Incident contained, investigation ongoing
The ransomware gang known as Gentlemen has claimed responsibility for an extortion attempt targeting Spanish defense and technology company Indra Group. The company has confirmed a cybersecurity incident affecting one of its subsidiaries.
Supply Chain Attacks increase
A new ranking reveals that hacker groups are increasingly targeting supply chains and relying on rented infrastructure with market shares of up to 89 percent.
U.S. healthcare provider One Medical
The cybercrime group ShinyHunters claims it has exfiltrated 8.8 terabytes of data from the U.S. healthcare provider One Medical, a subsidiary of Amazon. According to the group, the stolen dataset includes both corporate and patient-related information.
$25 Million Ransom Demand
The cyber extortion group FulcrumSec, active since October 2025, claims it maintained long-term access to systems at Danish pharmaceutical giant Novo Nordisk and exfiltrated more than one terabyte of sensitive data. The company did not pay the demanded ransom of $25 million.
Suspected Cyberattack
The cybercriminal group ShinyHunters has claimed responsibility for a large-scale data breach targeting the Council of Europe. According to the group, the incident involves personal and payroll data belonging to around 10,000 employees.
Oracle PeopleSoft Under Attack
The cybercriminal group ShinyHunters has exploited a critical zero-day vulnerability in Oracle PeopleSoft, compromising more than 100 organizations worldwide.
Exposed API Endpoint
A misconfigured API endpoint allowed unauthorized users to access data stored in ServiceNow instances. The company did not release a fix until several weeks after receiving a bug bounty report.
Attack on Global Exchange
A major global stock exchange operator has fallen victim to a cyber-espionage campaign after attackers maintained covert access to a senior executive’s email account for five months.
Ransomware Attack on Marks & Spencer
A cyberattack carried out by the Scattered Spider group has cost Marks & Spencer (M&S) CEO Stuart Machin his annual bonus for the 2025/26 financial year.
Lapsus$ Dumps 180GB of Vodafone Data
After a reportedly failed extortion attempt, the cybercrime group Lapsus$ has published around 180 GB of data from Vodafone, including software source code and network plans. According to the company, no customer data appears to be affected.