Gas station operators
May 15, 2026
•[ operational technology, critical infrastructure, cyberattack ]
Iranian hackers reportedly accessed internet-connected automatic tank gauge systems at gas stations in multiple U.S. states. Automatic tank gauges are OT systems used to monitor physical fuel tanks, but reporting indicates the attackers altered displayed readings rather than changing actual fuel volumes or physically manipulating fuel operations.
Chanhassen Dinner Theatres
May 15, 2026
•[ cyberattack, operational disruption, system outage ]
Chanhassen Dinner Theatres experienced a cyberattack affecting part of its computer network on May 15, 2026 and took systems offline while working with outside experts to restore operations. The incident disrupted internet, phone, customer-service, and operational functions and contributed to rescheduled or canceled performances, alongside a separate cast illness/norovirus disruption. Public reporting did not confirm encryption, data theft, a ransom demand, or a responsible actor.
Raise the Bottom
May 15, 2026
•[ substance use disorder treatment, addiction recovery, behavioral health services ]
Raise the Bottom, an Idaho substance use disorder treatment organization, was listed in a breach involving 57,507 indexed rows. DataBreach identified exposed names, email addresses, and phone numbers; BreachSense attributed the breach to CMD and described Raise the Bottom as an Idaho-based addiction recovery, counseling, and behavioral health services provider.
At least one node-ipc npm package users
May 14, 2026
•[ supply chain attack, malicious package, credential theft ]
Attackers abused a dormant node-ipc npm maintainer account, likely after re-registering an expired maintainer email domain, and published malicious node-ipc versions 9.1.6, 9.2.3, and 12.0.1 on May 14, 2026. The packages contained an obfuscated credential-stealing payload that harvested developer and CI/CD secrets and exfiltrated them through DNS TXT queries.
Murray County Government
May 13, 2026
•[ cyberattack, government, service disruption ]
Murray County, Georgia reported that a cyberattack hit the county government network, forcing several county offices to limit services or close until network systems were restored. The Tax Commissioner, Tax Assessor, Probate Court, and Juvenile Court offices were closed, while other county offices remained open with limited functionality; 911, public safety, and primary voting continued. Public reporting did not identify a threat actor, confirm ransomware or encryption, specify the technical mechanism, report data theft, or provide a final restoration date.
RubyGems.org
May 12, 2026
•[ malicious packages, supply chain attack, bot accounts ]
RubyGems.org temporarily suspended new account registrations after threat actors used bot accounts to push more than 500 junk or malicious packages, including packages carrying exploits. Existing packages were not compromised, and gem installs and pushes for existing users were unaffected while maintainers tightened account-creation rate limiting and WAF protections.
Boyne City, MI
May 12, 2026
•[ cybersecurity incident, municipal computer network, utility bill payments ]
Boyne City, Michigan reported a cybersecurity incident affecting limited portions of its municipal computer network and digital systems. The city worked with IT professionals and cybersecurity specialists to secure affected systems and notified the FBI. Later reporting said city computer systems were operating with limited functionality, online utility bill payments were temporarily disabled, account balance and payment history information was unavailable, the city could not accept utility payments in person, and utility late fees and shutoffs were waived during restoration. Public reporting did not identify a threat actor, confirm ransomware, specify the technical mechanism, report data theft, or confirm whether any data was compromised.
Foxconn North American operations
May 11, 2026
•[ cyberattack, data theft, operational disruption ]
Nitrogen claimed responsibility for a cyberattack against Foxconn and alleged theft of roughly 8TB of data spanning more than 11 million files. Foxconn confirmed that some North American factories suffered a cyberattack and said affected factories were resuming normal production. Public reporting supports operational disruption and alleged large-scale data theft, but does not confirm file encryption, data destruction, or the specific disruption mechanism.
Grafana Labs
May 11, 2026
•[ source code leak, extortion, compromised credentials ]
Grafana Labs confirmed that a cybercrime group used a compromised GitHub token to access its GitHub repositories and download its codebase and internal GitHub repository content. The attackers demanded ransom to prevent disclosure, but Grafana said customer production systems, Grafana Cloud, customer operations, customer data, and personal information from production systems were not compromised.
Škoda Auto
May 11, 2026
•[ data leak, vulnerability exploitation, unauthorized access ]
Attackers exploited a vulnerability in koda Auto's online shop software and gained temporary unauthorized access to the shop system. koda said customer names, addresses, contact details, order details, account information, and password hashes may have been accessed, but credit card data was not stored in the system. The company took the online shop offline for containment, patched the vulnerability, reviewed security controls, notified authorities, and retained external forensic experts; the specific threat actor was not identified.
Sistema Bancario Softbank
May 11, 2026
•[ data leak, source code exposure, dark web ]
Sistema Bancario Softbank was listed among the most severe Panamanian incidents in a Vecert Analyzer intelligence report cited by La Estrella de Panam. The incident was dated May 11, 2026 and described as compromising corporate and financial structures, with exposed data appearing in dark-web forums. Outside OSINT reporting attributed the leak to V0lt4r0x and referenced alleged source-code exposure for a Softbank banking system used in Latin America, but public reporting did not confirm the specific intrusion vector, encryption, data destruction, or operational disruption.
Direction générale de la Comptabilité publique et du Trésor
May 10, 2026
•[ cyberattack, data exfiltration, leak site ]
Senegal's Direction gnrale de la Comptabilit publique et du Trsor reported an incident affecting part of its information systems beginning May 10, 2026 and activated continuity measures. Senegalese and cyber-specialist reporting later described the incident as a cyberattack, with AuditTeam claiming exfiltration of more than 70 GB of sensitive data and listing the target on a leak site. Public reporting did not confirm the full data set, final recovery date, or whether personal data was included.
ВЗГЛЯД (Vzglyad)
May 9, 2026
•[ DDoS attack, cybersecurity, news media ]
The Russian news site reported a massive DDoS attack on the morning of May 9, 2026, detected at 9:45 Moscow time shortly before the Victory Day parade in Moscow. Technical staff and cybersecurity specialists said the main flow of junk traffic came from servers in the European Union, with peak loads from Germany and the Netherlands. Traffic filtering kept the site operational, with only a short slowdown in homepage updates.
Instructure
May 7, 2026
•[ vulnerability, page-alteration, threat actor ]
On May 7, 2026, ShinyHunters gained additional access through a second Canvas vulnerability and altered pages shown to some logged-in students and teachers. Instructure detected and disabled the page-alteration activity after approximately 10 minutes, took Canvas offline into maintenance mode to contain the incident, and later took Free-for-Teacher offline.
Powell Electronics
May 7, 2026
•[ data breach, Personally Identifiable Information (PII), extortion ]
PayoutsKING claimed responsibility for an attack on Powell Electronics and threatened to release sensitive data unless the company negotiated. DataBreach indexed 198,676 rows with names, email addresses, phone numbers, and street addresses. Later breach-notification reporting said Powell began notifying affected individuals that data including Social Security numbers and driver's license information had been accessed. Public reporting did not confirm encryption, data destruction, or attacker-caused operational disruption.
Nova Poshta
May 7, 2026
•[ DDoS attack, IT systems disruption, service availability ]
Nova Poshta reported a DDoS attack on its IT systems on May 7, 2026, warning users of minor temporary difficulties in company services. The company said the situation was under control, IT specialists were countering the attack, and backup service schemes had been activated.
Cushman & Wakefield
May 5, 2026
•[ vishing, extortion, data leak ]
In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group. Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.
Trellix
May 5, 2026
•[ source code leakage, unauthorized access, cyberattack ]
Trellix disclosed unauthorized access to a portion of its source code repository in May 2026. RansomHouse later claimed responsibility and published screenshots as proof of access. Trellix said it had found no evidence that its source-code release or distribution process was affected or that its source code had been exploited. Public reporting did not confirm encryption, data destruction, operational disruption, or customer data exposure.
Arbeitsgemeinschaft Wirtschaftlichkeitsprüfung Niedersachsen e.V. (Arwini)
May 5, 2026
•[ ransomware, data exfiltration, health information ]
Kairos ransomware actors attacked Arbeitsgemeinschaft Wirtschaftlichkeitsprfung Niedersachsen e.V. (Arwini), the prescription-review association for statutory health insurance prescriptions in Lower Saxony. Police confirmed Kairos was responsible, that ransomware was used to encrypt data, and that data exfiltration occurred. Potentially affected data included contact, health, and billing information for patients; more than 70,000 records may have been stolen, though the exact scope remained under investigation.
West Pharmaceutical Services
May 4, 2026
•[ ransomware, data exfiltration, encryption ]
West Pharmaceutical Services detected a ransomware intrusion on May 4, 2026. The company reported that attackers exfiltrated data and encrypted systems, prompting containment actions and disrupting manufacturing, shipping, and receiving operations across multiple global facilities. Public reporting did not identify the threat actor or specify the volume or type of exfiltrated data.