Skip to main content

Current cyber intelligence

Cybersecurity News: Latest Incidents & Threat Intelligence

Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.

215

Reports in 90 days

in the current rolling intelligence window

10

Active topics

represented in the same 90-day window

65

High priority

high or critical reports in 90 days

Latest reporting

Latest cybersecurity incidents

Showing 163180 of 215 reports published in the last 90 days.

Trumpmobile logo
Medium

Trump Mobile Data Breach Exposes Pre-Order Customer Information

Trump Mobile confirmed a data breach on May 26, 2026, affecting over 27,000 customers who pre-ordered the T1 smartphone. The incident was linked to a security flaw in the company's website pre-order form, exposing names, addresses, email addresses, order identifiers, and mobile phone numbers. No payment or highly sensitive financial data was reported as compromised.

Trumpmobile
Rhcountryclub logoRansomware
Medium

Round Hill Country Club Hit by Play Ransomware

The Play ransomware group launched a cyberattack against Round Hill Country Club, threatening to release sensitive data if their demands are not met. The attack was reported and discovered on May 25, 2026.

Rhcountryclub
Alignedortho logoUse of stolen credentials or exploit
Medium

Aligned Orthopedic Partners discloses email environment data breach

Aligned Orthopedic Partners discovered unauthorized access to its email environment between November 16, 2025, and December 16, 2025. The breach exposed protected health information of 7,213 individuals, including names, dates of birth, Social Security numbers, and medical treatment information.

Alignedortho
Unmc logoRansomware
Medium

University of Nebraska Medical Center (UNMC) reports data exposure due to third-party software vulnerability

May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities A round-up of data breaches recently announced by 9 HIPAA-regulated entities: University of Nebraska Medical Center, Singing River Health System, Tampa Bay Dental Implants & Prosthetics, Aligned Orthopedic Partners, South Alabama Regional Planning Commission, Pivot Health, LHC Group, Mays Housecall Home Health, and the World Trade Center Health Program. University of Nebraska Medical Center (UNMC) has discovered that a vulnerability in a third-party software application has been exploited by a threat actor, exposing patient information. UNMC learned about the vulnerability in the REDCap software application in February 2026. REDCap software is used by UNMC to support its research studies and public health activities. When UNMC learned about the vulnerability, the software was taken offline, and an investigation was launched to determine if the vulnerability had already been exploited. Assisted by third-party cybersecurity experts, UNMC determined that the vulnerability had been exploited on September 20, 2023, and access remained possible until February 3, 2026. The data review confirmed that the system contained a range of sensitive data, which varied from individual to individual depending on the nature of the research study/public health activities. That information may have included names, dates of birth, addresses, phone numbers, email addresses, medical record numbers, and information created or collected in connection with a research study. Such information may have included visit dates, diagnoses, medications, laboratory results, imaging or procedure information, questionnaire responses, or other health-related information. A subset of individuals also had their Social Security numbers exposed. In total, 26,937 individuals had data exposed. Individuals whose Social Security numbers were impacted have been offered complimentary credit monitoring services. Singing River Health System, a non-profit health system with three hospitals and more than 50 clinics serving the Mississippi Gulf Coast, has started notifying patients about a hacking incident identified on or around December 21, 2025. The forensic investigation confirmed unauthorized access to its computer network between December 19, 2025, and December 21, 2025, and on February 10, 2026, it was confirmed that files containing patient information were viewed and potentially copied. Immediate Delivery of Checklist Link To Your Email Address Data exposed varied from individual to individual and may have included names in combination with one or more of the following: contact information, Social Security numbers, driver’s license numbers, dates of birth, bank account information, health insurance information, provider names, internal patient identification numbers, dates of service, medication information, and treatment and/or diagnostic information. Singing River Health System said, “We will continue to implement and evaluate enhanced safeguards and security measures to further protect our systems and continue to provide security training to our employees.” The affected individuals have been advised to monitor their accounts and explanation of benefits statements for data misuse. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected. Tampa Bay Dental Implants & Prosthetics, which also does business as Tampa Bay Dental Implants, Periodontics & Oral Surgery, a dental care provider serving the St. Petersburg and Tampa Bay area in Florida, has recently disclosed a data breach affecting 6,400 individuals. Tampa Bay Dental discovered unauthorized access to its network on January 19, 2026, when ransomware was used to encrypt files. The attack affected a legacy server that contained a backup of electronic medical records. The file review confirmed that patient data was exposed, including names, contact information, birth dates, treatment notes, and clinical histories, and for a limited number of individuals, Social Security numbers. Tampa Bay Dental has implemented additional security measures to prevent similar incidents in the future, including enhancing its security logging, strengthening server encryption, and updating access controls. Credit monitoring and identity theft protection services do not appear to have been offered to the affected individuals. The World Trade Center (WTC) Health Program, which provides no-cost healthcare services to individuals harmed by the 9/11 attack on the World Trade Center, has reported a data security incident to the HHS’ Office for Civil Rights affecting 1,071 individuals. Highly sensitive data was compromised in the incident, which occurred at a vendor, Managed Care Advisors/Sedgwick Government Solutions. Hackers accessed a server containing files associated with the WTC Health Program and exfiltrated sensitive data before encrypting files. The TridentLocker ransomware group claimed responsibility for the attack. The attack was detected by Managed Care Advisors/Sedgwick Government Solutions on December 4, 2025, and the forensic investigation confirmed that the server was first breached on November 16, 2025. Data compromised in the incident includes names, addresses, Social Security numbers, dates of birth, and protected health information. TridentLocker proceeded to leak the stolen data on its dark web data site when the ransom was not paid. The affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months. Bethesda, Maryland-based ASC Ortho Management Company, LLC, doing business as Aligned Orthopedic Partners, has discovered unauthorized access to its email environment and the exposure of the protected health information of 7,213 individuals. The forensic investigation determined unauthorized access occurred between November 16, 2025, and December 16, 2025, during which time, emails and files may have been accessed or acquired. The file review determined on February 17, 2026, that the exposed data included names in combination with one or more of the following: date of birth, Social Security number, driver’s license or state identification number, Medicaid or Medicare number, financial account number, date(s) of service, medical provider name, mental or physical condition, medical treatment information, diagnosis or clinical information, prescription information, health insurance information, patient account number, and or medical record number. The affected individuals were notified on April 17, 2026, and complimentary identity protection services have been made available. Aligned Orthopedic Partners said steps have been taken to augment security to prevent similar incidents in the future. During that time, files containing member data were viewed or copied.

Unmc
Acm logoMisconfiguration or publishing error
Medium

Dutch civil servants from Authority for Consumers and Markets (ACM) affected by Microsoft data leak

Microsoft accused of leaking Dutch civil servants' names to U.S. government Microsoft has reportedly shared the names of Dutch civil servants working for two regulatory agencies with the U.S. House of Representatives. The agencies involved include the Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP), according to an article published on Friday by Vrij Nederland. The civil servants involved are working on implementing the Digital Services Act (DSA), the European law that forces online platforms to take stricter action against illegal content, online child sex abuse, and disinformation. The American government considers this law a form of censorship. Microsoft shared emails, minutes, and invitations sent by these civil servants without redacting their names in the documents. American tech companies are required to share data with the U.S. government due to the Cloud Act in force in that country. State Secretary Eric van der Burg of Interior is concerned that Microsoft simply shared civil servants’ names with the U.S. government. But he first wants to investigate how the names were shared and in what documents before drawing conclusions. State Secretary Willemijn Aerdts for Digital Economy and Sovereignty has spoken with the U.S. Ambassador Joe Popolo about the allegations. The D66 politician said this happened some time ago, and she raised the issue with Popolo during her introductory meeting with the ambassador. “I said how undesirable this is. If you have a problem, you fight it out with us or, if necessary, in Europe, but not against the backs of civil servants,” Aerdts told ANP before heading into the Council of Ministers meeting on Friday. There is a broad desire within the Netherlands to become less dependent on major American tech companies , specifically because of the Cloud Act. Both Aerdts and Van der Burg stressed that it will take time for the Netherlands to become digitally sovereign.

Acm
Sedgwick logoRansomware
Medium

World Trade Center Health Program data compromised via Managed Care Advisors/Sedgwick Government Solutions vendor breach

The World Trade Center (WTC) Health Program reported a data security incident affecting 1,071 individuals. Highly sensitive data was compromised at a vendor, Managed Care Advisors/Sedgwick Government Solutions, where hackers accessed a server and exfiltrated data before encrypting files. The TridentLocker ransomware group claimed responsibility.

Sedgwick
Lepainquotidien logoRansomware
Medium

Le Pain Quotidien US Hit by DragonForce Ransomware Attack

Het dreigingsniveau is aanzienlijk voor Nederland en België. Er zijn meerdere recente slachtoffers gemeld en er lopen actieve aanvalscampagnes. Verhoogde waakzaamheid en controle van uw beveiligingsmaatregelen zijn nodig. De Cyber Dreigingsradar geeft u dagelijks inzicht in de cyberdreigingen die relevant zijn voor organisaties in Nederland en België. U hoeft geen uren door beveiligingsrapporten te spitten, want de radar filtert automatisch wat voor uw organisatie écht belangrijk is. Zo start u elke werkdag met de juiste informatie en reageert uw organisatie sneller op nieuwe dreigingen, voordat ze uw bedrijfsvoering raken. Wat staat er hier? Ransomware is gijzelsoftware, criminelen versleutelen uw bestanden en eisen losgeld. Dit overzicht toont welke criminele groepen nu actief zijn. Door deze informatie kunt u proactief maatregelen nemen voordat uw organisatie aan de beurt is. Groepen met activiteit in de afgelopen 7 dagen. Toont opkomende of zelden geziene groepen die buiten de top 10 vallen. Cybercrimeinfo ontdekte dat de groep INC Ransom de Nederlandse financiële dienstverlener ASA International op haar lekwebsite noemt. De aanvallers beweren toegang tot de organisatie te hebben, maar delen geen controleerbare details over de vermeende inbraak. De bewering is niet onafhankelijk bevestigd. Cybercrimeinfo ontdekte dat de groep achter PLAY ransomware vijf nieuwe organisaties op haar lekwebsite noemt. Een daarvan is de Nederlandse Vee- en Vleeshandel A.G. Scholtes B.V. De Rijksinspectie Digitale Infrastructuur is een onderzoek begonnen naar de beveiligingsmaatregelen van de Nederlandse EPD leverancier ChipSoft. Aanleiding is de aanval met ransomware die ChipSoft op 7 april bekendmaakte. Daarbij zijn persoonsgegevens van patiënten buitgemaakt, waaronder medische gegevens. Rodschinson Investment, een in België gevestigd commercieel vastgoedbedrijf, is naar verluidt getroffen door een ransomware-aanval van de Everest ransomware-groep. Cybercrimeinfo ontdekte deze claim, die aangeeft dat het Belgische bedrijf doelwit is geworden. De Everest ransomware-groep beweert verantwoordelijk te zijn voor de aanval. De beruchte ransomwaregroep LockBit 5.0 heeft op 5 juni 2026 geclaimd een succesvolle cyberaanval te hebben uitgevoerd op Wessels Logistics B.V., een logistiek bedrijf gevestigd in Nederland. Deze melding, waargenomen door Cybercrimeinfo, duidt op een potentiële inbreuk binnen de Nederlandse transport- en opslagsector. LockBit 5.0, bekend als een van de meest actieve en productieve... De Qilin ransomwaregroep heeft vijf nieuwe slachtoffers toegevoegd aan hun darkweb-portal. Dit is ontdekt door Cybercrimeinfo. Onder de geclaimde organisaties bevindt zich het Belgische bedrijf Sintax. Wat staat er hier? De actuele cyberdreigingen op één plek, slachtoffers in Nederland en België, actuele dreigingen, kwetsbaarheden in software en algemeen cybersecurity nieuws. Dit gebeurt bij uw buren, leveranciers en concurrenten. De stad Mechelen heeft een waarschuwing uitgegeven voor frauduleuze praktijken met valse QR-codes op parkeerautomaten. Cybercriminelen plakken stickers met deze codes op de automaten, waardoor onoplettende burgers via een nagemaakte betaalpagina hun parkeergeld overmaken naar de rekening van de oplichters in plaats van naar het officiële parkeersysteem. Gedupeerden riskeren hierdoor niet alleen... Op een cybercrimeforum is recentelijk een dataset aangeboden die wordt toegeschreven aan BCD Travel, een zakelijke reisorganisatie met hoofdkantoor in Utrecht. De crimineel die de data aanbiedt, verwijst naar het in mei 2026 bekend geworden afpersingsincident waarbij ShinyHunters betrokken was en naar de publieke registratie van dat datalek. Dit suggereert dat het gaat om een doorverkoop of... Microsoft heeft een significante toename waargenomen in succesvolle ClickFix-aanvallen, waarbij cybercriminelen erin slagen wachtwoorden, tokens en gevoelige documenten van zakelijke klanten te stelen. Bij deze aanvalsmethode worden gebruikers misleid om kwaadaardige commando's op hun computer uit te voeren, vaak onder het mom van het oplossen van een captcha. Een concreet voorbeeld hiervan is de... Onderzoek van NOS en Nieuwsuur laat zien dat documenten van verschillende Nederlandse gemeenten persoonsgegevens bevatten die onvoldoende zijn afgeschermd. In de onderzochte stukken waren onder meer namen, adressen en andere gegevens van inwoners terug te vinden. Het gaat om openbare documenten die gemeenten publiceerden bij besluiten en procedures. De cybercrimegroep AiLock heeft Ferrovial uit Nederland vermeld op haar darkweb leksite op 16-jul-26. Op het moment van publicatie is geen onafhankelijke bevestiging beschikbaar. Ivanti heeft haar klanten laten weten dat zij rekening moeten houden met een toename van het aantal gevonden kwetsbaarheden en bijbehorende patches, een direct gevolg van de inzet van kunstmatige intelligentie (AI). Het softwarebedrijf waarschuwt tevens dat AI bijdraagt aan een versneld misbruik van deze beveiligingslekken door kwaadwillenden. Producten van Ivanti zijn regelmatig het doelwit van... De Franse campingboekingssite Secureholiday, beheerd door het bedrijf Ctoutvert, heeft de persoonlijke gegevens van bijna 42.000 Nederlandse reizigers gelekt. Dit datalek leidde vervolgens tot phishingaanvallen gericht op de slachtoffers. Veel Europese campings maken gebruik van de diensten van Secureholiday voor hun boekingssysteem. Een onbekende actor biedt op het darkweb een database aan die beweert toe te behoren aan LiteBit, het Nederlandse platform voor cryptovaluta. De dataset zou 279.642 records bevatten met informatie die dateert uit 2017. Dit is opmerkelijk, aangezien LiteBit in 2017 daadwerkelijk tweemaal het slachtof... Het Parket Limburg waarschuwt voor telefonische phishing bij boekhouders en financiële medewerkers van Belgische bedrijven. Bellers doen zich voor als medewerker van een online financieel beheerplatform en beweren dat er verdachte transacties klaarstaan. De aanvallers zetten medewerkers onder druk om geld over te boeken of software voor toegang op afstand te installeren. Beveiligingsonderzoekers van Bitdefender hebben op 16 juli drie technieken onthuld die misbruik maken van een weinig bekende functie van Windows, genaamd bind links, om producten voor endpoint detection and response (EDR) te misleiden. Deze technieken, aangeduid als File Binding, Process Binding en Silo Binding, exploiteren de manier waarop de Windows Bind Filter driver (bindflt.sys)... Beveiligingsonderzoekers van Group-IB hebben een nieuwe spionagemalware ontdekt, genaamd HollowGraph, die een gekaapte Microsoft 365 kalender misbruikt als communicatiekanaal voor command-and-control (C2). De malware verbergt instructies van de operator en smokkelt gestolen bestanden naar buiten door deze als bijlagen toe te voegen aan kalendergebeurtenissen die zijn gepland voor het jaar 2050....

Lepainquotidien
Lhcgroup logo
Medium

LHC Group patients affected by Doctor Alliance vendor data breach

LHC Group patients had their protected health information compromised due to a security incident at their technology vendor, Doctor Alliance. The breach, confined to Doctor Alliance's web-based portal, exposed names, dates of birth, demographic and health information, and insurance details for 8,644 individuals.

Lhcgroup
Pivothealth logo
Medium

Pivot Health data breach exposes sensitive health details from AWS environment

Pivot Health disclosed a data breach where an unauthorized actor gained access to its Amazon Web Services (AWS) cloud environment between February 26, 2026, and March 13, 2026. This exposed personal and health insurance information for 8,391 individuals, including names, dates of birth, health insurance details, and financial account information.

Pivothealth
Fluke logoRansomware
Medium

Fluke Corporation Discloses Data Breach Affecting 18,000 Individuals; Clop Ransomware Claims Responsibility

Fluke Corporation notified over 18,000 individuals of a data breach that originally occurred in August 2025. The breach, which reportedly lasted two months, compromised highly sensitive personal information including Social Security Numbers (SSNs), birth dates, and self-identified disability status. The incident was attributed to an exploited vulnerability in a third-party application used by the company. The Clop ransomware group claimed responsibility for the breach, listing Fluke Corporation on its dark web leak site.

Fluke
Aurora Il logoPhishing
Medium

City of Aurora loses $1.1M in phone scam cyber attack

The City of Aurora lost approximately $1.1 million from city bank accounts after an employee fell victim to a phone-based social engineering scam. Attackers gained access to city bank account information and fraudulently transferred public funds.

Aurora Il
Nccer logo
Medium

NCCER notifies individuals of data breach affecting personal information

The National Center for Construction Education and Research (NCCER) sent out notifications to individuals, including Louisiana residents, on May 21, 2026, regarding a cybercrime incident. The breach, detected in March 2025, involved unauthorized acquisition of personal information, which may include Social Security numbers, driver's license/state ID numbers, and username/password information.

Nccer
Bwhhotels logoPhishing
Medium

BWH Hotels (Best Western, WorldHotels, SureStay) Data Breach

BWH Hotels, the parent company of Best Western, WorldHotels, and SureStay, confirmed a major data breach that exposed sensitive customer information. Unauthorized activity was detected in a web application containing guest reservation data on April 22, 2026. Attackers had maintained access to the network for over six months. Thousands of reservations across BWH brands may have been exposed, raising concerns about targeted phishing attacks against travelers.

Bwhhotels
Github logoUse of stolen credentials or exploit
Medium

GitHub Confirms TeamPCP Hack of Internal Environment

GitHub confirmed that TeamPCP hackers breached a limited internal environment connected to the broader TanStack supply-chain campaign. While customer repositories and production systems remained secure, the incident raised concerns over software supply-chain integrity and developer platform security. The threat actor group TeamPCP claimed responsibility for stealing approximately four thousand developer code repositories and intended to sell the stolen internal source code.

Github
Nychealthandhospitals logo
Medium

NYC Health + Hospitals Vendor Breach Exposes 1.8 Million Patient Records

A data breach at NYC Health + Hospitals Corporation, the largest public health system in the U.S., may have affected over 1.8 million current and former patients and employees. The Department of Health and Human Services Office for Civil Rights breach portal was updated to reflect the compromise of personal and protected health information. Investigators found attackers had network access for 11 weeks, with the breach originating from a security incident involving one of the organization's vendors. Exposed data includes fingerprints and palm prints.

Nychealthandhospitals

Explore the intelligence

Explore current intelligence taxonomies

Explore the intelligence

Questions about current cybersecurity intelligence

Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.

12 answers across 4 topics

How to read and use the current intelligence overview.

What does this cybersecurity intelligence overview contain?

It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.

Where should I start exploring?

Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.

Does this page list every cybersecurity incident?

No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.

Browse current topics