Signature Healthcare Brockton Hospital
April 6, 2026
•[ cyberattack, data theft, healthcare ]
A cyberattack detected on April 6, 2026 affected information systems at Signature Healthcare and Signature Healthcare Brockton Hospital, triggering downtime procedures, ambulance diversion, chemotherapy cancellations, EHR and patient portal outages, pharmacy prescription-fill disruption, lab delays, and medical-record request disruption; Anubis claimed it stole 2 TB of data, but Signature Healthcare did not confirm data theft.
Undisclosed critical infrastructure organization
April 6, 2026
•[ Chinese-nexus intrusions, critical infrastructure, lateral movement ]
Darktrace reported Chinese-nexus intrusions affecting critical infrastructure organizations, with some high-value intrusions involving lateral movement before data exfiltration.
The McLamb Group, Inc.
April 6, 2026
•[ data leak, PII, Social Security numbers ]
PEAR claimed The McLamb Group, Inc. on its leak site with an estimated attack date of April 6, 2026. DataBreach indexed 124,203 rows and listed exposed fields including Social Security numbers, dates of birth, email addresses, phone numbers, names, and street addresses. Public reporting did not confirm encryption, data destruction, attacker-caused operational disruption, or the exact intrusion vector.
Minidoka Memorial Hospital
April 5, 2026
•[ cyber attack, healthcare, operational disruption ]
A cyber incident on Easter morning limited imaging services at Minidoka Memorial Hospital in Rupert, Idaho, leading to temporary emergency patient transfers; internal systems were affected but patient care continued, and imaging was fully restored by midnight on April 19, 2026.
Taiwan High Speed Rail Corporation
April 5, 2026
•[ radio interference, TETRA communications, software-defined radio ]
A 23-year-old university student identified by the surname Lin allegedly interfered with Taiwan High Speed Rail's TETRA radio communications system using software-defined radio equipment and handheld radios. The unauthorized General Alarm signal triggered emergency braking or emergency stop procedures, affecting four high-speed trains for approximately 48 minutes. Public reporting did not identify data theft, ransomware, or a financial motive.
Shine Aviation
April 4, 2026
•[ data leak, employee credentials, employee records ]
Anubis claimed on April 4, 2026 that it obtained 57 GB, or more than 68,000 files, from Geraldton-based Shine Aviation, including alleged employee credentials and records, access-card scans, operational documentation, and aircraft-related certificates; the claim was not independently verified.
Anodot
April 4, 2026
•[ data breach, token theft, unauthorized access ]
ShinyHunters allegedly breached Anodot, causing its data connectors to stop working and enabling downstream customer cloud-data access through stolen tokens.
Equity Life Indonesia
April 4, 2026
•[ ransomware, data theft, data encryption ]
The Gentlemen ransomware group claimed responsibility for an attack against Equity Life Indonesia on April 4, 2026, threatening to publish stolen data unless contacted. Independent ransomware trackers listed Equity Life Indonesia under The Gentlemen, and CYFIRMA reported the campaign objective as data theft, data encryption, and financial gain, but public sources did not confirm the exact data volume, affected record count, or operational disruption.
Amtrak
April 3, 2026
•[ data leak, ransomware, ShinyHunters ]
In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak. The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. The exposed data contained over 2M unique email addresses along with names, physical addresses and customer support records.
Hong Kong Hospital Authority (Kowloon East Cluster)
April 3, 2026
•[ data leak, unauthorized retrieval, patient data ]
The Hospital Authority detected unauthorized retrieval and leakage of patient data from the Kowloon East Cluster on April 3, 2026, affecting more than 56,000 patients; internal checks did not indicate a cyberattack, and police and privacy regulators were notified.
SongTrivia2
April 2, 2026
•[ data breach, data leak, password hashes ]
In April 2026, the music trivia platform SongTrivia2 suffered a data breach that was subsequently published to a public hacking forum. The data contained a total of 291k unique email addresses sourced from either Google OAuth logins or accounts created on the site, the latter also containing bcrypt password hashes. The data also included names, usernames and avatars.
PSK WIND Technologies
April 2, 2026
•[ data breach, hacktivism, server compromise ]
Handala claimed it breached PSK WIND Technologies servers and deleted sensitive information tied to Israeli air-defense command-and-control systems.
The Northern Ireland Education Authority
April 2, 2026
•[ cyberattack, personal information, data breach ]
The Northern Ireland Education Authority reported a cyberattack on the C2k school IT network that disrupted access and involved targeted access to confidential personal information.
Coral Bay Nickel Corporation
April 2, 2026
•[ ransomware, server encryption, cyberattack ]
Coral Bay Nickel suffered ransomware encryption of two servers, but production systems remained unaffected and operations continued.
DigiCert, Inc.
April 2, 2026
•[ social engineering, malicious ZIP file, EV code-signing certificates ]
A threat actor used DigiCert's customer support channel on April 2, 2026 to deliver a malicious ZIP file disguised as a customer screenshot, compromising two DigiCert support analyst systems. The attacker used analyst-level access to pivot into DigiCert's internal support portal and obtain initialization codes for approved EV code-signing certificate orders across specific customer accounts. DigiCert revoked 60 associated certificates by April 17, including 27 explicitly linked to the threat actor and 11 reported as used to sign Zhong Stealer malware; the specific perpetrator was not publicly identified.
Rituals
April 1, 2026
•[ data breach, unauthorized access, PII ]
Rituals confirmed that an unauthorized download of My Rituals membership data occurred in April 2026, affecting customers in Europe, the United Kingdom, and the United States. The downloaded data included names, dates of birth, gender, postal and email addresses, phone numbers, preferred store locations, and account types; Rituals did not disclose the exact number of affected members, and reporting stated that passwords and payment data were not accessed.
St. Joseph County
April 1, 2026
•[ data breach, cloud security, fax server ]
St. Joseph County confirmed a breach of an external cloud-based fax server while disputing Handalas broader 2 TB data-theft claim.
At least one spyware-targeted WhatsApp user
April 1, 2026
•[ spyware, malware, social engineering ]
WhatsApp said about 200 users were tricked into installing a fake WhatsApp app containing spyware.
National Health Insurance Company (CNAM)
April 1, 2026
•[ cyberattack, data exfiltration, health insurance ]
CNAM confirmed a cyberattack that may have resulted in limited data exfiltration from Moldovas health insurance database.
At least one Facebook Business account owner
April 1, 2026
•[ phishing, account takeover, credential harvesting ]
The AccountDumpling phishing campaign, linked to Vietnamese criminal actors, abused Google AppSheet as a phishing relay to send authenticated phishing emails impersonating Meta/Facebook support. The phishing pages harvested Facebook Business account credentials, recovery information, 2FA codes, and identity documents, enabling account takeover and resale through an illicit storefront. Reporting mapped roughly 30,000 compromised accounts across more than 50 countries.