Skip to main content

Evidence-led intelligence · rolling 90-day view

Cyber Incident Impact Areas

An impact area describes what a cyber incident actually caused, not how the attacker operated. Shadow Tier classifies an impact only when current reporting or precise upstream VERIS evidence confirms the consequence.

Published guides

Which cyber incident impacts can you explore?

How can you browse other classified impacts?

Use these filters to focus the current incidents on a specific consequence, including data exposure, service disruption, data integrity issues and financial loss.

Explore related intelligence

Explore this reporting from another angle

Based on the full current signal set matched to this view before the visible feed limit. Counts describe this reporting set, not overall incident prevalence.

Current signals

Which data integrity signals are visible now?

Data integrity
Medium

CBSE revaluation portal hit by cyber attack; around 50 students affected

The CBSE revaluation portal's payment system was hit by a 'malicious attack' on May 30, 2026, leading to unauthorized access by approximately 50 students. The cyber attack caused abnormal fee displays, with amounts fluctuating significantly, and allegedly altered revaluation-related records. The glitch was linked to the HDFC payment gateway integrated with the system. Experts from IIT Madras and IIT Kanpur, along with the Digital Infrastructure Corporation of India, are assisting in strengthening the system.

Data integrity
Medium

GitHub Confirms TeamPCP Hack of Internal Environment

GitHub confirmed that TeamPCP hackers breached a limited internal environment connected to the broader TanStack supply-chain campaign. While customer repositories and production systems remained secure, the incident raised concerns over software supply-chain integrity and developer platform security. The threat actor group TeamPCP claimed responsibility for stealing approximately four thousand developer code repositories and intended to sell the stolen internal source code.

Data integrity
High

West Pharmaceutical Services Discloses Material Cyberattack and Data Exfiltration

For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin. Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software, while stating that customer data and core network infrastructure were not affected by the incident. Cryptocurrency platform THORChain, based in Switzerland, has encountered a security breach that led to the theft of about $10.7M. Trading was halted after one of six vaults was compromised, and the company said losses were limited to protocol-owned assets across several blockchains. West Pharmaceutical Services, a global manufacturer of drug delivery components, has experienced a ransomware attack that disrupted shipping, manufacturing, and shared service functions. The company disclosed that some systems were encrypted and data was stolen, but no ransomware group has publicly claimed responsibility. Foxconn, a global electronics manufacturer, has confirmed it was hit by a cyberattack on its North American operations after the Nitrogen ransomware group claimed to have stolen 8TB of data. The company confirmed disruption at some factories and said affected facilities were resuming normal production. Researchers unveiled ‘Claw Chain’, four vulnerabilities in OpenClaw, an autonomous AI agent platform, that allow attackers to bypass sandbox controls, expose restricted files, leak secrets, and gain owner-level access. The flaws include the critical CVE-2026-44112, rated CVSS 9.6. Researchers developed an AI-assisted macOS kernel exploit that bypasses Apple’s Memory Integrity Enforcement on M5 chips and grants full system control on macOS 26.4.1. Anthropic’s Mythos Preview reportedly accelerated bug discovery, and the findings were privately reported to Apple before public disclosure. Researchers detailed how threat actors abuse Vercel’s AI website generator, v0.dev, to mass-produce realistic phishing pages mimicking brands such as Microsoft and Spotify. The campaigns utilize Telegram bots to capture credentials and payment details in real time. Researchers found a popular Hugging Face repository hiding Windows-targeting malware after it amassed over 200,000 downloads. The package posed as OpenAI’s privacy filter and installed an infostealer that harvested browser passwords, cookies, SSH keys, VPN configurations, and cryptocurrency wallets before exfiltrating the data. Two Windows zero-day vulnerabilities, YellowKey and GreenPlasma, affect Windows 11 and recent Windows Server versions. YellowKey allows BitLocker bypass through Windows Recovery Environment with physical access, while GreenPlasma abuses the CTFMON framework to escalate privileges to SYSTEM. Proof-of-concept code is public, and the vulnerabilities are still unpatched. F5 has fixed CVE-2026-42945, a critical memory flaw in the NGINX rewrite module affecting versions 0.6.27 through 1.30.0. The 18-year-old bug enables denial of service and, under specific configurations, possible remote code execution. Public exploit code requires memory protections to be disabled. Check Point IPS provides protection against this threat (Nginx Heap Overflow (CVE-2026-42945)) Cisco has addressed CVE-2026-20182, a critical authentication bypass in Catalyst SD-WAN controllers that is being actively exploited. The flaw allows remote, unauthenticated attackers to gain full administrative control of affected systems. CISA ordered federal agencies to patch vulnerable devices following Cisco’s fixes. Apple has released security updates for CVE-2026-28819, an out-of-bounds write flaw in the Wi-Fi component affecting iOS, iPadOS, and macOS. Successful exploitation could allow an app to execute code with kernel privileges. The issue was addressed with improved bounds checking. Check Point Research has analyzed an internal leak from The Gentlemen ransomware operation, exposing chats, infrastructure details, affiliate roles, and ransom negotiations. The report links the zeta88 account to the administrator, maps 8 affiliate TOX IDs, and details the use of Fortinet and Cisco vulnerabilities as well as NTLM relay and OWA/M365 for initial access in attacks. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research has summarized Q1 2026 ransomware trends, recording 2,122 leak-site victims, which is the second-highest Q1 on record, and renewed consolidation. The top 10 groups were responsible for 71% of victims. Qilin led with 338 victims, The Gentlemen rose to third, and LockBit 5.0 returned with 163 victims. Check Point Research have quantified a World Cup 2026-driven surge in cyber activity, with weekly attacks per organization rising in Mexico, Canada, and the United States in April, across the media, hospitality, transportation and travel sectors. FIFA-themed domains reached 9,741 in April, and by early May, one in 41 were malicious. Researchers attributed a months-long intrusion against an Azerbaijani oil and gas company to the Chinese-linked FamousSparrow group. Attackers exploited an unpatched Microsoft Exchange server to deploy web shells, then alternated between Deed RAT and TernDoor across three waves of persistent activity. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign StealthLoader Malware Leveraging Log4Shell BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies. May 2026 saw an evolution of the cyber incidents highlighted in SWK’s previous Cybersecurity News Recaps , including more suspected hacking by Iran-backed actors and an apparent major resurgence of the notorious ShinyHunters gang over the past few months. This month also saw several other significant cyber incidents within the manufacturing industry, as well as multiple upcoming compliance deadlines, though one of the latter has been disrupted due to federal funding issues and pushback from affected parties. Continue reading below to learn more about some of the top cybersecurity news stories from May 2026 in this recap by SWK Technologies: Lawsuit Filed Against OpenAI for Sharing Data A class action complaint filed in California federal court accuses OpenAI of embedding Meta’s Facebook Pixel and Google Analytics in the ChatGPT web interface, transmitting query topics, user identifiers and email addresses to those platforms without user consent. The suit argues that conversations users assumed were private — including questions about finances, health and legal matters — have been treated as marketing telemetry, in violation of the Electronic Communications Privacy Act, the California Invasion of Privacy Act and the California Constitution. SEC Regulation S-P June 3 Compliance Deadline Approaching ShinyHunters Hit Canvas, 7-Eleven and More Throughout 2026

Data integrity
High

Vimeo Data Breach Exposes Personal Information of 119,000 People

Biggest Cyber Attacks, Data Breaches, Ransomware Attacks of May 2026 May 2026 delivered yet another resounding reminder that no organisation is immune to cyber threats. From attacks impacting major technology providers and healthcare institutions to incidents affecting transportation, media, and manufacturing organisations, threat actors continued to demonstrate their ability to exploit weaknesses across diverse sectors.  This month's most significant cyber incidents include breaches and attacks involving Instructure, Mediaworks, Taiwan High Speed Rail Corporation (THSRC), OpenAI, Grafana, NYC Health + Hospitals, Trellix, Vimeo, and Foxconn. Vulnerabilities Discovered and Patches Released Advisories issued, reports, analysis etc. in May 2026 Collectively, these incidents highlight several key trends shaping today's threat landscape, including supply chain risks, ransomware and extortion campaigns, attacks against critical infrastructure, third-party vulnerabilities, and the growing challenges posed by increasingly sophisticated threat actors. As organisations become more interconnected and reliant on cloud platforms, SaaS services, and complex digital ecosystems, the consequences of a cyber incident continue to grow. The good news is that many of these risks can be mitigated through proactive preparation. By investing in robust cyber incident response plans , scenario-specific playbooks, cyber tabletop exercises , executive cyber crisis training, and regular cyber resilience assessments, organisations can significantly improve their ability to prevent, detect, respond to, and recover from cyber incidents. At Cyber Management Alliance, we help organisations build these capabilities through our NCSC Assured training programmes, cyber incident response services, cyber drills, tabletop exercises, incident response playbook review and creation  and executive resilience training. Our complete suite of services enables businesses to stay ahead of the evolving cyber threat landscape and reduce the likelihood and impact of future attacks in 2026. Ransomware group claims breach of pro-Orbán Hungarian media firm Hungarian media company Mediaworks confirmed that attackers stole and leaked nearly 8.5 TB of internal data, including payroll records, contracts, financial files, and internal communications, exposing sensitive business information and creating serious operational and reputational risks. Ransomware attack on Hungarian media firm pro-Orbán Foxconn confirms cyber attack after Nitrogen claims Apple, Nvidia data theft Foxconn confirmed a cyber attack after the Nitrogen ransomware gang claimed it had stolen sensitive files linked to Apple and NVIDIA projects, raising concerns over supply-chain exposure, intellectual property theft, and potential operational disruption within one of the world’s largest electronics manufacturing networks. West Pharma ransomware attack disrupts operations West Pharmaceutical suffered a ransomware attack that encrypted systems and stole data, forcing the company to shut down portions of its global network and disrupting manufacturing, shipping, and supply-chain operations critical to pharmaceutical and biotech customers worldwide. Grafana refuses to pay ransom after codebase theft Grafana Labs confirmed that attackers stole portions of its internal codebase during a supply-chain related breach, but the company refused to pay the ransom demand, raising concerns over potential source code exposure, downstream software integrity risks, and further exploitation attempts targeting customers and developers. Trellix source code breach - Hackers gain unauthorised access to repository Trellix disclosed that attackers gained unauthorised access to part of its internal source code repository, exposing sensitive proprietary code and creating potential supply-chain and vulnerability discovery risks, although there was no evidence of product tampering or customer impact. Instructure confirms data breach, ShinyHunters claims attack Instructure confirmed that attackers stole data from its systems in a cyber attack, potentially exposing information tied to its Canvas learning platform and thousands of educational institutions, raising concerns over student and staff data privacy. Later, reports suggested that Instructure most likely paid a ransom to the cyber criminals. Vimeo data breach exposes personal information of 119,000 people Vimeo’s breach exposed the personal data of over 119,000 users, including names and email addresses, after attackers exploited a third-party analytics provider, increasing the risk of phishing, impersonation, and targeted fraud against affected users. Zara data breach exposed personal information of 197,000 people the April 2026 Dark Web Breach Incident Trend Report is compiled from data breach cases posted on the deep web and dark web forums. some information is included in cases where it is difficult to fully verify the factuality of the information due to the nature of the source. data breaches and sales of initial access to military, government, financial, technology, healthcare, and energy sectors were widely observed on major dark web forums BreachForums (run by Hasan), DarkForums, Exploit, Spear, and PwnForums. ShinyHunters have claimed Data breaches against multinational organizations such as Vimeo Inc., 7-Eleven, ADT Inc., Alert 360, Udemy Inc., Zara, and others, while Cisco source code leaks and internal Telegram group chat data sharing have been observed. high-risk breaches involving military, government, and intelligence organizations were also highlighted. data from China’s People’s Liberation Army (PLA), Iran’s IRGC surveillance system and police databases, Taiwan’s military and cyber security data, Boeing’s SLS and Artemis-related data, Virginia-class submarine technical data, and initial access to firewalls for US aerospace and defense companies were traded or shared. in the South Korea Region, KAAC data, which purports to be an academic organization, was shared on DarkForums, and data related to the Family Federation for World Peace and Unification (Unification Church) was sold. vM Horizon access for an insurance company in the Korea Region was also observed being sold on Spear. The Dedale Office’s claimed breach of shared childcare and community education data was determined to be a fake AI-generated sample data, making it difficult to determine if it was a real breach. the technology, financial, and platform sectors also saw breaches. Data or source code from Blue Origin, Vercel Inc., Coinbase Global Inc., SoundCloud, Polymarket, Jaguar Land Rover Automotive PLC, and Cisco were sold or shared on forums. in the Middle East, Data from TAMM, Taif City e-Government Platform, 1Pass LLC’s CRM Panel data, Riyadh Chamber of Commerce & Industry, and talabat were traded. in Asia, Oceania and the Others Region, Japanese Driver’s License-Personal Data, Mynavi Corporation Personal Data, Singaporean Citizen Data, Agoda Malaysia Customer Data, Elite Cloud Pte. Ltd. data, Beijing Yuansxin Pharmacy Technology Co., Ltd. (Miaoshou Doctor) Data, and card data from Australia and Denmark.

Data integrity
Medium

American National Standards Institute (ANSI) Internal Database Leak

The American National Standards Institute (ANSI) suffered a data leak where its internal database, described as an 'internal vault,' was reportedly offered for sale online. The leaked archive is said to total 3.6 TB and contains a wide array of sensitive information, including standards drafts, committee records, internal communications, pricing data, and access logs. The incident was reported on a data breach forum on February 22, 2026. The exposure raises concerns about the integrity of standards development, potential for targeted phishing campaigns, and commercial risks due to the sensitive nature of the compromised data.

Data integrity
High

Western Sydney University Notifies Community of Data Breach Affecting Student Management System

Public Notification – Western Sydney University cyber incident On 31 October 2024 Western Sydney University notified its community of unauthorised access to the University’s Student Management System and other back-end data storage systems, including the Data Warehouse from 14 August to 31 August 2024. On 11 February 2025, the University issued a correction and an update to the public notification, confirming: The unauthorised access to these systems occurred from 14 August to 3 September, three days longer than we originally notified on 31 October 2024. Additional personally identifiable information that may have been accessed, including first in family status and parent education level. This information is required as part of the enrolment process. The recommendations for impacted individuals remain the same and are outlined in the notification under the section ‘What action should you take?’. The University has updated the below public notification and has again drawn this notification to the attention of our former and current students and staff of the University, The College and The International College, staff of Early Learning Ltd. The University is committed to keeping our community updated through our investigation process and communicating transparently. Information about the support services the University has available are detailed in the public notification below. 31 October 2024 (corrected and updated on 11 February 2025) Western Sydney University issued this public notification on 31 October 2024, and draws this to the attention of our former and current students and staff of the University, The College and The International College, and staff of Early Learning Ltd. This public notification is for a separate cyber incident to the incidents that the University notified our community of on 21 May 2024 related to the University’s Microsoft Office 365 environment, and 31 July 2024 related to the University’s storage platform (Isilon), including My Documents. The University is issuing this notification to ensure that our community stays vigilant to any signs their data may have been accessed. Please consider all of your personal information that has been impacted across all the University’s cyber incidents and take seriously the recommended actions you can take to protect yourself. The University sincerely apologises for this incident and the ongoing impact it is having on our community. We are committed to transparently rectifying this matter and will keep our community updated as our investigation progresses. The University can confirm that an IT account was compromised which provided a perpetrator with unauthorised access to some data from the Student Management System and other back-end data storage systems including the Data Warehouse, from 14 August 2024 until 3 September 2024. Our investigation has confirmed names, addresses, University-issued email addresses, student identification numbers, tuition fee information (including fees deferred to HELP/HECS), student admission and enrolment data (including subject, results and progression information, and parent education level), and student demographic data (including nationality, Indigenous status, country of birth, citizenship status, gender, date of birth and first in family information) were accessed. The University has undertaken a preliminary analysis and can also confirm the following: On 27 August 2024, the University detected the unauthorised access and took immediate steps to protect our network in response. On 3 September 2024, the unauthorised access was contained. On 1 October 2024, the University’s investigation confirmed that personal information was accessed. As at 11 February 2025, our investigation into what data from the Student Management System and Data Warehouse was accessed confirmed the personal information listed above. As this investigation progresses, additional personal information may be found to have been accessed. There is no evidence to date that student records have been altered. The University has not received any threats to disclose private information or demands in exchange for maintaining privacy. The University has dark web monitoring in place and there is no evidence to date that the data has been uploaded. The University’s investigation to date indicates the perpetrator has used sophisticated techniques to gain unauthorised access in a targeted, persistent and sustained manner. What the University has done to secure personal information and mitigate harm Hacked again – new data breach at Western Sydney Western Sydney has experienced its second major data breach for the year, with the University yesterday announcing that a hacker accessed its Student Management System and the University’s Data Warehouse in August. The hacker gained access to the system on 14 August and was not detected until 27 August, accessing, “names, addresses, University-issued email addresses, student identification numbers, tuition fee information (including fees deferred to HELP/HECS), student admission and enrolment data (including subject, results and progression information), and student demographic data (including nationality, Indigenous status, country of birth, citizenship status, gender and date of birth)”. The University is still investigating the hack alongside police, and conceded that additional personal information may also have been accessed, however it has confirmed that no student records appear to have been altered. Around 7,500 individuals were affected by an breach of the University’s Isilon storage platform in January, with around 580 terabytes of data accessed across 83 of 400 storage directories. The first hack was revealed in May, “On behalf of the University, I unreservedly apologise for this incident and the impact it is having on our community,” Vice-Chancellor George Williams said. “We are committed to supporting our students, staff and stakeholders, and have several support services in place.” The University has not received any threats in relation to the breach and has promised ongoing upgrades to cyber security. Future Campus acknowledges Traditional Owners of Country throughout Australia. We pay our respect to Aboriginal and Torres Strait Islander cultures; and to Elders past and present.

FAQ

How does Shadow Tier connect incidents to impacts?

What evidence is required?

The title or summary must explicitly confirm the impact, or a precise upstream VERIS attribute must support it.

Why separate attack and impact?

Ransomware, phishing and exploitation describe actions. Exposure and disruption describe consequences and require their own evidence.

Can one incident have several impacts?

Yes. The same incident can expose data, interrupt services, undermine data integrity and cause financial loss when the available evidence supports each consequence.