A cyber incident at CDK Global caused widespread disruption to U.S. auto dealerships that rely on CDK’s dealer management systems. Dealership groups disclosed operational disruption and potential financial impacts in statements and securities filings, and reporting described large portions of the dealership ecosystem switching to manual processes while systems were restored. The incident highlights concentrated third-party operational risk in industry-critical SaaS and managed platforms.
In 2024, multiple companies reported data theft and extortion attempts linked to unauthorized access to their Snowflake environments. Reporting and industry analysis described attackers using stolen credentials (often associated with infostealer infections) and, in many cases, lack of MFA on Snowflake accounts as a contributing risk factor. Snowflake stated it did not identify evidence that the activity was due to a vulnerability or breach of Snowflake’s platform itself.
A cyberattack affecting Change Healthcare caused widespread disruption to healthcare payment and pharmacy claims processing in the United States. UnitedHealth Group (Change Healthcare’s parent company) disclosed the incident and its impacts through SEC filings, describing significant operational disruption and material financial effects across the business. Subsequent filings and earnings-related documents discussed ongoing remediation costs and impacts, reflecting the scale of financial risk from a high-availability healthcare transaction intermediary being taken offline.
Ivanti and CISA warned of active exploitation of vulnerabilities affecting Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS), urging organizations to apply mitigations and updates. CISA issued emergency directives and alerts for federal agencies and provided guidance for broader organizations, reflecting the severity and active exploitation status. The incident illustrates the rapid operational and financial risk created when widely deployed VPN/access gateways are exploited at scale.
high confidencevuln exploitation • CVE-2023-46805 • IvantiT1190
Okta disclosed that its support case management system was breached and that files uploaded by customers for support, including HAR (HTTP Archive) files, were accessed. Okta warned that some HAR files can contain sensitive tokens or session data if captured incorrectly, creating downstream risk for affected customers. The incident underscores the financial and operational impact of third-party support system compromises, including emergency credential rotation and incident response work for customers.
Caesars Entertainment disclosed a cyber incident in an SEC filing, reporting unauthorized access to its network and exfiltration of data from its loyalty program database. Public reporting described the incident as involving an extortion demand and discussed alleged ransom payment amounts. The event shows how consumer-facing loyalty programs can create concentrated data exposure and how extortion pressure can drive direct financial costs in addition to remediation and notification expenses.
MGM Resorts disclosed a cybersecurity issue in September 2023 that disrupted certain company systems and operations, prompting incident response actions and public communications through SEC filings. In later SEC disclosures, MGM estimated the incident would reduce third-quarter adjusted property EBITDAR by approximately $100 million. The event is a clear example of a cyber incident driving both immediate operational disruption in hospitality and a quantified negative impact on financial results reported to investors.
Microsoft reported that the China-based threat actor it tracks as Storm-0558 used a stolen Microsoft account (MSA) signing key to forge authentication tokens and gain access to Outlook Web Access and Exchange Online mailboxes of targeted organizations, including government entities. Microsoft described mitigations taken to block the actor’s access and remediate the signing key issue. The U.S. Cyber Safety Review Board (CSRB) later issued a report on the incident, including recommendations related to cloud identity, logging, and key management.
A critical vulnerability in Progress Software’s MOVEit Transfer product (CVE-2023-34362) was exploited at scale in 2023 to steal data from affected organizations and enable extortion. Progress published advisories and mitigation guidance, and CISA issued a joint advisory describing the exploitation and attributing the campaign to the Cl0p ransomware group. The event led to widespread breach notifications and material response costs for many victims across industries.
high confidencevuln exploitation • CVE-2023-34362 • MOVEitT1190
Uber disclosed a security incident in September 2022 in which an attacker gained access to internal systems after obtaining credentials and leveraging social engineering techniques. The incident drew attention to MFA fatigue/social engineering risks and internal tooling exposure. The U.S. Cyber Safety Review Board (CSRB) later analyzed related intrusions in the period (including Lapsus$ activity), emphasizing systemic identity and access control weaknesses exploited through social engineering.
LastPass disclosed a security incident in August 2022 involving unauthorized access to portions of its development environment and source code. In subsequent updates, LastPass reported additional details about a related incident involving a third-party cloud storage service and the theft of customer vault data and backups. The disclosures highlight how incidents at security vendors can create downstream risk and drive significant customer remediation and trust impacts.
In 2022, multiple Costa Rican government agencies were hit by ransomware attacks that disrupted public services and contributed to the government declaring a national emergency. U.S. State Department reward announcements referenced the Conti ransomware group in connection with attacks affecting Costa Rica. News reporting described significant disruption to government functions and highlighted broader economic and operational impacts.
In July 2021, attackers exploited Kaseya VSA and leveraged its remote management capabilities to distribute ransomware to downstream customers, particularly through managed service providers (MSPs). CISA issued alerts and guidance during the incident response period, and public vulnerability records tracked the relevant Kaseya VSA weakness used in the campaign. The event illustrates how compromise of a widely deployed management platform can multiply financial and operational impact across many organizations.
med confidencesupply chain • CVE-2021-30116 • KaseyaT1195.002T1486
JBS reported a ransomware attack that affected IT systems supporting North American and Australian operations and temporarily disrupted meat processing. The company issued public statements on restoration progress, and media reporting described ransom payment discussions and operational impacts. The incident illustrates ransomware’s capacity to disrupt industrial and food supply operations and create significant financial and operational risk.
Ireland’s Health Service Executive (HSE) suffered a ransomware attack in May 2021 that led to major disruption across health services and IT systems. The HSE published ongoing public updates, and Ireland’s National Cyber Security Centre issued alerts about the situation. U.S. health-sector coordination reporting and other analyses highlighted the operational consequences and the need for resilient healthcare cybersecurity practices.
Colonial Pipeline experienced a ransomware incident that led the company to shut down pipeline operations temporarily, creating significant fuel supply disruption and economic impact. The U.S. Department of Justice later announced the seizure of approximately $2.3 million in cryptocurrency paid to the DarkSide ransomware extortionists. The incident became a prominent example of ransomware’s ability to drive operational shutdown decisions and significant downstream financial effects.
In early 2021, multiple vulnerabilities in Microsoft Exchange Server were exploited at scale, with Microsoft attributing early activity to the actor it tracked as HAFNIUM and subsequent widespread opportunistic exploitation. CISA issued a joint advisory describing the exploitation chain, victim impact, and remediation actions, including patching and web shell detection. The episode drove urgent patching across on-premises Exchange deployments and illustrates the financial and operational risk created by rapidly exploited internet-exposed enterprise services.
high confidencevuln exploitation • CVE-2021-26855 • Microsoft ExchangeT1190T1505.003
Attackers exploited vulnerabilities in Accellion’s legacy File Transfer Appliance (FTA) product to access and steal data from multiple organizations, frequently followed by extortion. CISA published a joint advisory describing the exploitation, IOCs, and mitigation steps, and affected organizations issued breach notifications and updates. The incident illustrates both the risk of end-of-life file transfer appliances and the financial and regulatory consequences of third-party data exposure.
med confidencevuln exploitation • CVE-2021-27101 • AccellionT1190
A supply chain compromise of SolarWinds Orion involved the distribution of maliciously modified software updates, enabling unauthorized access to affected customer environments. CISA issued an emergency directive for federal civilian agencies and published guidance on detection and response, while SolarWinds disclosed details and risks in SEC filings. The incident triggered broad remediation efforts across government and industry and remains a major reference case for software supply chain risk management.
Garmin experienced a multi-day outage affecting customer-facing services and internal operations in July 2020 and issued a public statement during restoration efforts. Security reporting and analyses characterized the event as a ransomware incident impacting Garmin’s systems and availability. The disruption highlights how ransomware can produce material downtime and business interruption even when customer data theft is not the primary public focus.
In July 2020, attackers gained access to Twitter’s internal tools through social engineering and used that access to take over high-profile verified accounts to promote a cryptocurrency scam. Twitter published updates describing the incident and remediation steps, and the New York Department of Financial Services (NYDFS) later issued a detailed report on control failures and recommendations. The incident demonstrated how compromise of internal administration tools can create outsized fraud and reputational damage even without large-scale data theft.
Capital One announced a data security incident involving unauthorized access to personal information and certain credit card application data. The company provided details on timing and affected populations and engaged law enforcement. The U.S. Office of the Comptroller of the Currency (OCC) later assessed an $80 million civil money penalty related to the incident, reflecting significant regulatory financial impact.
In May 2019, the City of Baltimore suffered a ransomware attack that disrupted municipal services such as property transactions and city systems. Public-sector testimony and reporting described substantial recovery expenses and prolonged disruption, illustrating the financial and operational impact ransomware can have on local government. The incident is commonly associated in public reporting with the “RobbinHood” ransomware family.
Norsk Hydro reported a ransomware attack in March 2019 that disrupted operations across its global aluminum and energy business, forcing parts of the organization into manual processes. Public reporting and case studies described significant operational disruption and material recovery costs reported by the company in subsequent communications. The incident has been used as a widely referenced case study in ransomware response and business continuity planning.
Marriott disclosed unauthorized access to the Starwood guest reservation database, reporting that information related to hundreds of millions of guests may have been exposed. Regulatory enforcement followed, including a penalty decision by the UK Information Commissioner’s Office (ICO) resulting in a monetary penalty. The incident drove significant remediation, legal, and compliance costs for the company and impacted global hospitality customers.
British Airways disclosed a breach affecting customer data, including payment card details for some bookings made through its website and mobile app. The UK Information Commissioner’s Office (ICO) later issued a monetary penalty notice, reflecting regulatory enforcement and financial consequences tied to the incident. The event underscores the financial and reputational impact of e-commerce data theft in large consumer-facing brands.
In March 2018, the City of Atlanta suffered a ransomware attack that disrupted multiple municipal services and required extensive recovery work. Government and public-sector reporting cited the incident as an example of how ransomware can impose prolonged operational disruption and significant recovery costs on local governments. Public analyses describe the event as involving ransomware activity consistent with encrypting systems and disrupting service delivery.
Equifax disclosed a breach that exposed sensitive personal information of a large portion of the U.S. population. Congressional investigations concluded the incident involved exploitation of an unpatched Apache Struts vulnerability (CVE-2017-5638). Regulators announced major financial settlements and remediation obligations, including a settlement involving the FTC, CFPB, and states.
high confidencebreach • CVE-2017-5638 • EquifaxT1190
NotPetya spread rapidly in June 2017, initially impacting organizations in Ukraine and then causing disruption in multiple countries. Although presented as ransomware, government and security reporting described it as destructive, with victims unable to recover data even after payment. U.S. and UK government statements publicly attributed the attack to Russia’s military, and security advisories documented widespread operational impact and significant financial losses across affected organizations.
WannaCry was a fast-spreading ransomware outbreak that disrupted organizations worldwide, including major impacts to the UK National Health Service (NHS). Microsoft and government advisories linked the outbreak to exploitation of SMB-related vulnerabilities addressed by Microsoft’s MS17-010 updates, and Microsoft referenced CVE-2017-0144 in its customer guidance. Government reporting described operational disruption and response costs for affected organizations.
high confidenceransomware • CVE-2017-0144 • WannaCryT1486T1210
Dyn reported large-scale distributed denial-of-service (DDoS) attacks against its managed DNS infrastructure on October 21, 2016, causing widespread service disruption for many internet platforms that depended on Dyn DNS resolution. U.S. prosecutors later announced guilty pleas related to the creation and operation of the Mirai botnet, which was used in major DDoS attacks during the period, including attacks affecting Dyn. The incident highlighted systemic availability risk from botnet-driven DDoS on core internet services.
Attackers compromised systems at the central bank of Bangladesh and used the SWIFT financial messaging system to send fraudulent transfer requests from the bank’s account at the Federal Reserve Bank of New York. The operation resulted in approximately $81 million being transferred and laundered, with additional transfers blocked. U.S. authorities later charged a North Korean regime-linked programmer for a campaign that included the Bangladesh Bank heist, tying the theft to broader state-backed illicit cyber activity.
The U.S. Office of Personnel Management (OPM) experienced major data breaches that exposed sensitive information about federal employees, contractors, and individuals involved in background investigations. Congressional oversight reporting described the scope of affected systems and weaknesses in security practices. The incident drove significant government response and remediation efforts, though precise total financial costs are not consolidated in the cited sources.
Anthem disclosed a cyberattack that exposed personal information of approximately 78.8 million current and former members. U.S. authorities later brought charges in connection with the breach, and regulators announced major financial settlements, including a record HIPAA settlement with HHS OCR and a multistate attorneys general settlement. These outcomes highlight substantial regulatory and legal financial consequences for large-scale healthcare data breaches.
Sony Pictures Entertainment suffered a destructive cyberattack that disrupted business operations and resulted in the theft and public release of internal data. The FBI publicly stated it concluded North Korea was responsible for the attack. Later U.S. Department of Justice statements about related cyber conspiracies also referenced the Sony Pictures incident.
Home Depot announced findings from its investigation into a data security incident involving malware on its U.S. and Canadian self-checkout point-of-sale systems. The company’s disclosures and subsequent filings described response actions, investigation, and costs associated with the incident. The event resulted in significant remediation and legal expenses, partially offset in some periods by insurance recoveries as disclosed in filings.
Target disclosed unauthorized access to payment card data for guests who shopped at U.S. Target stores during the 2013 holiday season. The company reported the incident publicly and in securities filings, describing ongoing investigation and remediation. Public reporting and subsequent investigations connected the incident to substantial response costs, litigation, and payments to affected parties, though precise totals vary by accounting period and source.
Saudi Aramco disclosed that a destructive malware attack affected its corporate computer systems and required restoration work, while stating oil production was unaffected. Public reporting described tens of thousands of workstations impacted and significant operational disruption to business IT. Vendor analyses characterize Shamoon as destructive malware designed to wipe systems.
Sony disclosed that an external intrusion affected the PlayStation Network and Qriocity services, leading to a multi-week service outage and exposure of user account data. Sony announced it was investigating the compromise and took systems offline while rebuilding security controls. Public reporting cited Sony’s estimate of roughly 14 billion yen (about $171 million at the time) in costs tied to response and customer remediation.
Stuxnet was a highly specialized malware campaign designed to target industrial control environments, including systems using Siemens Step7 software. Public technical advisories and analyses described how it could interfere with industrial processes while spreading in Windows environments. Public reporting and government analysis linked Stuxnet to Iran’s nuclear program, but a definitive public attribution was not formally confirmed in the cited sources.