware was pushed via Active Directory to every Norsk Hydro Windows workstation simultaneously, halting aluminium production globally and costing the company over $70M to recover.

Manufacturing · Ransomware · Unattributed (LockerGoga operators) · // deep dive
High
$75M
Estimated recovery cost

Marriott / Starwood — 500M guest records

Chinese state-sponsored actors spent four years inside Starwood's reservation system — surviving the Marriott acquisition — and exfiltrated passport numbers and stay records on 500 million guests.

Consumer Goods · Nation State · China-linked actors (US government attribution) · // deep dive
Critical
500M
Guest records exposed

Cosmos Bank — FASTCash ATM cashout

Lazarus compromised Cosmos Bank's ATM payment switch and co-ordinated 14,000 simultaneous withdrawals across 28 countries, stealing $13.5M in 13 hours — the canonical FASTCash demonstration.

Financial Services · Nation State · Lazarus Group (DPRK) · // deep dive
High
$13.5M
ATM cashout and SWIFT theft

Banco de Chile — MBR wiper and SWIFT theft

Lazarus deployed a master-boot-record wiper across 9,000 Banco de Chile workstations as a diversion, then issued $10M in fraudulent SWIFT transfers while responders focused on restoring desktops.

Financial Services · Nation State · Lazarus Group (DPRK) · // deep dive
High
$10M
SWIFT theft attempted; ~$4M net loss

Equifax — 147M consumer record breach

An unpatched Apache Struts flaw in Equifax's web portal exposed personal data on 147 million Americans, plus UK and Canadian consumers, in a 76-day intrusion.

Financial Services · Vulnerability Exploit · People's Liberation Army Unit 54th Research Institute (US DOJ attribution) · // deep dive
Critical
147M
Consumer records exposed

A.P. Moller-Maersk — NotPetya collateral damage

NotPetya, deployed by Russian military intelligence through Ukrainian tax software, destroyed Maersk's global IT estate in hours; the shipping giant reported $300M in losses and rebuilt 45,000 PCs.

Transport · Nation State · Sandworm / GRU Unit 74455 · // deep dive
Critical
$300M
Estimated business cost

NotPetya — Ukrainian-targeted destructive wiper

A destructive wiper disguised as ransomware spread via a poisoned Ukrainian M.E.Doc tax software update, propagated through EternalBlue and credential theft, causing $10B+ globally.

Government · Nation State · Sandworm / GRU Unit 74455 (Russian military intelligence) · // deep dive
Critical
$10B+
Estimated global damage

WannaCry — global SMB-worm ransomware

A North Korean ransomware worm using leaked NSA EternalBlue tooling encrypted 200,000+ Windows systems across 150 countries, including a third of NHS England Trusts.

Healthcare · Ransomware · Lazarus Group (DPRK, US/UK attribution) · // deep dive
Critical
200K
Systems infected globally

Ukrainian power grid — BlackEnergy + Industroyer

Russian Sandworm operators twice cut Ukrainian electricity using custom ICS malware — BlackEnergy in 2015 and Industroyer in 2016 — the first confirmed cyberattacks to cause power outages.

Energy · Nation State · Sandworm / GRU Unit 74455 · // deep dive
Critical
230K
Customers without power (2015)

Tesco Bank — debit-card fraud weekend

Attackers exploited a predictable card-number pattern and an authorisation flaw to drain £2.26M from 9,000 Tesco Bank accounts in a single weekend, earning the first FCA cyber fine.

Financial Services · Other · Unattributed criminal crew · // deep dive
High
£2.26M
Withdrawn from 9,000 accounts

Yahoo — three-billion account breach

Two breaches in 2013 and 2014, disclosed only in 2016, ultimately exposed all 3 billion Yahoo accounts — the largest user-data exposure ever disclosed.

Technology · Data Breach · Russian FSB-tasked criminals (DOJ indictment) · // deep dive
Critical
3B
User accounts exposed

Bitfinex — 119,756 BTC theft

Attackers exploited Bitfinex's BitGo multi-signature integration to steal 119,756 BTC worth $72M — later recovered by US authorities in 2022 as the largest crypto seizure in history.

Crypto · Wallet Compromise · Ilya Lichtenstein and Heather Morgan (US DOJ) · // deep dive
Critical
120K
BTC stolen

The DAO — recursive-call exploit

A reentrancy flaw in The DAO contract let an attacker drain 3.6M ETH worth roughly $50M; the Ethereum community's hard fork to reverse the theft remains controversial.

Crypto · Vulnerability Exploit · Unattributed exploiter · // deep dive
Critical
3.6M
ETH drained

Bangladesh Bank — SWIFT heist

Lazarus Group operators issued $951M in fraudulent SWIFT transfers from Bangladesh Bank's Federal Reserve account; $81M cleared via Manila before the heist was detected.

Financial Services · Nation State · Lazarus Group (DPRK) · // deep dive
Critical
$81M
Stolen via SWIFT

US Office of Personnel Management — federal records breach

Chinese state-sponsored actors exfiltrated 21.5 million federal personnel records from the Office of Personnel Management, including security-clearance files with detailed background investigation data.

Government · Nation State · China-linked actors (US government attribution) · // deep dive
Critical
21.5M
Federal personnel records

Carbanak / FIN7 — multi-bank ATM and SWIFT campaign

A multi-year campaign against banks combined spear-phishing, lateral movement and direct manipulation of payment infrastructure to steal $1B+ through ATM cash-outs and SWIFT transfers.

Financial Services · Nation State · Carbanak / FIN7 (Russian-speaking criminal group) · // deep dive
Critical
$1B+
Estimated total stolen

Anthem — 78.8M health-insurance records

Chinese state-sponsored actors spear-phished into Anthem's data warehouse and exfiltrated personal data on 78.8 million current and former health-insurance customers.

Healthcare · Nation State · China-linked actors (DOJ indictment) · // deep dive
Critical
78.8M
Customer records exposed

Sony Pictures Entertainment — Guardians of Peace wiper

North Korean Lazarus operators wiped Sony Pictures' IT estate, leaked unreleased films and executive emails, and threatened cinema chains — the first nation-state attack on a media company.

Media · Nation State · Lazarus Group (DPRK) · // deep dive
Critical
Wiped
Corporate IT destroyed

Home Depot — 56M card breach

Vendor credentials gave attackers network access nine months after the identical Target playbook was public; custom BlackPOS malware ran undetected for five months and captured 56 million cards.

Retail · Data Breach · Eastern European criminal crew (BlackPOS variant) · // deep dive
High
56M
Cards stolen

JPMorgan Chase — 2014 customer data breach

Attackers compromised a JPMorgan server missed by the bank's two-factor authentication rollout and exfiltrated contact details for 76M households and 7M small businesses.

Financial Services · Data Breach · Gery Shalon-led securities-fraud crew · // deep dive
High
76M
Households exposed

Mt. Gox — 850,000 BTC theft

The largest Bitcoin exchange of the early 2010s lost 850,000 BTC to multi-year wallet theft, filed for bankruptcy in 2014, producing a decade-long creditor process.

Crypto · Wallet Compromise · Alexander Vinnik (BTC-e operator) and unknown others · // deep dive
Critical
850K
BTC stolen

Target Corporation — 2013 card breach

Attackers entered Target's network through an HVAC supplier's stolen credentials, deployed memory-scraping malware on point-of-sale terminals, and exfiltrated 40M cards and 70M customer records.

Retail · Data Breach · Eastern European credit-card fraud crew (unattributed individuals) · // deep dive
Critical
40M
Cards stolen

Adobe — 153M user credentials

Attackers stole 153 million Adobe user records and source code for multiple products; weak password encryption meant the full credential database was effectively exposed.

Technology · Data Breach · Unattributed · // deep dive
High
153M
Credentials exposed

Saudi Aramco — Shamoon wiper

A Shamoon wiper deployed on the night of Lailat al-Qadr destroyed master boot records and overwrote files on 35,000 Saudi Aramco workstations, rendering them permanently inoperable.

Energy · Nation State · Cutting Sword of Justice / Iran-attributed · // deep dive
Critical
30,000
Workstations wiped

LinkedIn — 2012 password leak + 2021 scrape

A 2012 breach exposed 117 million LinkedIn password hashes stored without salting, which were cracked and used for credential-stuffing attacks for years after the original incident.

Technology · Data Breach · Yevgeniy Nikulin (DOJ indictment, 2012); unattributed (2021) · // deep dive
High
700M
Profiles in 2021 scrape

RSA SecurID — APT seed-record exfiltration

Spear-phishing via a malicious Excel attachment exploiting an Adobe Flash zero-day gave attackers RSA's SecurID seed database, compromising two-factor tokens used by defence contractors.

Technology · Nation State · Chinese state-sponsored actors (subsequently attributed) · // deep dive
Critical
Seeds
SecurID master seeds stolen

Stuxnet — Natanz uranium-enrichment sabotage

A US/Israeli joint operation deployed a Windows worm with four zero-day exploits to physically destroy Iranian uranium centrifuges by manipulating their Siemens PLCs — the first cyber weapon.

Defence · Nation State · United States and Israel (US/Israeli intelligence, attributed) · // deep dive
Critical
1,000
Centrifuges destroyed

Operation Aurora — Google + 30 US technology firms

Chinese state-sponsored attackers exploited an Internet Explorer zero-day to breach Google, Adobe and at least 30 other companies, targeting source code and human-rights activists' accounts.

Technology · Nation State · Elderwood Group / Chinese state-sponsored · // deep dive
Critical
30+
US tech firms compromised

Heartland Payment Systems — 2008 card breach

A SQL-injection attack on Heartland's web platform seeded memory-resident sniffers across the payment processor's network, exposing 130 million cards across 250,000 merchants.

Financial Services · Data Breach · Albert Gonzalez and co-conspirators · // deep dive
Critical
130M
Card records stolen

Hannaford Bros — point-of-sale card breach

Memory-scraping malware installed by the Albert Gonzalez crew on Hannaford supermarket POS systems harvested 4.2 million card numbers over three months without the company's knowledge.

Retail · Data Breach · Albert Gonzalez crew · // deep dive
High
4.2M
Cards stolen

Estonia — 2007 nation-scale DDoS

Three weeks of DDoS attacks against Estonian government, banking and media infrastructure following the relocation of a Soviet war memorial became the first nation-state cyber conflict.

Government · Ddos · Russian-attributed hacktivists / state-aligned actors · // deep dive
High
3 weeks
National infrastructure DDoS

TJX Companies — 94M card breach

Albert Gonzalez cracked the WEP network at a Marshalls store, pivoted to TJX's servers, and stole 45.6 million card numbers in the largest retail breach of its era.

Retail · Data Breach · Albert Gonzalez crew · // deep dive
Critical
94M
Cards stolen