Incident records

40 results
Outage

CDK Global cyber incident disrupts auto dealerships; dealers report financial impact

A cyber incident at CDK Global caused widespread disruption to U.S. auto dealerships that rely on CDK’s dealer management systems. Dealership groups disclosed operational disruption and potential financial impacts in statements and securities filings, and reporting described large portions of the dealership ecosystem switching to manual processes while systems were restored. The incident highlights concentrated third-party operational risk in industry-critical SaaS and managed platforms.

med confidenceoutage • CDK Global
View incident
Breach

Snowflake customer data theft campaign linked to stolen credentials and downstream extortion

In 2024, multiple companies reported data theft and extortion attempts linked to unauthorized access to their Snowflake environments. Reporting and industry analysis described attackers using stolen credentials (often associated with infostealer infections) and, in many cases, lack of MFA on Snowflake accounts as a contributing risk factor. Snowflake stated it did not identify evidence that the activity was due to a vulnerability or breach of Snowflake’s platform itself.

med confidencebreach • SnowflakeT1078
View incident
Ransomware

Change Healthcare cyberattack causes widespread healthcare claims disruption; UnitedHealth discloses material impacts

A cyberattack affecting Change Healthcare caused widespread disruption to healthcare payment and pharmacy claims processing in the United States. UnitedHealth Group (Change Healthcare’s parent company) disclosed the incident and its impacts through SEC filings, describing significant operational disruption and material financial effects across the business. Subsequent filings and earnings-related documents discussed ongoing remediation costs and impacts, reflecting the scale of financial risk from a high-availability healthcare transaction intermediary being taken offline.

med confidenceransomware • Change Healthcare
View incident
Vuln Exploitation

Active exploitation of Ivanti Connect Secure / Policy Secure vulnerabilities (CVE-2023-46805, CVE-2024-21887)

Ivanti and CISA warned of active exploitation of vulnerabilities affecting Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS), urging organizations to apply mitigations and updates. CISA issued emergency directives and alerts for federal agencies and provided guidance for broader organizations, reflecting the severity and active exploitation status. The incident illustrates the rapid operational and financial risk created when widely deployed VPN/access gateways are exploited at scale.

high confidencevuln exploitation • CVE-2023-46805 • IvantiT1190
View incident
Breach

Okta support case management system breach exposes customer support data (HAR files)

Okta disclosed that its support case management system was breached and that files uploaded by customers for support, including HAR (HTTP Archive) files, were accessed. Okta warned that some HAR files can contain sensitive tokens or session data if captured incorrectly, creating downstream risk for affected customers. The incident underscores the financial and operational impact of third-party support system compromises, including emergency credential rotation and incident response work for customers.

low confidencebreach • Okta
View incident
Breach

Caesars Entertainment cyber incident and extortion disclosed via SEC filing

Caesars Entertainment disclosed a cyber incident in an SEC filing, reporting unauthorized access to its network and exfiltration of data from its loyalty program database. Public reporting described the incident as involving an extortion demand and discussed alleged ransom payment amounts. The event shows how consumer-facing loyalty programs can create concentrated data exposure and how extortion pressure can drive direct financial costs in addition to remediation and notification expenses.

med confidencebreach • CaesarsT1041
View incident
Outage

MGM Resorts cyberattack disrupts operations; company discloses material financial impact

MGM Resorts disclosed a cybersecurity issue in September 2023 that disrupted certain company systems and operations, prompting incident response actions and public communications through SEC filings. In later SEC disclosures, MGM estimated the incident would reduce third-quarter adjusted property EBITDAR by approximately $100 million. The event is a clear example of a cyber incident driving both immediate operational disruption in hospitality and a quantified negative impact on financial results reported to investors.

med confidenceoutage • MGM Resorts
View incident
Espionage

Storm-0558 forges authentication tokens to access Exchange Online mailboxes

Microsoft reported that the China-based threat actor it tracks as Storm-0558 used a stolen Microsoft account (MSA) signing key to forge authentication tokens and gain access to Outlook Web Access and Exchange Online mailboxes of targeted organizations, including government entities. Microsoft described mitigations taken to block the actor’s access and remediate the signing key issue. The U.S. Cyber Safety Review Board (CSRB) later issued a report on the incident, including recommendations related to cloud identity, logging, and key management.

high confidenceespionage • MicrosoftT1550.001
View incident
Vuln Exploitation

MOVEit Transfer zero-day exploited for data theft and extortion (Cl0p campaign)

A critical vulnerability in Progress Software’s MOVEit Transfer product (CVE-2023-34362) was exploited at scale in 2023 to steal data from affected organizations and enable extortion. Progress published advisories and mitigation guidance, and CISA issued a joint advisory describing the exploitation and attributing the campaign to the Cl0p ransomware group. The event led to widespread breach notifications and material response costs for many victims across industries.

high confidencevuln exploitation • CVE-2023-34362 • MOVEitT1190
View incident
Breach

Uber security incident involving compromised credentials and internal access

Uber disclosed a security incident in September 2022 in which an attacker gained access to internal systems after obtaining credentials and leveraging social engineering techniques. The incident drew attention to MFA fatigue/social engineering risks and internal tooling exposure. The U.S. Cyber Safety Review Board (CSRB) later analyzed related intrusions in the period (including Lapsus$ activity), emphasizing systemic identity and access control weaknesses exploited through social engineering.

med confidencebreach • UberT1078T1566
View incident
Breach

LastPass discloses security incidents affecting development environment and customer vault data

LastPass disclosed a security incident in August 2022 involving unauthorized access to portions of its development environment and source code. In subsequent updates, LastPass reported additional details about a related incident involving a third-party cloud storage service and the theft of customer vault data and backups. The disclosures highlight how incidents at security vendors can create downstream risk and drive significant customer remediation and trust impacts.

high confidencebreach • LastPass
View incident
Ransomware

Costa Rica declares national emergency after ransomware attacks on government agencies

In 2022, multiple Costa Rican government agencies were hit by ransomware attacks that disrupted public services and contributed to the government declaring a national emergency. U.S. State Department reward announcements referenced the Conti ransomware group in connection with attacks affecting Costa Rica. News reporting described significant disruption to government functions and highlighted broader economic and operational impacts.

med confidenceransomware • Costa RicaT1486
View incident
Supply Chain

Kaseya VSA supply chain ransomware incident impacts managed service providers

In July 2021, attackers exploited Kaseya VSA and leveraged its remote management capabilities to distribute ransomware to downstream customers, particularly through managed service providers (MSPs). CISA issued alerts and guidance during the incident response period, and public vulnerability records tracked the relevant Kaseya VSA weakness used in the campaign. The event illustrates how compromise of a widely deployed management platform can multiply financial and operational impact across many organizations.

med confidencesupply chain • CVE-2021-30116 • KaseyaT1195.002T1486
View incident
Ransomware

JBS ransomware attack disrupts meat processing operations

JBS reported a ransomware attack that affected IT systems supporting North American and Australian operations and temporarily disrupted meat processing. The company issued public statements on restoration progress, and media reporting described ransom payment discussions and operational impacts. The incident illustrates ransomware’s capacity to disrupt industrial and food supply operations and create significant financial and operational risk.

med confidenceransomware • JBST1486
View incident
Ransomware

Ransomware attack disrupts Ireland’s Health Service Executive (HSE)

Ireland’s Health Service Executive (HSE) suffered a ransomware attack in May 2021 that led to major disruption across health services and IT systems. The HSE published ongoing public updates, and Ireland’s National Cyber Security Centre issued alerts about the situation. U.S. health-sector coordination reporting and other analyses highlighted the operational consequences and the need for resilient healthcare cybersecurity practices.

med confidenceransomware • HSET1486
View incident
Ransomware

Colonial Pipeline ransomware incident and DOJ seizure of ransom proceeds

Colonial Pipeline experienced a ransomware incident that led the company to shut down pipeline operations temporarily, creating significant fuel supply disruption and economic impact. The U.S. Department of Justice later announced the seizure of approximately $2.3 million in cryptocurrency paid to the DarkSide ransomware extortionists. The incident became a prominent example of ransomware’s ability to drive operational shutdown decisions and significant downstream financial effects.

med confidenceransomware • Colonial PipelineT1486
View incident
Vuln Exploitation

ProxyLogon exploitation of Microsoft Exchange Server (HAFNIUM and widespread scanning)

In early 2021, multiple vulnerabilities in Microsoft Exchange Server were exploited at scale, with Microsoft attributing early activity to the actor it tracked as HAFNIUM and subsequent widespread opportunistic exploitation. CISA issued a joint advisory describing the exploitation chain, victim impact, and remediation actions, including patching and web shell detection. The episode drove urgent patching across on-premises Exchange deployments and illustrates the financial and operational risk created by rapidly exploited internet-exposed enterprise services.

high confidencevuln exploitation • CVE-2021-26855 • Microsoft ExchangeT1190T1505.003
View incident
Vuln Exploitation

Accellion FTA exploitation and extortion across multiple organizations

Attackers exploited vulnerabilities in Accellion’s legacy File Transfer Appliance (FTA) product to access and steal data from multiple organizations, frequently followed by extortion. CISA published a joint advisory describing the exploitation, IOCs, and mitigation steps, and affected organizations issued breach notifications and updates. The incident illustrates both the risk of end-of-life file transfer appliances and the financial and regulatory consequences of third-party data exposure.

med confidencevuln exploitation • CVE-2021-27101 • AccellionT1190
View incident
Supply Chain

SolarWinds Orion supply chain compromise impacts government and enterprise networks

A supply chain compromise of SolarWinds Orion involved the distribution of maliciously modified software updates, enabling unauthorized access to affected customer environments. CISA issued an emergency directive for federal civilian agencies and published guidance on detection and response, while SolarWinds disclosed details and risks in SEC filings. The incident triggered broad remediation efforts across government and industry and remains a major reference case for software supply chain risk management.

high confidencesupply chain • SolarWindsT1195.002
View incident
Ransomware

Garmin service outage linked to ransomware incident

Garmin experienced a multi-day outage affecting customer-facing services and internal operations in July 2020 and issued a public statement during restoration efforts. Security reporting and analyses characterized the event as a ransomware incident impacting Garmin’s systems and availability. The disruption highlights how ransomware can produce material downtime and business interruption even when customer data theft is not the primary public focus.

med confidenceransomware • GarminT1486
View incident
Fraud

Twitter internal tool compromise leads to takeover of verified accounts for crypto scam

In July 2020, attackers gained access to Twitter’s internal tools through social engineering and used that access to take over high-profile verified accounts to promote a cryptocurrency scam. Twitter published updates describing the incident and remediation steps, and the New York Department of Financial Services (NYDFS) later issued a detailed report on control failures and recommendations. The incident demonstrated how compromise of internal administration tools can create outsized fraud and reputational damage even without large-scale data theft.

med confidencefraud • TwitterT1566T1078
View incident
Breach

Capital One data breach involving cloud-hosted data and subsequent OCC penalty

Capital One announced a data security incident involving unauthorized access to personal information and certain credit card application data. The company provided details on timing and affected populations and engaged law enforcement. The U.S. Office of the Comptroller of the Currency (OCC) later assessed an $80 million civil money penalty related to the incident, reflecting significant regulatory financial impact.

high confidencebreach • Capital One
View incident
Ransomware

Baltimore ransomware attack disrupts city services and drives major recovery costs

In May 2019, the City of Baltimore suffered a ransomware attack that disrupted municipal services such as property transactions and city systems. Public-sector testimony and reporting described substantial recovery expenses and prolonged disruption, illustrating the financial and operational impact ransomware can have on local government. The incident is commonly associated in public reporting with the “RobbinHood” ransomware family.

med confidenceransomware • BaltimoreT1486
View incident
Ransomware

Norsk Hydro ransomware attack disrupts global aluminum operations

Norsk Hydro reported a ransomware attack in March 2019 that disrupted operations across its global aluminum and energy business, forcing parts of the organization into manual processes. Public reporting and case studies described significant operational disruption and material recovery costs reported by the company in subsequent communications. The incident has been used as a widely referenced case study in ransomware response and business continuity planning.

med confidenceransomware • Norsk HydroT1486
View incident
Breach

Marriott discloses Starwood guest reservation database breach

Marriott disclosed unauthorized access to the Starwood guest reservation database, reporting that information related to hundreds of millions of guests may have been exposed. Regulatory enforcement followed, including a penalty decision by the UK Information Commissioner’s Office (ICO) resulting in a monetary penalty. The incident drove significant remediation, legal, and compliance costs for the company and impacted global hospitality customers.

med confidencebreach • Marriott
View incident
Breach

British Airways breach involving payment card and personal data; ICO monetary penalty

British Airways disclosed a breach affecting customer data, including payment card details for some bookings made through its website and mobile app. The UK Information Commissioner’s Office (ICO) later issued a monetary penalty notice, reflecting regulatory enforcement and financial consequences tied to the incident. The event underscores the financial and reputational impact of e-commerce data theft in large consumer-facing brands.

med confidencebreach • British Airways
View incident
Ransomware

City of Atlanta ransomware attack disrupts municipal services

In March 2018, the City of Atlanta suffered a ransomware attack that disrupted multiple municipal services and required extensive recovery work. Government and public-sector reporting cited the incident as an example of how ransomware can impose prolonged operational disruption and significant recovery costs on local governments. Public analyses describe the event as involving ransomware activity consistent with encrypting systems and disrupting service delivery.

med confidenceransomware • AtlantaT1486
View incident
Breach

Equifax breach tied to unpatched Apache Struts vulnerability

Equifax disclosed a breach that exposed sensitive personal information of a large portion of the U.S. population. Congressional investigations concluded the incident involved exploitation of an unpatched Apache Struts vulnerability (CVE-2017-5638). Regulators announced major financial settlements and remediation obligations, including a settlement involving the FTC, CFPB, and states.

high confidencebreach • CVE-2017-5638 • EquifaxT1190
View incident
Malware Campaign

NotPetya outbreak causes destructive disruption across Ukraine and globally

NotPetya spread rapidly in June 2017, initially impacting organizations in Ukraine and then causing disruption in multiple countries. Although presented as ransomware, government and security reporting described it as destructive, with victims unable to recover data even after payment. U.S. and UK government statements publicly attributed the attack to Russia’s military, and security advisories documented widespread operational impact and significant financial losses across affected organizations.

med confidencemalware campaign • NotPetyaT1485
View incident
Ransomware

WannaCry (WannaCrypt) ransomware outbreak exploiting SMB vulnerability

WannaCry was a fast-spreading ransomware outbreak that disrupted organizations worldwide, including major impacts to the UK National Health Service (NHS). Microsoft and government advisories linked the outbreak to exploitation of SMB-related vulnerabilities addressed by Microsoft’s MS17-010 updates, and Microsoft referenced CVE-2017-0144 in its customer guidance. Government reporting described operational disruption and response costs for affected organizations.

high confidenceransomware • CVE-2017-0144 • WannaCryT1486T1210
View incident
Outage

Dyn DNS DDoS attack causes widespread internet service disruption

Dyn reported large-scale distributed denial-of-service (DDoS) attacks against its managed DNS infrastructure on October 21, 2016, causing widespread service disruption for many internet platforms that depended on Dyn DNS resolution. U.S. prosecutors later announced guilty pleas related to the creation and operation of the Mirai botnet, which was used in major DDoS attacks during the period, including attacks affecting Dyn. The incident highlighted systemic availability risk from botnet-driven DDoS on core internet services.

med confidenceoutage • DynT1498
View incident
Fraud

Bangladesh Bank SWIFT fraud attempt resulting in $81 million theft

Attackers compromised systems at the central bank of Bangladesh and used the SWIFT financial messaging system to send fraudulent transfer requests from the bank’s account at the Federal Reserve Bank of New York. The operation resulted in approximately $81 million being transferred and laundered, with additional transfers blocked. U.S. authorities later charged a North Korean regime-linked programmer for a campaign that included the Bangladesh Bank heist, tying the theft to broader state-backed illicit cyber activity.

med confidencefraud • Bangladesh BankT1078
View incident
Breach

OPM breach involving U.S. federal personnel and background investigation data

The U.S. Office of Personnel Management (OPM) experienced major data breaches that exposed sensitive information about federal employees, contractors, and individuals involved in background investigations. Congressional oversight reporting described the scope of affected systems and weaknesses in security practices. The incident drove significant government response and remediation efforts, though precise total financial costs are not consolidated in the cited sources.

med confidencebreach • OPM
View incident
Breach

Anthem health insurer breach affecting tens of millions of individuals

Anthem disclosed a cyberattack that exposed personal information of approximately 78.8 million current and former members. U.S. authorities later brought charges in connection with the breach, and regulators announced major financial settlements, including a record HIPAA settlement with HHS OCR and a multistate attorneys general settlement. These outcomes highlight substantial regulatory and legal financial consequences for large-scale healthcare data breaches.

high confidencebreach • Anthem
View incident
Espionage

Destructive cyberattack and data leak at Sony Pictures Entertainment

Sony Pictures Entertainment suffered a destructive cyberattack that disrupted business operations and resulted in the theft and public release of internal data. The FBI publicly stated it concluded North Korea was responsible for the attack. Later U.S. Department of Justice statements about related cyber conspiracies also referenced the Sony Pictures incident.

med confidenceespionage • Sony Pictures
View incident
Breach

Home Depot payment card breach involving malware on point-of-sale systems

Home Depot announced findings from its investigation into a data security incident involving malware on its U.S. and Canadian self-checkout point-of-sale systems. The company’s disclosures and subsequent filings described response actions, investigation, and costs associated with the incident. The event resulted in significant remediation and legal expenses, partially offset in some periods by insurance recoveries as disclosed in filings.

med confidencebreach • Home Depot
View incident
Breach

Target payment card data breach disclosed during 2013 holiday season

Target disclosed unauthorized access to payment card data for guests who shopped at U.S. Target stores during the 2013 holiday season. The company reported the incident publicly and in securities filings, describing ongoing investigation and remediation. Public reporting and subsequent investigations connected the incident to substantial response costs, litigation, and payments to affected parties, though precise totals vary by accounting period and source.

med confidencebreach • Target
View incident
Malware Campaign

Shamoon wiper attack disrupts Saudi Aramco corporate systems

Saudi Aramco disclosed that a destructive malware attack affected its corporate computer systems and required restoration work, while stating oil production was unaffected. Public reporting described tens of thousands of workstations impacted and significant operational disruption to business IT. Vendor analyses characterize Shamoon as destructive malware designed to wipe systems.

med confidencemalware campaign • ShamoonT1485
View incident
Breach

Sony PlayStation Network and Qriocity intrusion and prolonged outage

Sony disclosed that an external intrusion affected the PlayStation Network and Qriocity services, leading to a multi-week service outage and exposure of user account data. Sony announced it was investigating the compromise and took systems offline while rebuilding security controls. Public reporting cited Sony’s estimate of roughly 14 billion yen (about $171 million at the time) in costs tied to response and customer remediation.

med confidencebreach • Sony
View incident
Malware Campaign

Stuxnet malware targets industrial control systems

Stuxnet was a highly specialized malware campaign designed to target industrial control environments, including systems using Siemens Step7 software. Public technical advisories and analyses described how it could interfere with industrial processes while spreading in Windows environments. Public reporting and government analysis linked Stuxnet to Iran’s nuclear program, but a definitive public attribution was not formally confirmed in the cited sources.

med confidencemalware campaign • Stuxnet
View incident