Skip to main content

Current cyber intelligence

Cybersecurity News: Latest Incidents & Threat Intelligence

Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.

216

Reports in 90 days

in the current rolling intelligence window

10

Active topics

represented in the same 90-day window

65

High priority

high or critical reports in 90 days

Latest reporting

Latest cybersecurity incidents

Showing 5572 of 216 reports published in the last 90 days.

Elparking logoUse of stolen credentials or exploit
High

ElParking, mobility app of Grupo Mutua Madrileña, suffers data breach exposing personal data

ElParking, a mobility application part of Grupo Mutua Madrileña, experienced a data breach where an unauthorized access was detected on June 14, 2026. The incident, disclosed on June 23, 2026, exposed basic identification and contact data of users, including names, email addresses, phone numbers, vehicle license plates, and DNI (national ID). Passwords and payment data were reportedly not compromised. The incident was reported to the Spanish Data Protection Agency (AEPD).

Elparking
Toweradmin logoUse of stolen credentials or exploit
Medium

Tower Administrative Services Data Breach Exposes SSNs and Financial Information

Tower Administrative Services Inc., a Pennsylvania-based insurance administration company, disclosed a data breach involving unauthorized access to its corporate network. The breach, which occurred around February 3, 2026, exposed names, Social Security numbers, addresses, and financial account information. Notifications to affected individuals began on June 23, 2026.

Toweradmin
Aclapc logoUse of stolen credentials or exploit
Medium

ACLA Data Breach Exposes Social Security Numbers and Medical Information

Anatomic and Clinical Laboratory Associates P.C. (ACLA) disclosed a data breach involving unauthorized access to its computer network. The breach, discovered in December 2025, exposed personally identifiable information (names, dates of birth, Social Security numbers, taxpayer identification numbers) and protected health information (medical dates of service, diagnoses, medical history) for 69 Massachusetts residents.

Aclapc
Bsis logoUse of stolen credentials or exploit
Medium

Saderat Bank Affected by Cyberattacks in Iran

Saderat Bank was among three major Iranian banks affected by a wave of cyberattacks reported on June 23, 2026. The incident prompted a temporary nationwide suspension of card-based services to prevent unauthorized access. This follows an earlier wave of disruptions in mid-June.

Bsis
Viennaairport logoRansomware
Medium

Vienna Airport Targeted in APT73/Bashe Ransomware Attack

The ransomware group APT73/Bashe claimed responsibility for a cyberattack against Vienna Airport (Flughafen Wien AG) on June 23, 2026, threatening to leak sensitive data. The airport acknowledged a limited leakage of old cargo-related files from one email inbox but denied a broader system compromise.

Viennaairport
Reynellaec logoRansomware
Medium

Reynella East College Data Dumped Online by Interlock Ransomware Group

Reynella East College, an Australian school, had over 600 gigabytes of its data dumped online by the Interlock ransomware group on June 23, 2026. The threat actor claimed to have extracted over 473,000 files across more than 68,000 folders. The school had initially notified parents of a system-wide breach two weeks prior.

Reynellaec
Wright Ryan logoUse of stolen credentials or exploit
Medium

Wright-Ryan Construction Data Breach Exposes Social Security Numbers and Passports

Wright-Ryan Construction, a commercial and residential construction firm, reported a data breach on June 22, 2026. The incident led to unauthorized access to its network and the exposure of highly sensitive personal information, including names, Social Security numbers, driver's licenses, and passports.

Wright Ryan
Fedcapgroup logoPhishing
Medium

The Fedcap Group Confirms Data Breach, Social Security Numbers Compromised

Attorneys working with ClassAction.org are looking into whether a class action lawsuit can be filed in light of the The Fedcap Group data breach. As part of their investigation, they need to hear from individuals who had their information exposed in the incident , including those who received notice of the The Fedcap Group data breach or otherwise believe they are affected. The Fedcap Group Security Incident: What Happened? The Fedcap Group, which operates a network of international nonprofit affiliates, has confirmed a data breach in a June 22, 2026  report submitted to the Vermont Attorney General's Office . The report revealed that Social Security numbers were among the information compromised in The Fedcap Group data breach. A sample notification letter is pictured below. What You Can Do After the The Fedcap Group Data Breach If your information was exposed in the The Fedcap Group data breach, attorneys want to hear from you. You may be able to start a class action lawsuit to recover compensation for loss of privacy, time spent dealing with the breach, out-of-pocket costs, and more. A successful case could also force The Fedcap Group to ensure they take proper steps to protect the information they were entrusted with. Affected by the The Fedcap Group data breach? Fill out the form on this page today. If you believe your information was exposed in the The Fedcap Group data breach, fill out the form on this page to get in touch with us. An attorney or legal representative may then reach out to you to explain more about this investigation and ask you a few questions. Remember, there is no cost to get in touch, and you are under no obligation to take action after speaking to someone. New cases and investigations, settlement deadlines, and news straight to your inbox. Whitfield Regional Hospital Data Breach 2026 Community Health Center of Buffalo Data Breach 2026 Advantage Home Health Care Data Breach 2026 Unlimited Technology Systems Data Breach 2026 Heart Care Centers of Illinois Data Breach 2026 Clover Health Investments Data Breach 2026 Morris Communications Company Data Breach 2026 Brown Health Medical Group-MA Data Breach 2026 Case & Associates Properties Data Breach 2026 Date occurred: January 7, 2026 - January 30, 2026 Source of breach: Insider threat (employee) Data types: Names, addresses, phone numbers, dates of birth, social security numbers, account numbers, and transactional data Status: Confirmed; reported on June 15, 2026. Severity: Medium; the exposure of social security numbers and account data significantly increases the risk of financial fraud and identity theft. TD (td.com) reported a data breach involving customer information on June 15, 2026. The incident was classified as an insider breach, where an employee accessed sensitive data without authorization between January 7 and January 30, 2026. The compromised information includes highly sensitive details such as names, social security numbers, and bank account numbers. This medium-severity incident is currently being investigated internally, and the bank is implementing measures to enhance its data protection protocols. The exposure of such comprehensive personal and financial data typically increases the risk of identity theft and fraudulent account activity. The attacker or cause of the incident has not been identified. Affected customers face significant risks due to the exposure of social security numbers and account details. This information could be leveraged by malicious actors for identity theft, opening fraudulent accounts, or conducting unauthorized financial transactions. Additionally, the availability of phone numbers and addresses increases the likelihood of targeted phishing or social engineering attempts. Typically, incidents of this nature lead to heightened scrutiny of internal security policies and potential regulatory oversight. Affected individuals should monitor their financial statements closely, consider placing a credit freeze, and remain vigilant against suspicious communications. Transparency regarding the breach helps customers take proactive steps to secure their personal data. How to protect against similar security incidents Following the insider breach at TD involving sensitive financial data and social security numbers, customers should take immediate steps to secure their personal and financial information. Monitor financial accounts and credit reports. Review bank statements and credit reports for any unauthorized activity or unfamiliar transactions. Set up real-time transaction alerts on your bank accounts to detect suspicious movements immediately. Implement a credit freeze or fraud alert. Contact major credit bureaus to place a freeze on your credit file, preventing unauthorized accounts from being opened. Alternatively, place a fraud alert to ensure lenders verify your identity before extending credit. Strengthen account security with MFA. Enable multi-factor authentication (MFA) on all financial and personal accounts where available. Use phishing-resistant MFA methods, such as hardware keys or authenticator apps, rather than SMS-based codes. Deploy internal security monitoring. For organizations, implement robust internal access controls and continuous monitoring to detect anomalous employee behavior. Utilize attack surface management tools to identify and mitigate vulnerabilities across the digital infrastructure. Taking proactive measures is essential to mitigating the long-term risks associated with the exposure of sensitive personal identifiers. What happened in the TD security breach? On June 15, 2026, TD (td.com) disclosed a security breach. According to initial reports, an employee compromised the personal information of customers between January 7 and January 30, 2026, including names, social security numbers, and account details. The TD breach was publicly reported on June 15, 2026. The exact date of the attack has not been disclosed. The breach exposed customer names, physical addresses, phone numbers, dates of birth, social security numbers, bank account numbers, and transactional data. If you have a relationship with TD, there is a risk that your personal data was compromised in this breach. Because the incident involved identifiers like social security numbers and bank account details, it is important to stay alert for suspicious activity and take proactive steps to protect your financial identity. What steps should companies take after being breached? TD is investigating the incident internally, notifying affected parties, and taking measures to enhance its data protection protocols and review internal security measures.

Fedcapgroup
Taiko logoUse of stolen credentials or exploit
High

Taiko Ethereum L2 Bridge Exploited for $1.7 Million Due to Leaked SGX Signing Key

On June 22, 2026, Taiko, an Ethereum Layer-2 network, suffered an exploit on its bridge, resulting in approximately $1.7 million in losses. The attack was caused by an SGX signing key for Taiko's Raiko prover being accidentally committed to a public GitHub repository. This leaked key allowed an attacker to register a malicious prover and forge fraudulent withdrawal proofs, enabling them to drain assets from the L1 bridge contracts. Taiko halted block production and urged users to withdraw funds from all bridges.

Taiko
Alsglobal logo
Medium

ALS Global Data Breach: Threat Actor Publishes Stolen Information

ALS Global, an Australian-based testing, inspection, and certification company, became aware around June 22, 2026, that a threat actor named 'Aur0ra' published information online allegedly obtained during a cyber incident identified in May 2026. The breach involved unauthorized third-party access to some of its IT systems, causing temporary disruption to operations.

Alsglobal
Ehg logoRansomware
High

EHG Bayern Hit by SafePay Ransomware Attack, Data Leak Threatened

On June 22, 2026, the SafePay ransomware group publicly claimed responsibility for a cyberattack against EHG Bayern (ehg.bayern), a German infrastructure provider. The group has threatened to release sensitive data unless their demands are met. EHG Bayern, founded in 1991, specializes in infrastructure operations. The incident poses a significant risk to the critical infrastructure sector.

Ehg
Lastpass logo
High

LastPass Discloses Supply Chain Security Incident via Third-Party Vendor Klue

LastPass reported a supply chain security incident on June 22, 2026, stemming from a breach at its third-party vendor, Klue. Attackers exploited compromised legacy credentials at Klue to obtain OAuth tokens, which were then used to access LastPass's Salesforce CRM environment. The compromised information includes customer names, email addresses, phone numbers, and physical addresses, as well as support case information. LastPass confirmed that its core infrastructure and password vaults were not affected, but the incident highlights risks associated with third-party integrations.

Lastpass
Coloradohealthnetwork logo
Medium

Colorado Health Network Discloses Data Breach Exposing PII and PHI

Colorado Health Network Inc., a Denver-based nonprofit, disclosed a data breach on June 22, 2026. The breach exposed a wide range of personally identifiable information (PII) and protected health information (PHI), including names, addresses, dates of birth, Social Security numbers, driver's license/state ID numbers, passport numbers, financial account information, and medical information.

Coloradohealthnetwork
Meta logoMisconfiguration or publishing error
High

Meta Pauses AI Employee Monitoring Program After Internal Data Leak

Meta temporarily paused its internal AI training program, the Model Capability Initiative (MCI), on June 22, 2026, following a security incident that exposed sensitive employee data to broader internal access than intended. The program, launched in April 2026, collected data on employees' work activities, including keystrokes, mouse movements, conversations, transcripts, and performance-related information, to train AI models. The leak reportedly exposed private employee conversations, performance data, and transcriptions. Meta classified the incident as a SEV 2 and is investigating, stating that privacy safeguards were in place and no external breaches were indicated.

Meta
Nidec logoRansomware
High

Nidec's Taiwanese subsidiary, Nidec Chaun Choung Technology, hit by ransomware attack

Nidec Chaun Choung Technology Corporation, a Taiwanese subsidiary of Nidec, detected a ransomware attack on some of its servers on June 22, 2026. The attack caused malfunctions in some information systems, including ERP. Emergency measures were implemented, including network isolation. While no leakage of personal or confidential information has been confirmed yet, investigations are ongoing. The Blackfield ransomware group later claimed responsibility and demanded a $2 million ransom.

Nidec
Tataelectronics logoRansomware
High

Tata Electronics confirms cyberattack and data breach, exposing Apple and Tesla confidential files

Tata Electronics, a major supplier for Apple and Tesla, confirmed a cybersecurity incident after the 'World Leaks' ransomware group published over 200,000 files (630GB) allegedly stolen from the company. The leaked data reportedly includes manufacturing records, technical drawings, employee passport scans, and confidential documents related to Apple (e.g., iPhone 18 Pro schematics, quality inspection standards) and Tesla (e.g., engineering documents, component files for Model Y and Model 3).

Tataelectronics
Onemedical logoUse of stolen credentials or exploit
High

ShinyHunters Threatens to Leak 8.8 TB of One Medical Seniors Patient Data by June 22 Deadline

Amazon-owned primary care provider One Medical faced a data extortion threat from the ShinyHunters group, which claimed to have stolen 8.8 terabytes of data from One Medical Seniors (formerly Iora Health) and threatened to leak it by June 22, 2026, if a ransom was not paid. One Medical had previously disclosed a cybersecurity incident on June 17, 2026, involving unauthorized access to a third-party file storage system containing archived patient information for One Medical Seniors. The unauthorized access occurred between June 8 and June 11, 2026. The potentially compromised information includes demographic and clinical records for some patients.

Onemedical
Mckaysugar logoRansomware
Medium

McKay Sugar Cyber Incident by Gentlemen Ransomware Group

McKay Sugar, a major Australian sugar producer, suffered a cyber incident that disrupted operations at its Farley and Racecourse Mills. The Gentlemen ransomware group claimed responsibility for the attack around June 15-16, 2026, on their leak site. Public reporting indicated that McKay Sugar was working to verify what data was stolen or accessed. The ransomware group claimed to have stolen over 26 million records containing PII of customers and other internal data. The incident was discussed in public reporting around June 21, 2026.

Mckaysugar

Explore the intelligence

Explore current intelligence taxonomies

Explore the intelligence

Questions about current cybersecurity intelligence

Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.

12 answers across 4 topics

How to read and use the current intelligence overview.

What does this cybersecurity intelligence overview contain?

It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.

Where should I start exploring?

Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.

Does this page list every cybersecurity incident?

No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.

Browse current topics