Boyne City, MI
May 12, 2026
•[ cybersecurity incident, municipal computer network, utility bill payments ]
Boyne City, Michigan reported a cybersecurity incident affecting limited portions of its municipal computer network and digital systems. The city worked with IT professionals and cybersecurity specialists to secure affected systems and notified the FBI. Later reporting said city computer systems were operating with limited functionality, online utility bill payments were temporarily disabled, account balance and payment history information was unavailable, the city could not accept utility payments in person, and utility late fees and shutoffs were waived during restoration. Public reporting did not identify a threat actor, confirm ransomware, specify the technical mechanism, report data theft, or confirm whether any data was compromised.
Foxconn North American operations
May 11, 2026
•[ cyberattack, data theft, operational disruption ]
Nitrogen claimed responsibility for a cyberattack against Foxconn and alleged theft of roughly 8TB of data spanning more than 11 million files. Foxconn confirmed that some North American factories suffered a cyberattack and said affected factories were resuming normal production. Public reporting supports operational disruption and alleged large-scale data theft, but does not confirm file encryption, data destruction, or the specific disruption mechanism.
Grafana Labs
May 11, 2026
•[ source code leak, extortion, compromised credentials ]
Grafana Labs confirmed that a cybercrime group used a compromised GitHub token to access its GitHub repositories and download its codebase and internal GitHub repository content. The attackers demanded ransom to prevent disclosure, but Grafana said customer production systems, Grafana Cloud, customer operations, customer data, and personal information from production systems were not compromised.
Škoda Auto
May 11, 2026
•[ data leak, vulnerability exploitation, unauthorized access ]
Attackers exploited a vulnerability in koda Auto's online shop software and gained temporary unauthorized access to the shop system. koda said customer names, addresses, contact details, order details, account information, and password hashes may have been accessed, but credit card data was not stored in the system. The company took the online shop offline for containment, patched the vulnerability, reviewed security controls, notified authorities, and retained external forensic experts; the specific threat actor was not identified.
Sistema Bancario Softbank
May 11, 2026
•[ data leak, source code exposure, dark web ]
Sistema Bancario Softbank was listed among the most severe Panamanian incidents in a Vecert Analyzer intelligence report cited by La Estrella de Panam. The incident was dated May 11, 2026 and described as compromising corporate and financial structures, with exposed data appearing in dark-web forums. Outside OSINT reporting attributed the leak to V0lt4r0x and referenced alleged source-code exposure for a Softbank banking system used in Latin America, but public reporting did not confirm the specific intrusion vector, encryption, data destruction, or operational disruption.
Direction générale de la Comptabilité publique et du Trésor
May 10, 2026
•[ cyberattack, data exfiltration, leak site ]
Senegal's Direction gnrale de la Comptabilit publique et du Trsor reported an incident affecting part of its information systems beginning May 10, 2026 and activated continuity measures. Senegalese and cyber-specialist reporting later described the incident as a cyberattack, with AuditTeam claiming exfiltration of more than 70 GB of sensitive data and listing the target on a leak site. Public reporting did not confirm the full data set, final recovery date, or whether personal data was included.
ВЗГЛЯД (Vzglyad)
May 9, 2026
•[ DDoS attack, cybersecurity, news media ]
The Russian news site reported a massive DDoS attack on the morning of May 9, 2026, detected at 9:45 Moscow time shortly before the Victory Day parade in Moscow. Technical staff and cybersecurity specialists said the main flow of junk traffic came from servers in the European Union, with peak loads from Germany and the Netherlands. Traffic filtering kept the site operational, with only a short slowdown in homepage updates.
Instructure
May 7, 2026
•[ vulnerability, page-alteration, threat actor ]
On May 7, 2026, ShinyHunters gained additional access through a second Canvas vulnerability and altered pages shown to some logged-in students and teachers. Instructure detected and disabled the page-alteration activity after approximately 10 minutes, took Canvas offline into maintenance mode to contain the incident, and later took Free-for-Teacher offline.
Powell Electronics
May 7, 2026
•[ data breach, Personally Identifiable Information (PII), extortion ]
PayoutsKING claimed responsibility for an attack on Powell Electronics and threatened to release sensitive data unless the company negotiated. DataBreach indexed 198,676 rows with names, email addresses, phone numbers, and street addresses. Later breach-notification reporting said Powell began notifying affected individuals that data including Social Security numbers and driver's license information had been accessed. Public reporting did not confirm encryption, data destruction, or attacker-caused operational disruption.
Nova Poshta
May 7, 2026
•[ DDoS attack, IT systems disruption, service availability ]
Nova Poshta reported a DDoS attack on its IT systems on May 7, 2026, warning users of minor temporary difficulties in company services. The company said the situation was under control, IT specialists were countering the attack, and backup service schemes had been activated.
Cushman & Wakefield
May 5, 2026
•[ vishing, extortion, data leak ]
In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group. Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.
Trellix
May 5, 2026
•[ source code leakage, unauthorized access, cyberattack ]
Trellix disclosed unauthorized access to a portion of its source code repository in May 2026. RansomHouse later claimed responsibility and published screenshots as proof of access. Trellix said it had found no evidence that its source-code release or distribution process was affected or that its source code had been exploited. Public reporting did not confirm encryption, data destruction, operational disruption, or customer data exposure.
Arbeitsgemeinschaft Wirtschaftlichkeitsprüfung Niedersachsen e.V. (Arwini)
May 5, 2026
•[ ransomware, data exfiltration, health information ]
Kairos ransomware actors attacked Arbeitsgemeinschaft Wirtschaftlichkeitsprfung Niedersachsen e.V. (Arwini), the prescription-review association for statutory health insurance prescriptions in Lower Saxony. Police confirmed Kairos was responsible, that ransomware was used to encrypt data, and that data exfiltration occurred. Potentially affected data included contact, health, and billing information for patients; more than 70,000 records may have been stolen, though the exact scope remained under investigation.
West Pharmaceutical Services
May 4, 2026
•[ ransomware, data exfiltration, encryption ]
West Pharmaceutical Services detected a ransomware intrusion on May 4, 2026. The company reported that attackers exfiltrated data and encrypted systems, prompting containment actions and disrupting manufacturing, shipping, and receiving operations across multiple global facilities. Public reporting did not identify the threat actor or specify the volume or type of exfiltrated data.
Braintrust
May 4, 2026
•[ unauthorized access, API keys, cloud security ]
Braintrust confirmed unauthorized access to an internal AWS account on May 4, 2026 that likely exposed customer org-level AI-provider API keys used to access cloud-based AI models. Braintrust locked down the compromised account, audited and restricted related systems, rotated internal secrets, and instructed customers to rotate affected keys.
Oriental Diamond Co., Ltd.
May 4, 2026
•[ ransomware, cyberattack, data leak ]
Oriental Diamond Co., Ltd. confirmed that on May 4, 2026 a third party used ransomware in a cyberattack against a company-managed server, encrypting system data and causing business stoppage. The company reported possible leakage of names, addresses, and phone numbers, said bank account, credit card, and My Number information were not included, and stated that it would stop using the VPN path identified as the intrusion route. Public Japanese security reporting linked the confirmed incident to a The Gentlemen leak-site claim.
Cushman & Wakefield
May 3, 2026
•[ vishing, PII, data leak ]
Cushman & Wakefield confirmed a vishing-related security breach in May 2026 after ShinyHunters and Qilin separately listed the company. ShinyHunters claimed theft of more than 500,000 Salesforce records containing PII and internal corporate data and later reportedly published a 50GB Salesforce-linked dataset after negotiations failed. DataBreach indexed 2,198,033 rows associated with the breach. Public sources did not confirm encryption or operational disruption.
Red Radimagen
May 3, 2026
•[ data leak, health-sector, medical records ]
Red Radimagen was listed among the Panamanian health-sector entities directly affected by data exposure in a Vecert Analyzer intelligence report cited by La Estrella de Panam. The incident was dated May 3, 2026. Outside OSINT reporting attributed the Radimagen leak to ohmydays, linked the actor to Waxx Org., and referenced exposed medical or patient-related records from an unsecured server, but public reporting did not confirm encryption, data destruction, or operational disruption.
4VPS
May 2, 2026
•[ ransomware, infrastructure compromise, billing systems ]
4VPS disclosed on May 2, 2026 that an attack affected its website and billing systems. DataBreaches.net reported that The Gentlemen ransomware group later acknowledged that part of its own backend infrastructure had been compromised because some of it was hosted with 4VPS. Public reporting did not identify the attacker, the exact intrusion method, the total data volume, or the duration of service disruption.
Standard-Examiner
May 2, 2026
•[ ransomware, data leak, cyberattack ]
Qilin listed Standard-Examiner on its leak site on May 2, 2026 and claimed responsibility for a cyberattack, threatening to release sensitive data. Separate reporting noted earlier April production difficulties at the newspaper, but the Standard-Examiner had not publicly confirmed ransomware, data theft, or a connection between the printing disruption and Qilin's claim.