109
Reports in 90 days
in the current rolling intelligence window
Current cyber intelligence
Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.
109
in the current rolling intelligence window
9
represented in the same 90-day window
48
high or critical reports in 90 days
Latest reporting
Showing 1–18 of 109 reports published in the last 90 days.
On August 11, 2026, it was reported that a data breach at CEVA Logistics, a logistics partner, had impacted several companies, including De Bijenkorf, a partner of DELTA Fiber Nederland. The incident led to significant delays in processing orders, returns, and refunds for De Bijenkorf customers. The breach potentially exposed personal data of customers across the affected companies. The Dutch data protection authority (AP) received twelve notifications from companies regarding potentially leaked customer data due to their collaboration with CEVA. While the full extent of the data compromise is still under investigation, companies like De Bijenkorf have informed customers that unauthorized parties may have accessed their personal information. DELTA Fiber Nederland, as the parent company of ZeelandNet which reported on the incident, is indirectly connected to this supply chain breach through its partner's reliance on CEVA Logistics. The incident highlights the widespread impact of supply chain attacks on various businesses and their customers.
On July 28, 2026, Origin Energy, a major Australian energy company, publicly confirmed a significant data breach impacting approximately 900,000 current and former customers. The breach led to unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. Origin Energy first identified a potential security threat in early July 2026, which was initially not deemed credible. However, new information on July 22, 2026, confirmed a security incident had occurred, prompting immediate action and notification of authorities. An alleged hacker provided a media outlet with a sample of 50 customer records and screenshots of internal Origin Energy systems, corroborating the data exfiltration. The incident is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. The specific technical vector used for initial access remains undisclosed.
The municipality of IJsselstein removed several documents from its website on July 27, 2026, after a resident discovered that they contained personal data. These documents were found within the municipal council's information system, which violates privacy legislation. The municipality has reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and is reviewing all published meeting documents dating back to January 1, 2014. While affected individuals will be informed, the specific types of data exposed have not been disclosed. Locoburgemeester Peter Bekker emphasized the need to restore trust in the handling of personal data and prevent future occurrences. An investigation into the error is expected to take several months, during which parts of the system may be temporarily inaccessible.
Jamf, a company specializing in Apple device management, was among roughly two dozen Klue customers impacted by a data incident. The incident, which became active on July 26, 2026, involved the Icarus threat group claiming responsibility for an attack. Further reports indicated that another hacking group might have obtained samples of the stolen Klue customer data and attempted to extort affected companies directly. While the full extent of Jamf's specific exposure through this third-party incident is not detailed, the broader event highlights the risks associated with supply chain compromises. Jamf's security efforts include initiatives like its Beacon threat-hunting service, which focuses on proactive detection and analysis of Mac threats, and its annual Security 360 report, which addresses key threats to Apple endpoints.
Iowa State University's Canvas learning management system was breached on July 26, 2026, displaying a hacker message that blocked access to the website and all its pages. The message advised users to "consult with a cyber advisory firm" and to "contact us privately at TOX to negotiate a settlement." This incident is part of a larger series of over 9,000 attacks affecting various educational institutions. The hackers, identified as the criminal extortion group ShinyHunters, had previously caused an outage on Canvas and are also linked to data thefts from Ticketmaster and Google. The compromised data includes names, email addresses, student ID numbers, and internal messages. Iowa State IT Security issued an email addressing the outage and advised students to seek alternative submission methods for coursework. The university's news service director, Angie Hunt, confirmed that Iowa State is one of many institutions affected by a nationwide Canvas platform outage. Instructure, the parent company of Canvas, has not provided a timeframe for resolving the issue. The group ShinyHunters claimed to have stolen over 3.65 terabytes of data, encompassing approximately 275 million records belonging to students, teachers, and staff, and threatened to release this data if their demands were not met. While the affected data may include full names, email addresses, student ID numbers, and messages, there is no evidence that passwords, dates of birth, government identifiers, or financial information were exposed. The sensitivity of some Canvas messages, which can contain medical and mental health information, adds to the concern. Officials are advising students, parents, and staff to be cautious of unsolicited messages claiming to be from Canvas or the university that request personal information or prompt immediate action. They also recommend monitoring accounts for unusual activity.
South Korean domain registrar Gabia experienced a cyberattack on Saturday, July 26, 2026, which impacted the online connectivity of approximately 100,000 registered domains. The incident led to the exposure of data belonging to 350,000 users. The compromised information included names, user IDs, passwords, and registration numbers. This breach highlights the significant risks associated with compromised credential reuse, as a large portion of the exposure originated from "Combolist sources." Additionally, active infostealer activity, linked to malware families such as LummaC2, Redline, and Rhadamanthys, was identified, further indicating a focus on credential theft impacting both clients and employees. The incident also revealed 245 compromised employee accounts, posing an infrastructure risk, and 30,782 leaked client credentials, creating regulatory liability. The timeline of related events showed an increase in client-related incidents from August 2025 through April 2026, with a peak in March 2026, and spikes in employee-related events in January, April, and May 2026. Remediation efforts should prioritize credential hygiene, multi-factor authentication enforcement, and enhanced monitoring for suspicious login activity, particularly targeting login forms and account management services. The incident was reported by the Korea Herald on Monday, July 28, 2026.
South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January. South Korea's Deputy Minister for Cybersecurity and Network Policy publicly attributed the incident to management failures and authentication vulnerabilities during a press conference on July 24, 2026. The attacker exploited user authentication vulnerabilities to gain unauthorized access to accounts without proper login credentials, leading to a large-scale unauthorized information leak. South Korean authorities emphasized that the breach was not the result of highly sophisticated intrusion techniques, but rather stemmed from fundamental security weaknesses in authentication mechanisms and inadequate security management practices. The breach resulted in large-scale unauthorized access to customer information. The unauthorized access has since been terminated. This incident has also led to a record fine of $422 million by South Korea's Personal Information Protection Commission (PIPC) and ongoing diplomatic discussions between South Korea and the U.S. due to Coupang being an American-owned company operating in South Korea.
Dropbox, a cloud storage company, experienced a data breach when its GitHub account was compromised on October 13. The attackers gained access to 130 code repositories containing sensitive data, including API keys used by Dropbox developers. The incident was a result of a successful email phishing campaign that targeted Dropbox employees, impersonating CircleCI, a continuous integration and delivery platform. The phishing emails directed victims to a fake login page where they were prompted to enter their GitHub credentials and a One-Time Password (OTP) from their hardware authentication key. Dropbox was notified of the potential breach by GitHub on October 14. While the attackers accessed some credentials and API keys, Dropbox stated that customer accounts, passwords, or payment information were not compromised, nor were its core apps or infrastructure. The data accessed also included the names and email addresses of a few thousand Dropbox employees, current and past customers, sales leads, and vendors. In response, Dropbox is enhancing its security by implementing WebAuthn and hardware tokens or biometrics.
DigiCert's security incident in April 2026 has been attributed to CylindricalCanine, a subgroup of the China-linked cybercrime group GoldenEyeDog (also known as APT-Q-27, Dragon Breath, and Miuuti Group). The attackers compromised a support employee's device using malware delivered via a phishing lure disguised as a screenshot or document sent through DigiCert's support-ticket workflow. This intrusion granted the threat actors access to initialization codes for customers renewing code-signing certificates. By intercepting these codes, the attackers were able to obtain 27 fraudulent code-signing certificates, which were then used to sign malware, including the "Zong Stealer" campaign. DigiCert identified the incident through third-party reports of certificates being used in malware and subsequently revoked 60 certificates by April 17, with 27 explicitly linked to the attackers. The company emphasized that its root certificates were never compromised, and the breach was limited to a finite set of certificates. DigiCert has since blocked high-risk file types at ingestion, removed malicious files from Salesforce cases and chat records, and is working on sandboxing controls for inbound support attachments.
On July 23, 2026, the Axios npm package, a widely used JavaScript HTTP client, was compromised in a sophisticated supply chain attack. The attackers hijacked a maintainer account and injected a malicious dependency, `plain-crypto-js`, into versions `axios@1.14.1` and `axios@0.30.4`. This malicious dependency was designed to download multi-stage payloads, including a remote access trojan, onto developer machines and CI/CD pipelines globally. The compromise was detected and the malicious packages were removed from npm within approximately three hours. The attack was characterized by its operational sophistication, bypassing standard security controls like MFA through a targeted social engineering campaign against the maintainer. The malicious code was capable of breaching major operating systems including Windows, macOS, and Linux. CISA issued an alert providing guidance for detection and remediation, urging organizations to monitor code repositories, CI/CD pipelines, and developer machines, and to rotate credentials that may have been exposed. Google Threat Intelligence Group publicly attributed the compromise to UNC1069, a North Korea-nexus, financially motivated threat actor. The incident highlights the significant risks associated with software supply chain attacks and the importance of robust security measures for open-source dependencies.
DoorDash, the popular food delivery platform, publicly acknowledged a cybersecurity incident that compromised the personal information of an undisclosed number of users. The breach, which occurred on October 25, was a result of a social engineering attack targeting a company employee. This allowed an unauthorized third party to gain access to DoorDash's internal systems. The compromised data varied by individual but potentially included first and last names, phone numbers, email addresses, and physical addresses of customers, Dashers (delivery drivers), and merchants across the United States, Canada, Australia, and New Zealand. DoorDash emphasized that no sensitive financial information, such as Social Security numbers, government-issued IDs, driver's license details, bank information, or payment card data, was accessed. The company's security team identified and shut down the unauthorized access shortly after its detection, launched an internal investigation, and notified law enforcement. DoorDash has also implemented multiple security enhancements, including upgraded security systems and additional employee training programs focused on social engineering awareness. While the company has stated there is no indication the data has been misused for fraud or identity theft, affected users are advised to be cautious of unsolicited communications requesting personal information. This incident marks DoorDash's third known cybersecurity incident in six years, highlighting the persistent threat of social engineering attacks.
On July 21, 2026, the Korea National Diplomatic Academy, an institution affiliated with South Korea's Ministry of Foreign Affairs, confirmed a significant data leak impacting approximately 10,000 records of current and retired diplomats. The breach, which occurred in the academy's online education system, was discovered in early February 2026 after suspicious access was reported by a government agency. An unidentified attacker exploited a zero-day vulnerability in the server software and weaknesses in system security settings, maintaining unauthorized access from April to May 2025 until February 2026. The compromised data reportedly included names, user IDs, email addresses, encrypted passwords, job titles, and affiliated departments. While sensitive personal information such as resident registration numbers, mobile phone numbers, and home addresses were not present on the affected server, the leak of diplomat information raises concerns, especially given that the full list of diplomats and personnel at overseas missions is not publicly disclosed. The Foreign Ministry is investigating the incident and has urgently shut down the compromised system. They are operating under the assumption that a substantial volume of data was compromised, though the exact scale of the damage is still being assessed. The incident highlights the challenges in detecting sophisticated attacks that leverage previously unknown vulnerabilities.
A widespread security incident affecting Canvas, a learning management system by Instructure, impacted thousands of institutions, including Rutgers University, which utilizes the Qualtrics survey tool. Instructure notified Rutgers that while there was no indication of passwords, dates of birth, government identifiers, or financial information being involved, the specific Rutgers data compromised remains unclear. Instructure reportedly reached an agreement with the unauthorized threat actor, and the stolen data was returned and destroyed. Canvas remained operational throughout the incident.
Lidl informed its webshop customers in the Netherlands about a security incident at an external IT service provider. Hackers briefly gained unauthorized access to a separately stored file containing customer data, resulting in the theft of personal information.
Lidl, the popular retail chain, announced on July 11, 2026, that it experienced a security incident involving an external IT service provider, resulting in the theft of customer data from its online shop. Unidentified attackers gained temporary access to a separate file containing customer information. The compromised data includes customers' titles, first and last names, phone numbers, email addresses, dates of birth, and customer numbers. Lidl has confirmed that passwords, billing and delivery addresses, bank details, or other payment information were not affected, and customer accounts remain secure. The company has stated that there is currently no concrete evidence of the stolen data being misused, but it has proactively warned affected customers about potential phishing attempts and identity theft. Lidl advises customers to be extra cautious with communications from unknown sources. The IT service provider involved has taken immediate steps to restore security, strengthen system protection, and has filed a criminal complaint. IT experts are also involved in the investigation to enhance future data protection. The Office for Personal Data Protection has been informed and is monitoring the case.
A data leak at the AI music generator Suno, which occurred in November 2025, became public in July 2026. The breach exposed data from over 55 million unique email addresses and, for users who registered with their phone numbers, those numbers as well. A small portion of the dataset also included payment processor Stripe data, leading to the leak of names, physical addresses, purchase amounts, and certain credit card details (card type, expiration date, and last four digits) for tens of thousands of users. Suno confirmed it does not have access to full credit card numbers via Stripe.
Lidl Czech Republic announced a security incident on July 10, 2026, affecting its e-shop customers. Attackers gained access to a separately stored file containing customer data from an IT service provider. The compromised data includes customers' salutations, first and last names, phone numbers, email addresses, dates of birth, and customer numbers. Lidl confirmed that passwords, billing and delivery addresses, bank details, or other payment information were not affected, and customer accounts were not compromised. The company stated that it currently has no concrete evidence of data misuse but has proactively warned affected customers about potential phishing attempts or identity theft. The IT service provider involved has taken measures to restore system security, filed a criminal complaint, and engaged IT experts for the investigation. The Office for Personal Data Protection was also informed of the incident. Lidl began notifying affected customers via email after discovering the incident earlier in the week.
Accenture, a global professional services company, confirmed a security incident in July 2026 after a threat actor, identified as "888," claimed to have stolen approximately 35 GB of data from the company. The stolen data reportedly includes source code, RSA keys, SSH keys, Azure personal access tokens (PATs), Azure Storage access keys, and configuration files. The threat actor advertised the data for sale on a cybercrime forum and provided a screenshot as proof of exfiltration from a private Azure DevOps repository associated with accenture.com. Accenture stated that it is aware of the "isolated matter" and has remediated its source, asserting that there was no impact on Accenture's operations and service delivery. This incident follows previous security challenges for Accenture, including a 2017 exposure of sensitive data on unsecured AWS S3 buckets and a LockBit ransomware attack in 2021.
Explore the intelligence
Compare incidents across industries and critical services.
Explore all sectors →Follow recurring intrusion methods and adversary behaviour.
Explore all attack patterns →Track consequences such as disruption and data exposure.
Explore all impacts →Compare reports by explicitly affected country.
Explore all countries →Explore the intelligence
Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.
12 answers across 4 topics
How to read and use the current intelligence overview.
It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.
Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.
No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.