Cuban Embassy in Washington D.C.
January 1, 2026
•[ cyberespionage, data exfiltration, email breach ]
China-linked hackers exploited long-unpatched Microsoft Exchange vulnerabilities on the Cuban Embassy in Washington D.C.s email servers beginning in January 2026, accessing and exfiltrating the full inboxes of 68 diplomatic officials, including the ambassador and deputy chief of mission.
Venezuelan Ministry of Foreign Affairs
January 1, 2026
•[ espionage, state-sponsored attack, data breach ]
The same China-linked espionage campaign that compromised the Cuban Embassy in Washington D.C. also reportedly exploited Microsoft Exchange servers used by Venezuelas Ministry of Foreign Affairs and accessed officials email communications during the same January 2026 regional campaign.
Undisclosed Mexican Bank #1
January 1, 2026
•[ ransomware, LockBit, electronic transfer services ]
Banco de Mxico reported that an undisclosed bank suffered a January 2026 ransomware incident involving LockBit that affected electronic transfer services; no customer financial impact was reported and the institutions financial impact remained pending.
At least one unnamed victim organization
January 1, 2026
•[ social engineering, credential theft, MFA manipulation ]
MuddyWater, an Iran-linked APT associated with Iran's Ministry of Intelligence and Security (MOIS), used Microsoft Teams social engineering against an unnamed victim organization in early 2026. The attackers established remote access, stole credentials, manipulated MFA protections, deployed AnyDesk and DWAgent for persistence, moved laterally, harvested VPN configuration files and other sensitive data, and exfiltrated information. The attackers later sent extortion emails referencing Chaos ransomware and directed the victim to a Chaos leak site, but reporting said no file-encrypting ransomware was deployed, indicating the ransomware framing was likely a false flag for espionage activity.
Mt. Spokane Pediatrics
January 1, 2026
•[ ransomware, data leak, healthcare ]
Mt. Spokane Pediatrics experienced unauthorized access to certain systems in its network environment on or about January 1, 2026, and files containing patient information were removed. LockBit 5.0 claimed responsibility on January 3, 2026 and threatened to leak the stolen data. The clinic's forensic investigation determined on April 22, 2026 that exfiltrated files contained personal and protected health information for 32,021 individuals, including 29,410 Washington accounts.
At least one IoT device compromised
December 31, 2025
•[ botnet, iot, vulnerability ]
Security researchers reported that the RondoDox botnet successfully exploited a critical vulnerability to take control of at least one internet-connected networking device, enrolling it into a botnet for malicious activity.
Sedgwick Government Solutions
December 31, 2025
•[ ransomware, data leak, file transfer system ]
SecurityWeek reported that Sedgwick confirmed a security incident at its subsidiary Sedgwick Government Solutions after the TridentLocker ransomware group claimed to have hacked it. Sedgwick stated the incident affected only an isolated file transfer system and that the subsidiary is segmented from the rest of Sedgwick, with no evidence of access to claims management servers and no impact on service delivery. The article noted that on New Years Eve, TridentLocker claimed it stole roughly 3.4GB of data from Sedgwick Government Solutions and leaked it publicly, while Sedgwick did not comment on the specifics of the attackers claims.
Missouri State Government Employee Self-Service
December 31, 2025
•[ unauthorized access, forensic investigation, financial fraud prevention ]
Missouris Office of Administration temporarily shut down the Employee Self-Service portal to contain suspicious activity and support a forensic investigation. The agency said the incident was highly localized and involved 47 accounts, and that fraud protection systems detected the unauthorized activity and prevented unauthorized transactions. Reporting noted the issue centered on an unauthorized attempt to access workers deferred savings account information and that the portal remained offline while the state worked to restore service before the next pay date, with contingency plans for pay stubs and W-2 access if downtime continued.
ManageMyHealth
December 30, 2025
•[ ransomware, data leak, healthcare ]
A significant volume of patient medical records was accessed and partially encrypted in a cyber intrusion targeting document systems The threat actor issued a ransom demand and published some data samples online before legal action was taken The breach was discovered in late December and publicly confirmed shortly after
Libya Telecom & Technology Company
December 30, 2025
•[ DDoS, service disruption, network security ]
Libya Telecom & Technology Company (LTT) reported that its systems and network were subjected to ongoing distributed denial-of-service (DDoS) attacks starting December 30, 2025. The company stated it activated an emergency protocol immediately upon detection, contained the majority of the impact, and worked to ensure continuity of essential services while the incident response plan remained in effect and monitoring continued for further attempts.
Sports Medicine and Orthopedics
December 30, 2025
•[ ransomware, data leak, healthcare ]
Sports Medicine & Orthopaedics, a now-closed practice in East Providence, Rhode Island, reported that it was impacted by a ransomware incident in October 2025. Reporting indicates the attack exposed personal and health-related information for roughly 4,000 patients, prompting the practice to issue breach notifications after it had already shut down operations. Public accounts describe a ransomware-driven compromise that resulted in unauthorized access to patient information (typical elements in these incidents include identifiers and clinical/billing-related data), with the key confirmed impact being exposure of patient data tied to the practice rather than a long-running operational outage (since the practice was shuttered).
Southern Oregon Neurosurgery
December 30, 2025
•[ email compromise, hacking, data leak ]
Southern Oregon Neurosurgery (Southern Oregon Neurosurgical and Spine Associates, PC) disclosed a hacking incident that stemmed from an email breach and affected at least 1,000 individuals. According to reporting, the incident occurred in November 2025; the organization said its IT staff isolated the issue immediately once identified. The breach was reported to HHS as a hacking/IT incident involving email, indicating unauthorized access to email content (and potentially attachments) that contained patient-related information. While public reporting did not enumerate every exposed field, the confirmed impact is unauthorized access via email compromise with resultant exposure risk to individuals whose information was present in the affected mailbox(es).
University of Lille
December 29, 2025
•[ data leak ]
Unauthorized access to university systems resulted in the exfiltration of student personal data later advertised on an underground forum.
WhiteDate
December 29, 2025
•[ data leak ]
In December 2025, the dating website "for a Europid vision" WhiteDate suffered a data breach that exposed 6k unique email addresses. The breach exposed extensive further personal information including data related to physical appearance, income, education and IQ.
WhiteDate
December 29, 2025
•[ data leak ]
In December 2025, the dating website "for a Europid vision" WhiteDate suffered a data breach that was subsequently leaked online, initially exposing 6.1k unique email addresses. The leaked data included extensive personal information such as physical appearance, income, education and IQ. A more comprehensive dataset was later provided to HIBP, containing usernames, IP addresses, private messages and a total of 20k unique email addresses.
WhiteDate
December 29, 2025
•[ data breach, data leak, personal information ]
In December 2025, the dating website "for a Europid vision" WhiteDate suffered a data breach that was subsequently leaked online, initially exposing 6.1k unique email addresses. The leaked data included extensive personal information such as physical appearance, income, education and IQ. A more comprehensive dataset was later provided to HIBP, containing usernames, IP addresses, private messages, phpBB password hashes and a total of 20k unique email addresses.
Undisclosed Poland distributed energy facilities
December 29, 2025
•[ cyberattack, OT security, critical infrastructure ]
Coordinated cyberattack targeted distributed energy sites in Poland, compromising OT control and communications systems at roughly 30 facilities and damaging some equipment beyond repair, but failing to disrupt electricity supply.
WhiteChild
December 28, 2025
•[ hacktivism, data deletion, white supremacy ]
Hacktivist Martha Root used AI chatbots and a Python script during a Chaos Communication Congress presentation to collect data from white-supremacist platforms and delete WhiteChild, a platform associated with white-supremacist sperm and egg donor matching. Reporting confirms WhiteChild was one of three distinct sites deleted during the same operation.
WhiteDeal
December 28, 2025
•[ hacktivism, data collection, site deletion ]
Hacktivist Martha Root used AI chatbots and a Python script during a Chaos Communication Congress presentation to collect data from white-supremacist platforms and delete WhiteDeal, a marketplace for racist freelance work. Reporting confirms WhiteDeal was one of three distinct sites deleted during the same operation.
Ubisoft
December 27, 2025
•[ data leak, service disruption ]
Ubisoft suffered a breach in which attackers accessed internal systems controlling the Rainbow Six Siege economy and moderation tools. Game services were globally disrupted, requiring rollback and shutdown of servers for nearly two days.