By |Last Updated: September 2nd, 2026|65 min read|Categories: Ransomware, 2026, Research|

Contents

PDF Report Banner 2026

Get our Quarterly Ransomware Report as a PDF

vCISO Report Banner 2026

Free vCISO Ransomware Assessment

The State Of Ransomware August 2026

1. Oceanside Unified School District in California suffered a suspected cyberattack that disrupted critical network services, leaving staff without access to work email, internet, Google Drive, and applications delivered through ClassLink. The incident occurred just days before student registration and less than two weeks before classes were scheduled to begin, prompting the district to work with cybersecurity experts and third-party forensic specialists to investigate the incident and restore services. At the time of reporting, the cause of the disruption and whether any data had been accessed remained unconfirmed.

2. Oleoductos del Valle (Oldelval), operator of Argentina’s primary oil pipeline network carrying much of the crude produced in Vaca Muerta, suffered a cyberattack that impacted its administrative systems. The company activated its cybersecurity protocols and restored the affected systems, while oil transportation continued without interruption. The ransomware-as-a-service group The Gentlemen reportedly claimed responsibility for the attack, although Oldelval has not confirmed the specific threat or attack vector and continues to assess the full scope of the incident.

3. Allstate Corporation is investigating a reported data breach after ExfilSquad claimed to have accessed more than 657,000 records and 15.1 GB of data from the insurance company. The group alleges the stolen information includes personally identifiable information, recruitment and onboarding records, licensing data, and internal employee account details. However, Allstate has not confirmed the scope of the alleged breach, and ExfilSquad’s claims have not been independently verified.

4. Biotechnology company Amgen disclosed a material cybersecurity incident after unauthorized activity was detected in cloud environments hosted by third-party service providers. The attackers exfiltrated proprietary company data, patient protected health information, and other sensitive records, while Amgen continues to investigate whether intellectual property, research and development data, and additional confidential information were compromised. The incident did not disrupt the company’s products, manufacturing operations, financial reporting systems, or ability to supply medicines to patients. Amgen has not identified the attackers or disclosed how they gained access to the affected cloud environments.

5. The Police National Legal Database (PNLD), operated by West Yorkshire Police and used by police forces across England and Wales, suffered a cyberattack that exposed information belonging to police officers, staff, criminal justice professionals, and members of the public. The compromised data included names, organizations, and work email addresses, which were subsequently published on the dark web. ExfilSquad claimed responsibility and alleged it obtained approximately 135,000 records, although this figure has not been officially confirmed. Authorities said there was no evidence that passwords or other security credentials were compromised.

6. Accesso Technology Group, a provider of technology solutions for the leisure, entertainment, and cultural sectors, suffered a cybersecurity incident involving unauthorized access to a limited portion of its internal systems. The company quickly contained the intrusion and reported no significant disruption to its operations or customer services. Coinbase Cartel claimed responsibility for the attack and alleged it exfiltrated internal files, although Accesso has not publicly attributed the incident to the group or confirmed that data was stolen.

7. Victoria-based commercial flooring specialist Asset Flooring Group Australia was named as a victim by Qilin, which claimed to have breached the company and stolen approximately 45 GB of data. The threat actor listed Asset Flooring on its dark web leak site, alleging that the stolen information included internal company files. However, Asset Flooring has not publicly confirmed the breach or attributed an incident to Qilin, leaving the group’s claims unverified.

8. Japanese telecommunications provider Sakura Mobile suffered a data breach after an unauthorized third party gained access to its systems. The incident potentially exposed customer names, email addresses, order details, payment method types, and delivery addresses associated with its Travel Plan services. Sakura Mobile detected and blocked the unauthorized access on July 27, 2026, replaced affected credentials, and notified Japanese authorities. Credit card details, passwords, and location data were not compromised, and no threat actor has publicly claimed responsibility for the attack.

9. European real estate developer Bonava suffered a data breach after unauthorized access exposed personal information belonging to customers and prospective homebuyers. The compromised data included names, addresses, contact details, sales status, and housing preference information. ExfilSquad claimed responsibility for the breach and listed Bonava among a group of organizations it allegedly compromised. Bonava confirmed the data breach but has not publicly attributed the incident to ExfilSquad.

10. UK-based nonprofit CRM provider Beacon suffered a cyberattack in which an unauthorized third party gained access to its Amazon Web Services (AWS) environment, likely using a compromised access key. A forensic investigation found evidence indicating that the attacker exported all data contained within Beacon’s database, including customer data and attachments, potentially exposing personal and sensitive information held by numerous charities using the platform. Beacon secured the affected environment and reset relevant credentials, while affected organizations reported the breach to UK regulators. No threat actor has been publicly identified, and there is currently no evidence that the stolen data has been published or misused.

11. More than six months after unauthorized access to a legacy file server in December 2025, Brown Health Medical Group-MA confirmed in June 2026 that the incident exposed sensitive information belonging to 311,760 individuals. The breach was subsequently reported to regulators in July, with potentially compromised data including Social Security numbers, financial information, government-issued IDs, and medical and employment records. Brown Health said its electronic medical record system was not affected and implemented additional security measures following the incident. No threat actor has publicly claimed responsibility.

12. Australian online travel agency BestPriceTravel has been named as the latest alleged victim of threat actor 2019, which claims to have stolen customer and booking data from the company. On August 4, 2026, the hacker was reported to be offering the data for sale on an underground forum, with a published sample appearing to contain customer names, email addresses, flight and destination information, booking details, and other travel-related records. The attacker also claimed to have obtained payment, refund, and cancellation information. BestPriceTravel has not publicly confirmed the breach, leaving the threat actor’s claims unverified.

13. Nigerian financial institution Zenith Bank confirmed a data breach on August 4, 2026, after unauthorized access exposed limited customer information, including email addresses and phone numbers. The disclosure came shortly after ExfilSquad listed Zenith Bank as an alleged victim on July 26 as part of a series of claims targeting organizations worldwide. The bank said no financial information was compromised and that its banking services and digital channels remained secure and operational. While the breach itself has been confirmed, Zenith Bank has not publicly attributed the incident to ExfilSquad.

14. The Municipality of Sithonia and the Municipal Port Fund of Sithonia in Halkidiki, Greece, were hit by a ransomware attack in early August 2026, affecting two public-sector organizations that appear to share parts of their IT infrastructure. Greek cybercrime authorities launched an investigation into the incident, while the country’s Data Protection Authority was also notified. The full impact remains unclear, with officials yet to determine whether sensitive municipal, financial, or port-related information was stolen or whether viable backups were available to support recovery. No ransomware group has publicly claimed responsibility for the attack.

15. The Kenaitze Indian Tribe in Alaska experienced a significant cybersecurity incident beginning July 27, 2026, disrupting internet, phone, email, and computer systems and limiting access to health care, education, transportation, elder care, and social services. The tribe brought in external cybersecurity experts and established temporary phone lines to maintain essential services while systems were investigated and restored. The Gentlemen claimed responsibility for the attack and alleged it had stolen internal files, although the tribe has not publicly attributed the incident to the group or confirmed that ransomware was deployed or data was stolen.

16. Austrian luxury jewelry manufacturer FREYWILLE disclosed a cyberattack on August 6, 2026, after detecting unauthorized activity in its IT systems four days earlier. The company confirmed that data was likely compromised, including customer contact, contract, communication, and billing information, as well as potentially personal information belonging to former employees. Ransomware group Aurora claimed responsibility for the attack and listed FREYWILLE on its leak site, alleging it had stolen internal company data. FREYWILLE has not publicly attributed the incident to Aurora, while its investigation into the full scope of the breach remains ongoing.

17. Court Services Victoria confirmed a data breach in late July 2026 after unauthorized access exposed information relating to online hearings at the Magistrates’ Court and Children’s Court of Victoria between 2022 and 2026. Some of the compromised information, including participant names, email addresses, job roles, case details, and other court-related data, was subsequently published on the dark web. A hacker known as 2019 claimed responsibility and alleged they obtained 28,600 lines of court records, although Court Services Victoria has not publicly attributed the breach to the threat actor. The number of individuals affected remains unknown, and Victoria Police’s Cybercrime Squad is investigating the incident.

18. Indian hosting provider HostDZire confirmed a ransomware attack on August 5, 2026, after multiple VMware ESXi virtualization nodes were compromised, causing widespread service outages and permanent customer data loss. The attack affected the company’s VMware infrastructure in India, as well as several nodes in the Netherlands and United States, with virtual disks on impacted servers encrypted beyond recovery. HostDZire was forced to rebuild affected systems from scratch and advised customers to restore their services using external backups where available. The company launched a forensic investigation into the incident, while the threat actor responsible has not been publicly identified.

19. Qilin claimed responsibility for a cyberattack on French professional rugby club Stade Français Paris in early August 2026, reportedly publishing documents relating to 18 players and threatening to release additional stolen data. The club confirmed that its IT environment had been targeted and acknowledged that a sample of allegedly compromised data was published online. Affected systems were restored from clean backups, while ticketing and online store services remained operational. Stade Français has not officially attributed the attack to Qilin and is continuing to investigate the extent of the data breach.

20. LockBit has claimed responsibility for a ransomware attack on the Rhein-Nahe municipal authority in Germany, which has been dealing with significant IT disruption since July 16, 2026. Attackers breached the municipality’s network perimeter from outside, locked administrators out of critical systems, and left a ransom demand offering to restore access in exchange for payment. The incident disrupted citizen services, financial administration, and email communications, forcing staff to rely on limited and manual processes while systems were restored. 

21. Emerging ransomware group Storm claimed responsibility for an attack on US healthcare provider OVP Health, alleging the theft of approximately 130 GB of sensitive data. The group listed OVP Health on its leak site in early August 2026, with reportedly compromised information including patient and employee records, medical documentation, financial data, and other internal files. OVP Health provides healthcare services across West Virginia, Kentucky, Ohio, and Virginia, including emergency department staffing, addiction treatment, behavioral health, and primary care. The organization has not publicly confirmed the incident or Storm’s claims, leaving the extent and nature of any data compromise unverified.

22. Operations across North Carolina’s three port facilities were disrupted on August 4, 2026, after an outside threat actor breached the North Carolina Ports Authority’s IT systems. The incident affected the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port, forcing staff to delay gate openings and switch to manual processing while systems were recovered. The breach was contained and normal operating schedules subsequently resumed, with the US Coast Guard and state authorities assisting with the investigation. Officials have not disclosed whether any data was stolen or whether ransomware was involved, and no threat actor has publicly claimed responsibility.

23. Customer contact information may have been exposed following a security incident involving Australian telehealth provider Updoc and one of its third-party systems. Detected on July 31, 2026, the incident involved a brief period of unauthorized access that potentially exposed account holders’ names, email addresses, and postal addresses. Updoc said its own systems were not breached and confirmed that health records, financial information, payment details, and account credentials were not compromised. The unauthorized access was quickly blocked, with no evidence of further activity identified, and no threat actor has publicly claimed responsibility.

24. Ransomware group Krybit has claimed responsibility for an attack on South African payment facilitator and debt clearinghouse DC Partner, listing the company on its dark web leak site on August 2, 2026. DC Partner subsequently confirmed that it had suffered a ransomware attack but said its systems remained fully operational as it investigated the incident and notified affected parties in line with South Africa’s data protection requirements. Krybit claims to have stolen and leaked company data, although the extent and contents of the compromised information remain unclear. FNB, which has a third-party relationship with DC Partner, said there was no indication that its customer information, systems, or technology environment had been impacted.

25. A ransomware attack targeting the Oklahoma Manufacturing Alliance (OMA) was quickly contained after malicious activity was detected on two employee computers. The affected systems were isolated, with OMA reporting no evidence that information was removed or client records were compromised. Ransomware group Booba Project later claimed responsibility, alleging it had stolen 10 GB of data and threatening to publish the material. OMA has not attributed the incident to Booba Project, and the group’s data theft claims remain unverified.

26. Nearly 23 GB of data allegedly stolen from French cleaning and facilities services company Reflet 2000 has begun appearing online following a ransomware attack claimed by Krybit. The published material reportedly includes files and directories associated with human resources, payroll, social security declarations, contracts, business management systems, and Microsoft SQL Server environments, potentially exposing highly sensitive employee and corporate information. Unlike incidents where attackers only threaten to leak stolen data, Krybit has already begun releasing files attributed to the company. Reflet 2000 has not publicly confirmed the breach or attributed the attack to Krybit, leaving the full scope of the compromise unclear.

27. A cyberattack on Suisun City, California, caused widespread disruption to municipal operations, forcing officials to shut down the city’s entire IT network and declare a state of emergency. Malicious software impacted critical public safety systems, including 911 routing, police and fire dispatch, city records, and other government services, with emergency calls temporarily routed through the neighboring Solano County dispatch center. City Hall services were also disrupted as the FBI, Department of Homeland Security, and state authorities assisted with the investigation and recovery. The attackers reportedly issued a demand to the city, but officials have not identified the threat actor or confirmed whether ransomware was involved.

28. More than 460,000 personal data records were exposed after an external threat actor gained unauthorized access to the application operated by South Korean financial media platform 3Pro TV. The compromised information varied between users but included names, phone numbers, email and postal addresses, device information, service activity, and financial details, with 2,979 bank account records and 317 partially masked credit card records among the exposed data. Operator E-Broadcasting blocked the attacker’s access and strengthened security controls while launching an external investigation and reporting the incident to South Korean privacy and cybersecurity authorities.

29. Ransomware group The Gentlemen has claimed responsibility for an attack on Australian vitamin and supplement manufacturer Vitex Pharmaceuticals, alleging it gained access to the company’s network and stole confidential information. The group claims the compromised material includes internal files and client data, which it has threatened to publish through its leak site. Vitex has not publicly confirmed the incident or attributed any cyberattack to The Gentlemen, meaning the group’s claims remain unverified.

30. Clop claimed responsibility for a cyberattack on global medical device manufacturer Mindray, adding the company to its leak site after allegedly gaining access to its systems. Mindray later confirmed that a ransomware group had gained unauthorized access to certain servers maintained by an overseas company organization supporting supplier-related processes. The medical technology giant, whose equipment is widely used by hospitals worldwide, has not publicly identified Clop as the attacker or confirmed the extent of any data theft. The incident remains under investigation as the company works to determine the full scope and potential impact of the compromise.

31. The City of Coweta, Oklahoma, refused to pay or negotiate with cybercriminals after a system-wide ransomware attack encrypted computers, files, and other digital services across the municipality. The Anubis ransomware group left city staff without access to everyday working files, although emergency services, the city website, and third-party online billing remained operational. Coweta was able to recover using off-site backups, with most systems subsequently restored and day-to-day operations returning to normal. Officials said there was no evidence that payment information was compromised and are continuing to investigate whether any personal data was accessed or stolen.

32. Phone, internet, payment, and facility services were disrupted at Woodhaven Lakes, a private recreational community in Illinois, after ransomware began encrypting locally stored files and documents across its network. The association contained the attack within hours and said its initial investigation found no breach of its Property Owner database, while affected files were recoverable from off-site backups. Play later claimed responsibility and alleged it had stolen internal data, threatening to publish the material unless contacted. Woodhaven Lakes has not publicly attributed the attack to Play or confirmed that any data was stolen.

33. A ransomware attack on Winnipeg’s Health Sciences Centre disrupted critical building management systems, including central monitoring of heating, ventilation and air conditioning, as well as systems used to issue and modify staff access cards. Despite the disruption, HVAC equipment remained operational under local monitoring and patient care and clinical services continued without interruption. The hospital brought in cybersecurity specialists and notified law enforcement while investigating whether any information had been accessed or stolen. Initial findings indicate that financial and personal health information were not compromised, and no ransomware group has publicly claimed responsibility for the attack.

34. RansomHouse published data allegedly stolen from Japanese frozen food giant Nichirei following a cyberattack that caused significant disruption to the company’s logistics operations. The leaked material reportedly includes personal information belonging to employees and business partners, internal HR, accounting and administrative documents, as well as credentials associated with corporate systems. Nichirei previously confirmed unauthorized access to its network and acknowledged the possibility of a personal data breach, while RansomHouse subsequently claimed responsibility for the attack. The company is aware that information has been published but has declined to comment on the leaked material.

35. Sensitive employee information is allegedly among 386 GB of data stolen from New Zealand textile and furnishings wholesaler Warwick Fabrics in an attack claimed by Kairos. The group listed Warwick on its leak site and claims the compromised files include employee passports, medical reports, salary information, and other internal company data. The potentially sensitive nature of the material could create significant privacy risks for affected employees if the claims prove accurate. Warwick Fabrics has not publicly confirmed the incident or the alleged data theft, leaving Kairos’ claims unverified.

36. PEAR claimed responsibility for a cyberattack on Arkansas Oral & Maxillofacial Surgeons that resulted in sensitive patient information being stolen from the organization’s network. A subsequent investigation confirmed that an unauthorized third party had exfiltrated files containing names, Social Security and other government identification numbers, medical record numbers, diagnoses, treatment information, prescription histories, health insurance details, and payment information. Affected patients have been notified of the breach, although the total number of individuals impacted has not yet been disclosed. PEAR specializes in data theft and extortion rather than file encryption, threatening to publish stolen information if its demands are not met.

37. Greek coffee chain Mikel Coffee has been named as a victim of The Gentlemen, which claims to have gained access to customer information from the company’s systems. The group alleges that the compromised records contain customer contact details and password-related data, while threatening to publish a full leak if the company does not make contact. No verifiable sample of the allegedly stolen data has been released, and Mikel Coffee has not publicly confirmed a cyberattack or data breach. The Gentlemen’s claims therefore remain unverified.

38. Ransomware group Majinahanashi has begun publishing data allegedly stolen from French audio and home entertainment retailer Son-Video.com, releasing more than 10,000 internal files totaling approximately 2.5 GB. The exposed material reportedly includes recent accounting and financial records, payment reconciliation documents, customer and supplier information, B2B records, invoices, and other administrative files. The publication of recent documents suggests the attackers gained access to current business information, potentially increasing the risk of targeted fraud and phishing against the company and its partners. While Majinahanashi has claimed the attack and published data attributed to Son-Video.com, there is currently no evidence confirming that the company’s systems were encrypted.

39. Medical device manufacturer Cook Medical has confirmed a cyberattack stemming from a social engineering scam that tricked an employee into providing an outside party with access to company systems. The intrusion exposed business contact information belonging to US and Canadian customers, Salesforce communications, employee names and email addresses, and certain internal files stored in SharePoint. ShinyHunters later claimed responsibility, alleging it stole more than 182 GB of customer, employee, and corporate data, although Cook Medical has not attributed the incident to the group or confirmed those claims. The company said it found no evidence that sensitive or protected data was accessed, and its manufacturing, products, and customer operations were unaffected.

40. Global shipping and logistics giant CEVA Logistics suffered a cyberattack that disrupted operations across eight of its European warehouses, preventing goods from being shipped and causing delays for a number of major customers. The incident also developed into a wider data breach, with organizations including Bol, De Bijenkorf, Ajax, ING, Ace & Tate, and Valve reporting that customer information handled by CEVA may have been accessed or stolen. Potentially compromised data includes names, addresses, email addresses, phone numbers, and order and delivery information. CEVA contained the intrusion to the affected warehouses and launched an investigation with authorities, while the identity of the attackers and the method used to compromise its systems remain unknown.

41. Colombia’s Ministry of Justice was hit by a ransomware attack that encrypted files and disrupted parts of its technology infrastructure, affecting public services related to legal processes, document management, and illicit drug monitoring. The incident occurred just days before the country’s presidential transition, prompting authorities to isolate compromised systems and begin a coordinated recovery effort with national and international cybersecurity specialists. Officials said their investigation found no evidence that information was stolen during the attack, although some systems remained unavailable as recovery efforts continued. No ransomware group has publicly claimed responsibility for the incident.

42. ExfilSquad published information allegedly stolen from global supply chain and distribution company Wesco after claiming to have exfiltrated approximately 2.6 million records from its cloud-based customer relationship management environment. The group alleges the data includes customer and employee information, account and contact details, CRM user profiles, business identifiers, and authentication metadata. Wesco confirmed it is investigating a CRM data exfiltration claim but said it does not believe payment card, financial account, or other sensitive customer and employee information is at risk. The company found no evidence of ransomware or malicious software within its broader IT environment, and operations have continued without disruption.

43. The full scale of a cyberattack on Family Medical Associates of Raleigh remains under investigation after the North Carolina healthcare provider confirmed that an unauthorized third party accessed its systems and potentially downloaded files containing protected health information. Exposed data may include patient names, contact and demographic details, medical and treatment information, health insurance and payment data, and government-issued identification numbers. Genesis ransomware group claimed responsibility for the attack, although the practice has not publicly attributed the incident to the group. Family Medical Associates said it has found no evidence of patient information being misused, while the number of individuals affected has yet to be determined.

44. Polish healthcare technology provider MyDr is investigating a major cyberattack that may have exposed sensitive information belonging to millions of people across Poland. The attackers claim to have stolen approximately 2.5 TB of data containing more than 18.8 million unique PESEL identification numbers, alongside names, dates of birth, phone numbers, prescription information, and other healthcare-related records. MyDr has confirmed that it was targeted by deliberate criminal activity affecting part of its data but has not verified the attackers’ claimed volume or full scope of the breach. Polish authorities are investigating the incident, while the country’s central e-health infrastructure remains unaffected.

45. More than 13,700 individuals have been notified of a data breach at Michigan-based Optalis Management Solutions following an investigation into unauthorized access to its network. The intrusion occurred in April 2025, but an extensive review of the affected documents was not completed until June 2026, when the organization determined which individuals and information were involved. Potentially compromised data includes names, Social Security and driver’s license numbers, payment and financial account information, health insurance details, and diagnosis and treatment records.

46. Helix claimed responsibility for a cyberattack on Uber Freight, alleging it stole nearly one million files from the logistics company’s systems. The group claims the compromised material includes employee mailboxes, OneDrive data, accounts receivable information, and dispatch-related documents, with some allegedly stolen files subsequently appearing on its leak site. Uber Freight confirmed unauthorized access to a portion of its systems and repositories but has not verified Helix’s claims or the authenticity of the published data. The company said the incident was contained and remediated, with business operations continuing without disruption and federal law enforcement engaged in the investigation.

47. The City of Mitchell, South Dakota, has restored its systems following a cyberattack that forced officials to shut down part of the municipal network as a precaution. Critical and emergency services remained operational throughout the disruption, while affected online systems were gradually returned to normal after forensic specialists helped secure the environment. Storm later claimed responsibility for the incident and listed the city on its leak site, although Mitchell has not publicly attributed the attack to the group or confirmed that ransomware was deployed or data was stolen. The potential exposure of personal or customer information also remains under investigation.

48. A voice-phishing attack gave ShinyHunters access to part of French intellectual property services provider Questel’s Microsoft 365 environment, with stolen information subsequently published online. ShinyHunters claims to have obtained more than 21 million records containing some personal information alongside over 147 GB of internal corporate data, although Questel has not confirmed the scale or full contents of the theft. The company said the intrusion was limited to a Sales SharePoint environment and did not affect its production tools, intellectual property platforms, or SaaS services. Questel has contained the unauthorized access, notified French regulators and law enforcement, and is reviewing the leaked material to determine the full extent of the breach.

49. Several months after detecting suspicious activity within its email environment, the Cardiovascular Institute of New England has begun notifying patients that their sensitive information may have been exposed in a data breach. An investigation confirmed that an unauthorized third party accessed email accounts containing names, dates of birth, financial account details, medical diagnoses, treatment and prescription information, and health insurance data. The Rhode Island heart care provider has found no evidence that the compromised information has been misused and is strengthening its email security measures in response.

50. ShinyHunters has published data allegedly stolen from US workwear manufacturer Carhartt after an extortion attempt reportedly failed. The group initially claimed to have obtained information relating to nearly 25 million accounts, but subsequent analysis of the leaked dataset identified approximately 12.9 million records believed to belong to genuine individuals, with millions of synthetic records inflating the original figure. The exposed information includes names, email addresses, phone numbers, and physical addresses, while passwords and payment card details do not appear to be part of the leak. Despite the publication and analysis of the data, Carhartt has not publicly confirmed the breach or attributed the incident to ShinyHunters.

51. Medical technology giant Baxter International is investigating a cybersecurity incident involving unauthorized activity within third-party applications, with ShinyHunters subsequently claiming responsibility for the breach. The group later published approximately 7.1 million records allegedly stolen from Baxter after an extortion deadline passed, although the company has not confirmed the scale or contents of the leaked information. Baxter said the incident did not disrupt manufacturing, customer operations, patient services, or business continuity, and there is no evidence that its medical products or connected healthcare technologies were affected. The investigation into what information may have been accessed or acquired remains ongoing.

52. Qilin claimed responsibility for the cyberattack that caused widespread technology disruption at Brazosport College in Texas, taking key systems offline and interfering with coursework, registration, financial aid, and other student services. The disruption was significant enough to extend summer academic deadlines and delay the start of two fall terms while systems were gradually restored and subjected to security testing. Qilin later listed the college on its leak site and claimed to have stolen internal data, although Brazosport College has not publicly attributed the attack to the group or confirmed that information was exfiltrated. The college’s investigation initially found no indication that student, faculty, or staff information had been accessed or acquired.

53. Australian truck and trailer manufacturer Midland has been named among dozens of organizations targeted by Clop. The group claims to have accessed approximately 500 MB of company data, including project information and at least one database, and listed Midland alongside several high-profile organizations on its leak site. The activity forms part of a wider wave of Clop data theft claims targeting organizations around the world. Midland has not publicly confirmed that its systems were compromised or that information was stolen, leaving the group’s claims unverified.

54. Energy giant Shell is investigating a potential cybersecurity incident after Clop claimed to have stolen approximately 89 GB of sensitive company data. The group alleges the compromised material includes engineering drawings, facility images, testing reports, and project plans, adding Shell to a growing list of organizations named in its latest data-theft campaign. Shell has not confirmed how its systems may have been compromised or verified Clop’s claims regarding the volume and nature of the stolen data. The company’s investigation into the incident remains ongoing.

55. Patient information may have been stolen in a cyberattack targeting Open Door Health Center of Illinois, a Chicago-based provider of primary care and sexual health services. The incident has been reported to the US Department of Health and Human Services as affecting at least 501 individuals, although the full number of patients impacted and the types of information exposed have not yet been disclosed. INC claimed responsibility for the attack and alleges it exfiltrated sensitive data before adding the healthcare provider to its dark web leak site. Open Door Health Center has not publicly attributed the incident to INC or confirmed the group’s data theft claims.

56. ExfilSquad claimed responsibility for a data breach at Newcastle University, alleging it stole approximately 440,000 records from the institution. The university confirmed that a configuration issue affecting a connection to one of its admissions systems allowed unauthorized access to personal information, including names, postal addresses, email addresses, and telephone numbers. Newcastle University said the vulnerability has since been resolved and found no evidence of ransomware, malware, or a broader compromise of its IT infrastructure. While ExfilSquad has made wider claims about the stolen information, the university maintains that admissions data and exam results were not exposed.

57. Australian furniture retailer Nick Scali was forced to take parts of its IT environment offline following a cyberattack, disrupting warehouse and delivery operations and requiring staff to manually process customer orders. The attackers reportedly issued a ransom demand and may have gained access to customer information, including residential addresses, although Nick Scali said its investigation had found no evidence of unauthorized access to customer data. Sales and deliveries continued throughout the disruption, albeit with delays and slower customer service response times. The Australian Cyber Security Centre and Australian Federal Police have been notified, while no threat actor has publicly claimed responsibility for the attack.

58. The Gentlemen claimed responsibility for a cyberattack on Hong Kong Baptist University (HKBU), with nearly 1,800 user accounts and around 130 staff accounts potentially affected. The university launched a comprehensive review of its IT systems and personal data security after becoming aware of online claims that its systems had been illegally accessed, while also engaging external specialists and notifying relevant authorities. HKBU has not confirmed that personal information was stolen and said it had received no ransom demand. The university has advised staff and students to remain vigilant for suspicious emails while the investigation continues.

59. A cybercriminal alerted the Beverly Hills plastic surgery practice of Dr. Terry J. Dubrow to a data breach after claiming to have accessed its computer systems and copied sensitive patient information. A subsequent investigation confirmed unauthorized network access and the theft of files containing patient records, potentially including Social Security and government identification numbers, prescription and treatment information, procedure images, X-rays, and contact details. The total number of individuals impacted has not yet been publicly disclosed.

60. Sensitive personal and financial information has been exposed in a cybersecurity incident affecting Nipro Medical Corporation, the US subsidiary of Japanese medical technology company Nipro. The company detected suspicious activity within its IT environment and determined that an unauthorized third party may have viewed or acquired information including Social Security numbers, credit and debit card details, and other government-issued identifiers.

61. A cloud-based file-sharing application used by Massachusetts medical device coatings manufacturer Integer Precision Technologies was compromised, allowing an unauthorized third party to access and copy files containing sensitive personal information. A subsequent review found that the stolen data potentially included names, contact details, dates of birth, Social Security numbers, driver’s license and passport information, financial account numbers, and some health-related information. The number of people impacted by the breach has not yet been publicly disclosed.

62. A cyberattack on the University of Texas at San Antonio caused widespread technology disruptions just as tens of thousands of students were preparing to begin the fall semester. The university proactively took systems offline after detecting unauthorized activity at the edge of its network, disrupting email, phone, registration, payment, and other essential services and ultimately forcing classes to be postponed. UT San Antonio said the activity was contained before reaching its core systems and that its investigation has found no evidence that university data was accessed or stolen. No threat actor has claimed responsibility.

63. Ransomware group Chaos claimed responsibility for an attack on Healthcare Highways, alleging it stole and published approximately 235 GB of sensitive data belonging to the healthcare network company. The leaked material reportedly includes protected health information, health insurance claims, and internal corporate documents, potentially exposing highly sensitive information belonging to members of employer-sponsored health plans. Chaos published the data after apparently failing to reach an agreement with the company over its ransom demands. Healthcare Highways has not publicly confirmed the breach or verified the authenticity and scope of the data released by the group.

64. A ransomware attack at Winnipeg’s Health Sciences Centre and CancerCare Manitoba disrupted critical facility-management systems, including central HVAC monitoring and ID-card access controls. While heating, ventilation, and air conditioning equipment continued operating under local monitoring, the incident temporarily prevented the hospital from issuing or modifying employee access cards and prompted additional security measures. Clinical services and patient care remained unaffected, and an initial investigation found no evidence that financial or personal health information had been accessed or stolen. No ransomware group has publicly claimed responsibility for the attack.

65. Philips has confirmed a cybersecurity breach involving an enterprise server containing internal company data after Clop named the technology and healthcare giant among its latest victims. The company said it identified and contained the compromise and stressed that customer environments were not affected. Clop claims to have stolen approximately 15.5 GB of data, allegedly including sensitive technical material such as drawings, diagrams, blueprints, backups, and project files. Philips has not publicly attributed the intrusion to Clop or verified the group’s claims regarding the volume and contents of the stolen data.

66. General Electric is investigating a potential cybersecurity incident after Clop claimed to have breached the company and stolen sensitive internal data. Clop alleges that the compromised material includes project-related information, backups, facility images, drawings, diagrams, and other technical documents. GE said it is aware of the group’s claims and is working to assess the potential issue but has not confirmed that its systems were compromised or that any information was stolen.

67. Sensitive patient and employee information was compromised in a cyberattack on Baylor Genetics, a major US provider of genetic testing and diagnostic services. An unauthorized third party gained access to part of the company’s network and potentially obtained patient names, dates of birth, medical testing information, laboratory results, health insurance details, and, for a limited number of patients, Social Security numbers. Employee Social Security numbers, government-issued identification, and financial account information may also have been exposed. Baylor Genetics said its laboratory operations and genetic testing services continued without interruption.

68. Emperador has claimed responsibility for a cyberattack affecting Baguio City’s online building permit system in the Philippines, alleging it stole 2.9 GB of government data. City officials subsequently confirmed that an unauthorized attacker had accessed and taken files from the BuildPASS platform, with compromised information including building plans, identification documents, and permit applications belonging to more than 100 individuals. The system was taken offline while authorities investigated and strengthened its security. Baguio City has not publicly attributed the intrusion to Emperador or confirmed that its systems were encrypted.

69. Australian children’s clothing retailer Ollie’s Place launched an investigation after The Gentlemen claimed to have breached the company and stolen data. The retailer became aware of the incident after the group’s name appeared on an affected point-of-sale computer, which was subsequently removed from service and replaced. The Gentlemen also listed Ollie’s Place on its leak site and threatened to publish allegedly stolen information, although it has provided few details about what may have been taken. Ollie’s Place has not yet determined the full scope or cause of the incident or confirmed whether any customer or employee data was compromised.

70. ShinyHunters claimed responsibility for a data breach at cloud communications provider RingCentral, alleging it stole more than 623 GB of company data following a social engineering attack. RingCentral confirmed that unauthorized activity affected data belonging to a limited portion of its customers, although its core platform remained unaffected and services continued without disruption. After the attackers published the allegedly stolen data, approximately 1.6 million unique email addresses were identified in the leak alongside names, physical addresses, and phone numbers. RingCentral has not publicly attributed the breach to ShinyHunters but is directly notifying customers affected by the incident.

71. Ransomware group Xpl0itrs has named BMW as a victim, claiming to have stolen around 800 documents containing motorcycle and dealership information from the German automotive giant. The group published sample archives containing hundreds of files with details on used motorcycles, vehicle prices, dealerships, and employee contact information. However, analysis of the leaked material found that some of the documents were already publicly available online, while Xpl0itrs’ broader claims of accessing configuration, API, subsidiary, and other sensitive data were not supported by the samples. BMW has not publicly confirmed a breach.

72. More than 3.75 million people have been affected by a major data breach at healthcare technology provider CareCloud after an unauthorized attacker gained access to one of its cloud-hosted electronic health record environments. Compromised information varies by individual but may include names, addresses, dates of birth, Social Security and government identification numbers, financial account and payment card details, and medical and health insurance information. CareCloud said the incident was contained to a single environment and has found no further unauthorized access to its systems. No threat group has publicly claimed responsibility for the attack.

73. American Addiction Centers disclosed a data breach after an unauthorized third party accessed its Salesforce environment and exfiltrated sensitive information collected during initial outreach with prospective patients. The stolen data potentially includes names, contact information, Social Security numbers, health insurance details, and brief descriptions individuals provided about their health. The company said the intrusion was limited to Salesforce and did not affect its wider network, systems, or electronic health records platform. The number of individuals impacted has not yet been publicly disclosed, and no threat actor has claimed responsibility for the breach.

74. MedusaLocker has named South African delivery company The Courier Guy as a victim, claiming to have breached its systems and stolen emails and other internal documents. The ransomware group displayed filenames allegedly belonging to the company, including material related to financial and strategic information, and advertised the purported stolen data for $30,000. The Courier Guy said it had found no evidence that its internal systems were compromised and was confident that no customer information had been breached, although it launched an investigation into the claims.

75. Xpl0itrs claimed responsibility for a data breach affecting Australian retailer Oz Hair and Beauty, alleging it obtained approximately 2.1 million customer records. The company confirmed that an unauthorized third party briefly accessed its online purchase and order platform through a third-party provider, exposing information including customer names, email addresses, phone numbers, and purchase history. Oz Hair and Beauty said credit card details, passwords, payment information, and street addresses were not compromised and has begun notifying affected customers. While the breach itself is confirmed, the retailer has not verified Xpl0itrs’ claim regarding the number of records stolen.

76. Rhysida has claimed responsibility for a cyberattack on Australian healthcare provider SIA Medical Centre, alleging it obtained around 20,000 patient records containing names, dates of birth, Medicare numbers, clinical notes, insurance information, and other sensitive medical data. SIA Medical confirmed unauthorized access to part of its systems and acknowledged that a small number of documents allegedly taken during the incident have been published online, with current findings indicating the breach was confined to its Footscray clinic. The ransomware group also claims to have stolen employee identity documents, credentials, HR records, and banking information, although the full extent of those claims has not been verified by the provider. Patient services have continued without disruption while SIA Medical investigates the breach and contacts individuals whose information is confirmed to be involved.

77. INC has claimed a cyberattack on Australia’s Brighton East Dental Clinic and published 37 GB of allegedly stolen data on its dark web leak site. The exposed files appear to contain highly sensitive patient information, including dental X-rays, referral and treatment details, specialist correspondence, consent forms, and an audio recording of a patient diagnosis, alongside employment contracts and other internal documents. More than 600 folders reportedly contain correspondence between the clinic and specialist healthcare providers relating to individual patients, with some of the material dating back more than two decades. Brighton East Dental Clinic has declined to comment on the incident.

78. Nearly 735,000 people have been affected by a data breach at US consumer lender Heights Finance after an attacker compromised a third-party cloud platform used to store customer information. The stolen data potentially includes names, contact details, Social Security and tax identification numbers, driver’s license information, and sensitive banking details such as account and routing numbers. Heights Finance said the intrusion was confined to the cloud platform and did not affect its loan management systems or wider IT network. No threat actor has claimed responsibility, and the company says it has not found evidence that the compromised information has been published on the dark web.

79. ShinyHunters named Logitech and its streaming software subsidiary Streamlabs as alleged victims, threatening to leak stolen data unless the companies respond to the cyber extortion group. Despite the threat, ShinyHunters has provided no details about what systems were supposedly compromised, how the intrusion occurred, or what information may have been stolen, and no data samples were released to substantiate the claim. Streamlabs provides streaming tools to more than 15 million creators, meaning a genuine compromise could potentially have significant implications for its user base.

80. The municipal government of San Luis Potosí, Mexico, has confirmed that hackers breached its systems and extracted employee information before attempting to extort the city for money. The compromised material primarily relates to municipal workers and includes records from 2021 and 2022, with officials saying much of the stolen information consisted of public asset declarations, although more complete versions containing additional data were obtained. The city refused to pay the attackers and has reported the incident to authorities while strengthening its cybersecurity defenses. No threat group has publicly claimed responsibility.

81. Power electronics manufacturer Inission Power has disclosed a ransomware attack that compromised sensitive information belonging to current and former employees, former shareholders, and individuals associated with company directors. The exposed data may include names, addresses, personal identity numbers, bank account and salary information, health data, and shareholding details, with portions of the affected databases subsequently discovered online. Inission Power isolated and restored the compromised server environment quickly and said the incident had no material impact on its business operations. No ransomware group has publicly claimed responsibility for the attack.

82. Ransomware group Xpl0itrs named US retail giant Target as a victim, claiming to have stolen 8.6 GB of source code and threatening to publish the data unless the company negotiates. The group has not released any samples to substantiate its allegations, raising questions over whether a new intrusion actually occurred. The claimed data may instead be connected to an earlier Target breach involving a much larger collection of internal source code, configuration files, and developer documentation. Target has not confirmed a new breach or attributed any recent security incident to Xpl0itrs.

83. Qilin claimed the University of the West Indies as a victim, prompting the institution to launch an investigation into a potential cybersecurity incident. UWI said technical teams are reviewing its systems for signs of compromise with assistance from cybersecurity experts and regional authorities, while students and staff have been warned to remain vigilant for suspicious links, attachments, and messages. However, the university has found no confirmed evidence that its IT environment has been breached or that any university information has been stolen or leaked.

84. Everest claimed to have breached Kingston Technology, alleging it stole more than 138 GB of internal data from the computer memory and storage manufacturer. The group says the cache contains more than 9,400 files, largely comprising Asia-Pacific marketing materials, product launch resources, localization packages, corporate communications, imagery, and content relating to Kingston’s HyperX gaming brand. Everest has threatened to publish the data, although the evidence released so far is limited to a screenshot of an alleged Kingston file directory. Kingston said it is investigating the claims and continues to operate normally without any disruption to its services but has not confirmed that a breach or data theft occurred.

85. ShinyHunters claimed cybersecurity company ReliaQuest as a victim after successfully phishing an employee and gaining temporary access to the company’s Okta identity dashboard. The attackers used a lookalike single sign-on page and impersonated a ReliaQuest security employee over the phone, convincing one worker to enter their credentials and approve an authentication request. However, ReliaQuest said the resulting session provided only view-level access and that its device-trust controls blocked attempts to reach connected applications, leaving company systems and customer data untouched. While ShinyHunters published screenshots demonstrating its brief access, there is no evidence that data was stolen or that ReliaQuest’s wider environment was compromised.

86. Medical device manufacturer Globus Medical has confirmed a cybersecurity incident involving unauthorized access to a limited number of employee corporate email accounts, files, and data. The company said the intrusion was contained and that preliminary findings showed no sensitive customer, consumer, or patient information was exfiltrated, with manufacturing, distribution, and other business operations continuing normally. Falcon ransomware group subsequently named Globus Medical on its leak site and claimed to have obtained nearly 3 TB of data, although the company has not attributed the incident to Falcon or verified its claims. Globus Medical also said it found no indication that ransomware or malware was involved and continues to investigate what information may have been accessed or acquired.

87. 2019 has claimed responsibility for a data breach affecting New Zealand Sotheby’s International Realty, offering allegedly stolen customer information for sale on an underground forum. The real estate company confirmed that unauthorized access occurred through a third-party CRM platform, potentially exposing client names, addresses, phone numbers, and email addresses. While the attacker claims to have obtained 1.6 million contacts, Sotheby’s disputes that figure, saying its database contains nowhere near that number and that duplicate records may explain the discrepancy. The company said property documents, email exchanges, and financial transaction information were not accessed and has notified New Zealand’s cybersecurity and privacy authorities.

88. Australian car dealership Westco Motors Cairns has been named by the Storm ransomware group, which claims to have breached the company and stolen customer and business data. To support its allegations, Storm published more than a dozen sample documents containing information such as tax invoices, vehicle identification numbers, email addresses, and mobile phone numbers, while threatening to release additional material. The group has not disclosed how much data it allegedly obtained or provided details of any ransom demand. Westco Motors has not publicly confirmed a cyberattack or data breach, leaving Storm’s claims unverified.

89. WallStreet claimed responsibility for a cyberattack that disrupted municipal and school systems in Andover, Massachusetts. The incident knocked the town’s shared network offline for four days, affecting email, online bill payments, and Andover Public Schools’ release of teacher assignments, while public safety agencies, utilities, and other critical services remained operational. WallStreet claims to possess documents, databases, emails, personal information, and other files allegedly stolen from Andover, but the town has not confirmed that any data was accessed or exfiltrated. 

90. DireWolf claimed responsibility for a cyberattack on the National Kidney Registry, alleging it stole approximately 253 GB of highly sensitive information from the nonprofit organization that helps coordinate living-donor kidney transplants across the United States. The ransomware group claims the compromised data includes potential organ donors’ names, medical information, transplant suitability details, and other records associated with the registry’s operations. DireWolf said the attack focused on data theft and did not disrupt the organization’s IT systems or transplant services. The National Kidney Registry has not publicly confirmed the breach or verified the group’s claims regarding the volume and contents of the allegedly stolen data.

91. Qilin claimed responsibility for a cyberattack on the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), which Department of Justice officials designated a “major incident.” The breach affected a standalone system used in connection with the Communications Assistance for Law Enforcement Act and containing information related to ATF investigative matters, but the agency said its wider network and operational systems were unaffected. Qilin subsequently claimed to have published data obtained from the compromised system, although the ATF has not confirmed the authenticity, nature, or scope of the material. The agency has also not attributed the attack to Qilin, and its investigation with the Department of Justice remains ongoing.

92. Medical device giant Boston Scientific is recovering from a major cyberattack that disrupted its global operations, affecting manufacturing as well as the processing and shipment of customer orders. The incident was limited to certain on-premises systems and also temporarily affected the activation of remote monitoring for some newly implanted cardiac devices, although existing implanted devices continued to function and the company found no impact to its cloud environment. Boston Scientific has begun restoring affected operations and says it has detected no further unauthorized activity since containing the intrusion.

93. The City of Circleville, Ohio, has restored its municipal computer systems following a ransomware attack that disrupted card payments and other technology-dependent city services. Officials took computers offline to contain the incident before rebuilding or recovering affected systems from clean environments, while emergency dispatch, water, wastewater, and telephone services continued operating. The city said it refused to pay a ransom and has found no evidence that sensitive information was stolen during the attack. Its investigation and post-incident security review remain ongoing.

94. Hacking group FulcrumSec has claimed responsibility for the cyberattack on Manchester Airports Group (MAG) that exposed personal information belonging to approximately 8.7 million customers. The stolen data relates to Manchester, London Stansted, and East Midlands airports and includes email addresses, phone numbers, vehicle registrations, and information associated with parking, Fast Track, lounge bookings, and airport Wi-Fi services. FulcrumSec subsequently published data allegedly obtained in the attack after MAG refused to meet an extortion demand, although the airport operator has not publicly attributed the breach to the group. MAG confirmed that the incident did not compromise any payment or banking information and caused no disruption to airport operations.

95. Australian publisher Hachette Australia & New Zealand is continuing to recover from a cyberattack that caused weeks of disruption to its book distribution operations. Unauthorized activity affected systems used by Hachette and its distribution subsidiary, Alliance Distribution Services, forcing parts of the ordering and fulfillment process to be handled manually and leaving booksellers struggling to replenish stock. Specialist teams from Hachette’s Australian, UK, and US operations are working to restore affected systems, but the company has not disclosed whether any information was stolen. No threat actor has publicly claimed responsibility for the attack.

96. Ransomware group Storm claimed responsibility for a cyber incident affecting Australian car dealership Sharp Motor Group, publishing samples of data it alleges was stolen and threatening to release the full dataset. The exposed material reportedly includes employee passport and driver’s license scans, financial information, customer invoices, and account credentials, although the group has not disclosed the total volume of data it claims to hold. Sharp Motor Group confirmed that its third-party IT provider was involved in a cyber incident and is working with cybersecurity specialists and relevant authorities while investigating the potential impact.

97. MedusaLocker claimed responsibility for a cyberattack on Hungry Lion, a fast-food chain operating more than 100 restaurants across several African countries, and is demanding $50,000 from the company. The ransomware group has published evidence allegedly taken from Hungry Lion’s point-of-sale environment, including data associated with its Unity POS, GAAP POS, and CoSoft POS systems. Analysis of the material released so far found no apparent personally identifiable information, suggesting the exposed files primarily contain structural and operational point-of-sale data rather than customer records. Hungry Lion has not publicly confirmed a breach or attributed an incident to MedusaLocker.

98. Berlin authorities have refused to pay a ransom demand following a major cyberattack that resulted in sensitive government data being stolen from state systems. Rhysida has since claimed responsibility, alleging it exfiltrated 5.79 TB of information spanning tens of thousands of contracts, emails, passwords, phone numbers, and potentially classified material, which it is attempting to auction for at least 30 Bitcoin. Officials have acknowledged that sensitive and potentially personal information was compromised but have not verified the scale or contents claimed by the ransomware group. Despite the timing of the attack, authorities said systems supporting Berlin’s upcoming election were not affected.

99. Most municipal services in Norcross, Georgia, are back online as the city continues recovering from a ransomware attack that compromised parts of its computer network. Officials brought in external cybersecurity specialists and notified law enforcement after discovering the intrusion, while affected systems were secured and gradually restored with additional protections in place. Some limited service disruptions may continue as recovery work is completed, but the city has not disclosed whether any resident or employee information was accessed or stolen. The attackers have not been publicly identified, and no ransomware group has claimed responsibility for the incident.

100. Highly sensitive medical information belonging to more than 150,000 patients may have been compromised after ransomware group Orova claimed to have breached Cardiology Associates of Port Huron, a Michigan cardiology practice operating across nine locations. The group alleges it obtained a substantial collection of patient records containing personally identifiable and protected health information. Cardiology Associates of Port Huron has not publicly confirmed the breach.

101. Video game publisher THQ Nordic, known for franchises including Darksiders, Gothic, and Destroy All Humans!, has been named as a victim by DireWolf. The attackers claim to have exfiltrated approximately 335 GB of data and compromised 254 users, while also alleging they obtained third-party employee credentials and identified dozens of externally exposed assets associated with the company. DireWolf has yet to publish sample files or other substantive evidence demonstrating what information was actually stolen, and there is no confirmation that THQ Nordic’s systems were encrypted.

102. Australian app developer DigiGround is investigating claims that it was targeted by Qilin but says it has so far found no evidence that its systems or data were compromised. Qilin named the Sydney-based company on its dark web leak site but provided no details about the alleged intrusion, the volume or type of information supposedly stolen, or any sample files to support its claim. DigiGround said it is treating the allegation seriously and will take further action if evidence of a security incident emerges.

103. ShinyHunters has claimed to have breached food and animal safety company Neogen and is threatening to publish data allegedly stolen from the biotechnology firm. The group issued an ultimatum demanding that Neogen make contact or face the release of the information alongside unspecified additional disruption. However, ShinyHunters has not revealed what data it allegedly obtained or published sample files that could substantiate its claims. Neogen has not publicly confirmed a security breach.

104. Healthcare and pharmaceutical distribution giant McKesson has confirmed that hackers stole customer data after gaining unauthorized access to third-party applications used by parts of its Oncology & Multispecialty and Medical-Surgical businesses. ShinyHunters claimed responsibility, alleging it compromised employee accounts through voice phishing before accessing cloud environments and exfiltrating roughly 1 TB of data containing 284 million records, including potentially sensitive medical and personal information. The group has also reportedly demanded around $55 million to prevent publication of the stolen data. McKesson says the unauthorized access has been stopped, and its distribution network remains operational.

105. Six casinos operated by Slovenian gambling and tourism group Hit were forced to close after a cyberattack knocked critical IT systems offline and disrupted operations across the business. The outage affected casinos including Perla, Park, Mond, Korona, Casino Fontana, and Casino Drive-in, while hotels remained open with limited services and some restaurants resorted to handwritten receipts when cash registers became unavailable. Hit has since begun reopening its casinos as systems are gradually restored, although some gaming functions and its loyalty program initially remained unavailable. The company has not disclosed whether any information was stolen or a ransom was demanded, and no threat actor has publicly claimed responsibility for the attack.

Share This Story, Choose Your Platform!

Related Posts