Cyber service disruption is a confirmed loss or material reduction of availability caused by, or reported alongside, a cyber incident. It can affect customer services, internal systems, manufacturing, logistics or critical operations and is distinct from an attack that causes no verified downtime.
This page tracks incidents where reporting or precise VERIS evidence confirms that a cyber event made a service unavailable, halted production or interrupted operations. Ransomware and other attacks are not treated as disruption unless downtime or interruption is explicitly supported.
What causes cyber service disruption & outage, who is affected and what should organizations do?
What causes it?
Ransomware, destructive malware and denial-of-service activity can affect systems directly when reporting confirms operational interruption.
Containment decisions may require organizations to take services offline while responders remove access and validate recovery.
Supplier, cloud, telecom or software-platform incidents can interrupt many dependent organizations through a shared point of failure.
Which sectors are affected?
Financial and digital services can face immediate customer and transaction effects when authentication, payments or online channels become unavailable.
Food, agriculture, manufacturing and logistics depend on production, automation and scheduling systems where interruption can affect physical output.
Healthcare, government and essential services may need manual workarounds to maintain safety and continuity during technology outages.
What are the consequences?
Downtime can delay customers, production and suppliers while creating recovery cost, backlogs and contractual or service-level consequences.
Manual workarounds can preserve critical activity but may increase error, fraud, safety or data-integrity risk if they are not controlled.
Restoring a technical system does not always restore the end-to-end service because identity, data, suppliers and operational backlogs remain dependent.
How should organizations respond?
Prioritize life-safety and essential business services, activate tested workarounds and establish clear ownership for operational decisions.
Contain the access path, preserve evidence and restore by verified business dependency rather than bringing systems online in an arbitrary order.
Communicate service status, uncertainty and recovery criteria consistently to customers, staff, suppliers and authorities as appropriate.
Explore related intelligence
Explore this reporting from another angle
Based on all current signals matched to cyber service disruption & outage before the visible feed limit. Counts describe this reporting set, not overall incident prevalence.
Which current incidents confirm cyber service disruption & outage?
Signals appear only when explicit reporting or precise upstream VERIS evidence supports the impact. Ransomware alone does not prove disruption, and generic breach language does not prove data exposure.
Cybersecurity breach reveals vulnerability of Latvia's strategic infrastructure: minister RIGA, June 26 (Xinhua) -- A recent incident in which hackers managed to access IT systems of Latvia's state-owned company Latvijas Valsts Mezi (LVM) revealed the relative vulnerability of the country's strategic infrastructure, Smart Administration and Regional Development Minister Edgars Tavars said Friday. The cybersecurity breach in LVM has caused particular concerns because the company has been entrusted with developing an electoral IT platform for Latvia's parliamentary elections, which are scheduled to take place this fall. In an interview with the TV3 channel on Friday, Tavars called on all state institutions to identify cybersecurity flaws in their own systems and learn a lession from the LVM incident. The minister believes, though, that in general, Latvian IT specialists are good enough to prevent similar incidents from repeating in the future. Tavars said that the electronic voter register, on which LVM has been working, was completed before the incident and was not at risk. In general, "we are definitely not ringing alarm bells about the elections," the minister said. LVM discovered the cybersecurity breach of its IT systems last weekend. In response, the company took all its external IT systems offline and also shut down some internal communication systems. A foreign ransomware group, which has carried out similar attacks against companies and government agencies in other countries, has claimed responsibility on the cyberattack on LVM. Cyberattack on Latvian State Forests detected LVM is one of three companies developing this year’s Saeima election system . However, the company noted that the development of the election system was kept separate and was not affected. Security measures will be reviewed as a precaution. The cyberattack occurred on Monday, June 22. According to the company, since the incident began, the external information technology (IT) systems maintained by LVM, including “LVM GEO,” the mapping service system, and the hunting app “Mednis”, have been shut down and are unavailable for security reasons. Several of LVM’s internal systems, which facilitate the company’s exchange of information with service providers and clients, have also been taken offline. LVM spokesperson Tomass Kotovičs stated that the threat has been eliminated, but it will take time to restore the systems to operation. Baiba Kaškina, head of “Cert.lv,” explained that the attack was thwarted immediately. According to her, there is no reason to believe that it was specifically targeted at Latvia. “Cert.lv” is inclined to believe that this was a commercially motivated attack aimed at demanding a ransom and demonstrating the attackers’ capabilities. The State Police Cybercrime Combating Directorate, based on publicly available information, has launched an internal investigation on its own initiative to clarify the circumstances of the incident and identify the possible perpetrator, according to the LETA news agency. Select text and press Ctrl+Enter to send a suggested correction to the editor Select text and press Report a mistake to send a suggested correction to the editor
McKay Sugar, a major Australian sugar producer, suffered a cyber incident that disrupted operations at its Farley and Racecourse Mills. The Gentlemen ransomware group claimed responsibility for the attack around June 15-16, 2026, on their leak site. Public reporting indicated that McKay Sugar was working to verify what data was stolen or accessed. The ransomware group claimed to have stolen over 26 million records containing PII of customers and other internal data. The incident was discussed in public reporting around June 21, 2026.
[8-K] River Financial Corp Reports Material Event Ransomware hits River Financial (RVRF), disrupting some operations River Financial Corporation reported a cybersecurity incident involving ransomware affecting its network, including River Bank & Trust. An unauthorized threat actor accessed its environment on or about June 16, 2026, and ransomware was deployed across parts of its server infrastructure, discovered on or about June 19, 2026. The company quickly disabled affected administrative accounts and took impacted systems offline, and is working with a third-party forensic firm and external cybersecurity professionals to investigate and restore operations. The investigation into whether any personally identifiable information was accessed or taken is ongoing, and River has not yet determined whether the incident is reasonably likely to materially impact its business or financial condition. The company plans to amend this report within four business days after it determines additional information is available. Ransomware attack and operational disruption : An unauthorized threat actor deployed ransomware across parts of River’s server environment, impacting certain operations while the company investigates the scope, data exposure, and potential business or financial effects. Banking risk and cybersecurity analyst neutral River discloses a ransomware attack with unresolved business impact. River Financial Corporation describes a ransomware incident affecting portions of its server environment and some operations. The company has contained the attack by disabling affected administrative accounts and taking systems offline, and has engaged a third-party forensic firm and external cybersecurity professionals. The filing states that the full nature, scope, and impact of the incident are not yet known, including whether any personally identifiable information was accessed or exfiltrated. It also notes that River has not determined whether the event is reasonably likely to materially affect its business or financial condition. The company indicates it will amend this report within four business days after additional information is available. Future disclosures in company filings may clarify operational disruption, potential data exposure, and any financial consequences linked to remediation, potential liabilities, or longer-term cybersecurity investments. AI-generated analysis. How Rhea-AI works . Not financial advice. What cybersecurity incident did River Financial Corporation (RVRF) disclose? When did the River Financial (RVRF) ransomware attack occur and get detected? Has River Financial (RVRF) confirmed any data or personally identifiable information exposure? How has the ransomware incident affected River Financial’s (RVRF) operations? Has River Financial (RVRF) determined the financial impact of the cyber incident? What future disclosures has River Financial (RVRF) committed to regarding the cyberattack? Date of earliest event reported: June 19 , 2026 (Exact Name of Registrant as Specified in its Charter) (Former Name or Former Address, if Changed Since Last Report) (Address of Principal Executive Offices) (Registrant’s telephone number, including area code) Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions (see General Instructions A.2. below): Date of earliest event reported: June 19 , 2026 (Exact Name of Registrant as Specified in its Charter) (Former Name or Former Address, if Changed Since Last Report) (Address of Principal Executive Offices) (Registrant’s telephone number, including area code) Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions (see General Instructions A.2. below): ☐ Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425) ☐ Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12) ☐ Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b)) ☐ Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c)) Securities registered pursuant to Section 12(b) of the Act: None Name of each exchange on which registered Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§ 230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§ 240.12b-2 of this chapter). If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ITEM 1.05 Material Cybersecurity Incidents. On or about June 16, 2026, an unauthorized threat actor gained access to the network environment of River Financial Corporation, including River Bank & Trust (together, “River”). River identified the activity on or about June 19, 2026, and determined that ransomware had been deployed across portions of its server environment. River promptly took containment measures, including disabling affected administrative accounts and taking impacted systems offline. River, with the assistance of a third-party forensic firm, is investigating the nature and scope of the incident, including whether any personally identifiable information was subject to unauthorized access or exfiltration. That investigation is ongoing. As of the date of this filing, the full nature, scope, and impact of the incident have not yet been determined. River has not yet determined whether the incident is reasonably likely to materially impact its business or financial condition. Certain operations have been impacted, but River is working with external cybersecurity professionals to fully restore these operations. River will file an amendment to this Current Report on Form 8-K within four business days after it determines that such information is available. ITEM 9.01 Financial Statements and Exhibits. Cover Page Interactive Data File (embedded within the Inline XBRL document) Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned hereunto duly authorized.
River Financial Corporation, including River Bank & Trust, reported a cybersecurity incident where an unauthorized threat actor gained access to its network environment on or about June 16, 2026. Ransomware was deployed across parts of its server infrastructure. The company discovered the malicious activity around June 19, 2026, and quickly disabled affected administrative accounts and took impacted systems offline. An investigation is ongoing to determine if any personally identifiable information was accessed or taken.
The University of Nottingham in the UK has confirmed suffering a data breach after the notorious ShinyHunters hacker collective leaked files stolen from the university’s systems. The University of Nottingham is a major research university in the UK, ranked among the world’s top 100 institutions and home to more than 35,000 students on its UK campuses, plus thousands more at its international branches in China and Malaysia. The ShinyHunters group listed the organization on its leak website and published gigabytes of files allegedly stolen from its systems. The hackers claimed to have obtained financial information pertaining to all of the university’s campuses. University of Nottingham hacked by ShinyHunters An analysis of the leaked files by the account breach notification service Have I Been Pwned showed that they contain roughly 455,000 unique email addresses, along with other types of personal information such as usernames, names, addresses, phone numbers, passport numbers, genders, and details on ethnicity, disabilities, academic enrolment, c itizenship status, and fee payments. In a statement issued on Wednesday, the University of Nottingham confirmed that hackers accessed “a significant amount of data” in its student record system. The university says the data breach impacts current students and alumni. “We are working to understand the data that has been accessed and have contacted those students and alumni affected directly. We are working closely with Action Fraud, the Information Commissioner’s Office, and other regulatory bodies,” the organization said. Advertisement. Scroll to continue reading. Related : Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools Related : 1.2 Million Affected by University of Hawaii Cancer Center Data Breach Related : 3.5 Million Affected by University of Phoenix Data Breach Related : University of Sydney Data Breach Affects 27,000 Individuals Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. The University of Nottingham, a UK research university, has suffered a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, passport numbers, enrollment information, and fee payment records later appeared online. According to analysts, this breach is part of a larger wave of attacks targeting more than 100 organizations by ShinyHunters, exploiting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows remote code execution. Check Point IPS provides protection against this threat (Oracle PeopleSoft Enterprise PeopleTools Server-Side Request Forgery (CVE-2026-35273)) Mackay Sugar, Australia’s second-largest sugar producer, has been hit by a cyberattack that disrupted operations and shut down its Farleigh and Racecourse mills in Queensland. The company instructed growers to stop harvesting and suspended cane haulage while temporary measures were deployed to maintain essential operations. Danish pharmaceutical giant Novo Nordisk has disclosed a breach after attackers accessed internal IT systems and copied pseudonymized clinical trial data from research systems. The exposed information included patient IDs, trial participation details, limited health data, and some healthcare professionals’ contact information. Check Point Research has demonstrated exploitable flaws in LangGraph, an open-source framework for stateful AI agents. Researchers chained SQL injection and unsafe deserialization issues to achieve remote code execution, with patches issued for SQLite, core, and Redis checkpointer components in affected deployments. Check Point IPS provides protection against this threat (LangChain LangGraph SQL Injection (CVE-2026-27022)) Researchers highlighted a China-based phishing-as-a-service network, Outsider, that allegedly used Gemini to generate fake websites and support SMS phishing campaigns. Google filed a lawsuit after linking the operation to thousands of phishing sites, more than 1.5 million URLs, and large-scale victim targeting. Researchers warned that prompt-injection attacks against Anthropic’s Claude Code GitHub Action could leak CI/CD workflow secrets. Malicious issue or pull request text can instruct the agent to read environment variables and expose API keys, enabling workflow abuse and impersonation inside software repositories. Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. Attacks began in May and increased in early June, affecting a limited number of organizations, with one case tied to Qilin ransomware activity. Check Point IPS provides protection against this threat (IKEv1 Remote Access Authentication Bypass PoC Exploit (CVE-2026-50751)) Microsoft released its largest Patch Tuesday update to date, addressing more than 200 Windows and Defender vulnerabilities amid an AI-driven surge in vulnerability discovery. The fixes include CVE-2026-45657, a critical Windows flaw with a CVSS score of 9.8 that could enable network-based propagation, CVE-2026-41091, which has been actively exploited to gain full system control, and CVE-2026-50507, a BitLocker bypass vulnerability.
Winona County, Minnesota, experienced a ransomware attack on April 8, 2026, attributed to the Medusa ransomware group. The attack severely disrupted critical county systems and municipal services, forcing systems offline and delaying public services. The incident prompted the deployment of the National Guard to support recovery efforts, indicating a significant impact on the county's operations and potential data exfiltration.
Campbell University identified a security incident on April 1, 2026, after detecting unauthorized access to one of its cloud-based data storage platforms. The unauthorized access occurred between March 31 and April 1, 2026. The incident was isolated to a single cloud platform and did not impact other campus systems. Potentially involved information includes full names, addresses, dates of birth, Social Security numbers, driver's license or state ID numbers, passport numbers, student identification numbers, medical record numbers, and various health-related information. The university responded by taking the affected system offline, resetting credentials, and working with its cloud provider to restore operations from secure backups. Law enforcement was notified, and cybersecurity experts were engaged.
Biggest Cyber Attacks, Data Breaches, Ransomware Attacks of March 2026 March 2026 didn’t just add more names to the growing list of breached organisations, it exposed how deeply embedded cyber risk has become across critical business functions. From healthcare and education to manufacturing and digital services, incidents involving Catalyst RCM , University of Hawaii , Stryker , Michelin , and LexisNexis show how attackers are increasingly targeting the systems that organisations rely on to operate, not just the data they store. Vulnerabilities Discovered and Patches Released Advisories issued, reports, analysis etc. in March 2026 A clear pattern e m er ges across breaches at Telus Digital , Cognizant ’s Intuitive platform, TriZetto , Navia , and CIBM : attackers are exploiting inter-dependencies . Whether through third-party vendors, shared platforms, or supply chain integrations, a single point of compromise can ripple across multiple organisations. These incidents are no longer isolated security failures. They are operational disruptions with far-reaching consequences , impacting customers, partners, and in some cases, essential services. At Cyber Management Alliance, we work with organisations to prepare for exactly these kinds of scenarios. Through cyber incident response training , cyber tabletop exercises , and playbook development, we help teams build the muscle memory needed to respond effectively under pressure. Because in today’s environment, resilience isn’t just about stopping attacks. It’s about ensuring your organisation can continue to function when systems, suppliers, or services are disrupted. Paint maker giant AkzoNobel confirms cyber attack on U.S. site AkzoNobel confirmed that hackers breached the network of one of its U.S. sites and stole large amounts of internal data, with samples of the stolen files later leaked online, though the company said the incident was contained and the overall impact remained limited. England Hockey investigating ransomware data breach England Hockey investigated a cyber attack after a ransomware gang claimed it breached the organization’s network and stole around 129 GB of internal data, threatening to leak the files unless a ransom was paid. Ransomware gang stole data of 672,000 people in 2025 cyber attack A ransomware attack on fintech firm Marquis led to the theft of sensitive personal and financial data—such as Social Security numbers, account details, and contact information—impacting approximately 672,000 individuals across multiple banks and credit unions. Russian botnet operator linked to major ransomware attacks sentenced in US Ilya Angelov, a Russian National, helped operate a botnet used by ransomware gangs The botnet operation enabled ransomware gangs to breach corporate systems and carry out attacks against dozens of U.S. companies, leading to widespread network compromises and significant financial extortion losses. Ransomware: Catholic school closed for days after cyber attack The ransomware attack forced the school to shut down operations for four days after its network was compromised, causing significant disruption to classes and administrative activities. Stats SA confirms data breach, hackers demand ransom The attack led to the theft of over 150GB of data from a human resources system, with hackers demanding ransom to prevent the release of hundreds of thousands of sensitive records, raising serious risks of data exposure and misuse. Suspected ShinyHunters’ vishing attack hits Ad Tech firm Optimizely, leaking business information Ad tech company Optimizely experienced a phishing-based intrusion where attackers accessed some internal systems and stole limited business contact information from CRM and internal documents, though sensitive customer data was not compromised and operations continued normally. Pathstone Family Office breached; records stolen Hackers claimed to have breached Pathstone Family Office and stolen around 641,000 records containing sensitive personal information and internal corporate documents, potentially exposing clients to identity theft, fraud, and reputational risks.
A large-scale, coordinated cyberattack disrupted operations at Delta, a prominent Russian provider of alarm and security systems for homes, businesses, and vehicles. While Delta claimed no customer data was compromised, an unidentified Telegram channel alleged to possess stolen data. The attack caused widespread service outages and forced the company to communicate via social media platform VKontakte. The attack was attributed to an unspecified 'hostile foreign state'.
Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 7 Oct – 13 Oct 2025 This week witnessed four significant cybersecurity incidents affecting major organizations across multiple sectors. The period from October 7-13, 2025, was marked by sophisticated attack campaigns targeting authentication systems, zero-day vulnerabilities, and supply chain compromises. DraftKings Credential Stuffing Attack (September 2, 2025): Targeted under 30 customer accounts through automated credential reuse Kido International Nursery Ransomware (September 25, 2025): Compromised sensitive data of over 8,000 children and families Discord Third-Party Data Breach (September 20, 2025): Exposed government IDs and support data for 70,000 users Harvard University Oracle Zero-Day Exploit (August 9, 2025): Leveraged CVE-2025-61882 for data exfiltration All incidents demonstrate evolving threat landscapes targeting authentication weaknesses, supply chain vulnerabilities, and zero-day exploits in enterprise systems. >> Outpace Attackers With AI-Based Automated Penetration Testing 1. DraftKings Credential Stuffing Account Breach DraftKings, the Boston-based sports betting platform, experienced a credential stuffing attack affecting fewer than 30 customer accounts. Attackers utilized automated tools to test stolen username-password combinations from external data breaches against DraftKings authentication systems. The attack leveraged MITRE ATT&CK technique T1110 (Brute Force) under the Initial Access tactic. Threat actors deployed automated scripts conducting rapid sequential login attempts across multiple accounts using credential pairs likely obtained from underground forums or previous data breaches. The attack pattern showed: High-volume login attempts from suspicious IP addresses Anomalous user agent strings in authentication logs Sequential failed authentication events (Windows Event ID 4625) followed by successful logins (Event ID 4624) No evidence of malware deployment or lateral movement within DraftKings infrastructure Compromised customer data included names, addresses, dates of birth, phone numbers, email addresses, last four digits of payment cards, profile photos, transaction history, account balances, and password modification timestamps. No government-issued identification numbers or complete financial account details were accessed. Suspicious IP ranges conducting multiple authentication attempts Elevated failed login event volumes preceding successful access Account lockout patterns followed by credential validation No evidence of malicious file execution or registry modifications Mandatory password resets for affected accounts Multi-factor authentication enforcement for DK Horse accounts Enhanced fraud detection algorithms implementation Additional technical measures to prevent similar credential-based attacks 13th October – Threat Intelligence Report For the latest discoveries in cyber research for the week of 13th October, please download our Threat Intelligence Bulletin . Qilin ransomware group has claimed responsibility for targeting Asahi, Japan’s largest brewing company, that had been hacked on September 29 th . The attack resulted in the exfiltration of over 9,300 files totaling 27GB of sensitive data, including financial documents, employee IDs, contracts, and internal reports. The attack disrupted operations at six breweries, impacting the production of thirty labels and potentially causing hundreds of millions in losses. Check Point Threat Emulation provides protection against this threat (Ransomware.Wins.Qilin) Sugar Land city in Texas has been a victim of a cyber-attack that resulted in outages to several online municipal services, including bill pay, permit payments, and utility billing systems, but did not affect critical infrastructure or emergency services. The incident impacted the digital access of nearly 110,000 residents, exposing service interruptions but with no disclosed evidence of data theft. American law firm Williams & Connolly has confirmed a cyber attack that resulted in unauthorized access to email accounts belonging to a small number of attorneys. The firm reported no evidence that confidential client data was stolen from central databases, and the scope of the compromised information appears limited to email accounts. The attack has been attributed to suspected China affiliated threat actors. Crimson Collective threat group, who claimed the Red Hat intrusion last week, is now targeting AWS environments for data theft and extortion. The group harvests exposed AWS credentials, creates new IAM users and access keys, assigns AdministratorAccess for privilege escalation and enumerates cloud assets. Afterwards, the group resets RDS master passwords and snapshots EBS volumes to spin up EC2 instances under permissive security groups, then delivers extortion notes through SES from within AWS victim accounts. Post-disclosure, Crimson Collective partnered with “Scattered Lapsus$ Hunters” to amplify pressure and has reused IPs across incidents, aiding cross-case correlation. Electronic components maker Avnet has suffered a data breach that resulted in unauthorized access to an externally hosted EMEA internal-sales database. A threat actor has claimed responsibility for stealing 1.3TB of compressed data and demanding ransom, but most data is reportedly unreadable without proprietary tools, and the total number of affected individuals remains unknown. American gambling company DraftKings has experienced a data breach that resulted in unauthorized access to customer accounts through credential stuffing attacks, exposing personal information such as names, phone numbers, email addresses, last four digits of payment cards and more. The breach has reportedly impacted fewer than 30 customers, and no sensitive data was accessed. A new large-scale botnet campaign, RondoDox, is actively exploiting 56 vulnerabilities – including RCE and command injection CVEs like CVE-2023-1389, CVE-2024-3721, and CVE-2024-12856 – across 30+ device types (DVRs, NVRs, CCTV, web servers). Active since June, it exploits new and legacy bugs (including unpatched EOL devices), weaponizes Pwn2Own code, and uses an “exploit shotgun” to maximize infections and seize device/network control. Check Point IPS provides protection against this threat (TP-Link Archer AX21 Command Injection (CVE-2023-1389); TBK DVR Devices Command Injection (CVE-2024-3721); Four-Faith F3x Series Command Injection (CVE-2024-12856)) Oracle E-Business Suite zero-day CVE-2025-61882 enables unauthenticated RCE via the BI Publisher Integration component with a single low-complexity HTTP request, allowing data theft from internet-exposed EBS apps. The flaw is actively leveraged by Cl0p and other threat actors for extortion. Check Point IPS provides protection against this threat (Oracle Concurrent Processing Remote Code Execution (CVE-2025-61882)) Redis has patched CVE-2025-49844, a critical use-after-free RCE in the default-enabled Lua engine affecting all versions. Authenticated exploits enable sandbox escape and full host compromise (reverse shells, credential theft, lateral movement, malware); at least 60k of ~330k Internet-exposed Redis servers lack auth, and the flaw is already being abused by botnets and ransomware. Check Point IPS provides protection against this threat (Redis Use After Free (CVE-2025-49844)) StealthLoader Malware Leveraging Log4Shell
On October 12, 2025, Heywood Healthcare, encompassing Heywood Hospital and Athol Hospital, experienced a network outage due to a cyberattack. The incident disrupted critical services including radiology, lab services, and email, leading to a 'Code Black' and the diversion of ambulances. The Sinobi ransomware group later claimed responsibility for the attack, threatening to publish 550GB of stolen data. Potentially exposed information includes names, dates of birth, Social Security numbers, driver's license or state ID numbers, medical records, health insurance details, and contact information.
Get our Quarterly Ransomware Report as a PDF June saw 102 publicly disclosed ransomware attacks across 21 countries, with Australia experiencing a particularly active month at 21 attacks. Healthcare remained the top target with 30 incidents, followed by services with 15 and education with 14. The ransomware ecosystem also continued to fragment, with 31 groups claiming victims. The newly emerged 2019 ransomware group led the month with 12 claimed victims, making it one of June’s most notable developments. 1. The Melbourne International Film Festival (MIFF) suffered a data breach after attackers compromised its third-party ticketing provider, Ferve, exposing the personal information of around 26,700 customers. While payment card details and passwords were not affected, names, email addresses, phone numbers and residential addresses were potentially accessed. Ransomware group 2019 has claimed responsibility for the attack and allegedly advertised a much larger dataset for sale, although MIFF disputes those claims and the attribution remains unverified. 2. VSP Solutions , an Australian distributor of video security products, confirmed it is investigating a cyber incident after the Stormous ransomware group claimed responsibility for the attack. Stormous alleges it stole more than 40 GB of sensitive data, including financial records, email archives and customer databases, although VSP says the compromised information was historical and that business operations were not disrupted. The company has engaged forensic experts and notified the relevant authorities while its investigation continues. 3. The UN World Food Programme (WFP) disclosed that a cyberattack exposed the personal data of approximately 600,000 households in Gaza after attackers compromised its Palestine self-registration platform. The exposed information included names, ID numbers, mobile phone numbers, and location data used to register for food and cash assistance. WFP took the affected system offline, launched an investigation, and stated that no ransomware group had claimed responsibility for the attack. 4. IMA Diligence Services confirmed it had notified 525,306 individuals that their personal information was compromised in a December 2025 cyberattack involving a legacy server hosted by a third-party provider. The exposed data included Social Security numbers, financial information, medical records, and government-issued IDs. Genesis ransomware group claimed responsibility for the attack, alleging it stole 700 GB of data, although the company did not confirm the attribution or the volume of data reportedly exfiltrated. 5. More than 3,100 individuals were notified by Bronsky Orthodontics after unauthorized access to multiple employee email accounts exposed protected health information. The compromised data included patient names, dates of birth, contact information, dental and orthodontic treatment records, insurance information, and, for a limited number of individuals, Social Security numbers, financial account information, and government-issued IDs. The practice said it secured the affected accounts, completed a forensic investigation, and is reviewing its data privacy and security policies. 6. Hampr , an Australian workplace catering provider, said it was investigating claims that a ransomware group had stolen and published more than 360,000 customer records on a hacking forum. 2019 ransomware group alleged the leaked data included customer IDs, names, mobile phone numbers, account details, dietary preferences, payment information, billing data, and workspace details. Hampr said it had notified customers and relevant cybersecurity authorities while its investigation remained ongoing, and the claims had not been independently verified. 7. Bridle Trails Family Dentistry disclosed that 20,976 current and former patients were affected by a data breach stemming from the compromise of an employee email account in November 2024. The potentially exposed information included names, dates of birth, Social Security numbers, medical and treatment records, medical record numbers, health insurance information, driver’s license numbers, and taxpayer ID numbers. The practice said it was unaware of any misuse of the data and has enhanced its security measures. 8. A ransomware attack against the National Federation of Subpostmasters (NFSP) disrupted communications with the UK Post Office after attackers exploited a critical cPanel vulnerability. The attackers encrypted the federation’s website files and demanded a ransom, prompting the Post Office to temporarily suspend email communications with the NFSP as a precaution. While the incident caused ongoing operational disruption, the NFSP said its investigation found no evidence that data had been lost or exfiltrated. 9. More than 25,000 Australian Centre for the Moving Image (ACMI) customers were allegedly impacted after ransomware group 2019 claimed to have breached the organization’s systems and published customer data on a hacking forum. The actor alleged the stolen data included names, email addresses, dates of birth, gender, sign-in details, invoicing information, and IP addresses. ACMI said it was investigating a separate breach involving a third-party system used for its Cinema 3 streaming service, emphasized that payment card details and passwords were not compromised, and had not confirmed the group’s claims. 10. IKEA said it was investigating claims that the LAPSUS$ extortion group had stolen and was attempting to sell 180 GB of internal data allegedly taken from Ingka Group , the retailer’s largest franchisee. The ransomware group claimed the data included source code repositories, e-commerce architecture, supply chain systems, cloud infrastructure, and AI/MLOps projects, but there was no evidence that customer data was involved. IKEA had not confirmed the breach or the authenticity of the claims at the time of publication. 11. An unauthorized third party accessed and exfiltrated customer data from Australian luxury fashion brand Camilla , prompting the company to confirm a cyber incident affecting its Australian operations. The compromised information included customer names, dates of birth, email addresses, and phone numbers stored in its point-of-sale system, while payment card and banking information were not affected. Camilla said it notified impacted customers and the Office of the Australian Information Commissioner, and that business operations continued without disruption while the investigation remained ongoing. 12. More than 17,300 MMJ Real Estate clients may have had their personal data exposed after 2019 ransomware group claimed to have breached the Australian real estate agency and posted the data on a hacking forum. The allegedly compromised records included full names, email addresses, mobile numbers, addresses, business interests, property price ranges, and inquiry timestamps.
Hacker steals 1 million Cock.li user records in webmail data breach Email hosting provider Cock.li has confirmed it suffered a data breach after threat actors exploited flaws in its now-retired Roundcube webmail platform to steal over a million user records. The incident exposed all users who had logged in to the mail service since 2016, estimated at 1,023,800 people, along with contact entries for an additional 93,000 users. Cock.li is a Germany-based free email hosting provider with a privacy-focused ethos and lax moderation policies, run by a single operator known as 'Vincent Canfield' since 2013. It is promoted as an alternative to mainstream email providers, supporting standard security protocols like SMTP, IMAP, and TLS. Cock.li is used by people who distrust major providers and members of infosec and open-source communities. It is also popular among cybercriminals, such as affiliates from Dharma, Phobos, and other ransomware gangs. Late last week, the Cock.li service was disrupted without public explanation, leaving users wondering what might have happened. Soon after, a threat actor claimed to be selling two databases containing dumped from Cock.li that contained sensitive user information, offering them for sale for a minimum of one Bitcoin ($92.5k). Cock.li published a statement on its website yesterday, confirming the breach and the validity of the threat actor's claims. The email service confirmed that the following information has been exposed for 1,023,800 user accounts: A serialized blob of Roundcube settings and email signature Contact names (only for a subset of 10,400 accounts) Contact email addresses (only for a subset of 10,400 accounts) vCards (only for a subset of 10,400 accounts) Comments (only for a subset of 10,400 accounts) The service's announcement clarifies that user account passwords, email content, and IP addresses were not compromised, as these are not present in the stolen databases. Meanwhile, the 10,400 account holders who had third-party contact information exposed will be getting a separate notification. For everyone who used the service since 2016, it is recommended to reset their account passwords. The Cock.li data breach could be valuable to researchers and law enforcement, as the exposed information can be used to learn more about the threat actors who use the platform. Cock.li says they believe the data was stolen using an old RoundCube SQL injection vulnerability tracked as CVE-2021-44026. This breach comes just as Cock.li recently analyzed an RCE flaw in Roundcube, CVE-2025-49113, which is believed to be actively exploited in attacks . Their analysis led them to remove the software from their platform in June 2025. "Cock.li will no longer be offering Roundcube webmail," explained the service admins. "Regardless of whether our version was vulnerable to this, we've learned enough about Roundcube to pull it from the service for good." "Another webmail is definitely on the table, but it is not an immediate priority for us."
For the latest discoveries in cyber research for the week of 5th May, please download our Threat Intelligence Bulletin . Three major UK retailers – Co-op , Harrods and Marks & Spencer (M&S) – were hit by cyberattacks that disrupted operations and compromised sensitive data. The attacks are believed linked to the Scattered Spider gang, while DragonForce ransomware gang claimed responsibility for the attacks. The American non-profit healthcare system, Ascension, experienced a data breach following a third-party hacking incident in December 2024. The attack led to the theft of patients’ personal and health information, including names, addresses, Social Security numbers, and inpatient records. Although no threat actor has claimed responsibility, the timeline suggests a possible link to a series of Cl0p ransomware attacks that exploited a zero-day vulnerability in the Cleo secure file transfer software. Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Ransomware.Win.Clop; Ransomware.Wins.Clop; Ransomware.Wins.Clop.ta.*) Hitachi Vantara, a subsidiary of Japanese Hitachi, has suffered a cyberattack that disrupted parts of its systems. The attack was claimed by Akira ransomware gang which allegedly stole files from the company’s network and left ransom notes on compromised machines. Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Ransomware.Wins.Akira.ta.*; Ransomware.Wins.Akira; Ransomware.Win.Akira; Trojan.Win.Akira) Media firm Urban One was hit by a cyberattack that occurred in February, resulting in data leakage of 2.5TB of employees’ personal data such as names, addresses, Social Security numbers, direct deposit information and W-2 information. The attack was claimed by Cactus ransomware gang. Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Ransomware.Win.Cactus; Ransomware.Wins.Cactus.ta.*) Several public and private organizations in the Netherlands have confirmed a series of DDoS attacks linked to the pro-Russian hacktivist group NoName057(16). These attacks caused access issues and service disruptions across key entities. While no data breaches or system compromises have been reported, the group appears to be responding to the Netherlands’ military support for Ukraine. Texas-based employee benefits administration company, VeriSource Services, has been a victim of a data breach that occurred in February 2024, impacting over four million people. The breach exposed sensitive data, including full names, addresses, dates of birth, gender, and Social Security numbers. Nova Scotia Power, along with its parent company Emera, suffered a cyberattack affecting their Canadian network and business servers. The incident disrupted customer service and online access for over 500,000 clients. Operations remained unaffected, however delays have increased. SonicWall reported active exploitation of two older vulnerabilities (CVE-2023-44221 and CVE-2024-38475) affecting its Secure Mobile Access (SMA) appliances. CVE-2023-44221 is a high-severity command injection flaw in the SMA100 SSL-VPN interface exploitable by admins, while CVE-2024-38475 affects Apache HTTP Server and allows unauthenticated remote code execution. Check Point IPS provides protection against this threat (SonicWall SMA Command Injection (CVE-2023-44221), Apache HTTP Server Remote Code Execution) Google’s 2024 0-days report highlighted 75 zero-day vulnerabilities exploited in the wild, with 33 targeting enterprise technologies. Enterprise-focused products – especially security and networking software – accounted for 44% of the total. Many of the exploits involved platforms such as WebKit, Firefox, revealing attackers’ focus on both widely used and specialized technologies. A set of 17 vulnerabilities, dubbed “Airborne”, was discovered in Apple’s AirPlay protocol and SDK. Two flaws (CVE-2025-24252 and CVE-2025-24132) enable wormable zero-click RCE attacks, allowing local network compromise of Apple and third-party devices. Apple issued patches for affected products, including iPhones, iPads, Macs, and Apple Vision Pro. Two misconfiguration-related vulnerabilities, CVE-2025-23242 and CVE-2025-23243, have been disclosed in NVIDIA Riva deployments. These flaws could allow unauthorized access and potential abuse of AI services like speech recognition and text-to-speech. Check Point Research released 2025 AI Security Report with an analysis detailing main AI-driven threats, including LLM poisoning, retrieval manipulation, and AI-powered malware. The report highlights AI powered social engineering and the complete loss of digital identities in the age of AI. It also covers Dark LLMs like WormGPT and how AI is used by cybercriminals to process stolen data. Researchers have uncovered Outlaw, a Perl-based cryptomining botnet targeting Linux systems by exploiting weak or default SSH credentials. The attackers deploy custom XMRig miners, terminate competing miners to conserve resources, and use an IRC-based client for DDoS attacks, file uploads, and backdoor access. The botnet primarily targets devices in the United States. Researchers have discovered a coordinated supply chain attack involving 21 backdoored Magento extensions from vendors Tigren, Meetanshi, and MGS, affecting 500–1,000 e-commerce stores. The PHP backdoor, injected as early as six years ago and activated on April 20, allows remote code execution leading to data theft, skimmer injection, and admin account creation. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign StealthLoader Malware Leveraging Log4Shell BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies. CloudWize Acquired By DoiT International
April 2025 Data Breaches: 4 Million SSNs Leaked, 23M+ in Settlements Stay up to date with Pomerium news and announcements. You have successfully joined our subscriber list. Cyber attacks didn’t slow down this past April 2025, recording sizable breaches and settlements—one data breach compromised the personal identifiable data of 4 million individuals. The cause behind many of these breaches was undisclosed, however, there is a recurring theme of insufficient access controls, third-party vulnerabilities, and delayed breach detection—all weaknesses that zero-trust security measures could have addressed. Compiled on May 1, the following list of data breach headlines published during the month of April contains details behind the cause of the breach (if available). Source articles have been organized by cause of breach (compromised credentials, insider threat, malware, third party data breach, ransomware, social engineering, system vulnerability, and undisclosed) with articles organized in reverse chronological order. Security Breaches Reported in April 2025 Alternate Solutions Health Network Notifies Patients About May 2024 Email Breach | HIPAA Journal Email accounts have been compromised at four HIPAA-regulated organizations: Alternate Solutions Health Network in Ohio; Park Royal Hospital in Florida; 90 Degree Benefits in Minnesota; and the Charleston Fire Department in West Virginia. Almost 107,000 individuals have been affected. Data Breach at Onsite Mammography Impacts 350,000 | SecurityWeek Massachusetts medical services provider Onsite Mammography is notifying over 350,000 people that their personal and health information was compromised in a data breach. The incident was discovered in October 2024 and involved unauthorized access to an employee’s email account, the firm reveals in a notification letter mailed to the impacted individuals.Some of the emails in the compromised account’s inbox, Onsite says, exposed both personally identifiable information (PII) and protected health information (PHI). 33,529 more Texans' data breached by now-fired state workers | The Texas Tribune Texas Health and Human Services Commission late Wednesday began notifying another 33,529 recipients of state benefits that their private information had been improperly accessed. Three months ago, the state notified 61,104 Texans that their personal information may have been improperly accessed by state employees. A total of nine state employees had accessed individuals’ accounts without a stated business reason. SK Telecom shares plunge after data breach due to cyberattack | Reuters SK Telecom shares fell as much as 8.5% on Monday to hit their lowest level since August last year, after South Korea's biggest mobile carrier disclosed it suffered a leak of customer data earlier this month caused by a cyberattack. The company said in a statement it would take full responsibility for any harm caused as a result of the breach that was detected on April 18. It described the incident as a large-scale leak of data due to malware, without providing more details. Marks & Spencer breach linked to Scattered Spider ransomware attack | Bleeping Computer Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted by threat actors known as "Scattered Spider" BleepingComputer has learned from multiple sources. M&S confirmed it suffered a cyberattack that caused widespread disruption, including to its contactless payment system and online ordering. The threat actors are believed to have first breached M&S as early as February, when they reportedly stole the Windows domain's NTDS.dit file. Hitachi Vantara takes servers offline after Akira ransomware attack | Bleeping Computer Hitachi Vantara, a subsidiary of Japanese multinational conglomerate Hitachi, was forced to take servers offline over the weekend to contain an Akira ransomware attack. While the company's cloud services are not impacted, Hitachi Vantara systems and Hitachi Vantara Manufacturing were disrupted as part of the containment effort. Additionally, while Hitachi Vantara's remote and support operations are down, customers with self-hosted environments can still access their data as usual. Ransomware Attack on Frederick Health Medical Group Affects 934,000 Patients | HIPAA Journal Frederick Health Medical Group is facing several potential class action lawsuits over a recent data breach that affected more than 900,000 patients. Frederick Health Medical Group, a Maryland-based healthcare group, announced on January 27, 2025, that it had fallen victim to a ransomware attack and had called in cybersecurity experts to investigate the incident. Two Ransomware Hacks Affect 1.1 Million Patients | BankInfoSecurity Two separate ransomware hacks of a Maryland medical group and a California hospital resulted in data thefts affecting more than 1.1 million patients, according to recent reports to regulators. Cybercriminals claim to have leaked 480 gigabytes of data from one of the attacks. Frederick Health in a report filed on March 28 to the U.S. The Department of Health and Human Services said 934,326 people were affected by its hacking incident early this year. California-based Dameron Hospital reported the breach affected nearly 211,000 people.
Lee Enterprises, a major U.S. media company, was targeted by the Qilin ransomware group. Qilin claimed responsibility on February 27, 2025, for an attack that disrupted operations and stole 350 GB of data, including government ID scans, financial spreadsheets, contracts, and non-disclosure agreements. The group threatened to leak all data by March 5, 2025.
A major McDonald’s delivery system in India exposed the personal information of its customers and drivers due to several simple security flaws, TechCrunch has exclusively learned. The flaws, discovered by Traceable AI security researcher Eaton Zveare, were found in the APIs of the delivery system associated with McDonald’s India (West & South) , which is owned by Hardcastle Restaurants. Zveare exclusively told TechCrunch that bugs in the company’s delivery system, McDelivery, meant anyone could access, hijack, redirect, or real-time track orders, or make legitimate orders for $0.01, by interacting with the company’s API, which apps and websites use for placing orders and tracking. This is because the API wasn’t properly checking to make sure the person making requests was allowed to make requests. The bugs also allowed access to invoices and provided the ability to submit feedback for customer orders. The security flaws exposed McDelivery customer full names, email addresses, and phone numbers of McDonald’s India (West & South) customers, and exposed access to vehicle numbers, profile pictures, and tracked the real-time location of the restaurant chain’s drivers delivering orders. In a since-published blog post , Zveare found the vulnerabilities and reported them to the restaurant chain in July. They were fixed in late September, per the researcher. McDonald’s India told TechCrunch that a “thorough verification of systems and logs” showed the flaws did not result in a breach of its customer data. “We conduct regular audits and assessments to continuously strengthen our security measures, and have all the necessary enhancements implemented, ensuring all our systems are up to date and secure,” Sulakshna Mukherjee, a spokesperson at McDonald’s India (West & South), said in a statement emailed to TechCrunch. McDonald’s India did not disclose the number of customers whose information may have been exposed by the bugs. However, the researcher told TechCrunch that the flaws exposed access to hundreds of millions of orders. “The McDelivery (West & South) mobile app uses the same exact back-end APIs as the website. As a result, both were vulnerable to the same exploits,” the researcher told TechCrunch. This is not the first time McDonald’s India has exploited its customers’ sensitive data. In 2017, the delivery app of McDonald’s India (West & South) leaked the personal information of about 2.2 million customers. When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Jagmeet covers startups, tech policy-related updates, and all other major tech-centric developments from India for TechCrunch. He previously worked as a principal correspondent at NDTV. You can contact or verify outreach from Jagmeet by emailing mail@journalistjagmeet.com . View Bio October 13 – 15 San Francisco Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $330 toda y! AI music generator Suno breach affects 55M users, per Have I Been Pwned Anthropic’s landmark $1.5B copyright settlement is approved Judge pauses $110B Paramount-Warner Bros. merger Apple and Google ordered to purge ‘nudify’ apps from App Stores Coca-Cola suspended production at its Fairlife dairy after a ransomware attack Tesla driver in fatal Texas crash pressed accelerator 100%, NTSB confirms Amid hardware legal battle, OpenAI releases a $230 keyboard for Codex
The State of Rhode Island's RIBridges system, which supports online applications and eligibility processing for various benefits (Medicaid, SNAP, TANF, etc.), suffered a major cyberattack. On December 13, 2024, the state was informed by its vendor, Deloitte, that a cybercriminal likely obtained files containing personally identifiable information from the system. The state has taken the system offline and advises all users of RIBridges to assume their data has been compromised.
It is a confirmed cyber-related loss or material reduction of service availability, production capacity or normal business operations.
The classification requires evidence of downtime, unavailable service or operational interruption. An intrusion, vulnerability or ransomware report alone does not establish disruption when the affected organization continues operating normally.
No. Ransomware can involve encryption, data theft or extortion without verified downtime, so disruption must be confirmed separately.
Headlines often combine attack method and impact, but they answer different questions. Shadow Tier requires explicit availability evidence before connecting an incident to this page, reducing the risk of overstating operational consequences.
Why do organizations take systems offline during a cyber incident?
Planned isolation can limit attacker movement, protect data and create a controlled environment for investigation and trusted recovery.
Containment downtime may still have serious business effects, even when malware did not directly disable the service. Decision makers should compare ongoing threat, safety, evidence preservation and service criticality before changing containment.
A service is available only when its full chain works. Recovery planning should map technical and operational dependencies, required people, validation steps and third-party escalation routes instead of treating each server as an isolated asset.
How should organizations prioritize services during recovery?
Prioritize safety and time-critical outcomes, then restore the trusted identity, data, infrastructure and suppliers those services require.
Business impact analysis should guide the sequence, but responders must update it with current compromise evidence. Bringing a high-priority service back too early can recreate attacker access or depend on data that has not been validated.
What should companies communicate during a cyber outage?
Communications should state affected services, available workarounds, the next update time and verified facts without speculating about cause or scope.
Different audiences need consistent operational guidance. Separating service status from investigation conclusions helps customers and staff act safely while allowing technical, legal and regulatory assessments to develop as evidence changes.
How can current outage news improve cyber resilience?
Use comparable incidents to test dependency maps, manual workarounds, supplier escalation, recovery order and communications under realistic pressure.
Current events make resilience exercises more concrete. Teams can ask whether the same platform, service chain or failure mode exists internally, then assign owners to close gaps rather than using outage headlines only as general awareness.