Skip to main content

Current cyber intelligence

Cybersecurity News: Latest Incidents & Threat Intelligence

Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.

216

Reports in 90 days

in the current rolling intelligence window

10

Active topics

represented in the same 90-day window

65

High priority

high or critical reports in 90 days

Latest reporting

Latest cybersecurity incidents

Showing 145162 of 216 reports published in the last 90 days.

Fadv logoPhishing
Medium

First Advantage Corporation Data Breach Exposes SSNs and Driver's Licenses

First Advantage Corporation, a global background screening company, experienced a cybersecurity incident in November 2025. An unauthorized actor gained access to a single employee's email inbox within its Drug & Occupational Health Screening Unit through a sophisticated phishing attack. The attacker downloaded the contents of the inbox, potentially exposing sensitive personal information for 4,669 individuals. This data included names, Social Security numbers, driver's license numbers, email addresses, and passwords to Profile Advantage accounts. First Advantage began notifying affected individuals on or about May 29, 2026.

Fadv
Imadiligence logoRansomware
Medium

IMA Diligence Services, LLC Data Breach Affects Over 525,000 Individuals

IMA Diligence Services, LLC, a financial due diligence and risk management firm, experienced a data breach in December 2025, where an unauthorized actor gained access to a legacy file server between December 8-16, 2025. The ransomware group Genesis later claimed responsibility. Notification letters were mailed to impacted individuals starting May 29, 2026. The breach affected approximately 525,306 people and exposed names, driver's license numbers, Social Security numbers, financial account information, health insurance information, medical information, and passport numbers.

Imadiligence
Lpb logo
High

Cyberattack on Landeszentrale für politische Bildung Rheinland-Pfalz

The websites of the Landeszentrale für politische Bildung Rheinland-Pfalz (lpb.rlp.de) and its associated memorials (gedenkstaette-osthofen-rlp.de, ns-dokuzentrum-rlp.de) were targeted by a cyberattack. Systems were immediately isolated, and an investigation is underway to determine if subscriber and customer data was exfiltrated. The incident was publicly reported on May 29, 2026.

Lpb
Plazahomemortgage logoUse of stolen credentials or exploit
Medium

Plaza Home Mortgage Data Breach Impacts Over 137,000 Individuals

Plaza Home Mortgage, a national wholesale and correspondent mortgage lender, disclosed a data breach affecting over 137,000 customers and employees. Unauthorized access to an employee's computer occurred on or around February 17, 2026, leading to broader system access. Notification letters were sent to impacted individuals starting May 29, 2026. Exposed data includes names, addresses, Social Security numbers, birth dates, driver's licenses or other government identification, mortgage application/servicing information for customers, and usernames/passwords for employees.

Plazahomemortgage
Z H logoRansomware
High

Data Leak at Zuther+Hautmann: Healthcare Sector Again Targeted by Cybercriminals

Zuther+Hautmann GmbH & Co. KG, a German specialist dealer for medical and hospital supplies and a homecare service provider, experienced a data leak. The ransomware group 'Play' is suspected to be responsible. The incident was registered on May 20, 2026, with public reporting and updates on May 28-29, 2026.

Z H
Carnivalcorp logoPhishing
High

Carnival Corporation Confirms Data Breach Affecting Nearly 6 Million Individuals

Carnival Corporation, one of the world's largest cruise operators, confirmed a data breach on May 28, 2026, weeks after the ShinyHunters hacking group claimed to have stolen millions of customer records. The incident originated from a phishing attack in April 2026 that compromised an employee's account, granting unauthorized access to a limited portion of the company's IT system. Notifications to affected individuals began on May 27, 2026.

Carnivalcorp
Microsoft logo
Medium

Microsoft Accused of Leaking Dutch Civil Servants' Data to US Government

Microsoft has been accused of leaking data belonging to Dutch civil servants, specifically those working for the Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP), to the US House of Representatives. The leaked data includes emails, minutes, and invitations with unredacted names.

Microsoft
Registrucentras logoMisconfiguration or publishing error
High

Major Data Leak at Lithuania's State Enterprise Centre of Registers Affects Nearly 20% of Population

A significant data leak at Lithuania's State Enterprise Centre of Registers exposed personal data of approximately 540,000 to over 600,000 people, nearly one-fifth of the country's population. The incident involved the misuse of login credentials, with some data potentially stolen as early as January 2026. The public disclosure and official statements occurred on May 28, 2026.

Registrucentras
Metro logo
Medium

Iranian Hackers Blamed for Los Angeles County Metropolitan Transportation Authority Breach

Iranian hackers were reportedly responsible for a breach of the Los Angeles County Metropolitan Transportation Authority (LA Metro) that disrupted parts of the transit environment in California. The investigation involved exposed internal data and operational disruption. Security researchers linked the intrusion to Iran-aligned Ababil activity, with reports describing stolen emails, backups, and a video showing access inside the target network.

Metro
Dentaquest logoUse of stolen credentials or exploit
Medium

DentaQuest Data Breach: ShinyHunters Threatens to Leak Data, Company Confirms Investigation

Attorneys working with ClassAction.org are looking into whether a class action lawsuit can be filed in light of the DentaQuest data breach. As part of their investigation, they need to hear from individuals who may have had their information exposed in the incident , including current and former DentaQuest members. DentaQuest Security Incident: What Happened? DentaQuest, a nationwide dental and vision insurance provider, has experienced a data breach involving the sensitive information of potentially millions of Americans. According to a  notice posted to its website on July 16, 2026 , DentaQuest detected on May 20, 2026 that unauthorized individuals had accessed certain data on its computer network. The company eventually determined following an investigation with independent cybersecurity experts that the breach occurred between May 17, 2026 and May 20, 2026, resulting in the acquisition and publish of sensitive information online. The notice states that the information affected by the DentaQuest data breach included names, addresses, Social Security numbers, member identification numbers, Medicaid and Medicare numbers, as well as dental or vision health information, including provider names, diagnoses, treatments and billing information. Dentaquest began sending affected individuals notice of the data breach, a sample of which can be seen below, on July 17, 2026. Though the total count has not been publicly disclosed, state government offices have preliminarily indicated that the body of affected individuals includes approximately 522,000 Massachusetts residents ,  3,973,000 Texas residents and  17,100 South Carolina residents . What You Can Do After the DentaQuest Data Breach If your information may have been exposed in the DentaQuest data breach, attorneys want to hear from you. You may be able to start a class action lawsuit to recover compensation for loss of privacy, time spent dealing with the breach, out-of-pocket costs, and more. A successful case could also force DentaQuest to ensure they take proper steps to protect the information they were entrusted with. Possibly affected by the DentaQuest data breach? Fill out the form on this page today. If you believe your information may have been exposed in the DentaQuest data breach, fill out the form on this page to get in touch with us. An attorney or legal representative may then reach out to you to explain more about this investigation and ask you a few questions. Remember, there is no cost to get in touch, and you are under no obligation to take action after speaking to someone. New cases and investigations, settlement deadlines, and news straight to your inbox. Whitfield Regional Hospital Data Breach 2026 Community Health Center of Buffalo Data Breach 2026 Advantage Home Health Care Data Breach 2026 Unlimited Technology Systems Data Breach 2026 Heart Care Centers of Illinois Data Breach 2026 Clover Health Investments Data Breach 2026 In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files ( ASC X12 transaction sets ) with some containing Medicaid IDs, while additional data appeared in member records and related files. DentaQuest acknowledged "a cybersecurity incident involving unauthorized access to a limited portion of our network" , and advised they had contained the attack and mitigated the threat. Use a password manager to generate and store strong, unique passwords for all your accounts. 1Password helps protect your data with industry-leading security. In Nederland adviseert een samenwerking van publieke en private organisaties mensen over hun online veiligheid op veiliginternetten.nl. If you haven’t already changed the password affected by this breach, do so immediately on every account where it was used. Wherever 2FA is supported, add an extra layer of security to your account.

Dentaquest
Nissanusa logoUse of stolen credentials or exploit
Medium

Nissan Americas Employee Data Compromised in Oracle PeopleSoft Zero-Day Attack by ShinyHunters

Nissan Americas confirmed a data breach affecting current and former employees, stemming from a targeted cyberattack exploiting a critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft software. The exploitation, attributed to the ShinyHunters extortion group, began as early as May 27, 2026, and continued until June 9, 2026. Sensitive employee data, including contact information, banking details, Social Security numbers, and tax records, was accessed.

Nissanusa
Beaconmutual logoRansomware
Medium

Beacon Mutual Insurance Co. Ransomware Attack Compromises 131,000 Rhode Islanders' Data

Beacon Mutual Insurance Co., Rhode Island's largest workers' compensation insurer, disclosed that highly sensitive personal information belonging to over 131,000 Rhode Islanders was compromised in a ransomware attack earlier in the year. An unauthorized person gained access to the company's system between January 7th and January 14th, accessing files containing names, Social Security numbers, driver's license numbers, financial account numbers, health insurance information, and/or medical treatment details.

Beaconmutual
Theoncologyinstitute logoRansomware
Medium

The Oncology Institute Reports Third-Party Cyber Attack Impacting Patient Information

U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522 Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits OpenSSL Fixes HollowByte Memory Exhaustion Bug Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer's Network U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets A cyberattack hit Nichirei, one of Japan's largest food companies New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog A deeper insight into the CloudWizard APT’s activity revealed a long-running activity Experts warn of a threat actor, tracked as CloudWizard APT, that is targeting organizations involved in the region of the Russo-Ukrainian conflict. On March 2023, researchers from Kaspersky spotted a previously unknown APT group, tracked as Bad Magic (aka Red Stinger), that targeted organizations in the region of the Russo-Ukrainian conflict. The attackers were observed using PowerMagic and CommonMagic implants. Looking for other implants with similarities with PowerMagic and CommonMagic, the researchers identified a different cluster of even more sophisticated malicious activities associated with the same threat actor. The victims of this cluster were located not only in the Donetsk, Lugansk and Crimea regions, but also in central and western Ukraine. The APT group targeted individuals, as well as diplomatic and research organizations in the area of the conflict. In the latest campaign uncovered by Kaspersky, the APT group, used a modular framework dubbed CloudWizard that supports spyware capabilities, including taking screenshots, microphone recording, harvesting Gmail inboxes, and keylogging. The Oncology Institute reports patient data potentially exposed in third-party vendor breach The Oncology Institute has confirmed that patient information was impacted in a cybersecurity incident involving a third-party software provider. The healthcare network first disclosed the security breach in November 2025, while the vendor’s investigation was still ongoing, as reported by Security Affairs. The Oncology Institute disclosed on May 20, 2026, that Kroll, a third-party administrator for an unnamed vendor, detected unauthorized access to systems that may have affected patient data. This incident follows a larger breach at Cognizant-owned TriZetto Provider Solutions in March 2026, which exposed sensitive information for over 3.4 million patients. The TriZetto breach, which began in November 2024, involved unauthorized access to records for insurance eligibility verification transactions, potentially exposing names, addresses, Social Security numbers, and insurance details. While no ransomware group has claimed responsibility for either incident, the potential exposure of patient data highlights significant risks within the healthcare supply chain. The Oncology Institute stated that the vendor has established a patient portal to provide information and address inquiries related to the breach.

Theoncologyinstitute
Charter logoUse of stolen credentials or exploit
Medium

Charter Communications (Spectrum) Data Breach Confirmed After ShinyHunters Extortion Threat

Charter Communications, operating as Spectrum, confirmed a data breach after the ShinyHunters extortion group claimed to have stolen customer data. The breach, which occurred around April 1, 2026, involved a vishing attack that compromised an employee's Microsoft Entra account, leading to unauthorized access and export of records from Charter's Salesforce environment. ShinyHunters threatened to leak the data if a ransom was not paid.

Charter
Docketwise logoPhishing
Medium

Docketwise Data Breach Impacts 143,000 Individuals

Docketwise, an immigration software provider, disclosed a data breach that exposed sensitive personal and immigration-related information belonging to approximately 143,000 individuals. The breach occurred around October 2025 when a threat actor cloned third-party partner repositories using valid credentials. The compromised data included names, addresses, dates of birth, Social Security numbers, driver's license numbers, passport and government ID numbers, financial account numbers and credentials, payment card numbers, tax identification numbers, health insurance policy numbers, medical condition or treatment information, and username and access information for non-financial accounts. This incident increases the risk of identity theft, targeted phishing, legal fraud, and misuse of confidential client records.

Docketwise
Grafana logoUse of stolen credentials or exploit
Medium

Grafana Labs Confirms Source Code Theft and Extortion Attempt

Grafana Labs confirmed that hackers stole its private codebase from a GitHub repository and attempted to extort the company. The breach was linked to a stolen access token, potentially compromised through a known vulnerability or a broader supply chain attack (TanStack campaign). Grafana Labs refused to pay the ransom.

Grafana
Spectrum logoMisconfiguration or publishing error
Medium

Charter Communications (Spectrum) Data Breach Confirmed After ShinyHunters Extortion Threat

Charter Communications, operating as Spectrum, confirmed a data breach on May 26, 2026, following threats from the ShinyHunters extortion group to leak stolen data. The breach, which occurred around April 1, 2026, involved a vishing attack that compromised an employee's Microsoft Entra account, granting access to Salesforce data. While Charter initially stated no sensitive personal information or CPNI was exfiltrated, later breach monitoring indicated the exposed dataset was tied to 4.9 million accounts, including names, email addresses, phone numbers, physical addresses, and job titles. Researchers later reported the leak covered at least 13 million people and nearly 10 million customer-support records.

Spectrum

Explore the intelligence

Explore current intelligence taxonomies

Explore the intelligence

Questions about current cybersecurity intelligence

Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.

12 answers across 4 topics

How to read and use the current intelligence overview.

What does this cybersecurity intelligence overview contain?

It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.

Where should I start exploring?

Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.

Does this page list every cybersecurity incident?

No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.

Browse current topics