Shadow Tier organizes cybersecurity news and threat intelligence around the questions security and risk professionals ask: which sectors are affected, which attack patterns are visible and what impact do those developments create?
On July 28, 2026, Origin Energy, a major Australian energy company, publicly confirmed a significant data breach impacting approximately 900,000 current and former customers. The breach led to unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. Origin Energy first identified a potential security threat in early July 2026, which was initially not deemed credible. However, new information on July 22, 2026, confirmed a security incident had occurred, prompting immediate action and notification of authorities. An alleged hacker provided a media outlet with a sample of 50 customer records and screenshots of internal Origin Energy systems, corroborating the data exfiltration. The incident is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. The specific technical vector used for initial access remains undisclosed.
The municipality of IJsselstein removed several documents from its website on July 27, 2026, after a resident discovered that they contained personal data. These documents were found within the municipal council's information system, which violates privacy legislation. The municipality has reported the incident to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and is reviewing all published meeting documents dating back to January 1, 2014. While affected individuals will be informed, the specific types of data exposed have not been disclosed. Locoburgemeester Peter Bekker emphasized the need to restore trust in the handling of personal data and prevent future occurrences. An investigation into the error is expected to take several months, during which parts of the system may be temporarily inaccessible.
Iowa State University's Canvas learning management system was breached on July 26, 2026, displaying a hacker message that blocked access to the website and all its pages. The message advised users to "consult with a cyber advisory firm" and to "contact us privately at TOX to negotiate a settlement." This incident is part of a larger series of over 9,000 attacks affecting various educational institutions. The hackers, identified as the criminal extortion group ShinyHunters, had previously caused an outage on Canvas and are also linked to data thefts from Ticketmaster and Google. The compromised data includes names, email addresses, student ID numbers, and internal messages. Iowa State IT Security issued an email addressing the outage and advised students to seek alternative submission methods for coursework. The university's news service director, Angie Hunt, confirmed that Iowa State is one of many institutions affected by a nationwide Canvas platform outage. Instructure, the parent company of Canvas, has not provided a timeframe for resolving the issue. The group ShinyHunters claimed to have stolen over 3.65 terabytes of data, encompassing approximately 275 million records belonging to students, teachers, and staff, and threatened to release this data if their demands were not met. While the affected data may include full names, email addresses, student ID numbers, and messages, there is no evidence that passwords, dates of birth, government identifiers, or financial information were exposed. The sensitivity of some Canvas messages, which can contain medical and mental health information, adds to the concern. Officials are advising students, parents, and staff to be cautious of unsolicited messages claiming to be from Canvas or the university that request personal information or prompt immediate action. They also recommend monitoring accounts for unusual activity.
South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January. South Korea's Deputy Minister for Cybersecurity and Network Policy publicly attributed the incident to management failures and authentication vulnerabilities during a press conference on July 24, 2026. The attacker exploited user authentication vulnerabilities to gain unauthorized access to accounts without proper login credentials, leading to a large-scale unauthorized information leak. South Korean authorities emphasized that the breach was not the result of highly sophisticated intrusion techniques, but rather stemmed from fundamental security weaknesses in authentication mechanisms and inadequate security management practices. The breach resulted in large-scale unauthorized access to customer information. The unauthorized access has since been terminated. This incident has also led to a record fine of $422 million by South Korea's Personal Information Protection Commission (PIPC) and ongoing diplomatic discussions between South Korea and the U.S. due to Coupang being an American-owned company operating in South Korea.
Dropbox, a cloud storage company, experienced a data breach when its GitHub account was compromised on October 13. The attackers gained access to 130 code repositories containing sensitive data, including API keys used by Dropbox developers. The incident was a result of a successful email phishing campaign that targeted Dropbox employees, impersonating CircleCI, a continuous integration and delivery platform. The phishing emails directed victims to a fake login page where they were prompted to enter their GitHub credentials and a One-Time Password (OTP) from their hardware authentication key. Dropbox was notified of the potential breach by GitHub on October 14. While the attackers accessed some credentials and API keys, Dropbox stated that customer accounts, passwords, or payment information were not compromised, nor were its core apps or infrastructure. The data accessed also included the names and email addresses of a few thousand Dropbox employees, current and past customers, sales leads, and vendors. In response, Dropbox is enhancing its security by implementing WebAuthn and hardware tokens or biometrics.
On July 23, 2026, the Axios npm package, a widely used JavaScript HTTP client, was compromised in a sophisticated supply chain attack. The attackers hijacked a maintainer account and injected a malicious dependency, `plain-crypto-js`, into versions `axios@1.14.1` and `axios@0.30.4`. This malicious dependency was designed to download multi-stage payloads, including a remote access trojan, onto developer machines and CI/CD pipelines globally. The compromise was detected and the malicious packages were removed from npm within approximately three hours. The attack was characterized by its operational sophistication, bypassing standard security controls like MFA through a targeted social engineering campaign against the maintainer. The malicious code was capable of breaching major operating systems including Windows, macOS, and Linux. CISA issued an alert providing guidance for detection and remediation, urging organizations to monitor code repositories, CI/CD pipelines, and developer machines, and to rotate credentials that may have been exposed. Google Threat Intelligence Group publicly attributed the compromise to UNC1069, a North Korea-nexus, financially motivated threat actor. The incident highlights the significant risks associated with software supply chain attacks and the importance of robust security measures for open-source dependencies.
Each signal can connect an affected sector, the attack pattern used and the resulting impact. Exploring these views together shows not only what happened, but how and where the risk may be relevant.