threat-intel Finland issues wanted notice for hacker behind massive psychotherapy data breach Finnish authorities have issued a wanted notice for convicted hacker Aleksanteri Kivimäki, following a Supreme Court ruling, in connection with a massive data breach targeting psychotherapy provider Vastaamo. The breach,… The Record · Jul 14, 2026 High FIdata breachcybercrimehacking
ransomware Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence Two major ransomware figures have been brought to justice in separate U.S. court cases. Karen Vardanyan, a Ryuk ransomware operator, pleaded guilty to conspiracy and computer fraud, while Angelo Martino, a ransomware neg… The Record · Jul 10, 2026 High FRUKUNransomwarenegotiatorextortion
threat-intel U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case A U.S. government entity reportedly paid $1 million to the group known as Kairos to prevent the leak of stolen data following a data breach at Union County, Ohio. Kairos, however, operated solely through data theft extor… The Hacker News · Jul 4, 2026 High USRUdatatheftextortionnegotiation
ransomware The Gentlemen ransomware: what you need to know The Gentlemen ransomware group is a sophisticated and aggressive cybercriminal operation, despite its seemingly formal name. They are known for deploying double extortion tactics, stealing data and threatening to leak it… Graham Cluley · Jul 2, 2026 High ransomwaredouble extortioncybercrime
threat-intel 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges This article reports the extradition of a 19-year-old, Peter Stokes, known as "Bouquet," from Finland to the United States to face charges related to computer intrusion, fraud, and conspiracy as part of the Scattered Spi… The Hacker News · Jul 1, 2026 High USFIUKsocial engineeringphishinghelp desk
data-breach Scope of Salesforce Attacks Expands as Icarus Leaks Data A series of attacks originating from the Icarus extortion group have expanded the scope of breaches affecting Salesforce customers. Initially targeting Klue’s OAuth tokens, attackers leveraged this access to steal custom… Dark Reading · Jun 23, 2026 High USsalesforceoauthdata breach
supply-chain Klue OAuth breach victim list grows as Icarus hackers claim attack A security breach at Klue, a market intelligence platform, has resulted in the theft of OAuth tokens used to connect to customer Salesforce environments. The attack, attributed to the ‘Icarus’ extortion group, impacted m… BleepingComputer · Jun 19, 2026 High USoauthsalesforcedata breach
supply-chain Cybersecurity Firms Impacted by Klue Supply Chain Attack A supply chain attack targeting the Klue market intelligence platform resulted in the unauthorized harvesting of customer data from various integrations, including Salesforce and HubSpot. The attack, attributed to a new… SecurityWeek · Jun 19, 2026 High supply-chainoauthcrm
data-breach Nintendo confirms data stolen in WebMD subsidiary cyberattack Nintendo of America experienced a data breach following a cyberattack on its internal employee survey platform, TinyPulse, operated by WebMD’s subsidiary. Threat actor Shadowbyt3$ stole survey data and employee personal… BleepingComputer · Jun 18, 2026 High USemployee datasurvey dataransomware
data-breach Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks A recent breach at Klue, a market intelligence platform, allowed the "Icarus" threat actor to steal Salesforce CRM data from multiple organizations, triggering an ongoing extortion campaign. The attackers leveraged stole… BleepingComputer · Jun 18, 2026 High USoauthsalesforcedata theft
ransomware INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 INC ransomware has grown into a significant RaaS threat, impacting over 830 organizations since August 2023. The group leverages a combination of established techniques, including credential dumping from Veeam backups an… The Hacker News · Jun 18, 2026 High CVE-2023-3519CVE-2025-5777CVE-2023-48788USransomware-as-a-servicecredential dumpinglateral movement
ransomware INC Ransomware Thrives by Mastering the Basics The INC ransomware group has emerged as a significant threat, particularly thriving through a focus on established ransomware-as-a-service (RaaS) tactics and targeting sectors with high pressure to pay, such as healthcar… Dark Reading · Jun 17, 2026 High CVE-2025-5777CVE-2024-57727CVE-2023-3519UKraasransomwareextortion
ransomware Silent Ransom Group: what you need to know The Silent Ransom Group is employing a novel and highly disruptive extortion tactic, shifting away from purely digital attacks. They are proactively contacting victims' employees via phone, impersonating IT support, and… Graham Cluley · Jun 11, 2026 High ransomwaresocial-engineeringusb-drive
data-breach Nottingham University data breach affects over 450,000 students The University of Nottingham experienced a significant data breach affecting over 450,000 current and former students due to a cyberattack by the ShinyHunters extortion group. The attackers gained access to student recor… BleepingComputer · Jun 11, 2026 High UKCHMAstudent datapeoplesoftextortion
threat-intel Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks The ShinyHunters extortion gang is targeting Oracle PeopleSoft servers in ongoing data theft attacks, having already compromised over 300 instances across more than 100 organizations. They are exploiting a chain of old a… BleepingComputer · Jun 10, 2026 High UKpeoplesoftzero-daydata theft
threat-intel Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks The Silent Ransom group is conducting a targeted extortion campaign against US law firms, utilizing a sophisticated multi-stage attack chain involving vishing, IT impersonation, and physical intrusions. Google’s Mandiant… Dark Reading · Jun 8, 2026 High USvishingsocial engineeringremote access
threat-intel UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign UNC3753, also known as Chatty Spider and the Silent Ransom Group, is a threat actor engaged in a financially motivated data theft and extortion campaign targeting organizations in the U.S. between January and May 2026. T… The Hacker News · Jun 8, 2026 High USvishingsocial engineeringdata exfiltration
threat-intel Silent Ransom Group targets law firms with fake IT support calls The Silent Ransom Group is aggressively targeting U.S. law firms through sophisticated social engineering attacks, primarily involving fake IT support calls. These attacks begin with phishing emails and escalate to remot… BleepingComputer · Jun 7, 2026 High USsocial engineeringphishingremote access
data-breach Cruise giant Carnival confirms data breach affecting nearly 6 million people Carnival Corporation has confirmed a data breach impacting nearly 6 million individuals, stemming from a cyberattack attributed to the ShinyHunters hacking group. The attackers gained access through a compromised employe… The Record · May 28, 2026 High USdata-theftemployee-accountextortion
data-breach Carnival Cruise confirms data breach affecting nearly 6 million people Carnival Corporation confirmed a data breach impacting nearly 6 million individuals, attributed to the ShinyHunters extortion gang. The breach occurred through a social engineering attack targeting an employee’s account,… BleepingComputer · May 28, 2026 High social engineeringloyalty programdata theft