Skip to main content

Current cyber intelligence

Cybersecurity News: Latest Incidents & Threat Intelligence

Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.

216

Reports in 90 days

in the current rolling intelligence window

10

Active topics

represented in the same 90-day window

65

High priority

high or critical reports in 90 days

Latest reporting

Latest cybersecurity incidents

Showing 127144 of 216 reports published in the last 90 days.

Sofi logoUse of stolen credentials or exploit
Medium

SoFi Hong Kong Confirms Third-Party Data Breach

SoFi Hong Kong, a subsidiary of the financial technology company SoFi, confirmed a data breach after hackers gained unauthorized access to a database at a third-party vendor containing customer information. The company is advising customers to update passwords, enable two-factor authentication, and monitor their accounts.

Sofi
Wfp logoUse of stolen credentials or exploit
Medium

UN World Food Programme Data Breach Exposes 600,000 Gaza Households

The United Nations World Food Programme (WFP) disclosed on June 8, 2026, unauthorized access to its Gaza self-registration application. The breach exposed names, identification numbers, mobile numbers, and location data for approximately 600,000 Palestinian households in Gaza. WFP suspended the platform while responding to the incident.

Wfp
Dentaquest logoRansomware
Medium

DentaQuest Data Breach by ShinyHunters Affects 2.6 Million Accounts

Dentaquest Hit with Cyberstrike Affecting 2.6M Dental benefits administrator hit with cyberstrike affecting 2.6M | DrBicuspid.com Dental benefits administrator and insurance provider DentaQuest was hit recently by a cybersecurity incident, allegedly exposing the personal data of 2.6 million accounts, according to a story published June 4 on Bleeping Computer . DentaQuest wrote in a statement posted June 1 on its website that it’s actively managing the data breach, which involved “unauthorized access to a limited portion of our network.” Despite the incident, DentaQuest’s systems are fully operational with limited disruption to its customers, according to a statement. In May, extortion group ShinyHunters listed DentaQuest on its data leak site, claiming it had 234GB of stolen data, including names, government-issued identification cards, and health insurance information, from the company, according to Bleeping Computer . The cyber gang publicly released the stolen information after it reportedly could not reach an agreement with DentaQuest, according to the story. DentaQuest did not confirm the number of accounts affected. It stated that it took immediate action to mitigate the threat after discovering the incident. Furthermore, the company wrote in the statement that it was working with a cybersecurity expert, forensic investigators, and law enforcement. “We are working as quickly and carefully as possible to determine the exact scope of the incident, including the nature and extent of any data that may have been compromised,” DentaQuest stated. DentaQuest, which is part of Sun Life , serves more than 30 million members in U.S. and manages plans and provider networks for employers, individuals, Medicaid recipients, and Medicare Advantage beneficiaries. Data Breach Roundup (May 29 - June 4, 2026) Charter Communications data breach affects 4.9 million accounts An update to a breach from last week, there's not much new here except that we now know how many people were impacted. ShinyHunters claims the data includes consumer and business customer names, email addresses, physical addresses, phone numbers, phone types, plan information, support ticket data, and some CPNI data. Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers Atlas Menu is a popular cheat service for Grand Theft Auto V online, and has now suffered a data breach. Stolen data includes email addresses, usernames, hashed passwords, IP addresses, and support tickets of about 64,000 accounts. There's no information in this article about how Atlas Menu was breached. Ultrahuman says hackers accessed customers’ wellness data via internal tool Ultrahuman sells smart rings and metabolic health-tracking devices that enable users to monitor metrics such as sleep, activity, and recovery. The startup is best known for its Ring Air, which competes with the Oura Ring. The company says the incident was the result of gaining credentials stolen from an employee’s malware-infected laptop. They have declined to say how many people or what data was impacted, citing an ongoing investigation. UN food agency discloses breach affecting 600,000 Gaza households The UN's World Food Programme (WFP) says that the self-registration application (SRA) for Palestine was breached. Affected data included names, ID numbers, phone numbers, and location information (such as neighborhood data recorded during registration). DentaQuest data breach exposed info of 2.6 million accounts DentaQuest, is one of the largest dental benefits administrators in the United States. The breach is the result of the ShinyHunters ransomware gang, and impacts Email addresses full names, phone numbers, government-issued IDs, health insurance information, genders, and dates of birth. California AG sues 23andMe over 2023 breach exposing health data A small update to a story that just won't end. This breach alleges "failure to protect sensitive customer genetic and personal information." We will update you if there's any further information.

Dentaquest
Numerique logoInfostealer
Medium

French Government Messaging Service Tchap Compromised

More 70,000 French government employees had personal details stolen. Why and by whom? On June 8, 2026, DINUM announced that the official French government chat service (Tchap) had been breached on June 7. At the same time, a threat actor calling itself ‘ misere ’ claimed responsibility. DINUM is the French government’s interministerial digital directorate in charge of Tchap.  Tchap is a ‘secure’ sovereign instant messaging service for French government employees designed to combine the principle of data sovereignty with increased security over third-party foreign systems. It includes secure chat rooms that are end-to-end encrypted, and ‘public’ chat rooms that are not encrypted. Misere is… unknown. There is no public record of a threat actor known as ‘misere’. DINUM says the system was compromised following account hijacking, and states, “Of the more than 825,000 registered agents, 73,467 are reportedly affected by this incident, representing less than 9% of registered users.” Advertisement. Scroll to continue reading. Misere supposedly claimed almost precisely the same: theft of more than 70k accounts (aligning with DINUM’s statement); but added that it stole 13.5GB of files across more than 643,000 messages. However, we cannot verify misere’s claim because it was reported rather than published by the OSINT FrenchBreaches community, and the original misere claim is not or no longer available on the internet. So, we’re left with a conundrum. An official announcement states the breach occurred (not was discovered but occurred) on June 7 and was limited to 9% of the users. Classic, but not inaccurate, downplaying. But almost immediately, an unknown threat actor agrees with the number of affected accounts but claims theft of 13.5GB of actual data. We cannot verify this latter detail since we only have reports of a report – but if we assume accuracy and honesty, is it realistic to believe that this amount of data can be gathered and exfiltrated in a single day by an otherwise unknown threat actor? For additional insights into the cause and effect, we talked to Ilia Kolochenko , a qualified attorney, and CEO, founder and chief architect at ImmuniWeb. ImmuniWeb operates a dark web monitoring and threat intelligence service for its clients and sees thousands of different incidents daily. Could misere be a pseudonym adopted by a state actor for this small and relatively innocuous breach – for example, Russia embarrassing France over its pro Ukraine position; or the US doing the same for its anti-Iran war position? Kolochenko doesn’t think so, “Because it’s a little trivial. This is too small for large power intelligence agencies to bother with.” Before 2024, he had seen state actors compromise systems and rapidly act on the compromise. “But since 2024,” he continued, “state actors tend to infiltrate and lay low. What is alarming now is a new trend with state actors breaching critical national infrastructure and its suppliers silently. They just backdoor everything to get control of a nation’s infrastructure. They just go deeper and deeper and deeper, trying to get access to as many critical systems as possible.” The motivation is to pre-position with the ability to bring down multiple if not all the critical industries in an enemy nation simultaneously. This is cyberwar in preparation for or defense against a possible kinetic war. Nor does he think that the suggestion that the breach was an account take-over event is informative. It could be as simple as a hacker getting the credentials from stealer logs; but if it were an advanced hacker, that would not be necessary. “In today’s cloud and AI world, you don’t need to steal cookies with infostealers. You don’t need zero days. You just send a legitimate request to an API, and you’ll get all the records of a governmental institution or a private company, and everything will be on your hard drive within several hours.” Such an hypothesis could explain how misere could exfiltrate 3.5GB on the same day as the breach was discovered. Does the name misere give any clue to the actor or motivation? Again, no. “The name given to this actor is meaningless,” suggested Kolochenko. “Sometimes a hacker or group wants to protect a reputation for doing more meaningful hacks and adopts a ‘burner’ identity. Sometimes one group will impersonate another group that might be considered a rival or affiliated with a different adversarial nation.” The fact that the name is unknown does not mean that the actor is unknown. Overall, this attack by an unknown hacker against a secure government chat system does not present itself as an APT attack. But that could even be the purpose. After all, it involves 70,000 government employees. DINUM specifies in its breach disclosure announcement, “The potentially exposed user account data includes, at a minimum: first and last name, email address, affiliated entity, and avatar.” The affiliated entity would expose which government department is involved, the email address is provided, and Misere further claimed to have scraped 640,000 (plaintext) chat messages. This combination would be a treasure trove for subsequent targeted spear-phishing, valuable to both financially motivated cyber gangs and state actors ultimately targeting not Tchap but the ministries employing the Tchap users. But – and this is the point of this discussion – we just don’t know the truth: everything is conjecture. Frankly, trying to understand the cause and motivation behind any cyber incident is based on conjecture with little known truth. Related : Maine Disables Data Breach Portal Due to Fake Submissions Related : University of Nottingham Confirms Breach After Hackers Leak Data Related : 174,000 Impacted by Lansing Community College Data Breach Related : Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Numerique
Carnival logoPhishing
Medium

Carnival Cruise Lines Data Breach Exposes Personal Information of Nearly 6 Million Passengers

Carnival Cruise Lines reported that nearly 6 million passengers had their personal information exposed after a data breach. The breach was discovered in mid-April 2026, following an employee falling victim to a social engineering attack that granted hackers access to the IT system. Although Carnival acted quickly, a significant amount of customer information was stolen, including names, addresses, contact information, birth dates, and government ID numbers. Affected passengers are being notified and offered free credit monitoring.

Carnival
Charter logoMisconfiguration or publishing error
Medium

Charter Communications Data Breach by ShinyHunters Exposes Millions of Records

Telecommunications giant Charter Communications (Spectrum) suffered a data breach attributed to the ShinyHunters hacking group. The group posted data on a dark web leak site after ransom negotiations failed. While Charter stated no sensitive data was stolen, ShinyHunters claimed to have released 42 million records, including 13 million customer records and nearly 27,000 employee records. The compromised data allegedly includes full names, email addresses, home and company addresses, and support ticket details for customers, and work emails, job titles, and home addresses for employees. The initial breach occurred around April 1, 2026, via a vishing attack on an employee's Microsoft Entra account, with the data leak and significant reporting occurring on June 5, 2026.

Charter
Carnivalcorp logoPhishing
Medium

Carnival Cruise Lines Data Breach Exposes Information of Nearly 6 Million Passengers

Carnival Cruise Lines disclosed a data breach affecting nearly 6 million passengers. The breach was discovered in mid-April 2026 after an employee fell victim to a social engineering attack, granting hackers access to the company's IT system. Although Carnival acted quickly, attackers managed to steal significant customer information, including names, addresses, contact information, birth dates, and government ID numbers (such as passport and driver's license numbers). Affected passengers are being notified and offered credit monitoring. While an initial disclosure may have occurred in late May, new details and significant reporting made this a top headline on June 5, 2026.

Carnivalcorp
Tving logo
Medium

South Korean Streaming Platform TVING Suffers Major Data Breach

Seoul Mayor Oh Se-hoon fined $6,760 in political funds case, threatening mayorship if upheld Seoul Mayor Oh Se-hoon was convicted Wednesday of violating the Political Funds Act and fined 10 million won ($6,760) over opinion polls conducted by political broker Myung Tae-kyun. The sentence, if upheld on appeal, would strip Oh of his mayorship, dealing a critical blow to the political career of one of the nation's most prominent conservative heavyweights. The five-term mayor said he would appeal immediately. The Seoul Central District Court found that Oh commissioned Myung to conduct five opinion polls ahead of the 2021 Seoul mayoral by-election and asked businessman and longtime supporter Kim Han-jung to cover 21 million won in polling costs. “The defendant requested his supporter to pay the polling costs,” the court said in the ruling, adding that the payment constituted an illegal political contribution under the act. “Having served as both a lawmaker and mayor, he had been well aware of the act, but he has kept denying his responsibility ... A sentence that would make him lose the public post is inevitable,” it said. Under Korean law, elected officials lose their office

Tving
Ultrahuman logoInfostealer
High

Ultrahuman Data Breach Exposes Customer Wellness Data

Wearable health-tech startup Ultrahuman confirmed a data breach where hackers accessed customer wellness data through credentials stolen from an employee's malware-infected laptop. Approximately 0.1% of its user base was affected.

Ultrahuman
Hospecs logoPhishing
High

Data Breach Hits Over 100 Dutch Hotels via Shared Booking Software

Hospecs, a Dutch hospitality services firm, confirmed a data breach affecting at least 100 Dutch hotels, with reports also coming from Belgium and Ireland. The breach exposed guests' contact details and reservation information, which criminals are using for phishing attacks.

Hospecs
7 Eleven logoRansomware
Medium

7-Eleven data breach exposes franchisee applicant data

Cybersecurity Week in Review: May 26, 2026 – June 1, 2026 Cyberattacks, data breaches, zero-days, and global responses—discover the biggest cybersecurity headlines of this week. This week’s cybersecurity landscape was marked by a surge in high-impact data breaches, aggressive exploitation of critical vulnerabilities, and a series of government advisories aimed at bolstering defenses across sectors. The period from Tuesday, May 26, through Monday, June 1, 2026, saw threat actors targeting major enterprises, public infrastructure, and widely used software platforms, underscoring the relentless pace and sophistication of modern cyber threats. Charter Communications: Massive Data Leak Impacts Millions Charter Communications, one of the largest US telecommunications providers, suffered a significant data breach after the ShinyHunters group leaked over 13 million customer records on the dark web. Exposed data included full names, email addresses (primarily workplace domains), company and home addresses, and details from nearly 10 million customer support tickets. Additionally, records on approximately 27,000 employees—including work emails and job titles—were compromised. The breach is believed to have originated from a vishing attack that compromised an employee’s Microsoft Entra account, allowing attackers to pivot into the company’s Salesforce environment. Charter has denied that sensitive personal or proprietary network information was exfiltrated, but the leaked data poses substantial risks for social engineering and spearphishing attacks targeting both customers and staff 1 ​ 2 . Attack vector: Vishing, credential compromise, Salesforce exploitation Response: Charter refused ransom demands, leading to public data release; authorities notified Trump Mobile: Pre-Order Customer Data Exposed Trump Mobile confirmed a data breach affecting over 27,000 customers who pre-ordered the T1 smartphone. The incident was traced to a security flaw in the company’s website pre-order form, which exposed names, addresses, email addresses, order identifiers, and mobile phone numbers. No payment or highly sensitive financial data was reported as compromised. The company has implemented additional safeguards and is evaluating notification obligations 3 . Attack vector: Web application vulnerability Data exposed: Personal contact details of pre-order customers Response: Security enhancements, customer vigilance advisories 7-Eleven: Franchisee and Customer Data Breach 7-Eleven disclosed a breach that exposed the personal information of approximately 185,000 individuals, including franchisee application records. The breach increased the risk of identity theft and phishing attacks across its North American franchise network 4 . Attack vector: Internal system compromise Data exposed: Names, addresses, sensitive franchisee data LA Metro: State-Sponsored Attack Disrupts Public Transit A disruptive cyberattack targeting the Los Angeles Metro system was attributed to Iranian state-sponsored hackers. The incident highlights the ongoing threat posed by nation-state actors to critical infrastructure in the US 5 . Impact: Service disruption, heightened sectoral alert Canvas (Instructure): Ransomware Attack Disrupts Education Sector Instructure, the parent company of the Canvas learning platform, reached an agreement with the ShinyHunters group after a ransomware attack threatened to leak data tied to nearly 275 million users across 9,000 educational institutions. The attackers claimed to have exfiltrated over 3.65 TB of data, including student records, email addresses, and private communications. The incident caused widespread disruption during a critical academic period and underscored the dilemma organizations face when negotiating with cybercriminals 6 . Attack vector: Ransomware, data exfiltration

7 Eleven
Ox logo
Medium

Oxford University Discloses Data Breach via Third-Party Career Platform CareerConnect

Oxford University disclosed a data security incident on June 1, 2026, after being notified by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised. The breach, which occurred on May 28, exposed the full names, email addresses, and encrypted passwords of students, alumni, research staff, and recruiters who did not use Single Sign-On (SSO). Oxford's internal systems were not affected, and the breach was contained within Group GTI's infrastructure.

Ox
Dashlane logo
Medium

Dashlane Brute-Force Attack on User Accounts

Password manager Dashlane disclosed a brute-force attack that began on May 31, 2026, targeting user accounts to bypass two-factor authentication (2FA) protections. Attackers aimed to register new devices on existing user accounts. While Dashlane's internal systems were not compromised, encrypted vaults of fewer than 20 personal plan users were successfully downloaded. The company's automated security controls temporarily suspended targeted accounts, and affected users were directly notified. The vault data remains protected by the users' Master Passwords.

Dashlane
Cbse logoUse of stolen credentials or exploit
Medium

CBSE revaluation portal hit by cyber attack; around 50 students affected

The CBSE revaluation portal's payment system was hit by a 'malicious attack' on May 30, 2026, leading to unauthorized access by approximately 50 students. The cyber attack caused abnormal fee displays, with amounts fluctuating significantly, and allegedly altered revaluation-related records. The glitch was linked to the HDFC payment gateway integrated with the system. Experts from IIT Madras and IIT Kanpur, along with the Digital Infrastructure Corporation of India, are assisting in strengthening the system.

Cbse
Eecu logo
Medium

Educational Employees Credit Union (EECU) Data Breach Exposes Member Information

Educational Employees Credit Union (EECU) reported a data breach where an unauthorized individual gained access to a single employee email account on December 15, 2025. Following an investigation, EECU determined on May 8, 2026, that emails within the compromised account contained members' personal information. Notification letters were sent to affected individuals starting May 29, 2026. The exposed data includes names, addresses, Social Security numbers, driver's license numbers, and financial information.

Eecu
Ukvisaportal logoUse of stolen credentials or exploit
Medium

UK Visa Portal Data Leak Exposes 100,000 Applicants' Passports and Selfies

UK Visa Portal Data Leak Exposes Sensitive Information TechCrunch Security reports a significant data breach involving a third-party website used in the UK visa application process. The breach exposed thousands of applicants' sensitive information, including passports, selfies, and location data. Instead of addressing the vulnerability, the website opted to engage legal counsel. This incident highlights the critical need for robust data protection measures, particularly when handling personal information. This breach serves as a stark reminder of the risks associated with third-party service providers. For UK businesses, the exposure of sensitive data not only damages trust but also poses significant regulatory and reputational risks. Organisations must ensure that their partners adhere to stringent data protection standards and have clear incident response plans in place to mitigate such risks. Organisations should review their third-party data handling practices to ensure compliance with data protection regulations. It's crucial to assess the security measures of any external partners handling sensitive information and to establish clear protocols for incident response. Regular audits and compliance checks can help identify potential vulnerabilities and improve overall data security.

Ukvisaportal
Paytel logoRansomware
High

Prison Communication Service Pay Tel Exposed Hundreds of Thousands of Driver's Licenses

Prison communication service Pay Tel exposed hundreds of thousands of driver’s licenses As reported by TechCrunch, prison calling service Pay Tel has experienced a significant data security lapse, exposing sensitive information of its users due to a publicly accessible cloud server. Cybersecurity firm UpGuard discovered an unprotected Microsoft Azure server managed by Pay Tel containing at least 300,000 driver's license scans and other government-issued identification documents. The server, left without a password, also exposed inmate communications, including text messages, handwritten notes, and financial records. Users signing up for Pay Tel's services are required to submit identification documents and profile photos, which were among the compromised data. Some uploaded photos contained precise location data, potentially revealing home addresses. This marks Pay Tel's second security incident in two years, following a ransomware attack in June 2025. The company has not yet publicly acknowledged the breach or stated whether it will notify affected individuals or state attorneys general as required by data breach notification laws. A security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers’ driver’s licenses Pay Tel, a service that facilitates phone calls for inmates, has inadvertently exposed a significant security vulnerability, leading to the public accessibility of a cloud server containing sensitive personal data. Cybersecurity firm UpGuard uncovered the issue, revealing that a Microsoft Azure-hosted server held at least 300,000 scans of driver’s licenses and other government-issued identification documents used by Pay Tel customers. The server was found to be unsecured, lacking a password, which allowed anyone with internet access to locate and view the stored data. Pay Tel provides communication devices, such as tablets, to prisons across the United States, requiring customers to submit identification documents and profile photos for service activation. Unfortunately, this sensitive information was among the data that became exposed. In addition to personal identification, researchers from UpGuard indicated that various inmate communications—including text messages, handwritten notes, and financial records—were also compromised due to this security breach. UpGuard notified Pay Tel about the vulnerability on May 7, and despite follow-ups, it appears the server remained unsecured for several days. As of now, Pay Tel has not publicly acknowledged this security incident. This leak adds to a worrying trend where technology companies fail to adequately protect sensitive user information, often due to misconfigurations or inadequate cybersecurity practices. UpGuard highlighted that many of the uploaded images contained geolocation data, which could potentially reveal the home addresses of the individuals involved. This incident marks Pay Tel's second known security issue in just two years, following a ransomware attack in June 2025. The company's president, Vincent Townsend, has not responded to inquiries regarding this latest breach, and it remains uncertain whether affected individuals will be notified or if any legal obligations under state data breach laws will be fulfilled. The accountability for cybersecurity practices at Pay Tel remains unclear. Startup Founder Secures $31 Million to Revolutionize AI Cooling Solutions As artificial intelligence technology continues to advance, the need for effective cooling systems for data centers has ... Google Employees Rally for Enhanced Layoff Protections Amid AI Restructuring In the face of widespread layoffs fueled by ongoing AI-driven transformations, anxiety is palpable among Google’s workfo ... Revolutionizing Training: Synthesia Launches AI-Powered Roleplay Sessions Synthesia, a pioneering British startup, is taking a bold step beyond its traditional focus on creating interactive trai ... Apple Set to Introduce Flexible Upgrade Program for Devices Apple is on the verge of launching an innovative program called the 'Apple Upgrade,' developed in collaboration with Kla ... Rumors of Anthropic's Acquisition of Robotics Firm Ignite AI Community This year has been monumental for AI acquisitions, with companies like Anthropic and OpenAI aggressively expanding their ... We’re excited to explore how we can turn your ideas into impactful solutions.

Paytel
Nightwing logo
Medium

CISA Contractor Nightwing Exposed Sensitive Government Credentials on Public GitHub

A public GitHub repository named 'Private-CISA', maintained by a contractor from Nightwing, a government defense contractor, was found to have exposed highly sensitive internal credentials and systems used by the US Cybersecurity and Infrastructure Security Agency (CISA). The repository, publicly accessible from November 13, 2025, until May 18, 2026, contained 844 MB of CISA's internal DevSecOps infrastructure, including administrative credentials for AWS GovCloud accounts, plaintext usernames and passwords for internal CISA systems, SSH keys, and an RSA private key. The contractor reportedly disabled GitHub's default secret-scanning push protections. Public reporting and analysis of the exposure occurred around May 18-29, 2026.

Nightwing

Explore the intelligence

Explore current intelligence taxonomies

Explore the intelligence

Questions about current cybersecurity intelligence

Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.

12 answers across 4 topics

How to read and use the current intelligence overview.

What does this cybersecurity intelligence overview contain?

It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.

Where should I start exploring?

Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.

Does this page list every cybersecurity incident?

No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.

Browse current topics