216
Reports in 90 days
in the current rolling intelligence window
Current cyber intelligence
Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.
216
in the current rolling intelligence window
10
represented in the same 90-day window
65
high or critical reports in 90 days
Latest reporting
Showing 55–72 of 216 reports published in the last 90 days.
ElParking, a mobility application part of Grupo Mutua Madrileña, experienced a data breach where an unauthorized access was detected on June 14, 2026. The incident, disclosed on June 23, 2026, exposed basic identification and contact data of users, including names, email addresses, phone numbers, vehicle license plates, and DNI (national ID). Passwords and payment data were reportedly not compromised. The incident was reported to the Spanish Data Protection Agency (AEPD).
Tower Administrative Services Inc., a Pennsylvania-based insurance administration company, disclosed a data breach involving unauthorized access to its corporate network. The breach, which occurred around February 3, 2026, exposed names, Social Security numbers, addresses, and financial account information. Notifications to affected individuals began on June 23, 2026.
Anatomic and Clinical Laboratory Associates P.C. (ACLA) disclosed a data breach involving unauthorized access to its computer network. The breach, discovered in December 2025, exposed personally identifiable information (names, dates of birth, Social Security numbers, taxpayer identification numbers) and protected health information (medical dates of service, diagnoses, medical history) for 69 Massachusetts residents.
Saderat Bank was among three major Iranian banks affected by a wave of cyberattacks reported on June 23, 2026. The incident prompted a temporary nationwide suspension of card-based services to prevent unauthorized access. This follows an earlier wave of disruptions in mid-June.
The ransomware group APT73/Bashe claimed responsibility for a cyberattack against Vienna Airport (Flughafen Wien AG) on June 23, 2026, threatening to leak sensitive data. The airport acknowledged a limited leakage of old cargo-related files from one email inbox but denied a broader system compromise.
Reynella East College, an Australian school, had over 600 gigabytes of its data dumped online by the Interlock ransomware group on June 23, 2026. The threat actor claimed to have extracted over 473,000 files across more than 68,000 folders. The school had initially notified parents of a system-wide breach two weeks prior.
Wright-Ryan Construction, a commercial and residential construction firm, reported a data breach on June 22, 2026. The incident led to unauthorized access to its network and the exposure of highly sensitive personal information, including names, Social Security numbers, driver's licenses, and passports.
Attorneys working with ClassAction.org are looking into whether a class action lawsuit can be filed in light of the The Fedcap Group data breach. As part of their investigation, they need to hear from individuals who had their information exposed in the incident , including those who received notice of the The Fedcap Group data breach or otherwise believe they are affected. The Fedcap Group Security Incident: What Happened? The Fedcap Group, which operates a network of international nonprofit affiliates, has confirmed a data breach in a June 22, 2026 report submitted to the Vermont Attorney General's Office . The report revealed that Social Security numbers were among the information compromised in The Fedcap Group data breach. A sample notification letter is pictured below. What You Can Do After the The Fedcap Group Data Breach If your information was exposed in the The Fedcap Group data breach, attorneys want to hear from you. You may be able to start a class action lawsuit to recover compensation for loss of privacy, time spent dealing with the breach, out-of-pocket costs, and more. A successful case could also force The Fedcap Group to ensure they take proper steps to protect the information they were entrusted with. Affected by the The Fedcap Group data breach? Fill out the form on this page today. If you believe your information was exposed in the The Fedcap Group data breach, fill out the form on this page to get in touch with us. An attorney or legal representative may then reach out to you to explain more about this investigation and ask you a few questions. Remember, there is no cost to get in touch, and you are under no obligation to take action after speaking to someone. New cases and investigations, settlement deadlines, and news straight to your inbox. Whitfield Regional Hospital Data Breach 2026 Community Health Center of Buffalo Data Breach 2026 Advantage Home Health Care Data Breach 2026 Unlimited Technology Systems Data Breach 2026 Heart Care Centers of Illinois Data Breach 2026 Clover Health Investments Data Breach 2026 Morris Communications Company Data Breach 2026 Brown Health Medical Group-MA Data Breach 2026 Case & Associates Properties Data Breach 2026 Date occurred: January 7, 2026 - January 30, 2026 Source of breach: Insider threat (employee) Data types: Names, addresses, phone numbers, dates of birth, social security numbers, account numbers, and transactional data Status: Confirmed; reported on June 15, 2026. Severity: Medium; the exposure of social security numbers and account data significantly increases the risk of financial fraud and identity theft. TD (td.com) reported a data breach involving customer information on June 15, 2026. The incident was classified as an insider breach, where an employee accessed sensitive data without authorization between January 7 and January 30, 2026. The compromised information includes highly sensitive details such as names, social security numbers, and bank account numbers. This medium-severity incident is currently being investigated internally, and the bank is implementing measures to enhance its data protection protocols. The exposure of such comprehensive personal and financial data typically increases the risk of identity theft and fraudulent account activity. The attacker or cause of the incident has not been identified. Affected customers face significant risks due to the exposure of social security numbers and account details. This information could be leveraged by malicious actors for identity theft, opening fraudulent accounts, or conducting unauthorized financial transactions. Additionally, the availability of phone numbers and addresses increases the likelihood of targeted phishing or social engineering attempts. Typically, incidents of this nature lead to heightened scrutiny of internal security policies and potential regulatory oversight. Affected individuals should monitor their financial statements closely, consider placing a credit freeze, and remain vigilant against suspicious communications. Transparency regarding the breach helps customers take proactive steps to secure their personal data. How to protect against similar security incidents Following the insider breach at TD involving sensitive financial data and social security numbers, customers should take immediate steps to secure their personal and financial information. Monitor financial accounts and credit reports. Review bank statements and credit reports for any unauthorized activity or unfamiliar transactions. Set up real-time transaction alerts on your bank accounts to detect suspicious movements immediately. Implement a credit freeze or fraud alert. Contact major credit bureaus to place a freeze on your credit file, preventing unauthorized accounts from being opened. Alternatively, place a fraud alert to ensure lenders verify your identity before extending credit. Strengthen account security with MFA. Enable multi-factor authentication (MFA) on all financial and personal accounts where available. Use phishing-resistant MFA methods, such as hardware keys or authenticator apps, rather than SMS-based codes. Deploy internal security monitoring. For organizations, implement robust internal access controls and continuous monitoring to detect anomalous employee behavior. Utilize attack surface management tools to identify and mitigate vulnerabilities across the digital infrastructure. Taking proactive measures is essential to mitigating the long-term risks associated with the exposure of sensitive personal identifiers. What happened in the TD security breach? On June 15, 2026, TD (td.com) disclosed a security breach. According to initial reports, an employee compromised the personal information of customers between January 7 and January 30, 2026, including names, social security numbers, and account details. The TD breach was publicly reported on June 15, 2026. The exact date of the attack has not been disclosed. The breach exposed customer names, physical addresses, phone numbers, dates of birth, social security numbers, bank account numbers, and transactional data. If you have a relationship with TD, there is a risk that your personal data was compromised in this breach. Because the incident involved identifiers like social security numbers and bank account details, it is important to stay alert for suspicious activity and take proactive steps to protect your financial identity. What steps should companies take after being breached? TD is investigating the incident internally, notifying affected parties, and taking measures to enhance its data protection protocols and review internal security measures.
On June 22, 2026, Taiko, an Ethereum Layer-2 network, suffered an exploit on its bridge, resulting in approximately $1.7 million in losses. The attack was caused by an SGX signing key for Taiko's Raiko prover being accidentally committed to a public GitHub repository. This leaked key allowed an attacker to register a malicious prover and forge fraudulent withdrawal proofs, enabling them to drain assets from the L1 bridge contracts. Taiko halted block production and urged users to withdraw funds from all bridges.
ALS Global, an Australian-based testing, inspection, and certification company, became aware around June 22, 2026, that a threat actor named 'Aur0ra' published information online allegedly obtained during a cyber incident identified in May 2026. The breach involved unauthorized third-party access to some of its IT systems, causing temporary disruption to operations.
On June 22, 2026, the SafePay ransomware group publicly claimed responsibility for a cyberattack against EHG Bayern (ehg.bayern), a German infrastructure provider. The group has threatened to release sensitive data unless their demands are met. EHG Bayern, founded in 1991, specializes in infrastructure operations. The incident poses a significant risk to the critical infrastructure sector.
LastPass reported a supply chain security incident on June 22, 2026, stemming from a breach at its third-party vendor, Klue. Attackers exploited compromised legacy credentials at Klue to obtain OAuth tokens, which were then used to access LastPass's Salesforce CRM environment. The compromised information includes customer names, email addresses, phone numbers, and physical addresses, as well as support case information. LastPass confirmed that its core infrastructure and password vaults were not affected, but the incident highlights risks associated with third-party integrations.
Colorado Health Network Inc., a Denver-based nonprofit, disclosed a data breach on June 22, 2026. The breach exposed a wide range of personally identifiable information (PII) and protected health information (PHI), including names, addresses, dates of birth, Social Security numbers, driver's license/state ID numbers, passport numbers, financial account information, and medical information.
Meta temporarily paused its internal AI training program, the Model Capability Initiative (MCI), on June 22, 2026, following a security incident that exposed sensitive employee data to broader internal access than intended. The program, launched in April 2026, collected data on employees' work activities, including keystrokes, mouse movements, conversations, transcripts, and performance-related information, to train AI models. The leak reportedly exposed private employee conversations, performance data, and transcriptions. Meta classified the incident as a SEV 2 and is investigating, stating that privacy safeguards were in place and no external breaches were indicated.
Nidec Chaun Choung Technology Corporation, a Taiwanese subsidiary of Nidec, detected a ransomware attack on some of its servers on June 22, 2026. The attack caused malfunctions in some information systems, including ERP. Emergency measures were implemented, including network isolation. While no leakage of personal or confidential information has been confirmed yet, investigations are ongoing. The Blackfield ransomware group later claimed responsibility and demanded a $2 million ransom.
Tata Electronics, a major supplier for Apple and Tesla, confirmed a cybersecurity incident after the 'World Leaks' ransomware group published over 200,000 files (630GB) allegedly stolen from the company. The leaked data reportedly includes manufacturing records, technical drawings, employee passport scans, and confidential documents related to Apple (e.g., iPhone 18 Pro schematics, quality inspection standards) and Tesla (e.g., engineering documents, component files for Model Y and Model 3).
Amazon-owned primary care provider One Medical faced a data extortion threat from the ShinyHunters group, which claimed to have stolen 8.8 terabytes of data from One Medical Seniors (formerly Iora Health) and threatened to leak it by June 22, 2026, if a ransom was not paid. One Medical had previously disclosed a cybersecurity incident on June 17, 2026, involving unauthorized access to a third-party file storage system containing archived patient information for One Medical Seniors. The unauthorized access occurred between June 8 and June 11, 2026. The potentially compromised information includes demographic and clinical records for some patients.
McKay Sugar, a major Australian sugar producer, suffered a cyber incident that disrupted operations at its Farley and Racecourse Mills. The Gentlemen ransomware group claimed responsibility for the attack around June 15-16, 2026, on their leak site. Public reporting indicated that McKay Sugar was working to verify what data was stolen or accessed. The ransomware group claimed to have stolen over 26 million records containing PII of customers and other internal data. The incident was discussed in public reporting around June 21, 2026.
Explore the intelligence
Compare incidents across industries and critical services.
Explore all sectors →Follow recurring intrusion methods and adversary behaviour.
Explore all attack patterns →Track consequences such as disruption and data exposure.
Explore all impacts →Compare reports by explicitly affected country.
Explore all countries →Explore the intelligence
Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.
12 answers across 4 topics
How to read and use the current intelligence overview.
It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.
Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.
No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.