Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 87 results
Active filter:tag: #data-breach✕ clear
Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoinhighperson_alertThreat Actor
person_alertThreat Actor

Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin

The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.

Apple27 Jul · 15:29 UTC
ShinyHunters Claims Ernst & Young Breach via Supply-Chain Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Ernst & Young Breach via Supply-Chain Attack

ShinyHunters is a financially motivated cybercrime extortion gang known for conducting data breaches and operating a data leak site to pressure victims into paying ransoms.

Ernst & Young27 Jul · 13:12 UTC
ShinyHunters-themed sextortion campaign exploits leaked breach datahighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters-themed sextortion campaign exploits leaked breach data

ShinyHunters is a known extortion group that has leaked data from multiple high-profile breaches including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill.

BleepingComputer25 Jul · 12:16 UTC
AI Agent Used in Alleged Breach of Thai Finance MinistryhighpublicGeopolitical
publicGeopolitical

AI Agent Used in Alleged Breach of Thai Finance Ministry

The alleged intrusion into Thailand's Ministry of Finance represents a significant evolution in cyber threat tradecraft, demonstrating the operational use of autonomous AI agents to automate post-exploitation activities.

Hermes AI agent24 Jul · 17:09 UTC
Illinois man sentenced for social engineering attack on 750+ Snapchat usershighpublicGeopolitical
publicGeopolitical

Illinois man sentenced for social engineering attack on 750+ Snapchat users

This case represents a domestic criminal prosecution within the United States for cybercrime targeting individual consumers. The incident reflects the persistent challenge of social engineering attacks against commercial platform users and the exploi…

Snapchat24 Jul · 09:17 UTC
Origin Energy breach exposes 2M Australian customer recordshighpublicGeopolitical
publicGeopolitical

Origin Energy breach exposes 2M Australian customer records

The breach of Origin Energy, Australia's largest energy retailer with $8.5 billion in annual revenue and cross-border holdings in UK renewable energy, underscores the persistent targeting of critical infrastructure providers in the Indo-Pacific regio…

Origin Energy23 Jul · 18:14 UTC
South Korea discloses 10-month breach of diplomatic training platformhighpublicGeopolitical
publicGeopolitical

South Korea discloses 10-month breach of diplomatic training platform

The compromise of South Korea's National Diplomatic Academy represents a significant intelligence collection operation targeting a key U.S. ally in Northeast Asia.

BleepingComputer22 Jul · 18:06 UTC
Autonomous AI Agent Breaches Hugging Face Repositoryhighperson_alertThreat Actor
person_alertThreat Actor

Autonomous AI Agent Breaches Hugging Face Repository

The threat actor is identified as an autonomous AI agent system—a novel adversary class representing machine-driven attack capabilities operating with minimal or no human intervention.

Hugging Face20 Jul · 03:27 UTC
Mount Royal University in Calgary confirms data breach and deletionhighpublicGeopolitical
publicGeopolitical

Mount Royal University in Calgary confirms data breach and deletion

The breach of Mount Royal University represents a typical pattern in the current cyber threat landscape affecting higher education institutions across North America.

Mount Royal University8 Jul · 19:26 UTC
KDDI breach exposes 12M records across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 12M records across Japanese ISP ecosystem

The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.

KDDI8 Jul · 09:24 UTC
Scattered Spider Linked to U.S. Luxury Retail Breach via Device IDhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Linked to U.S. Luxury Retail Breach via Device ID

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.

The Hacker News7 Jul · 11:27 UTC
Kairos extorts $1M from U.S. government via data theft without encryptionhighperson_alertThreat Actor
person_alertThreat Actor

Kairos extorts $1M from U.S. government via data theft without encryption

Kairos is a financially motivated threat actor that employs extortion tactics focused on data theft without deploying traditional ransomware encryption. The group targeted a U.S.

The Hacker News4 Jul · 10:47 UTC
FBI seizes NetNut proxy domains linked to two-million-device botnethighpublicGeopolitical
publicGeopolitical

FBI seizes NetNut proxy domains linked to two-million-device botnet

The FBI's seizure of domains associated with NetNut, a residential proxy service operated by Israeli firm Alarum Technologies, represents a significant law enforcement action targeting the infrastructure enabling large-scale botnet operations.

Alarum Technologies2 Jul · 17:27 UTC
ShinyHunters Breaches Medtronic Healthcare Device Manufacturerhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Medtronic Healthcare Device Manufacturer

ShinyHunters is a financially-motivated cybercrime group known for large-scale data breaches and database exfiltration operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive data…

Medtronic2 Jul · 02:25 UTC
Kubota North America reports month-long network intrusion in 2024highpublicGeopolitical
publicGeopolitical

Kubota North America reports month-long network intrusion in 2024

The extended unauthorized access to Kubota North America's network systems highlights vulnerabilities in critical infrastructure sectors, particularly manufacturing and agriculture.

Kubota1 Jul · 19:09 UTC
DHS Confirms Breach of Homeland Security Information NetworkhighpublicGeopolitical
publicGeopolitical

DHS Confirms Breach of Homeland Security Information Network

The compromise of the Homeland Security Information Network (HSIN) represents a significant breach of a critical federal information-sharing infrastructure.

Department of Homeland Security1 Jul · 15:32 UTC
Aflac Japan breach exposes personal and financial datahighpublicGeopolitical
publicGeopolitical

Aflac Japan breach exposes personal and financial data

The breach at Aflac's Japan subsidiary underscores the persistent targeting of financial services firms operating in major economies. Japan represents a high-value target environment due to its advanced digital economy, aging population with signific…

Aflac30 Jun · 09:12 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…

Oracle29 Jun · 18:40 UTC
ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIChighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…

Oracle29 Jun · 18:30 UTC
Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searcheshighperson_alertThreat Actor
person_alertThreat Actor

Malicious Chrome Extension Impersonates Perplexity AI to Intercept Searches

The threat actor behind this campaign remains unattributed. The operation demonstrates a financially or espionage-motivated adversary leveraging social engineering through brand impersonation of Perplexity AI, a popular search technology.

Google29 Jun · 16:40 UTC
KDDI breach exposes 14.2M email accounts across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 14.2M email accounts across Japanese ISP ecosystem

The breach at KDDI Corporation, one of Japan's largest telecommunications operators, highlights systemic vulnerabilities in shared infrastructure models within critical communications sectors.

KDDI Corporation28 Jun · 12:13 UTC
Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assetshighperson_alertThreat Actor
person_alertThreat Actor

Polish Authorities Dismantle SIM-Swapping Gang Targeting Crypto Assets

This organized cybercrime group operated in Poland, conducting SIM-swapping attacks with the primary motivation of financial gain through cryptocurrency theft.

BleepingComputer25 Jun · 20:37 UTC
Snoopy Sentenced to 18 Months for DraftKings Account Compromisehighperson_alertThreat Actor
person_alertThreat Actor

Snoopy Sentenced to 18 Months for DraftKings Account Compromise

Snoopy is a 21-year-old individual arrested and sentenced for unauthorized access to customer accounts on the DraftKings sports betting platform in November 2022.

DraftKings24 Jun · 19:55 UTC
Tata Electronics confirms cyberattack and data leak on IT infrastructurehighpublicGeopolitical
publicGeopolitical

Tata Electronics confirms cyberattack and data leak on IT infrastructure

Tata Electronics, a subsidiary of India's Tata Group conglomerate, has confirmed a cyberattack that compromised portions of its IT infrastructure and resulted in data exfiltration.

Tata Electronics23 Jun · 19:06 UTC
Scattered Spider Members Plead Guilty to Transport for London Attackhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Members Plead Guilty to Transport for London Attack

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944 by various vendors) is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.

Transport for London23 Jun · 14:12 UTC
Scattered Spider Members Plead Guilty to Transport for London Breachhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Members Plead Guilty to Transport for London Breach

Scattered Spider (G1015), also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944, is a financially motivated cybercrime group known for sophisticated social engineering and identity-based attacks.

Transport for London23 Jun · 13:31 UTC
Icarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokenshighperson_alertThreat Actor
person_alertThreat Actor

Icarus Extortion Group Breaches Klue, Steals Salesforce OAuth Tokens

Icarus is an extortion-focused threat actor that has publicly claimed responsibility for breaching the market intelligence platform Klue. The group's motivation appears to be financially driven, targeting SaaS and market intelligence platforms to ste…

Klue19 Jun · 20:31 UTC
Texas Parks and Wildlife vendor breach exposes 3M+ recordshighpublicGeopolitical
publicGeopolitical

Texas Parks and Wildlife vendor breach exposes 3M+ records

The breach at a Texas state agency vendor underscores persistent vulnerabilities in third-party supply chains supporting U.S. public administration. While no attribution has been disclosed, the exposure of driver's license data and personally identif…

BleepingComputer19 Jun · 14:12 UTC
CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leakhighpublicGeopolitical
publicGeopolitical

CISA warns of 74,000 Fortinet credentials exposed in FortiBleed leak

The exposure of approximately 74,000 Fortinet firewall and VPN credentials represents a significant supply-side vulnerability affecting critical infrastructure globally.

Fortinet19 Jun · 04:47 UTC
Icarus Threat Actor Exploits OAuth to Steal Salesforce Data via Kluehighperson_alertThreat Actor
person_alertThreat Actor

Icarus Threat Actor Exploits OAuth to Steal Salesforce Data via Klue

Icarus is a threat actor conducting an ongoing extortion campaign targeting organizations through supply chain compromise. The actor exploited OAuth authentication mechanisms to breach Klue, a market intelligence platform, gaining unauthorized access…

Klue18 Jun · 12:19 UTC