Skip to main content

Current cyber intelligence

Cybersecurity News: Latest Incidents & Threat Intelligence

Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.

109

Reports in 90 days

in the current rolling intelligence window

9

Active topics

represented in the same 90-day window

48

High priority

high or critical reports in 90 days

Latest reporting

Latest cybersecurity incidents

Showing 1936 of 109 reports published in the last 90 days.

Srbancorp logo
High

SR Bancorp Discloses Data Security Incident at Internal Audit Provider Mercadien, Exposing Somerset Regal Bank Customer Data

SR Bancorp, Inc. reported a data security incident on July 10, 2026, involving its internal audit service provider, Mercadien, P.C. CPAs. An unauthorized actor accessed and acquired files from Mercadien's servers that contained sensitive customer data belonging to Somerset Regal Bank. The compromised information included customer names, Social Security numbers, account numbers, identification documents, and dates of birth. Importantly, SR Bancorp confirmed that the bank's own business systems, payment systems, customer access to accounts, and core information technology infrastructure were not directly impacted or disrupted by this incident. The company is coordinating customer notifications through Mercadien as required by applicable federal and state laws and regulatory guidance. While the incident exposes SR Bancorp to regulatory notification requirements, reputational risk, and potential legal liability, the company has initially assessed the financial impact as immaterial to its consolidated financial condition or results of operations. However, this assessment could change if the data is published or misused, or if further cybersecurity incidents occur. This event highlights the inherent risks associated with third-party vendors handling sensitive customer information.

Srbancorp
Mercadien logo
High

SR Bancorp's Internal Audit Provider, Mercadien, Experiences Data Security Incident

Mercadien, P.C. CPAs, an internal audit service provider for SR Bancorp and Somerset Regal Bank, reported a data security incident on July 10, 2026. An unauthorized actor accessed and acquired files from Mercadien's servers containing sensitive customer data belonging to Somerset Regal Bank. The compromised data included customer names, Social Security numbers, account numbers, identification documents, and dates of birth. Importantly, SR Bancorp confirmed that its own business systems, payment systems, customer access to accounts, and core information technology infrastructure were not affected by the incident. The bank is coordinating with Mercadien to provide notifications to affected customers as required by federal and state laws and regulatory guidance. While the incident exposes customers to potential identity theft and fraud, SR Bancorp currently assesses the financial impact as immaterial to its consolidated financial condition or results of operations. This incident highlights the significant risks associated with third-party vendors handling sensitive customer information.

Mercadien
Anthropic logoMisconfiguration or publishing error
High

Internal Documents Suggest Anthropic Seeks 1.4 GW Data Center Capacity in Australia

Leaked internal documents, reportedly shared by 'Serenity on X,' indicate that Anthropic plans to secure approximately 1.4 GW of data center power capacity in Australia, representing an estimated $21.6 billion investment. This leak reveals sensitive internal business strategies and infrastructure expansion plans.

Anthropic
Tata logoRansomware
High

Tata Electronics Data Leak Exposes Apple iPhone 18 Pro Details

India probes Tata Electronics breach exposing iPhone secrets India is investigating a data breach at Tata Electronics that reportedly exposed confidential information linked to Apple’s unreleased iPhone 18 Pro, the country’s IT secretary said on Thursday (July 3), marking the government’s first public response to the incident. Sensitive documents, including component lists, supplier details and images of the iPhone 18 Pro, were allegedly posted on the dark web by a ransomware group that targeted Tata Electronics, an Apple supplier in India, Reuters reported. “We are investigating,” said S. Krishnan, secretary at the Ministry of Electronics and Information Technology, adding that the case has been referred to India’s Computer Emergency Response Team, the national cybersecurity agency. The breach raises concerns over Apple’s tightly controlled global supply chain, where production of iPhones relies on multiple international suppliers. Apple is expected to launch the iPhone 18 Pro and Pro Max in September. The leaked files are said to include at least six documents revealing supplier assignments for specific components—information Apple does not publicly disclose. Tata Electronics has reportedly hired a global consultancy firm to carry out a forensic audit following the leak, which also allegedly involved documents related to Tesla, Qualcomm and TSMC being published on the dark web, according to Reuters. (Newswire)

Tata
Sla logoRansomware
High

Singapore Land Authority Data Breach Exposes 70,000 Records via IBM Testing Environment

Singapore Land Authority data breach exposes 70,000 records after IBM testing environment compromised SINGAPORE, July 3 — Personal data belonging to about 70,000 individuals has been compromised in a cybersecurity incident involving the Singapore Land Authority (SLA) and a cloud environment managed by IBM. SLA said the breach stemmed from unauthorised access to a dataset created for vendor development and systems integration testing, CNA reported. IBM oversees the testing environment for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS), which are used to submit property transfer and caveat documents. Preliminary checks showed the dataset, first created in 1998 and updated periodically, was intended to contain only mock and anonymised records. It was later discovered to include real information such as names, NRIC numbers and past property addresses of around 70,000 people. SLA stressed that the affected environment is separate from its live operational systems, adding that property ownership and lodgment records in STARS and ELS remain secure. IBM has revoked access to the compromised system to prevent further unauthorised entry. As a precaution, SLA has begun notifying affected individuals and advising them on assistance measures. The authority said it is working with IBM, the Government Technology Agency of Singapore and the Cyber Security Agency of Singapore to investigate the incident and implement remedial steps. According to CNA, a police report has been lodged and the Personal Data Protection Commission has been notified. SLA has not yet disclosed when the breach occurred or how many affected individuals have been contacted. Singapore’s first dedicated hospital for native wildlife opens at Mandai Singapore bookie aged 69 jailed for illegal betting on Hong Kong horse races Fatal dispute between Singapore Redhill flat neighbours leads to murder charge PDRM prepares security operations for Negeri Sembilan state election Defence weighs AGC appeal for driver in fatal Klang crash Amirudin: Pakatan banks on micro-campaign strategy to win over Negeri Sembilan voters ÑеÑгей ÑаÑанÑÑа - stock.adobe.com The Singapore Land Authority (SLA) has revealed that the personal information of about 70,000 individuals was exposed following unauthorised access to a cloud environment managed by IBM, its technology supplier. IBM was appointed to support and maintain SLA’s Singapore Titles Automated Registration System (Stars) and eLodgment System (ELS), which underpin property title registration and the lodgement of property documents in the city-state. As part of that work, the supplier managed the development and systems integration testing environment for the two systems. In a statement on 3 July 2026, SLA said it had been informed by IBM of the incident, with preliminary investigations indicating that a dataset created solely for development and testing purposes had been accessed without authorisation. The dataset, created in 1998 and updated periodically over the years, was meant to contain only mock and anonymised testing data based on property ownership and lodgement records. However, SLA said it has since uncovered that the dataset also contained the names, National Registration Identity Card (NRIC) numbers and property addresses of the affected individuals at the time. “This information should have been anonymised but was not,” the agency said, adding that investigations are ongoing to determine how this occurred. SLA noted that the affected environment is “distinct and separate” from its operational systems, with no connection to, or compromise of, the live systems that run Stars, ELS or any other SLA systems. Property ownership and lodgement records remain secure and unaffected, it added. IBM has revoked access associated with the affected environment to prevent further unauthorised access, while SLA has identified the individuals whose information was contained in the dataset, and has begun notifying them and advising them on how to seek further information and assistance. Singapore mobilised over 100 cyber defenders to neutralise a sophisticated APT actor which infiltrated Singtel, StarHub, M1 and Simba networks in the country’s  largest coordinated cyber incident response to date . Japan’s Nikkei has confirmed a major data breach that potentially  exposed the personal information of more than 17,000 employees  and business partners after hackers infiltrated its internal Slack messaging platform. Australian privacy commissioner warns that the  human factor is a growing threat  as notifications caused by staff mistakes rose significantly even as total breaches declined 10% from a record high. Philippine bank  BDO is shoring up its cyber security capabilities  to protect its data and systems as it moves more services to the cloud and expands its physical presence into remote areas of the archipelago. The agency is working with IBM, the Government Technology Agency and the Cyber Security Agency of Singapore (CSA) to establish the full facts and ensure remedial measures are taken. It has also lodged a police report and notified the Personal Data Protection Commission, and urged the public to remain vigilant against phishing emails, websites, text messages and phone calls from parties claiming to represent government agencies or other organisations. “We apologise for the concern and inconvenience this incident may cause,” the SLA said. The incident underscores the long-standing risk of real personal data finding its way into development and test environments , which are typically less closely guarded than production systems – a risk that is compounded when those environments are operated by third parties. It is also the latest in a series of supply chain security incidents in Singapore in recent years. In April 2025, Toppan Next Tech, a printing supplier for DBS Bank and the Singapore branch of Bank of China, was hit by a ransomware attack that saw customer data stolen by the threat actor . Some 8,200 DBS customers – mostly holders of DBS Vickers trading accounts and Cashline loans – and around 3,000 Bank of China customers were potentially affected. A year earlier, in August 2024, a hacker who gained unauthorised access to Mobile Guardian , a mobile device management platform then deployed across Singapore’s schools, remotely wiped the iPads and Chromebooks of about 13,000 students from 26 secondary schools. The Ministry of Education subsequently removed the software from all student devices and terminated its contract with the supplier.

Sla
Fortinet logoRansomware
High

FortiBleed gekoppeld aan ransomwaregroepen INC en Lynx

The 'FortiBleed' cyber campaign, which previously exposed login credentials for thousands of Fortinet firewalls, has now been linked to the ransomware groups INC and Lynx. Forensic investigations revealed evidence on a Windows server used in the attack infrastructure, showing administrators had access to negotiation portals of both ransomware groups. This suggests a strong connection between the credential theft and subsequent extortion campaigns. Researchers estimate that over 430,000 FortiGate firewalls worldwide were targeted, with sniffers installed on approximately 19,000 systems to intercept network traffic.

Fortinet
Xsolis logoPhishing
High

Xsolis Data Breach Exposes 1.4 Million Patient Records Across Eight Health Systems

A targeted phishing attack on healthcare AI company Xsolis has exposed the data of at least 1.4 million patients across eight U.S. health systems. Xsolis develops utilization management and care coordination technology widely used by hospitals and health systems. This breach now ranks among the most significant healthcare vendor cyberattacks of 2026. The U.S. Department of Health and Human Services (HHS) confirmed the patient impact figure on June 22, after Xsolis filed its breach report on June 5. Moreover, legal action over the incident has already been filed in at least one case, signaling growing accountability pressure on AI vendors handling sensitive patient data. The breach did not begin with the disclosure. Instead, the unauthorized access occurred months earlier. On January 20, 2026, an unidentified actor accessed portions of Xsolis’s IT environment. The attacker then acquired a limited number of files from within the system. Xsolis did not report the incident to HHS until June 5 — roughly four and a half months after the initial intrusion. This delay has drawn scrutiny. Furthermore, Hendrick Health in Abilene, Texas, faced a separate lawsuit specifically citing delayed patient notification as a key concern. Xsolis has stated the company is not currently aware of any misuse of the stolen data. However, the company has declined to specify which types of patient information were exposed. A spokesperson confirmed Xsolis is notifying affected individuals but is not commenting beyond its June 5 public statement. The following health systems have confirmed involvement in the Xsolis data breach : Rochester Regional Health — Rochester, N.Y. Together, these eight organizations collectively serve patients across six states. Consequently, the breach spans a wide geographic footprint — from the Pacific Northwest to the Southeast and Midwest. Xsolis took several steps after discovering the breach . First, the company reported the incident to HHS on June 5. Next, it began notifying affected patients directly. Additionally, Xsolis released a formal public statement through PR Newswire acknowledging the security incident. However, critics note that the five-month gap between the January intrusion and the June disclosure raises serious questions. Under HIPAA, covered entities and business associates generally must report breaches within 60 days of discovery. Health systems and regulators are now examining whether this timeline met legal standards. Why This Breach Matters for Healthcare AI This incident highlights a critical vulnerability in modern healthcare operations. Health systems increasingly rely on third-party AI vendors for functions like utilization management and care coordination. As a result, these vendors hold highly sensitive patient records — making them attractive targets for cybercriminals. Phishing attacks remain the leading method hackers use to gain unauthorized access. Notably, a single successful phishing email at a vendor like Xsolis can cascade into a breach affecting millions of patients at multiple health systems simultaneously. Third-Party Risk in Healthcare Is Growing Third-party vendor breaches now account for a rising share of healthcare data incidents. Therefore, health systems that outsource clinical and operational functions to AI companies must treat vendor cybersecurity as a direct extension of their own risk management. Regulators, including HHS’s Office for Civil Rights, actively scrutinize business associate agreements (BAAs) and breach timelines. Health systems found to lack adequate vendor oversight face fines and reputational harm alongside their vendors. Health system leaders should act quickly when a vendor breach occurs. First, they must verify whether their organization was part of the affected vendor’s client base. Next, they should request a full incident report from the vendor, including the timeline and scope of data access. Additionally, health systems must assess their own HIPAA obligations independently. Even when a vendor like Xsolis handles patient notifications, the covered health system retains compliance responsibility. Going forward, health systems should strengthen third-party risk programs. Key actions include conducting annual security assessments of all AI and health IT vendors, requiring vendors to carry cyber liability insurance, and including clear breach notification timelines in every BAA. Furthermore, phishing awareness training must extend beyond a health system’s own staff. Health systems should require vendors to demonstrate regular employee security training as a contract condition. Ultimately, a vendor’s security posture directly affects every patient record that vendor touches. Vendor breaches, regulatory shifts, and the governance gaps in between. Here's what happened this month in third-party risk management news. Financial institutions are legally accountable for what their vendors do with customer data. Outsourcing a function doesn't outsource the liability that comes with it — a principle that runs through GLBA Safeguards Rule requirements, state privacy laws, and open banking obligations under Part 1033. Vendor contracts need to do more than check a compliance box: they should specify permitted data uses, require breach notification within 24–48 hours, include audit rights, and address AI governance for any vendor using automated decision-making. Fourth-party risk also warrants explicit contract language requiring vendors to disclose and flow down obligations to their own subcontractors. A phishing attack on a healthcare AI vendor exposed 1.4 million patient records. Xsolis, which provides AI-powered utilization management to hospitals and health insurers, was breached through a single phishing email, exposing Social Security numbers, health insurance details, and medical treatment records across seven major hospital systems including Mayo Clinic. At least one organization — Rochester Regional Health — had ended its relationship with Xsolis in 2021, yet its patient data was still in scope at the time of the breach. Most of the 1.4 million affected had no idea the vendor held their information at all. Third-party vendor incidents now account for 58% of all healthcare data breaches, and this case is a concrete reminder that data deletion at offboarding is a risk control, not an administrative afterthought. The Klue breach reached LastPass customer data. Attackers used OAuth tokens stolen from Klue to access LastPass's Salesforce environment, exposing customer names, contact details, and support case records. Password vaults were unaffected, but the stolen data is enough to fuel targeted phishing. Fourth-party risk in practice: a vendor relationship several steps removed still produced direct customer harm. How to Avoid Common Third-Party Risk Management Mistakes

Xsolis
Aivd logoUse of stolen credentials or exploit
High

CTIVD: AIVD en MIVD verwerken persoonsgegevens in bulkdata onrechtmatig

The Dutch intelligence services, AIVD and MIVD, have unlawfully processed personal data in bulk datasets, according to a ruling by the Committee for the Supervision of the Intelligence and Security Services (CTIVD). The report, published on July 1, 2026, states that groups of employees had unauthorized access to personal data, and large quantities of data were stored for too long. The bulk datasets, sometimes containing millions of records, include names, phone numbers, location data, social media data, and communication content, sourced from government agencies, commercially available datasets, or stolen datasets offered by criminals. The CTIVD has issued thirteen recommendations to improve the situation.

Aivd
Aflac logoUse of stolen credentials or exploit
Medium

Aflac Life Insurance Japan Suffers Cybersecurity Breach Exposing Policyholder Data

Aflac Life Insurance Japan disclosed unauthorized access to its systems between June 15 and June 25, 2026. The breach affected files containing policy details, personal information, and bank account information of approximately 4.38 million customers. The company has suspended affected systems and is investigating the incident with third-party cybersecurity experts.

Aflac
Naic logoUse of stolen credentials or exploit
Medium

National Association of Insurance Commissioners (NAIC) Confirms Data Breach via Oracle PeopleSoft Zero-Day

The National Association of Insurance Commissioners (NAIC), a US insurance regulatory standards body, confirmed a cyberattack after the ShinyHunters group claimed theft of 3.1TB of data. The breach was reportedly achieved through an Oracle PeopleSoft zero-day vulnerability. ShinyHunters claimed access to regulatory filings, production logs, cloud configuration files, and other internal records.

Naic
Polymarket logo
Medium

Polymarket Confirms Supply Chain Attack, $3 Million Stolen

Polymarket, a cryptocurrency-based prediction market, confirmed a supply chain attack. A breach of a third-party frontend vendor led to malicious JavaScript being injected into its website. Attackers tricked users into approving fraudulent transactions, resulting in approximately $3 million being stolen from fewer than 15 accounts. The backend systems remained unaffected.

Polymarket
Kddi Web logoUse of stolen credentials or exploit
Medium

KDDI Web Communications Customer Data Affected by KDDI Email System Breach

KDDI Web Communications, a subsidiary of KDDI, was impacted by the data breach in KDDI Corporation's email system, disclosed on June 28, 2026. The incident, caused by a third-party software vulnerability, led to the potential exposure of up to 14.2 million email addresses and passwords belonging to customers across six Japanese ISPs, including KDDI Web Communications.

Kddi Web
Biglobe logoUse of stolen credentials or exploit
Medium

BIGLOBE Inc. Affected by KDDI Corporation Data Breach

BIGLOBE Inc., a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. BIGLOBE Inc. customers' email addresses and passwords may have been compromised.

Biglobe
Ctc logoUse of stolen credentials or exploit
Medium

Chubu Telecommunications C., Inc. Affected by KDDI Corporation Data Breach

Chubu Telecommunications C., Inc., a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. Chubu Telecommunications customers' email addresses and passwords may have been compromised.

Ctc
Jcom logoUse of stolen credentials or exploit
Medium

JCOM Co., Ltd. Affected by KDDI Corporation Data Breach

Data breach exposes up to 14.2 million email logins at six ISPs Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. The company says that it discovered the compromise on June 17 and responded immediately by blocking the attacker and implementing defense measures. The investigation determined that the hackers exploited a vulnerability in an unnamed third-party software that KDDI Corporation used on its system. “Although technical defensive measures have already been implemented for the system, there remains a possibility that customers' email addresses and passwords were obtained by unauthorized third parties as a result of the incident,” KDDI warns . KDDI is one of Japan’s largest ISPs, with 45,000 employees and an annual revenue of $32.4 billion. It is a public entity that has operated since 2000, following the merger of IDO, DDI, and KDD, Japan's former state-monopoly international telecommunications provider. The company says that the incident impacted the following five ISP operators and their email services: Although the investigation into the incident is still underway and the exact number of impacted accounts has yet to be determined, KDDI said it may have exposed the email addresses and passwords of up to 14,22 million customers. This figure includes current and former customers, as well as inactive accounts that may no longer be in use. Another mitigating factor, according to KDDI, is that some passwords were stored in hashed and/or encrypted form, meaning that they cannot be readily abused for account hijacks even if exposed. However, KDDI did not specify what type of encryption was used or what percentage of accounts had passwords stored in plaintext. KDDI says it has been contacting affected ISPs since June 17 and has also notified Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications. The company is currently working with affected ISPs to implement additional security measures to mitigate the risks arising from this exposure. Meanwhile, customers who may have been exposed are advised to reset their email account passwords as soon as possible. If two-factor authentication (2FA) is available, it would be prudent to set it up as well for additional protection. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Telco giant KDDI says data breach affects over 12 million people Insurance giant Aflac discloses data breach after subsidiary hack Japanese energy firm loses drive with data of 10.9 million clients Chick-fil-A discloses data breach after credential stuffing attacks Estée Lauder discloses data breach via Oracle E-Business flaw

Jcom
Eogb logoRansomware
Medium

eogb.co.uk Hit by Stormous Ransomware Group

eogb.co.uk, a UK-based organization, was claimed as a victim by the Stormous ransomware group. The incident was discovered on June 28, 2026, at 21:29 UTC, with deep access to Microsoft Dynamics GP, internal legal documents, partnership agreements, customer contracts, operational spreadsheets, financial reports, and executive documents.

Eogb
Stnet logoUse of stolen credentials or exploit
Medium

STNet, Inc. Affected by KDDI Corporation Data Breach

STNet, Inc., a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. STNet customers' email addresses and passwords may have been compromised.

Stnet

Explore the intelligence

Explore current intelligence taxonomies

Explore the intelligence

Questions about current cybersecurity intelligence

Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.

12 answers across 4 topics

How to read and use the current intelligence overview.

What does this cybersecurity intelligence overview contain?

It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.

Where should I start exploring?

Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.

Does this page list every cybersecurity incident?

No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.

Browse current topics