Based Apparel
May 21, 2026
•[ malware, infostealer, social engineering ]
Based Apparel's merchandise website was compromised and used to present visitors with a fake Cloudflare-style verification prompt that attempted to trick macOS users into running commands that installed infostealer malware. Reporting described the malware as commodity infostealer/Trojan activity intended to steal credentials and passwords. The website was taken offline after the compromise was reported; no confirmed theft of Based Apparel data or visitor data was publicly reported.
Presidential Office of the Republic of North Macedonia
May 21, 2026
•[ insider threat, espionage, data theft ]
An unnamed IT administrator in the Presidential Office of the Republic of North Macedonia was reportedly suspected of copying, decrypting, encrypting, and storing confidential state data from presidential administration computer systems, with allegations that the material may have been intended for a foreign intelligence service. Public reporting did not name the administrator, identify the foreign service, quantify the data, or confirm operational disruption.
Central Board of Secondary Education
May 21, 2026
•[ unauthorized access, payment gateway vulnerability, price manipulation ]
The CBSE revaluation portal's payment system was hit by an unauthorized malicious attack linked to the HDFC payment gateway integration when the portal went live. Approximately 50 students gained unauthorized access or were affected after displayed fee amounts were manipulated, causing payable amounts in some cases to range from Re 1 to nearly Rs 67,000-68,000. Public reporting did not identify the individuals or confirm theft of student data.
Village of Chase
May 19, 2026
•[ Business Email Compromise (BEC), Fraud, Financial Loss ]
A vendors email account was compromised, causing the Village of Chase to send a payment to fraudulent bank details, resulting in a loss of $44,536; most of the funds were recovered and the loss was covered by prioryear surplus.
Undisclosed Arizona dermatology clinic
May 18, 2026
•[ healthcare data breach, medical data, HHS breach tracker ]
A small dermatology clinic in Arizona was reported in the HHS breach tracker as having suffered a healthcare data breach. The initial public figure of 3 million affected individuals was later corrected in the HHS tracker to 500 individuals; the clinic name, breach method, exposed data fields, and threat actor were not reported.
E-Control Systems
May 18, 2026
•[ ransomware, data-extortion, IoT ]
The Gentlemen ransomware group publicly claimed responsibility for a data-extortion attack against E-Control Systems, a California-based IoT-powered wireless temperature-monitoring technology company, on May 18, 2026 and threatened to publish sensitive data unless negotiations began. Public reporting did not confirm encryption, deletion, operational disruption, or the specific data volume.
GitHub
May 18, 2026
•[ poisoned extension, data breach, internal repositories ]
GitHub confirmed that attackers compromised an employee device through a poisoned Visual Studio Code extension and exfiltrated approximately 3,800 internal repositories. TeamPCP claimed responsibility and reportedly offered the stolen data for sale, while GitHub said customer repositories and external enterprise customer data were not impacted.
Delano Public Schools
May 18, 2026
•[ ransomware, network compromise, service disruption ]
Delano Public Schools experienced a network compromise discovered after unauthorized activity caused ransom messages to print throughout the district. The district shut down internet access while experts tested systems and canceled classes on May 20, 2026. Public reporting did not confirm data theft or successful encryption.
Koa Glass Co., Ltd.
May 17, 2026
•[ ransomware, cyberattack, encryption ]
Koa Glass Co., Ltd., a Japanese glass-container manufacturer, publicly reported on May 26, 2026 that some of its internal servers had been encrypted after a third-party ransomware cyberattack. The company said it was working with outside specialists to determine the cause, scope, and recovery path, and that it had not confirmed external data leakage at the time of disclosure. Public Japanese security reporting linked the confirmed incident to a The Gentlemen leak-site claim.
Advanced Diagnostic Imaging, P.C. d/b/a AdvancedHEALTH
May 16, 2026
•[ data leak, ransomware, healthcare ]
DragonForce listed AdvancedHEALTH on its leak site on May 16, 2026 and claimed to have stolen 390 GB of data, including 2.3 million lines of patient data, partner agreements, management, payroll, and HR files. Public reporting noted that AdvancedHEALTH had not confirmed the full scope of DragonForce's claim.
THORChain
May 15, 2026
•[ cryptocurrency theft, vulnerability exploit, private key reconstruction ]
THORChain said a malicious newly churned node operator exploited a vulnerability in the GG20 threshold signature scheme on May 15, 2026, reconstructed a vault private key, and drained approximately $10.7 million from one vault across multiple blockchains. THORChain halted trading and signing operations as a defensive response after the exploit was identified. Public reporting did not identify the perpetrator by name or country.
Salt Mobile SA
May 15, 2026
•[ DDoS attack, service disruption, network security ]
On May 15, 2026, Salt's fixed-line services in Switzerland were disrupted for about 40 minutes by an external distributed denial-of-service attack. Salt said technical teams activated protective measures and restored service; the mobile network was not affected.
WholeHealth Chicago
May 15, 2026
•[ data leak, PII, cyberattack ]
Cmdorganization claimed responsibility for a cyberattack against WholeHealth Chicago on May 15, 2026. DataBreach later indexed 36,409 rows allegedly tied to the breach, including dates of birth, email addresses, phone numbers, and names. Public sources did not confirm file encryption, operational disruption, or a precise intrusion vector.
Gas station operators
May 15, 2026
•[ operational technology, critical infrastructure, cyberattack ]
Iranian hackers reportedly accessed internet-connected automatic tank gauge systems at gas stations in multiple U.S. states. Automatic tank gauges are OT systems used to monitor physical fuel tanks, but reporting indicates the attackers altered displayed readings rather than changing actual fuel volumes or physically manipulating fuel operations.
Chanhassen Dinner Theatres
May 15, 2026
•[ cyberattack, operational disruption, system outage ]
Chanhassen Dinner Theatres experienced a cyberattack affecting part of its computer network on May 15, 2026 and took systems offline while working with outside experts to restore operations. The incident disrupted internet, phone, customer-service, and operational functions and contributed to rescheduled or canceled performances, alongside a separate cast illness/norovirus disruption. Public reporting did not confirm encryption, data theft, a ransom demand, or a responsible actor.
Raise the Bottom
May 15, 2026
•[ substance use disorder treatment, addiction recovery, behavioral health services ]
Raise the Bottom, an Idaho substance use disorder treatment organization, was listed in a breach involving 57,507 indexed rows. DataBreach identified exposed names, email addresses, and phone numbers; BreachSense attributed the breach to CMD and described Raise the Bottom as an Idaho-based addiction recovery, counseling, and behavioral health services provider.
At least one node-ipc npm package users
May 14, 2026
•[ supply chain attack, malicious package, credential theft ]
Attackers abused a dormant node-ipc npm maintainer account, likely after re-registering an expired maintainer email domain, and published malicious node-ipc versions 9.1.6, 9.2.3, and 12.0.1 on May 14, 2026. The packages contained an obfuscated credential-stealing payload that harvested developer and CI/CD secrets and exfiltrated them through DNS TXT queries.
Golf Canada
May 14, 2026
•[ leak, misconfiguration, technology ]
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada didn't respond to multiple attempts to make contact, and it remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.
Murray County Government
May 13, 2026
•[ cyberattack, government, service disruption ]
Murray County, Georgia reported that a cyberattack hit the county government network, forcing several county offices to limit services or close until network systems were restored. The Tax Commissioner, Tax Assessor, Probate Court, and Juvenile Court offices were closed, while other county offices remained open with limited functionality; 911, public safety, and primary voting continued. Public reporting did not identify a threat actor, confirm ransomware or encryption, specify the technical mechanism, report data theft, or provide a final restoration date.
RubyGems.org
May 12, 2026
•[ malicious packages, supply chain attack, bot accounts ]
RubyGems.org temporarily suspended new account registrations after threat actors used bot accounts to push more than 500 junk or malicious packages, including packages carrying exploits. Existing packages were not compromised, and gem installs and pushes for existing users were unaffected while maintainers tightened account-creation rate limiting and WAF protections.