Compare shared topics, actors and incident patterns before opening the full signal.
Originenergy·Jul 28, 2026Same sectorSame impact area
On July 28, 2026, Origin Energy, a major Australian energy company, publicly confirmed a significant data breach impacting approximately 900,000 current and former customers. The breach led to unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. Origin Energy first identified a potential security threat in early July 2026, which was initially not deemed credible. However, new information on July 22, 2026, confirmed a security incident had occurred, prompting immediate action and notification of authorities. An alleged hacker provided a media outlet with a sample of 50 customer records and screenshots of internal Origin Energy systems, corroborating the data exfiltration. The incident is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. The specific technical vector used for initial access remains undisclosed.
Iastate·Jul 26, 2026Same sectorSame impact area
Iowa State University's Canvas learning management system was breached on July 26, 2026, displaying a hacker message that blocked access to the website and all its pages. The message advised users to "consult with a cyber advisory firm" and to "contact us privately at TOX to negotiate a settlement." This incident is part of a larger series of over 9,000 attacks affecting various educational institutions. The hackers, identified as the criminal extortion group ShinyHunters, had previously caused an outage on Canvas and are also linked to data thefts from Ticketmaster and Google. The compromised data includes names, email addresses, student ID numbers, and internal messages. Iowa State IT Security issued an email addressing the outage and advised students to seek alternative submission methods for coursework. The university's news service director, Angie Hunt, confirmed that Iowa State is one of many institutions affected by a nationwide Canvas platform outage. Instructure, the parent company of Canvas, has not provided a timeframe for resolving the issue. The group ShinyHunters claimed to have stolen over 3.65 terabytes of data, encompassing approximately 275 million records belonging to students, teachers, and staff, and threatened to release this data if their demands were not met. While the affected data may include full names, email addresses, student ID numbers, and messages, there is no evidence that passwords, dates of birth, government identifiers, or financial information were exposed. The sensitivity of some Canvas messages, which can contain medical and mental health information, adds to the concern. Officials are advising students, parents, and staff to be cautious of unsolicited messages claiming to be from Canvas or the university that request personal information or prompt immediate action. They also recommend monitoring accounts for unusual activity.
Axios·Jul 23, 2026Same sectorSame impact area
On July 23, 2026, the Axios npm package, a widely used JavaScript HTTP client, was compromised in a sophisticated supply chain attack. The attackers hijacked a maintainer account and injected a malicious dependency, `plain-crypto-js`, into versions `axios@1.14.1` and `axios@0.30.4`. This malicious dependency was designed to download multi-stage payloads, including a remote access trojan, onto developer machines and CI/CD pipelines globally. The compromise was detected and the malicious packages were removed from npm within approximately three hours. The attack was characterized by its operational sophistication, bypassing standard security controls like MFA through a targeted social engineering campaign against the maintainer. The malicious code was capable of breaching major operating systems including Windows, macOS, and Linux. CISA issued an alert providing guidance for detection and remediation, urging organizations to monitor code repositories, CI/CD pipelines, and developer machines, and to rotate credentials that may have been exposed. Google Threat Intelligence Group publicly attributed the compromise to UNC1069, a North Korea-nexus, financially motivated threat actor. The incident highlights the significant risks associated with software supply chain attacks and the importance of robust security measures for open-source dependencies.
Dropbox·Jul 23, 2026Same sectorSame impact area
Dropbox, a cloud storage company, experienced a data breach when its GitHub account was compromised on October 13. The attackers gained access to 130 code repositories containing sensitive data, including API keys used by Dropbox developers. The incident was a result of a successful email phishing campaign that targeted Dropbox employees, impersonating CircleCI, a continuous integration and delivery platform. The phishing emails directed victims to a fake login page where they were prompted to enter their GitHub credentials and a One-Time Password (OTP) from their hardware authentication key. Dropbox was notified of the potential breach by GitHub on October 14. While the attackers accessed some credentials and API keys, Dropbox stated that customer accounts, passwords, or payment information were not compromised, nor were its core apps or infrastructure. The data accessed also included the names and email addresses of a few thousand Dropbox employees, current and past customers, sales leads, and vendors. In response, Dropbox is enhancing its security by implementing WebAuthn and hardware tokens or biometrics.
Doordash·Jul 22, 2026Same sectorSame impact area
DoorDash, the popular food delivery platform, publicly acknowledged a cybersecurity incident that compromised the personal information of an undisclosed number of users. The breach, which occurred on October 25, was a result of a social engineering attack targeting a company employee. This allowed an unauthorized third party to gain access to DoorDash's internal systems. The compromised data varied by individual but potentially included first and last names, phone numbers, email addresses, and physical addresses of customers, Dashers (delivery drivers), and merchants across the United States, Canada, Australia, and New Zealand. DoorDash emphasized that no sensitive financial information, such as Social Security numbers, government-issued IDs, driver's license details, bank information, or payment card data, was accessed. The company's security team identified and shut down the unauthorized access shortly after its detection, launched an internal investigation, and notified law enforcement. DoorDash has also implemented multiple security enhancements, including upgraded security systems and additional employee training programs focused on social engineering awareness. While the company has stated there is no indication the data has been misused for fraud or identity theft, affected users are advised to be cautious of unsolicited communications requesting personal information. This incident marks DoorDash's third known cybersecurity incident in six years, highlighting the persistent threat of social engineering attacks.
Yonsei·Jul 21, 2026Same sectorSame impact area
On July 21, 2026, the Korea National Diplomatic Academy, an institution affiliated with South Korea's Ministry of Foreign Affairs, confirmed a significant data leak impacting approximately 10,000 records of current and retired diplomats. The breach, which occurred in the academy's online education system, was discovered in early February 2026 after suspicious access was reported by a government agency. An unidentified attacker exploited a zero-day vulnerability in the server software and weaknesses in system security settings, maintaining unauthorized access from April to May 2025 until February 2026. The compromised data reportedly included names, user IDs, email addresses, encrypted passwords, job titles, and affiliated departments. While sensitive personal information such as resident registration numbers, mobile phone numbers, and home addresses were not present on the affected server, the leak of diplomat information raises concerns, especially given that the full list of diplomats and personnel at overseas missions is not publicly disclosed. The Foreign Ministry is investigating the incident and has urgently shut down the compromised system. They are operating under the assumption that a substantial volume of data was compromised, though the exact scale of the damage is still being assessed. The incident highlights the challenges in detecting sophisticated attacks that leverage previously unknown vulnerabilities.