240
Reports in 90 days
in the current rolling intelligence window
Current cyber intelligence
Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.
240
in the current rolling intelligence window
10
represented in the same 90-day window
77
high or critical reports in 90 days
Latest reporting
Showing 19–36 of 240 reports published in the last 90 days.
A widespread security incident affecting Canvas, a learning management system by Instructure, impacted thousands of institutions, including Rutgers University, which utilizes the Qualtrics survey tool. Instructure notified Rutgers that while there was no indication of passwords, dates of birth, government identifiers, or financial information being involved, the specific Rutgers data compromised remains unclear. Instructure reportedly reached an agreement with the unauthorized threat actor, and the stolen data was returned and destroyed. Canvas remained operational throughout the incident.
Glendale Community College (GCC) is actively investigating a cybersecurity incident that occurred on June 16, 2026. The college is working with third-party specialists to address the incident and provide updates to the public. This ongoing disclosure was prominently featured on the college's website on July 14, 2026.
Lidl informed its webshop customers in the Netherlands about a security incident at an external IT service provider. Hackers briefly gained unauthorized access to a separately stored file containing customer data, resulting in the theft of personal information.
A new macOS information stealer, identified as 'CrashStealer,' was reported on July 13, 2026. This malware is designed to harvest sensitive data from compromised macOS systems, specifically targeting credentials from 14 password managers, including NordPass, alongside browser data, cryptocurrency wallet extensions, and keychain material. The malware utilizes a signed and Apple-notarized dropper to bypass Gatekeeper checks, and exfiltrates the collected data to an attacker-controlled server. While NordPass's own systems were not breached, user data stored in NordPass could be compromised if a user's macOS device is infected with CrashStealer.
Lidl, the popular retail chain, announced on July 11, 2026, that it experienced a security incident involving an external IT service provider, resulting in the theft of customer data from its online shop. Unidentified attackers gained temporary access to a separate file containing customer information. The compromised data includes customers' titles, first and last names, phone numbers, email addresses, dates of birth, and customer numbers. Lidl has confirmed that passwords, billing and delivery addresses, bank details, or other payment information were not affected, and customer accounts remain secure. The company has stated that there is currently no concrete evidence of the stolen data being misused, but it has proactively warned affected customers about potential phishing attempts and identity theft. Lidl advises customers to be extra cautious with communications from unknown sources. The IT service provider involved has taken immediate steps to restore security, strengthen system protection, and has filed a criminal complaint. IT experts are also involved in the investigation to enhance future data protection. The Office for Personal Data Protection has been informed and is monitoring the case.
A data leak at the AI music generator Suno, which occurred in November 2025, became public in July 2026. The breach exposed data from over 55 million unique email addresses and, for users who registered with their phone numbers, those numbers as well. A small portion of the dataset also included payment processor Stripe data, leading to the leak of names, physical addresses, purchase amounts, and certain credit card details (card type, expiration date, and last four digits) for tens of thousands of users. Suno confirmed it does not have access to full credit card numbers via Stripe.
Lidl Czech Republic announced a security incident on July 10, 2026, affecting its e-shop customers. Attackers gained access to a separately stored file containing customer data from an IT service provider. The compromised data includes customers' salutations, first and last names, phone numbers, email addresses, dates of birth, and customer numbers. Lidl confirmed that passwords, billing and delivery addresses, bank details, or other payment information were not affected, and customer accounts were not compromised. The company stated that it currently has no concrete evidence of data misuse but has proactively warned affected customers about potential phishing attempts or identity theft. The IT service provider involved has taken measures to restore system security, filed a criminal complaint, and engaged IT experts for the investigation. The Office for Personal Data Protection was also informed of the incident. Lidl began notifying affected customers via email after discovering the incident earlier in the week.
Accenture, a global professional services company, confirmed a security incident in July 2026 after a threat actor, identified as "888," claimed to have stolen approximately 35 GB of data from the company. The stolen data reportedly includes source code, RSA keys, SSH keys, Azure personal access tokens (PATs), Azure Storage access keys, and configuration files. The threat actor advertised the data for sale on a cybercrime forum and provided a screenshot as proof of exfiltration from a private Azure DevOps repository associated with accenture.com. Accenture stated that it is aware of the "isolated matter" and has remediated its source, asserting that there was no impact on Accenture's operations and service delivery. This incident follows previous security challenges for Accenture, including a 2017 exposure of sensitive data on unsecured AWS S3 buckets and a LockBit ransomware attack in 2021.
U.S. insurance provider AssuranceAmerica confirmed a data breach affecting the personal information and driver's license numbers of 6.9 million people. The company discovered hackers in its computer systems on March 17, 2026, and concluded its investigation on June 15, 2026, with notification letters scheduled to be sent out on July 10, 2026.
SR Bancorp, Inc. reported a data security incident on July 10, 2026, involving its internal audit service provider, Mercadien, P.C. CPAs. An unauthorized actor accessed and acquired files from Mercadien's servers that contained sensitive customer data belonging to Somerset Regal Bank. The compromised information included customer names, Social Security numbers, account numbers, identification documents, and dates of birth. Importantly, SR Bancorp confirmed that the bank's own business systems, payment systems, customer access to accounts, and core information technology infrastructure were not directly impacted or disrupted by this incident. The company is coordinating customer notifications through Mercadien as required by applicable federal and state laws and regulatory guidance. While the incident exposes SR Bancorp to regulatory notification requirements, reputational risk, and potential legal liability, the company has initially assessed the financial impact as immaterial to its consolidated financial condition or results of operations. However, this assessment could change if the data is published or misused, or if further cybersecurity incidents occur. This event highlights the inherent risks associated with third-party vendors handling sensitive customer information.
Mercadien, P.C. CPAs, an internal audit service provider for SR Bancorp and Somerset Regal Bank, reported a data security incident on July 10, 2026. An unauthorized actor accessed and acquired files from Mercadien's servers containing sensitive customer data belonging to Somerset Regal Bank. The compromised data included customer names, Social Security numbers, account numbers, identification documents, and dates of birth. Importantly, SR Bancorp confirmed that its own business systems, payment systems, customer access to accounts, and core information technology infrastructure were not affected by the incident. The bank is coordinating with Mercadien to provide notifications to affected customers as required by federal and state laws and regulatory guidance. While the incident exposes customers to potential identity theft and fraud, SR Bancorp currently assesses the financial impact as immaterial to its consolidated financial condition or results of operations. This incident highlights the significant risks associated with third-party vendors handling sensitive customer information.
Leaked internal documents, reportedly shared by 'Serenity on X,' indicate that Anthropic plans to secure approximately 1.4 GW of data center power capacity in Australia, representing an estimated $21.6 billion investment. This leak reveals sensitive internal business strategies and infrastructure expansion plans.
India probes Tata Electronics breach exposing iPhone secrets India is investigating a data breach at Tata Electronics that reportedly exposed confidential information linked to Apple’s unreleased iPhone 18 Pro, the country’s IT secretary said on Thursday (July 3), marking the government’s first public response to the incident. Sensitive documents, including component lists, supplier details and images of the iPhone 18 Pro, were allegedly posted on the dark web by a ransomware group that targeted Tata Electronics, an Apple supplier in India, Reuters reported. “We are investigating,” said S. Krishnan, secretary at the Ministry of Electronics and Information Technology, adding that the case has been referred to India’s Computer Emergency Response Team, the national cybersecurity agency. The breach raises concerns over Apple’s tightly controlled global supply chain, where production of iPhones relies on multiple international suppliers. Apple is expected to launch the iPhone 18 Pro and Pro Max in September. The leaked files are said to include at least six documents revealing supplier assignments for specific components—information Apple does not publicly disclose. Tata Electronics has reportedly hired a global consultancy firm to carry out a forensic audit following the leak, which also allegedly involved documents related to Tesla, Qualcomm and TSMC being published on the dark web, according to Reuters. (Newswire)
Singapore Land Authority data breach exposes 70,000 records after IBM testing environment compromised SINGAPORE, July 3 — Personal data belonging to about 70,000 individuals has been compromised in a cybersecurity incident involving the Singapore Land Authority (SLA) and a cloud environment managed by IBM. SLA said the breach stemmed from unauthorised access to a dataset created for vendor development and systems integration testing, CNA reported. IBM oversees the testing environment for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS), which are used to submit property transfer and caveat documents. Preliminary checks showed the dataset, first created in 1998 and updated periodically, was intended to contain only mock and anonymised records. It was later discovered to include real information such as names, NRIC numbers and past property addresses of around 70,000 people. SLA stressed that the affected environment is separate from its live operational systems, adding that property ownership and lodgment records in STARS and ELS remain secure. IBM has revoked access to the compromised system to prevent further unauthorised entry. As a precaution, SLA has begun notifying affected individuals and advising them on assistance measures. The authority said it is working with IBM, the Government Technology Agency of Singapore and the Cyber Security Agency of Singapore to investigate the incident and implement remedial steps. According to CNA, a police report has been lodged and the Personal Data Protection Commission has been notified. SLA has not yet disclosed when the breach occurred or how many affected individuals have been contacted. Singapore’s first dedicated hospital for native wildlife opens at Mandai Singapore bookie aged 69 jailed for illegal betting on Hong Kong horse races Fatal dispute between Singapore Redhill flat neighbours leads to murder charge PDRM prepares security operations for Negeri Sembilan state election Defence weighs AGC appeal for driver in fatal Klang crash Amirudin: Pakatan banks on micro-campaign strategy to win over Negeri Sembilan voters ÑеÑгей ÑаÑанÑÑа - stock.adobe.com The Singapore Land Authority (SLA) has revealed that the personal information of about 70,000 individuals was exposed following unauthorised access to a cloud environment managed by IBM, its technology supplier. IBM was appointed to support and maintain SLA’s Singapore Titles Automated Registration System (Stars) and eLodgment System (ELS), which underpin property title registration and the lodgement of property documents in the city-state. As part of that work, the supplier managed the development and systems integration testing environment for the two systems. In a statement on 3 July 2026, SLA said it had been informed by IBM of the incident, with preliminary investigations indicating that a dataset created solely for development and testing purposes had been accessed without authorisation. The dataset, created in 1998 and updated periodically over the years, was meant to contain only mock and anonymised testing data based on property ownership and lodgement records. However, SLA said it has since uncovered that the dataset also contained the names, National Registration Identity Card (NRIC) numbers and property addresses of the affected individuals at the time. “This information should have been anonymised but was not,” the agency said, adding that investigations are ongoing to determine how this occurred. SLA noted that the affected environment is “distinct and separate” from its operational systems, with no connection to, or compromise of, the live systems that run Stars, ELS or any other SLA systems. Property ownership and lodgement records remain secure and unaffected, it added. IBM has revoked access associated with the affected environment to prevent further unauthorised access, while SLA has identified the individuals whose information was contained in the dataset, and has begun notifying them and advising them on how to seek further information and assistance. Singapore mobilised over 100 cyber defenders to neutralise a sophisticated APT actor which infiltrated Singtel, StarHub, M1 and Simba networks in the country’s largest coordinated cyber incident response to date . Japan’s Nikkei has confirmed a major data breach that potentially exposed the personal information of more than 17,000 employees and business partners after hackers infiltrated its internal Slack messaging platform. Australian privacy commissioner warns that the human factor is a growing threat as notifications caused by staff mistakes rose significantly even as total breaches declined 10% from a record high. Philippine bank BDO is shoring up its cyber security capabilities to protect its data and systems as it moves more services to the cloud and expands its physical presence into remote areas of the archipelago. The agency is working with IBM, the Government Technology Agency and the Cyber Security Agency of Singapore (CSA) to establish the full facts and ensure remedial measures are taken. It has also lodged a police report and notified the Personal Data Protection Commission, and urged the public to remain vigilant against phishing emails, websites, text messages and phone calls from parties claiming to represent government agencies or other organisations. “We apologise for the concern and inconvenience this incident may cause,” the SLA said. The incident underscores the long-standing risk of real personal data finding its way into development and test environments , which are typically less closely guarded than production systems – a risk that is compounded when those environments are operated by third parties. It is also the latest in a series of supply chain security incidents in Singapore in recent years. In April 2025, Toppan Next Tech, a printing supplier for DBS Bank and the Singapore branch of Bank of China, was hit by a ransomware attack that saw customer data stolen by the threat actor . Some 8,200 DBS customers – mostly holders of DBS Vickers trading accounts and Cashline loans – and around 3,000 Bank of China customers were potentially affected. A year earlier, in August 2024, a hacker who gained unauthorised access to Mobile Guardian , a mobile device management platform then deployed across Singapore’s schools, remotely wiped the iPads and Chromebooks of about 13,000 students from 26 secondary schools. The Ministry of Education subsequently removed the software from all student devices and terminated its contract with the supplier.
The 'FortiBleed' cyber campaign, which previously exposed login credentials for thousands of Fortinet firewalls, has now been linked to the ransomware groups INC and Lynx. Forensic investigations revealed evidence on a Windows server used in the attack infrastructure, showing administrators had access to negotiation portals of both ransomware groups. This suggests a strong connection between the credential theft and subsequent extortion campaigns. Researchers estimate that over 430,000 FortiGate firewalls worldwide were targeted, with sniffers installed on approximately 19,000 systems to intercept network traffic.
A targeted phishing attack on healthcare AI company Xsolis has exposed the data of at least 1.4 million patients across eight U.S. health systems. Xsolis develops utilization management and care coordination technology widely used by hospitals and health systems. This breach now ranks among the most significant healthcare vendor cyberattacks of 2026. The U.S. Department of Health and Human Services (HHS) confirmed the patient impact figure on June 22, after Xsolis filed its breach report on June 5. Moreover, legal action over the incident has already been filed in at least one case, signaling growing accountability pressure on AI vendors handling sensitive patient data. The breach did not begin with the disclosure. Instead, the unauthorized access occurred months earlier. On January 20, 2026, an unidentified actor accessed portions of Xsolis’s IT environment. The attacker then acquired a limited number of files from within the system. Xsolis did not report the incident to HHS until June 5 — roughly four and a half months after the initial intrusion. This delay has drawn scrutiny. Furthermore, Hendrick Health in Abilene, Texas, faced a separate lawsuit specifically citing delayed patient notification as a key concern. Xsolis has stated the company is not currently aware of any misuse of the stolen data. However, the company has declined to specify which types of patient information were exposed. A spokesperson confirmed Xsolis is notifying affected individuals but is not commenting beyond its June 5 public statement. The following health systems have confirmed involvement in the Xsolis data breach : Rochester Regional Health — Rochester, N.Y. Together, these eight organizations collectively serve patients across six states. Consequently, the breach spans a wide geographic footprint — from the Pacific Northwest to the Southeast and Midwest. Xsolis took several steps after discovering the breach . First, the company reported the incident to HHS on June 5. Next, it began notifying affected patients directly. Additionally, Xsolis released a formal public statement through PR Newswire acknowledging the security incident. However, critics note that the five-month gap between the January intrusion and the June disclosure raises serious questions. Under HIPAA, covered entities and business associates generally must report breaches within 60 days of discovery. Health systems and regulators are now examining whether this timeline met legal standards. Why This Breach Matters for Healthcare AI This incident highlights a critical vulnerability in modern healthcare operations. Health systems increasingly rely on third-party AI vendors for functions like utilization management and care coordination. As a result, these vendors hold highly sensitive patient records — making them attractive targets for cybercriminals. Phishing attacks remain the leading method hackers use to gain unauthorized access. Notably, a single successful phishing email at a vendor like Xsolis can cascade into a breach affecting millions of patients at multiple health systems simultaneously. Third-Party Risk in Healthcare Is Growing Third-party vendor breaches now account for a rising share of healthcare data incidents. Therefore, health systems that outsource clinical and operational functions to AI companies must treat vendor cybersecurity as a direct extension of their own risk management. Regulators, including HHS’s Office for Civil Rights, actively scrutinize business associate agreements (BAAs) and breach timelines. Health systems found to lack adequate vendor oversight face fines and reputational harm alongside their vendors. Health system leaders should act quickly when a vendor breach occurs. First, they must verify whether their organization was part of the affected vendor’s client base. Next, they should request a full incident report from the vendor, including the timeline and scope of data access. Additionally, health systems must assess their own HIPAA obligations independently. Even when a vendor like Xsolis handles patient notifications, the covered health system retains compliance responsibility. Going forward, health systems should strengthen third-party risk programs. Key actions include conducting annual security assessments of all AI and health IT vendors, requiring vendors to carry cyber liability insurance, and including clear breach notification timelines in every BAA. Furthermore, phishing awareness training must extend beyond a health system’s own staff. Health systems should require vendors to demonstrate regular employee security training as a contract condition. Ultimately, a vendor’s security posture directly affects every patient record that vendor touches. Vendor breaches, regulatory shifts, and the governance gaps in between. Here's what happened this month in third-party risk management news. Financial institutions are legally accountable for what their vendors do with customer data. Outsourcing a function doesn't outsource the liability that comes with it — a principle that runs through GLBA Safeguards Rule requirements, state privacy laws, and open banking obligations under Part 1033. Vendor contracts need to do more than check a compliance box: they should specify permitted data uses, require breach notification within 24–48 hours, include audit rights, and address AI governance for any vendor using automated decision-making. Fourth-party risk also warrants explicit contract language requiring vendors to disclose and flow down obligations to their own subcontractors. A phishing attack on a healthcare AI vendor exposed 1.4 million patient records. Xsolis, which provides AI-powered utilization management to hospitals and health insurers, was breached through a single phishing email, exposing Social Security numbers, health insurance details, and medical treatment records across seven major hospital systems including Mayo Clinic. At least one organization — Rochester Regional Health — had ended its relationship with Xsolis in 2021, yet its patient data was still in scope at the time of the breach. Most of the 1.4 million affected had no idea the vendor held their information at all. Third-party vendor incidents now account for 58% of all healthcare data breaches, and this case is a concrete reminder that data deletion at offboarding is a risk control, not an administrative afterthought. The Klue breach reached LastPass customer data. Attackers used OAuth tokens stolen from Klue to access LastPass's Salesforce environment, exposing customer names, contact details, and support case records. Password vaults were unaffected, but the stolen data is enough to fuel targeted phishing. Fourth-party risk in practice: a vendor relationship several steps removed still produced direct customer harm. How to Avoid Common Third-Party Risk Management Mistakes
The Dutch intelligence services, AIVD and MIVD, have unlawfully processed personal data in bulk datasets, according to a ruling by the Committee for the Supervision of the Intelligence and Security Services (CTIVD). The report, published on July 1, 2026, states that groups of employees had unauthorized access to personal data, and large quantities of data were stored for too long. The bulk datasets, sometimes containing millions of records, include names, phone numbers, location data, social media data, and communication content, sourced from government agencies, commercially available datasets, or stolen datasets offered by criminals. The CTIVD has issued thirteen recommendations to improve the situation.
Aflac Life Insurance Japan disclosed unauthorized access to its systems between June 15 and June 25, 2026. The breach affected files containing policy details, personal information, and bank account information of approximately 4.38 million customers. The company has suspended affected systems and is investigating the incident with third-party cybersecurity experts.
Explore the intelligence
Compare incidents across industries and critical services.
Explore all sectors →Follow recurring intrusion methods and adversary behaviour.
Explore all attack patterns →Track consequences such as disruption and data exposure.
Explore all impacts →Compare reports by explicitly affected country.
Explore all countries →Explore the intelligence
Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.
12 answers across 4 topics
How to read and use the current intelligence overview.
It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.
Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.
No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.