This week
This week.
Incidents reported in the last 90 days, with the way in as the source states it and what we check for it. Each item has its own page, and the source is cited there.
- 8 Oct 2026 · United StatesUS critical infrastructureHow they got in, as reported: a known flaw in software the victim ran.
- 8 Oct 2026 · United StatesThousands of US organizationsHow they got in, as reported: a known flaw in software the victim ran.
- 8 Oct 2026 · South KoreaSouth Korean financial firmsHow they got in, as reported: a known flaw in software the victim ran.
- 8 Oct 2026 · RussiaOrganizations using Fortinet devicesHow they got in, as reported: stolen or reused passwords.
- 8 Oct 2026 · United StatesOracle HealthHow they got in, as reported: stolen or reused passwords.
- 8 Oct 2026 · United StatesClients of MonsterCloudThe source does not state how they got in.
- 7 Oct 2026 · JapanAdvantestThe source does not state how they got in.
- 7 Oct 2026 · United StatesSouthern CompanyThe source does not state how they got in.
- 7 Oct 2026 · South KoreaAdvantest CorporationThe source does not state how they got in.
- 7 Oct 2026 · South KoreaSpotifyThe source does not state how they got in.
- 7 Oct 2026 · South KoreaExposed AI server operatorsHow they got in, as reported: a system left reachable from the internet.
- 7 Oct 2026 · South KoreaGoogleHow they got in, as reported: a supplier or vendor that was compromised first.
- 7 Oct 2026 · South KoreaFortinet FortiGate firewall ownersHow they got in, as reported: stolen or reused passwords.
- 7 Oct 2026 · South KoreaMonsterCloud customersThe source does not state how they got in.
- 7 Oct 2026 · United StatesArizona court systemHow they got in, as reported: email made to look like it came from a trusted sender.
- 7 Oct 2026 · United StatesThousands of US entitiesThe source does not state how they got in.
- 6 Oct 2026 · GermanyWikimedia FoundationHow they got in, as reported: automated AI tools that work through many organizations at once.
- 5 Oct 2026 · United StatesWindRose Health NetworkHow they got in, as reported: a supplier or vendor that was compromised first.
- 5 Oct 2026 · United StatesUniversity of Illinois Chicago (College of Medicine)The source does not state how they got in.
- 3 Oct 2026 · DenmarkTechnical University of DenmarkHow they got in, as reported: stolen or reused passwords.
- 2 Oct 2026 · CanadaKingston PoliceHow they got in, as reported: stolen or reused passwords.
- 2 Oct 2026 · United StatesUniversities and private organizations in USThe source does not state how they got in.
- 2 Oct 2026 · United StatesUS think tanks and universitiesHow they got in, as reported: email made to look like it came from a trusted sender.
- 2 Oct 2026 · United StatesU.S. financial institutionsThe source does not state how they got in.
- 2 Oct 2026 · United StatesFrontline EducationHow they got in, as reported: a supplier or vendor that was compromised first.
- 2 Oct 2026 · United StatesVicksburg, MississippiThe source does not state how they got in.
- 2 Oct 2026 · United StatesAngMar Management ServicesThe source does not state how they got in.
- 2 Oct 2026 · United StatesA US universityHow they got in, as reported: a known flaw in software the victim ran.
- 2 Oct 2026MicrosoftThe source does not state how they got in.
- 1 Oct 2026 · CanadaArchives Canada / Canadian government websitesHow they got in, as reported: automated AI tools that work through many organizations at once.
- 1 Oct 2026 · CanadaLibrary and Archives CanadaHow they got in, as reported: automated AI tools that work through many organizations at once.
- 1 Oct 2026 · CanadaUS and Canadian government websitesHow they got in, as reported: a known flaw in software the victim ran.
- 1 Oct 2026 · United StatesCPAP Medical Supplies and ServicesThe source does not state how they got in.
- 1 Oct 2026 · United StatesSaber HealthcareThe source does not state how they got in.
- 1 Oct 2026 · United StatesVictims across the US and Puerto RicoHow they got in, as reported: a known flaw in software the victim ran.
- 1 Oct 2026 · United StatesKillSec victimsHow they got in, as reported: a known flaw in software the victim ran.
- 1 Oct 2026 · United StatesAI experts across universities and firmsHow they got in, as reported: email made to look like it came from a trusted sender.
- 1 Oct 2026 · United StatesAmerican universities and companiesHow they got in, as reported: stolen or reused passwords.
- 30 Sep 2026 · United StatesThe Mental Health AssociationThe source does not state how they got in.
- 30 Sep 2026 · United StatesUS healthcare organizationsThe source does not state how they got in.
- 30 Sep 2026Ukraine-supporting organizations and governmentsHow they got in, as reported: email made to look like it came from a trusted sender.
- 30 Sep 2026 · United StatesDefense Manpower Data Center (U.S. Department of Defense)How they got in, as reported: a known flaw in software the victim ran.
- 30 Sep 2026 · United StatesComputer Systems Integrated Inc.The source does not state how they got in.
- 29 Sep 2026 · United StatesUsers searching for ChatGPTHow they got in, as reported: an AI answer pointing people to the wrong place.
- 29 Sep 2026 · United StatesBusinesses in Iowa and across USHow they got in, as reported: stolen or reused passwords.
- 29 Sep 2026 · United StatesOrganizations in North America and EuropeHow they got in, as reported: a known flaw in software the victim ran.
- 29 Sep 2026 · United StatesArizona Supreme CourtThe source does not state how they got in.
- 28 Sep 2026 · United StatesModoc Medical CenterThe source does not state how they got in.
- 28 Sep 2026 · CanadaHealth P.E.I.How they got in, as reported: a supplier or vendor that was compromised first.
- 28 Sep 2026 · United StatesTelecommunications companiesHow they got in, as reported: stolen or reused passwords.
- 28 Sep 2026 · United StatesHogan LovellsThe source does not state how they got in.
- 28 Sep 2026A grandfather fooled by a cloned voiceHow they got in, as reported: a cloned voice or video of a real person.
- 28 Sep 2026Federal Bureau of InvestigationHow they got in, as reported: a known flaw in software the victim ran.
- 28 Sep 2026 · United StatesAT&T and VerizonHow they got in, as reported: stolen or reused passwords.
- 26 Sep 2026 · United StatesOracle PeopleSoft usersHow they got in, as reported: a known flaw in software the victim ran.
- 25 Sep 2026 · United StatesUniversity of New MexicoThe source does not state how they got in.
- 25 Sep 2026 · CanadaOpenAIThe source does not state how they got in.
- 25 Sep 2026Supabase customersHow they got in, as reported: a system left reachable from the internet.
- 25 Sep 2026 · CanadaÉcole Guillaume-MathieuThe source does not state how they got in.
- 25 Sep 2026 · United StatesWayne Memorial HospitalThe source does not state how they got in.
- 25 Sep 2026 · United StatesMedImpact Healthcare SystemsThe source does not state how they got in.
- 25 Sep 2026 · CanadaRetail banking customersHow they got in, as reported: a domain made to look like the real one.
- 25 Sep 2026 · United StatesUS healthcare and pharmaceutical organizationsHow they got in, as reported: a domain made to look like the real one.
- 24 Sep 2026 · CanadaBurnaby School DistrictThe source does not state how they got in.
- 24 Sep 2026 · United StatesGastroenterology & Hepatology of Central New YorkThe source does not state how they got in.
- 22 Sep 2026National Capital CommissionThe source does not state how they got in.
- 22 Sep 2026 · United StatesUS water and wastewater providersHow they got in, as reported: stolen or reused passwords.
- 21 Sep 2026 · United StatesUnited Language GroupThe source does not state how they got in.
- 21 Sep 2026 · CanadaIDScan.netThe source does not state how they got in.
- 18 Sep 2026 · United StatesDefense Manpower Data CenterHow they got in, as reported: a known flaw in software the victim ran.
- 14 Sep 2026 · United StatesVictims of Dover AFB BEC scamHow they got in, as reported: stolen or reused passwords.
- 29 Jul 2026 · United StatesAmgen Cloud Data Exfiltration IncidentThe source does not state how they got in.