Leading banks client data compromised in cyberattack targeting technology vendor @ SitusAMC

In November 2025, SitusAMC, a technology vendor providing services to the real estate finance industry, experienced a cyberattack that potentially compromised sensitive client data. The breach, detected on November 12, 2025, involved unauthorized acce...

Senior software developer guilty of sabotaging ex-employer's systems @ Eaton Corporation

In March 2025, Davis Lu, a former senior software developer, was found guilty of sabotaging his ex-employer, Eaton Corporation. Lu, who had been with the company from November 2007 to October 2019, introduced malware onto the company's production syst...

Unauthorised third party accessed network and accessed certain individuals’ personal and sensitive information @ Archie Cochrane Motors

In March 2025, Federman & Sherwood announced an investigation into a data breach affecting Archie Cochrane Motors, a Ford dealership headquartered in Billings, Montana. The breach was reported to the Attorney General of Vermont on February 27, 2025, a...

$150 million linked to LastPass breaches @ Ripple

In January 2024, Ripple co-founder Chris Larsen suffered a $150 million cryptocurrency theft, which has now been linked to the LastPass security breach of 2022. U.S. federal investigators have reached the same conclusion as security researchers who, s...

Threat actors listed district on leak site @ Renton school district

In March 2025, it was revealed that the Renton School District suffered a ransomware attack in August 2023, with the Akira ransomware group claiming responsibility and threatening to leak 200 gigabytes of stolen data, including sensitive medical infor...

Cyberattack impacted operations and some systems @ Endless Mountains Health Systems

Endless Mountains Health Systems (EMHS) in Pennsylvania is currently managing a cyberattack that has disrupted its operations and affected some of its systems. The organization first acknowledged the issues on its Facebook page starting March 3, 2025,...

Unauthorised access to customer data via third-party applications @ Gainsight and Salesforce, Inc.

In November 2025, Salesforce confirmed it was investigating a security incident involving unusual activity within Gainsight-published applications connected to its platform. The investigation revealed that unauthorized access to certain customers' Sal...

Hacker claimed to have stolen 2.3TB data @ FS Italiane Group

A significant cyber security incident has come to light involving Italy's national railway operator, FS Italiane Group (FS), and their IT services provider, Almaviva. A threat actor claims to have successfully breached Almaviva's systems, resulting in...

Unauthorised access occurred at third parties' data environment @ Norway Savings Bank

In November 2025, Norway Savings Bank (NSB), a Maine-based financial institution, announced a data breach that may have compromised the personal information of approximately 51,000 individuals. The breach occurred on August 14, 2025, at Marquis Softwa...

Data breach affected over 4,500 customers @ Coupang, Inc.

In November 2025, Coupang, a major e-commerce company, experienced a significant data breach that compromised the personal information of over 4,500 customers. Unauthorized access to user accounts occurred on November 6th, but the breach went undetect...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...