215
Reports in 90 days
in the current rolling intelligence window
Current cyber intelligence
Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.
215
in the current rolling intelligence window
10
represented in the same 90-day window
65
high or critical reports in 90 days
Latest reporting
Showing 181–198 of 215 reports published in the last 90 days.
Caesars Entertainment officially reported a data breach on May 19, 2026, following an external system compromise. The incident, which occurred on February 23, 2026, and was discovered on April 19, 2026, affected 862 individuals. The breach compromised records stored in cloud-hosted platforms, exposing personal information such as names, Social Security numbers, driver's license or state ID card numbers, full dates of birth, and passport numbers. Caesars is offering two years of complimentary identity theft protection services to affected individuals.
Data Breaches Announced by Florida Retina Center; Acadia Healthcare Company Florida Retina Center has identified unauthorized access to systems containing the protected health information of more than 13,600 patients. Acadia Healthcare Company has experienced a breach affecting 1,800 patients. Bonita Springs-based Florida Retina Center has announced a cybersecurity incident that was first identified on January 30, 2026. Immediate action was taken to secure its network, and an investigation was launched to determine the nature and scope of the unauthorized activity. On May 19, 2026, Florida Retina Center confirmed unauthorized access to parts of its network containing patient data. The file review confirmed that the data of 13,652 patients was exposed and potentially acquired in the incident. The exposed data included names, dates of birth, Social Security numbers, driver’s license numbers, and medical information. Notification letters have been mailed to the affected individuals, and 12 months of complimentary credit monitoring and identity theft protection services have been made available. At the time of issuing notification letters, no misuse of the affected data had been identified. Franklin, Tennessee-based Acadia Healthcare Company, Inc., a provider of psychiatric and chemical dependency services, has announced a data breach affecting 1,807 individuals. Unusual activity was identified within an employee’s email account on March 25, 2026. The account was secured, and an investigation was launched, which confirmed unauthorized access to a single employee’s email account and associated SharePoint files between March 21, 2026, and March 25, 2026. There was no unauthorized access to any other email accounts, other systems, or the electronic medical record system. Immediate Delivery of Checklist Link To Your Email Address The types of data involved varied from individual to individual, and for the majority of affected individuals, involved one or more of the following data elements in addition to their names: address, date of birth, treatment information, dates of treatment, type of treatment, and health insurance information. Certain individuals also had their Medicare Health Insurance Claim Number (HICN) exposed, which may include their Social Security number. Notification letters were mailed to the affected individuals on May 22, 2026, and additional safeguards have been implemented to prevent similar incidents in the future.
Cryptocurrency platform THORChain, based in Switzerland, encountered a security breach that led to the theft of about $10.7 million. The exploit occurred on May 15, 2026, when a vulnerability in the GG20 threshold signature scheme was exploited by a newly churned node operator, leading to funds being drained from one of its six vaults. The incident was reported in a threat intelligence report on May 18, 2026, and trading was halted.
Vodafone, a major international telecom, sustained a source code leak claimed by the Lapsus$ extortion group on May 18, 2026. The company confirmed limited access to GitHub files through compromised third-party development software, but stated that customer data and core network infrastructure were not affected.
HDFC Asset Management Company Ltd. (HDFC AMC), one of India's largest mutual fund managers, identified a cybersecurity incident on May 16, 2026, after receiving communication from an anonymous source claiming access to parts of its IT systems. The company promptly activated containment and incident response protocols and engaged a specialist cybersecurity firm for a forensic assessment. Preliminary findings suggest no material impact on operations or business continuity, though investor identity and financial data may have been exposed. The incident led to a drop in the company's stock price.
A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. The exposure was flagged by GitGuardian on May 15, 2026, and reported to KrebsOnSecurity. The repository, named 'Private-CISA,' contained plaintext credentials, cloud keys, tokens, and internal CISA files, exposed since November 2025. CISA acknowledged the leak and took the repository offline.
American Lending Center this week revealed that a data breach discovered last year has impacted more than 123,000 individuals. American Lending Center (ALC) is a California-based non-bank lender that manages a $3 billion portfolio specializing in government-guaranteed small business loans. The organization is notifying individuals affected by the data breach that information such as names, dates of birth, and SSNs may have been stolen in a ransomware attack detected in July 2025. “Through a forensic investigation into this breach, it was discovered that the threat actor compromised internal network, executed a ransomware attack, and accessed certain files that may have contained personal identifying or sensitive information,” ALC said in its notification to impacted customers, a c opy of which was submitted to the Maine attorney general’s office. The investigation was completed on April 8, and ALC has found no evidence that the potentially compromised information has been misused. Companies often include a statement in their data breach notifications that there is no evidence of misuse, even when information has been made public by cybercriminals. Advertisement. Scroll to continue reading. In the case of ALC, no known ransomware group appears to have taken credit for the attack, which could indicate either that a ransom has been paid or that the financial institution has been targeted by a cybercrime gang that does not have a public leak website. SecurityWeek has reached out to ALC for clarification and will update this article if it responds. Related : Foxconn Confirms North American Factories Hit by Cyberattack Related : 716,000 Impacted by OpenLoop Health Data Breach Related : BWH Hotels Says Hackers Had Access to Reservation Data for 6 Months Related : Deal Reached With Hackers to Delete Data Stolen From the Canvas Educational Platform Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! American Lending Center data breach impacts over 123,000 individuals American Lending Center revealed that a data breach discovered last year has impacted more than 123,000 individuals. The California-based non-bank lender, which specializes in government-guaranteed small business loans, is notifying affected individuals that personal information may have been stolen in a ransomware attack detected in July 2025, according to a recent report by Security Week. The breach involved a ransomware attack where threat actors compromised the internal network and accessed files containing personal identifying information. This potentially includes names, dates of birth, and Social Security numbers for over 123,000 individuals. A forensic investigation completed on April 8 found no evidence of misuse of the compromised data. It is unclear which ransomware group, if any, is responsible for the attack, as no known group has claimed responsibility.
Real estate services firm Cushman & Wakefield confirmed a data breach linked to a vishing (voice phishing) attack. Cybercrime groups ShinyHunters and Keelin both claimed responsibility for compromising the company. The firm activated incident response procedures, contained unauthorized activity, and engaged third-party cybersecurity experts to investigate.
Universiteit Maastricht was among the Dutch universities affected by the Instructure Canvas data breach by ShinyHunters. Student and staff data, including names, email addresses, student numbers, and messages, were compromised. The university took precautionary measures and communicated with its community about the ongoing situation, with the resolution of data deletion announced on May 12, 2026.
Fontys Hogescholen was among the Dutch educational institutions affected by the Instructure Canvas data breach by ShinyHunters. Student and staff data, including names, email addresses, student numbers, and messages, were compromised. The institution took precautionary measures and communicated with its community about the ongoing situation, with the resolution of data deletion announced on May 12, 2026.
Sysco, the world's largest food distributor, was targeted in a cyberattack by the Qilin ransomware group. Qilin claimed responsibility and listed the company on its dark web leak site, setting a May 12, 2026, deadline for undisclosed ransom negotiations. As proof of access, the ransomware group published screenshots of alleged internal documents and company data.
New York Life Insurance disclosed a data breach that exposed sensitive personal information belonging to its customers and individuals connected to its services. This incident increases the risk of identity theft, insurance fraud, phishing attacks, and the misuse of financial and personal records for affected individuals.
Foxconn confirmed a cyber attack on some of its North American factories. The Nitrogen ransomware group claimed responsibility, alleging they stole 8 terabytes of sensitive data, including schematics, project details, and customer documents linked to major technology clients such as Apple and NVIDIA. Foxconn stated that affected factories were resuming normal production after the incident.
Czech automaker Škoda Auto disclosed a data breach affecting its official online merchandise shop. Attackers exploited a vulnerability in the e-commerce platform's software, gaining unauthorized access to customer data. Exposed information includes names, postal addresses, email addresses, phone numbers, order details, and hashed passwords. No credit card or direct payment data was compromised as these are handled by third-party providers. The company took the shop offline, patched the vulnerability, and notified relevant authorities.
On May 8, 2026, Zara, a brand of the Spanish fashion giant Inditex, confirmed a data breach that exposed personal information of approximately 197,000 customers. The incident was attributed to the ShinyHunters extortion group, which exploited compromised authentication tokens of a former third-party analytics provider, Anodot, to access customer data. Exposed data included email addresses, geographic locations, purchase history, and support tickets, though Inditex stated that names, passwords, addresses, and payment information were not compromised.
DFI AMERICA, LLC, a U.S.-based company operating in the financial services industry, was affected by a ransomware attack by the Titan group, with an estimated attack date of May 8, 2026. Data stolen included MSSQL-DB, HR Documents, and Contracts.
On May 8, 2026, the RansomHouse ransomware group publicly claimed responsibility for a cyberattack against Trellix, a leading U.S. cybersecurity company. Trellix had previously confirmed unauthorized access to a portion of its internal source code repository around May 2, 2026. RansomHouse threatened to release sensitive data unless negotiations were initiated, and reportedly published screenshots showing access to internal Trellix services.
ViaQuest Psychiatric & Behavioral Solutions, an Ohio-based provider of behavioral and mental health services, disclosed a data breach to the U.S. Department of Health and Human Services (HHS) on May 8, 2026. The cybersecurity incident affected at least 6,420 individuals, compromising both personally identifiable information (PII) and protected health information (PHI). The types of information exposed include names, Social Security Numbers, dates of birth, addresses, government IDs, and medical information. The breach was classified as a hacking/network server incident.
Explore the intelligence
Compare incidents across industries and critical services.
Explore all sectors →Follow recurring intrusion methods and adversary behaviour.
Explore all attack patterns →Track consequences such as disruption and data exposure.
Explore all impacts →Compare reports by explicitly affected country.
Explore all countries →Explore the intelligence
Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.
12 answers across 4 topics
How to read and use the current intelligence overview.
It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.
Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.
No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.