Skip to main content

Company intelligence

Sans cybersecurity incidents and threat signals

sans.org

Sans logo

This company page brings together public reporting currently associated with Sans. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

1

High or critical

confidence classifications

August 5, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Sans. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Sans

Sans logoPhishing
High

SANS Institute Suffers Data Breach Affecting 28,000 Member Records Due to Phishing Attack

The SANS Institute, a cybersecurity training organization, confirmed a data breach that exposed personally identifiable information (PII) of approximately 28,000 members. The incident was discovered on August 6, 2020, during a routine review of email configurations and rules. An investigation revealed that a SANS employee had fallen victim to a phishing attack, leading to the compromise of a single email account. The attackers used a malicious Office 365 add-in to establish an email forwarding rule, which subsequently forwarded 513 emails to an unauthorized external address. The forwarded emails contained subsets of PII, including email addresses, first and last names, work titles, company names, industries, addresses, and countries of residence. SANS stated that no passwords or financial information were compromised in the breach. The organization promptly removed the malicious forwarding rule and add-in, and began notifying affected individuals.

Sans

FAQ

Questions about Sans cybersecurity reporting

What does the Sans page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Sans.

Does every mention of Sans appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.