Customers suffer data theft attacks after third-party issue @ Snowflake

In April 2026, a supply chain attack targeting Anodot, an AI-powered analytics platform, led to data theft from multiple Snowflake customer accounts. The ShinyHunters extortion group claimed responsibility, stating they had gained access to Anodot's i...

Unauthorised access led to transfer of approx. 50.903 Bitcoin valued at $3.665 million from company-controlled wallets @ Bitcoin Depot, Inc.

On March 23, 2026, Bitcoin Depot Inc. experienced a cyber attack resulting in the unauthorized transfer of approximately 50.903 Bitcoin, valued at $3.665 million, from company-controlled wallets. Upon detection, Bitcoin Depot activated its incident re...

Breach posed critical threat to national medical infrastructure @ ChipSoft

In April 2026, ChipSoft, the leading healthcare software provider in the Netherlands, was targeted in a significant cyber attack. The company's flagship product, HiX, manages patient records for a majority of Dutch hospitals, making the breach a criti...

Staff member developed programme to circumvent internal security controls to access and download users images @ Facebook, Inc.

In April 2026, a former Meta engineer was accused of a mass data breach involving Facebook user images. The individual allegedly developed a program to bypass Meta's internal security controls, enabling unauthorized access and downloading of user data...

Over 6 million customer and employee records breached @ Russell Cellular

In April 2026, Russell Cellular, a Verizon authorized retailer based in Missouri, is under investigation following a significant data breach that compromised the sensitive information of approximately 6.3 million customers and employees. The law firm ...

Data breach affected driving school @ AAA Driving School

In April 2026, AAA Northeast's Driver Training School faced a class action lawsuit following a data breach that affected its customers. The breach, which occurred in December, was discovered and reported to AAA Northeast by its software vendor. An una...

Unauthorised access to storage system that contained discovery documents from previously adjudicated or settled civil litigation cases @ LAPD and Los Angeles Police Department

In late March 2026, the Los Angeles City Attorney’s Office experienced a significant data breach that compromised sensitive Los Angeles Police Department (LAPD) records. The breach occurred within a third-party digital storage system used by the City ...

Cyber attack impaired county’s ability to deliver vital emergency and municipal services @ Winona County

In April 2026, Winona County, Minnesota, experienced a significant cyberattack that disrupted critical systems and digital services, impairing the county's ability to deliver essential emergency and municipal services. Governor Tim Walz issued an exec...

Cyber breach due to a “major lapse” in security measures @ Opexus

In early 2025, Opexus, a software company providing services to numerous U.S. federal agencies, experienced a significant cyber breach. Two employees, twin brothers Muneeb and Suhaib Akhter, who had prior convictions for hacking into the U.S. State De...

Unauthorised access to credentials associated with partner-managed repository @ DocketWise

In October 2025, DocketWise, a software platform used by U.S. immigration professionals for case management, discovered a data breach involving unauthorized access to credentials associated with a partner-managed repository. The breach stemmed from an...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...