Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

27 / 87 results
Active filter:tag: #data-breach✕ clear
Junior Hacker targets French automotive sector with credential thefthighperson_alertThreat Actor
person_alertThreat Actor

Junior Hacker targets French automotive sector with credential theft

Junior Hacker is a French-speaking threat actor targeting small businesses in the French automotive sector. The actor demonstrates financially motivated objectives, focusing on credential theft for banking and email access.

The Hacker News17 Jun · 14:00 UTC
ShinyHunters Claims Responsibility for Kodak Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Responsibility for Kodak Data Breach

ShinyHunters is a financially motivated cybercrime group known for conducting data theft and extortion operations against organizations across multiple sectors.

Kodak17 Jun · 05:07 UTC
ShinyHunters Claims Council of Europe Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Council of Europe Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, targeting organizations across multiple sectors to steal sensitive databases and person…

Council of Europe15 Jun · 14:37 UTC
China-Linked Espionage Group Deploys InfiniteRed via REDCap Servershighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Espionage Group Deploys InfiniteRed via REDCap Servers

This activity is attributed to a China-linked espionage group targeting healthcare and medical research sectors. The actor's motivation appears to be intelligence collection focused on sensitive medical research data, consistent with strategic intere…

REDCap15 Jun · 12:00 UTC
ShinyHunters Breaches 137K+ School Staff via Salesforce Attackhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 137K+ School Staff via Salesforce Attack

ShinyHunters is a financially motivated cybercrime actor specializing in large-scale data theft and extortion operations. The group has established a reputation for targeting cloud-based platforms and third-party service providers to compromise downs…

Salesforce15 Jun · 10:38 UTC
Former Iowa school IT employee sentenced for insider cyberattackhighpublicGeopolitical
publicGeopolitical

Former Iowa school IT employee sentenced for insider cyberattack

This incident represents a domestic insider threat case within the United States education sector, rather than a state-sponsored or geopolitically motivated cyberattack. The prosecution and sentencing reflect U.S.

BleepingComputer13 Jun · 18:53 UTC
Novo Nordisk discloses clinical trial data breach in DenmarkhighpublicGeopolitical
publicGeopolitical

Novo Nordisk discloses clinical trial data breach in Denmark

The breach at Novo Nordisk, a Danish pharmaceutical giant controlling approximately 50% of the global insulin market, highlights the strategic vulnerability of critical healthcare infrastructure.

Novo Nordisk12 Jun · 08:13 UTC
French Government Messaging Platform Tchap Breached, 73,000 Accounts AffectedhighpublicGeopolitical
publicGeopolitical

French Government Messaging Platform Tchap Breached, 73,000 Accounts Affected

The compromise of Tchap, France's sovereign encrypted messaging solution developed as an alternative to foreign platforms, represents a significant breach of government communications infrastructure.

Tchap12 Jun · 05:09 UTC
Japanese utility loses drive with 10.9M customer recordshighpublicGeopolitical
publicGeopolitical

Japanese utility loses drive with 10.9M customer records

The incident at Kyushu Electric Power Co., Inc. represents a physical security failure rather than a cyber intrusion, but underscores the vulnerability of critical infrastructure operators to data exposure.

Kyushu Electric Power Co., Inc.11 Jun · 21:14 UTC
South Korea issues record $409M fine to Coupang for 37M-user breachhighpublicGeopolitical
publicGeopolitical

South Korea issues record $409M fine to Coupang for 37M-user breach

The unprecedented fine against Coupang reflects South Korea's increasingly assertive regulatory posture on data protection, aligning Seoul with global trends toward stringent enforcement of privacy frameworks.

Coupang11 Jun · 10:52 UTC
University of Nottingham breach exposes 450,000+ student recordshighpublicGeopolitical
publicGeopolitical

University of Nottingham breach exposes 450,000+ student records

The breach at the University of Nottingham represents a significant compromise of a major UK higher education institution, affecting a substantial population of current and former students.

University of Nottingham11 Jun · 05:27 UTC
ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Thefthighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has gained notoriety for breaching numerous organizations and exfiltrating sensitive data, which is then used for extortion…

Oracle10 Jun · 16:31 UTC
SoFi Hong Kong reports third-party vendor breach exposing customer datahighpublicGeopolitical
publicGeopolitical

SoFi Hong Kong reports third-party vendor breach exposing customer data

The incident reflects the persistent vulnerability of financial services supply chains in Hong Kong, a major international financial hub operating under the "One Country, Two Systems" framework.

SoFi8 Jun · 19:55 UTC
Oxford University CareerConnect platform breached via third-party providerhighpublicGeopolitical
publicGeopolitical

Oxford University CareerConnect platform breached via third-party provider

The breach of Oxford University's CareerConnect platform represents a supply chain compromise affecting a high-value target within the United Kingdom's higher education sector.

Group GTI8 Jun · 09:14 UTC
Spanish Police Arrest Doxer Targeting National Cybersecurity PersonnelhighpublicGeopolitical
publicGeopolitical

Spanish Police Arrest Doxer Targeting National Cybersecurity Personnel

The arrest underscores Spain's efforts to protect critical cybersecurity infrastructure personnel from targeted information operations. Doxing of government cybersecurity staff represents a significant operational security risk, potentially enabling…

BleepingComputer1 Jun · 19:28 UTC
California sues 23andMe over 2023 breach of genetic datahighpublicGeopolitical
publicGeopolitical

California sues 23andMe over 2023 breach of genetic data

The lawsuit against 23andMe highlights growing regulatory enforcement around biometric and genetic data protection in the United States, particularly within the healthcare and biotechnology sectors.

23andMe29 May · 16:08 UTC
US national sentenced for selling 7M elderly records to Jamaican fraudstershighpublicGeopolitical
publicGeopolitical

US national sentenced for selling 7M elderly records to Jamaican fraudsters

This case illustrates the transnational nature of cybercrime and data exploitation, where domestic actors facilitate cross-border fraud schemes targeting vulnerable populations.

BleepingComputer29 May · 09:07 UTC
ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches Charter Communications, Exfiltrates 4.9M Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting enterprises. The group specializes in exfiltrating sensitive customer data from corporate databases and either selling the…

Charter Communications29 May · 06:29 UTC
Romanian National Sentenced for Hacking Oregon Government Networkhighperson_alertThreat Actor
person_alertThreat Actor

Romanian National Sentenced for Hacking Oregon Government Network

A Romanian national individual actor who conducted unauthorized access operations targeting U.S. government and private sector networks. The actor's motivation appears to be financially driven cybercrime, operating from Romania to compromise Oregon s…

BleepingComputer28 May · 10:43 UTC
ShinyHunters Claims Breach of Carnival Corporation, 6M Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims Breach of Carnival Corporation, 6M Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has been active since at least 2020, specializing in breaching corporate databases and exfiltrating customer and employee re…

Carnival Corporation28 May · 08:49 UTC
ShinyHunters Extorts Charter Communications After Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Extorts Charter Communications After Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

Charter Communications26 May · 17:46 UTC
ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

7-Eleven26 May · 05:01 UTC
Italy Dismantles CINEMAGOAL Piracy Network Targeting Streaming PlatformshighpublicGeopolitical
publicGeopolitical

Italy Dismantles CINEMAGOAL Piracy Network Targeting Streaming Platforms

The disruption of the CINEMAGOAL piracy ecosystem represents a law enforcement action against organized digital piracy infrastructure rather than a state-sponsored cyber operation.

Netflix23 May · 12:23 UTC
CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repositorycriticalperson_alertThreat Actor
person_alertThreat Actor

CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository

The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.

Amazon Web Services22 May · 14:34 UTC
18-Year-Old Infostealer Operator Arrested for Compromising 28K Accountshighperson_alertThreat Actor
person_alertThreat Actor

18-Year-Old Infostealer Operator Arrested for Compromising 28K Accounts

An 18-year-old individual from Odesa, Ukraine, identified by Ukrainian cyberpolice in coordination with U.S. law enforcement. The operator is suspected of deploying infostealer malware to harvest credentials and compromise user accounts.

BleepingComputer20 May · 19:36 UTC
TeamPCP Lists GitHub Source Code for Sale After Repository Breachhighperson_alertThreat Actor
person_alertThreat Actor

TeamPCP Lists GitHub Source Code for Sale After Repository Breach

TeamPCP is a threat actor that has emerged in the cybercrime ecosystem, demonstrating capability to compromise high-value technology platforms. The actor's motivation appears financially driven, as evidenced by their decision to monetize stolen GitHu…

The Hacker News20 May · 02:01 UTC
ShinyHunters Claims 7-Eleven Data Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims 7-Eleven Data Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and database theft. The group emerged around 2020 and has been linked to numerous high-profile data exfiltration incidents targeting organizations across var…

7-Eleven19 May · 12:16 UTC