Skip to main content

Explore Shadow Tier

Cybersecurity Topics

Shadow Tier organizes cybersecurity news and threat intelligence around the questions security and risk professionals ask: which sectors are affected, which attack patterns are visible and what impact do those developments create?

Live news

What’s happening now?

View all current signals →
High

CEVA Logistics Data Breach Impacts DELTA Fiber Nederland Partner, De Bijenkorf, Affecting Customer Data and Operations

On August 11, 2026, it was reported that a data breach at CEVA Logistics, a logistics partner, had impacted several companies, including De Bijenkorf, a partner of DELTA Fiber Nederland. The incident led to significant delays in processing orders, returns, and refunds for De Bijenkorf customers. The breach potentially exposed personal data of customers across the affected companies. The Dutch data protection authority (AP) received twelve notifications from companies regarding potentially leaked customer data due to their collaboration with CEVA. While the full extent of the data compromise is still under investigation, companies like De Bijenkorf have informed customers that unauthorized parties may have accessed their personal information. DELTA Fiber Nederland, as the parent company of ZeelandNet which reported on the incident, is indirectly connected to this supply chain breach through its partner's reliance on CEVA Logistics. The incident highlights the widespread impact of supply chain attacks on various businesses and their customers.

Explore data exposure and breach intelligence
High
Originenergy logoOriginenergy

Origin Energy Discloses Data Breach Affecting 900,000 Customers

On July 28, 2026, Origin Energy, a major Australian energy company, publicly confirmed a significant data breach impacting approximately 900,000 current and former customers. The breach led to unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. Origin Energy first identified a potential security threat in early July 2026, which was initially not deemed credible. However, new information on July 22, 2026, confirmed a security incident had occurred, prompting immediate action and notification of authorities. An alleged hacker provided a media outlet with a sample of 50 customer records and screenshots of internal Origin Energy systems, corroborating the data exfiltration. The incident is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. The specific technical vector used for initial access remains undisclosed.

Explore data exposure and breach intelligence
High
Ijsselstein logoIjsselstein

Municipality of IJsselstein Takes Files Offline Due to Data Leak

The municipality of IJsselstein removed several documents from its website on July 27, 2026, after a resident discovered that they contained personal data. These documents were found within the municipal council's information system, which violates privacy legislation. The municipality has reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and is reviewing all published meeting documents dating back to January 1, 2014. While affected individuals will be informed, the specific types of data exposed have not been disclosed. Locoburgemeester Peter Bekker emphasized the need to restore trust in the handling of personal data and prevent future occurrences. An investigation into the error is expected to take several months, during which parts of the system may be temporarily inaccessible.

Explore data exposure and breach intelligence
High
Iastate logoIastate

Iowa State University's Canvas Learning Platform Breached, Student Data Exposed

Iowa State University's Canvas learning management system was breached on July 26, 2026, displaying a hacker message that blocked access to the website and all its pages. The message advised users to "consult with a cyber advisory firm" and to "contact us privately at TOX to negotiate a settlement." This incident is part of a larger series of over 9,000 attacks affecting various educational institutions. The hackers, identified as the criminal extortion group ShinyHunters, had previously caused an outage on Canvas and are also linked to data thefts from Ticketmaster and Google. The compromised data includes names, email addresses, student ID numbers, and internal messages. Iowa State IT Security issued an email addressing the outage and advised students to seek alternative submission methods for coursework. The university's news service director, Angie Hunt, confirmed that Iowa State is one of many institutions affected by a nationwide Canvas platform outage. Instructure, the parent company of Canvas, has not provided a timeframe for resolving the issue. The group ShinyHunters claimed to have stolen over 3.65 terabytes of data, encompassing approximately 275 million records belonging to students, teachers, and staff, and threatened to release this data if their demands were not met. While the affected data may include full names, email addresses, student ID numbers, and messages, there is no evidence that passwords, dates of birth, government identifiers, or financial information were exposed. The sensitivity of some Canvas messages, which can contain medical and mental health information, adds to the concern. Officials are advising students, parents, and staff to be cautious of unsolicited messages claiming to be from Canvas or the university that request personal information or prompt immediate action. They also recommend monitoring accounts for unusual activity.

Explore data exposure and breach intelligence
High
Coupang logoCoupang

Coupang Data Breach: Authentication Failures Expose Customer Data in South Korea

South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January. South Korea's Deputy Minister for Cybersecurity and Network Policy publicly attributed the incident to management failures and authentication vulnerabilities during a press conference on July 24, 2026. The attacker exploited user authentication vulnerabilities to gain unauthorized access to accounts without proper login credentials, leading to a large-scale unauthorized information leak. South Korean authorities emphasized that the breach was not the result of highly sophisticated intrusion techniques, but rather stemmed from fundamental security weaknesses in authentication mechanisms and inadequate security management practices. The breach resulted in large-scale unauthorized access to customer information. The unauthorized access has since been terminated. This incident has also led to a record fine of $422 million by South Korea's Personal Information Protection Commission (PIPC) and ongoing diplomatic discussions between South Korea and the U.S. due to Coupang being an American-owned company operating in South Korea.

Explore data exposure and breach intelligence
High
Dropbox logoDropbox

Dropbox Suffers Data Breach in Phishing Attack Targeting GitHub Account

Dropbox, a cloud storage company, experienced a data breach when its GitHub account was compromised on October 13. The attackers gained access to 130 code repositories containing sensitive data, including API keys used by Dropbox developers. The incident was a result of a successful email phishing campaign that targeted Dropbox employees, impersonating CircleCI, a continuous integration and delivery platform. The phishing emails directed victims to a fake login page where they were prompted to enter their GitHub credentials and a One-Time Password (OTP) from their hardware authentication key. Dropbox was notified of the potential breach by GitHub on October 14. While the attackers accessed some credentials and API keys, Dropbox stated that customer accounts, passwords, or payment information were not compromised, nor were its core apps or infrastructure. The data accessed also included the names and email addresses of a few thousand Dropbox employees, current and past customers, sales leads, and vendors. In response, Dropbox is enhancing its security by implementing WebAuthn and hardware tokens or biometrics.

Explore phishing and social-engineering intelligence

How is Shadow Tier intelligence organized?

Each signal can connect an affected sector, the attack pattern used and the resulting impact. Exploring these views together shows not only what happened, but how and where the risk may be relevant.

Where can you start exploring now?

FAQ

Questions about Shadow Tier topics

What is a cybersecurity topic on Shadow Tier?

A topic is a structured way to explore current reporting by attack method, incident impact, affected sector, company or country.

Can one signal belong to several topics?

Yes. The same incident can involve multiple attack methods, cause several impacts and affect more than one organization or sector.

How do topic pages stay current?

Topic pages use the current classified signal set, so their examples and counts update as reporting is added and reviewed.