Skip to main content

Current cyber intelligence

Cybersecurity News: Latest Incidents & Threat Intelligence

Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.

240

Reports in 90 days

in the current rolling intelligence window

10

Active topics

represented in the same 90-day window

77

High priority

high or critical reports in 90 days

Latest reporting

Latest cybersecurity incidents

Showing 3754 of 240 reports published in the last 90 days.

Naic logoUse of stolen credentials or exploit
Medium

National Association of Insurance Commissioners (NAIC) Confirms Data Breach via Oracle PeopleSoft Zero-Day

The National Association of Insurance Commissioners (NAIC), a US insurance regulatory standards body, confirmed a cyberattack after the ShinyHunters group claimed theft of 3.1TB of data. The breach was reportedly achieved through an Oracle PeopleSoft zero-day vulnerability. ShinyHunters claimed access to regulatory filings, production logs, cloud configuration files, and other internal records.

Naic
Polymarket logo
Medium

Polymarket Confirms Supply Chain Attack, $3 Million Stolen

Polymarket, a cryptocurrency-based prediction market, confirmed a supply chain attack. A breach of a third-party frontend vendor led to malicious JavaScript being injected into its website. Attackers tricked users into approving fraudulent transactions, resulting in approximately $3 million being stolen from fewer than 15 accounts. The backend systems remained unaffected.

Polymarket
Kddi Web logoUse of stolen credentials or exploit
Medium

KDDI Web Communications Customer Data Affected by KDDI Email System Breach

KDDI Web Communications, a subsidiary of KDDI, was impacted by the data breach in KDDI Corporation's email system, disclosed on June 28, 2026. The incident, caused by a third-party software vulnerability, led to the potential exposure of up to 14.2 million email addresses and passwords belonging to customers across six Japanese ISPs, including KDDI Web Communications.

Kddi Web
Biglobe logoUse of stolen credentials or exploit
Medium

BIGLOBE Inc. Affected by KDDI Corporation Data Breach

BIGLOBE Inc., a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. BIGLOBE Inc. customers' email addresses and passwords may have been compromised.

Biglobe
Ctc logoUse of stolen credentials or exploit
Medium

Chubu Telecommunications C., Inc. Affected by KDDI Corporation Data Breach

Chubu Telecommunications C., Inc., a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. Chubu Telecommunications customers' email addresses and passwords may have been compromised.

Ctc
Jcom logoUse of stolen credentials or exploit
Medium

JCOM Co., Ltd. Affected by KDDI Corporation Data Breach

Data breach exposes up to 14.2 million email logins at six ISPs Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. The company says that it discovered the compromise on June 17 and responded immediately by blocking the attacker and implementing defense measures. The investigation determined that the hackers exploited a vulnerability in an unnamed third-party software that KDDI Corporation used on its system. “Although technical defensive measures have already been implemented for the system, there remains a possibility that customers' email addresses and passwords were obtained by unauthorized third parties as a result of the incident,” KDDI warns . KDDI is one of Japan’s largest ISPs, with 45,000 employees and an annual revenue of $32.4 billion. It is a public entity that has operated since 2000, following the merger of IDO, DDI, and KDD, Japan's former state-monopoly international telecommunications provider. The company says that the incident impacted the following five ISP operators and their email services: Although the investigation into the incident is still underway and the exact number of impacted accounts has yet to be determined, KDDI said it may have exposed the email addresses and passwords of up to 14,22 million customers. This figure includes current and former customers, as well as inactive accounts that may no longer be in use. Another mitigating factor, according to KDDI, is that some passwords were stored in hashed and/or encrypted form, meaning that they cannot be readily abused for account hijacks even if exposed. However, KDDI did not specify what type of encryption was used or what percentage of accounts had passwords stored in plaintext. KDDI says it has been contacting affected ISPs since June 17 and has also notified Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications. The company is currently working with affected ISPs to implement additional security measures to mitigate the risks arising from this exposure. Meanwhile, customers who may have been exposed are advised to reset their email account passwords as soon as possible. If two-factor authentication (2FA) is available, it would be prudent to set it up as well for additional protection. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Telco giant KDDI says data breach affects over 12 million people Insurance giant Aflac discloses data breach after subsidiary hack Japanese energy firm loses drive with data of 10.9 million clients Chick-fil-A discloses data breach after credential stuffing attacks Estée Lauder discloses data breach via Oracle E-Business flaw

Jcom
Eogb logoRansomware
Medium

eogb.co.uk Hit by Stormous Ransomware Group

eogb.co.uk, a UK-based organization, was claimed as a victim by the Stormous ransomware group. The incident was discovered on June 28, 2026, at 21:29 UTC, with deep access to Microsoft Dynamics GP, internal legal documents, partnership agreements, customer contracts, operational spreadsheets, financial reports, and executive documents.

Eogb
Stnet logoUse of stolen credentials or exploit
Medium

STNet, Inc. Affected by KDDI Corporation Data Breach

STNet, Inc., a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. STNet customers' email addresses and passwords may have been compromised.

Stnet
Nifty logoUse of stolen credentials or exploit
Medium

NIFTY Corporation Affected by KDDI Corporation Data Breach

NIFTY Corporation, a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. NIFTY Corporation customers' email addresses and passwords may have been compromised.

Nifty
Dialog logoMisconfiguration or publishing error
Medium

Peter Thiel's Dialog Society Data Leak Exposes Senior US Officials

Pentagon Probes Data Leak at Peter Thiel's Dialog Exposing Senior US Officials The Pentagon is investigating a data exposure at Peter Thiel's secretive Dialog group after a misconfigured website unmasked senior U.S. intelligence officials and active-duty special operations personnel, raising operational security risks. The briefing room at the Pentagon in Virginia, January 8, 2020 - Reuters The Pentagon has launched an operations security examination into a major data exposure at Dialog, a secretive private events group co-founded by Peter Thiel. The breach compromised the personal information of multiple U.S. national security personnel. These include an active-duty intelligence officer embedded with a Tier 1 special operations unit and a senior National Security Council official advising President Donald Trump, according to WIRED. The exposure revealed private details of 222 registrants for the Dialog event. The database included current and former senior military and national security officials from the United States and allied nations. The active-duty military intelligence officer and the NSC official were registered as new participants. Both were invited to attend Dialog’s upcoming August retreat located outside Dublin, Ireland. The White House declined to comment on the exposure. Officials requested that the NSC official, a former CIA officer, remain unnamed on national security grounds. Dialog internally classified the incident as a cyberattack. However, evidence indicates the files were exposed due to a misconfiguration in the group’s website. Anyone could create an account with an email address to access the files. Users simply needed to load the group’s application landing page to view the dossiers. Outside counsel for Dialog issued a letter stating that the data was stolen and demanding its return. The organization did not respond to press inquiries regarding the incident. The discovery originated from a tip by Swiss cybersecurity researcher maia arson crimew. She was indicted by federal prosecutors in 2021 on hacking-related charges but has not been convicted. Exposed files contained dates of birth, home addresses, mobile numbers, headshot photos, and private authentication tokens. Some records also listed spouses and family members as emergency contacts. Dialog collected registrant questionnaires that prompted personal disclosures. The NSC official predicted that future espionage will target behavior more than secrets. Another former Pentagon technology office director warned of domestic terrorism targeting artificial intelligence datacenters. The individual also noted possessing one of Saddam Hussein’s gold-plated AK-47s. The database exposed more than 20 current and former military and intelligence officials. This included a retired U.S. general and a retired official who held a senior security role in Israel and the Palestinian territories. GOP Facing Severe Political Dilemma Over Trump's Iran War Soaring Costs in Iran War Burn Through Pentagon's Cash

Dialog
Lvm logoRansomware
Medium

Latvijas Valsts Mezi (LVM) Suffers Cybersecurity Breach

Cybersecurity breach reveals vulnerability of Latvia's strategic infrastructure: minister RIGA, June 26 (Xinhua) -- A recent incident in which hackers managed to access IT systems of Latvia's state-owned company Latvijas Valsts Mezi (LVM) revealed the relative vulnerability of the country's strategic infrastructure, Smart Administration and Regional Development Minister Edgars Tavars said Friday. The cybersecurity breach in LVM has caused particular concerns because the company has been entrusted with developing an electoral IT platform for Latvia's parliamentary elections, which are scheduled to take place this fall. In an interview with the TV3 channel on Friday, Tavars called on all state institutions to identify cybersecurity flaws in their own systems and learn a lession from the LVM incident. The minister believes, though, that in general, Latvian IT specialists are good enough to prevent similar incidents from repeating in the future. Tavars said that the electronic voter register, on which LVM has been working, was completed before the incident and was not at risk. In general, "we are definitely not ringing alarm bells about the elections," the minister said. LVM discovered the cybersecurity breach of its IT systems last weekend. In response, the company took all its external IT systems offline and also shut down some internal communication systems. A foreign ransomware group, which has carried out similar attacks against companies and government agencies in other countries, has claimed responsibility on the cyberattack on LVM. Cyberattack on Latvian State Forests detected LVM is one of three companies developing this year’s Saeima election system . However, the company noted that the development of the election system was kept separate and was not affected. Security measures will be reviewed as a precaution. The cyberattack occurred on Monday, June 22. According to the company, since the incident began, the external information technology (IT) systems maintained by LVM, including “LVM GEO,” the mapping service system, and the hunting app “Mednis”, have been shut down and are unavailable for security reasons. Several of LVM’s internal systems, which facilitate the company’s exchange of information with service providers and clients, have also been taken offline. LVM spokesperson Tomass Kotovičs stated that the threat has been eliminated, but it will take time to restore the systems to operation. Baiba Kaškina, head of “Cert.lv,” explained that the attack was thwarted immediately. According to her, there is no reason to believe that it was specifically targeted at Latvia. “Cert.lv” is inclined to believe that this was a commercially motivated attack aimed at demanding a ransom and demonstrating the attackers’ capabilities. The State Police Cybercrime Combating Directorate, based on publicly available information, has launched an internal investigation on its own initiative to clarify the circumstances of the incident and identify the possible perpetrator, according to the LETA news agency. Select text and press Ctrl+Enter to send a suggested correction to the editor Select text and press Report a mistake to send a suggested correction to the editor

Lvm
Xsolis logoRansomware
Medium

Healthcare AI Company Xsolis Suffers Data Breach Impacting 1.4 Million Individuals

Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information.  While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals.  The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519.  Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”. It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts.  Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolis’s hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.

Xsolis
Riskstrategies logo
Medium

Risk Strategies Discloses Data Breach Involving Personal and Medical Information

Risk Strategies Data Breach Exposes Social Security Numbers Risk Strategies , officially known as RSC Insurance Brokerage Inc., disclosed a data breach involving sensitive personal and medical information. Between January 15, 2026, and January 16, 2026, an unauthorized user gained access to the Microsoft 365 account of a Risk Strategies employee. An investigation of the affected files, which concluded on June 1, 2026, determined the files contained personal information belonging to individuals. The incident compromised names, Social Security numbers and medical records. Risk Strategies began mailing affected individuals notification letters concerning the incident on June 23, 2026. A total number of 15,055 individuals were affected nationwide including 76 Nebraska residents and 47 Massachusetts residents were impacted. Risk Strategies is offering affected individuals a complimentary 24-month membership to credit monitoring services provided by Epiq. The service, called Privacy Solutions ID 3B Credit Monitoring, can be activated at privacysolutionsid.com . Affected individuals received a unique activation code and enrollment deadline in their notification letter. Affected individuals with questions about the incident can call Risk Strategies at 866-659-7098, Monday through Friday, from 9:00 a.m. to 9:00 p.m. EST. For help with the Epiq enrollment process, individuals can call 866-675-2006, Monday through Friday, from 9:00 a.m. to 5:30 p.m. ET. SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION Affected information types not yet disclosed This browser does not support inline PDFs. Please download the PDF to view it: Download PDF Class actions settlements delivered to your inbox. SportsMed Physical Therapy Data Breach Exposes Health Information Trudeau Center Breach Affects 5,630 Individuals Alkegen Data Breach Exposes Personal and Protected Health Information Whitfield Hospital Breach Exposed Medical and Health Information Attorneys working with ClassAction.org are looking into whether a class action lawsuit can be filed in light of the Risk Strategies data breach. As part of their investigation, they need to hear from individuals who had their information exposed in the incident , including those who received notice of the Risk Strategies data breach or otherwise believe they are affected. Risk Strategies Security Incident: What Happened? RSC Insurance Brokerage, which operated as Risk Strategies before merging with Brown & Brown, has reported a data breach involving personal information. According to a sample notification letter (pictured below), names and Social Security numbers were involved. For some of those impacted by the Risk Strategies data breach, medical information and health, dental, and/or vision insurance information may have been compromised. A report detailing the cybersecurity incident was submitted to the Massachusetts Office of Consumer Affairs and Business Regulation on June 23, 2026. What You Can Do After the Risk Strategies Data Breach If your information was exposed in the Risk Strategies data breach, attorneys want to hear from you. You may be able to start a class action lawsuit to recover compensation for loss of privacy, time spent dealing with the breach, out-of-pocket costs, and more. A successful case could also force Risk Strategies to ensure they take proper steps to protect the information they were entrusted with. Affected by the Risk Strategies data breach? Fill out the form on this page today. If you believe your information was exposed in the Risk Strategies data breach, fill out the form on this page to get in touch with us. An attorney or legal representative may then reach out to you to explain more about this investigation and ask you a few questions. Remember, there is no cost to get in touch, and you are under no obligation to take action after speaking to someone. New cases and investigations, settlement deadlines, and news straight to your inbox. Whitfield Regional Hospital Data Breach 2026 Community Health Center of Buffalo Data Breach 2026 Advantage Home Health Care Data Breach 2026 Unlimited Technology Systems Data Breach 2026 Heart Care Centers of Illinois Data Breach 2026 Clover Health Investments Data Breach 2026 Morris Communications Company Data Breach 2026 Brown Health Medical Group-MA Data Breach 2026 Case & Associates Properties Data Breach 2026

Riskstrategies
Huntsvillehospital logo
Medium

Huntsville Hospital Health System Notifies Patients of Data Exposure from Cerner Breach

Huntsville Hospital Health System informed patients on June 26, 2026, about a data exposure stemming from a 2025 breach on Cerner's (now Oracle Health) legacy systems. The breach, which occurred on January 22, 2025, exposed personal and medical information. Cerner had notified its healthcare clients, including Huntsville Hospital, on August 12, 2025, but patient notification was delayed at the request of law enforcement.

Huntsvillehospital
Snyk logo
Medium

Snyk CRM Data Accessed in Klue OAuth Breach

Snyk, a developer security company, was among the confirmed victims of the Klue OAuth breach. The Icarus extortion group compromised Klue's infrastructure, a market intelligence platform, gaining access to CRM data of its customers, including Snyk. The attack, which occurred on June 11, 2026, exploited a compromised legacy credential at Klue.

Snyk
Ahisd logoRansomware
Medium

Alamo Heights ISD Reports Data Breach Following Ransomware Attack

Alamo Heights Independent School District (ISD) reported a data breach impacting over 26,000 people, disclosed to the Texas Attorney General's office on June 25, 2026 (published June 26, 2026 UTC). The breach was linked to a ransomware attack by the Qilin group, which occurred on April 9, 2026. The compromised information included names, Social Security numbers, driver's license numbers, and bank and medical information.

Ahisd
Trenitalia logoUse of stolen credentials or exploit
Medium

Trenitalia Suffers Cyberattack, Customer Data Compromised

Trenitalia, the Italian state-owned railway company, notified customers on June 26, 2026, about a cyberattack that led to unauthorized access of personal data related to travel tickets. The company detected the incident through internal checks and attributed it to 'unidentified external parties.' The attack itself reportedly occurred in November 2025. Compromised data included demographic and identification details, contact information, travel specifics, and loyalty card numbers, but no payment information or account credentials were affected.

Trenitalia
Insee logo
Medium

France's National Statistics Department (Insee) Reports Cyberattack on Staff Data

France's national statistics department, Insee, reported a cyberattack that exposed identity and professional contact data for approximately 12,800 current and former staff and related civil service personnel. The breach, detected on June 19, 2026, involved an internal staff directory (trombi.insee.fr). Insee stated that no sensitive information such as passwords, personal contact details, bank details, social security numbers, or health information was accessed. News of the incident was widely reported on June 26, 2026.

Insee

Explore the intelligence

Explore current intelligence taxonomies

Explore the intelligence

Questions about current cybersecurity intelligence

Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.

12 answers across 4 topics

How to read and use the current intelligence overview.

What does this cybersecurity intelligence overview contain?

It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.

Where should I start exploring?

Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.

Does this page list every cybersecurity incident?

No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.

Browse current topics