Government of Guam
May 2, 2026
•[ zero-day vulnerability, cyber incident response, website disruption ]
The Government of Guam activated its cyber incident response on May 2, 2026 after hackers exploited a critical zero-day vulnerability affecting globally used cPanel-hosted websites. Multiple GovGuam websites were disrupted, prompting a government-wide assessment and response. Officials said emergency services remained unaffected; public reporting did not identify the actor, confirm data theft, or quantify the disruption duration.
MiniMed Panamá
May 2, 2026
•[ data exposure, PII, plaintext credentials ]
MiniMed Panam was listed among the Panamanian health-sector platforms directly affected by data exposure in a Vecert Analyzer intelligence report cited by La Estrella de Panam. The incident was dated May 2, 2026, and outside OSINT reporting described roughly 400,000 exposed records associated with MiniMed, including a usersdata table with 74,233 records containing PII and plaintext credentials. Public reporting did not identify the threat actor, encryption, data destruction, or operational disruption.
Clínica Hospital Panamericano
May 2, 2026
•[ data leak, healthcare, patient database exposure ]
Ch-panamericana.com was listed among the Panamanian incidents in a Vecert Analyzer intelligence report cited by La Estrella de Panam. The domain appears to correspond to Clnica Hospital Panamericano, a healthcare provider in Panam Oeste, and outside monitoring referenced alleged patient database exposure from ch-panamericano.com. The incident was dated May 2, 2026. Outside OSINT reporting linked the leak to ohmydays and Waxx Org., but public reporting did not confirm encryption, data destruction, or operational disruption.
webhostingnz.com
May 1, 2026
•[ API token compromise, authentication bypass, unauthorized access ]
A fullaccess API token was added to a cPanel account for webhostingnz.com server rosie.whsl206.com, giving an attacker control of the account for several hours. The client area and server login were unavailable for ~6hours, and the provider did not shut down the server. The incident is linked to the cPanel authentication bypass vulnerability (CVE202641940).
Reborn Gaming
April 30, 2026
•[ data breach, gaming, vulnerability ]
In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM). The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.
Canonical
April 30, 2026
•[ DDoS, hacktivism, service outage ]
A hacktivist group claimed responsibility for a distributed denialofservice attack that flooded Canonicals publicfacing infrastructure on 1May2026, causing Ubuntu website, package repositories and security API to become unavailable for over 24hours.
Kentwood Public Schools
April 30, 2026
•[ malware, insider threat, network disruption ]
A student deployed malicious software that interfered with Kentwood Public Schools network, causing districtwide WiFi connectivity loss, which was later isolated and restored with help from external experts.
Advanced Diagnostic Imaging
April 30, 2026
•[ ransomware, electronic medical records, healthcare ]
Columbia Surgical Partners said it was unable to access electronic medical records after its parent company, Advanced Diagnostic Imaging, was hit by a reported ransomware attack. Available reporting confirms EHR-access disruption at Columbia Surgical Partners, but does not publicly confirm a responsible ransomware group, data theft, ransom demand, restoration timeline, or whether other ADI systems or sites were affected.
At least one Claude Code user
April 30, 2026
•[ malware, fake installer, credential harvesting ]
A fake Claude Code installer campaign likely affected many users searching for Anthropic's Claude Code tool, though public reporting did not identify specific victims or quantify the total number infected. The campaign delivered a PowerShell payload that extracted decrypted cookies, saved passwords, and payment data from Chromium-based browsers on infected machines. Public reporting did not identify the specific actor, country, volume of stolen data, or any operational disruption.
Undisclosed Pakistani government entity
April 30, 2026
•[ cyber espionage, Shadow-Earth-053, Microsoft Exchange ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Pakistani government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Thai government entity
April 30, 2026
•[ espionage, vulnerability exploitation, web shells ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Thai government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Indian government entity
April 30, 2026
•[ espionage, web shell, ShadowPad ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Indian government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Myanmar government entity
April 30, 2026
•[ cyber espionage, vulnerability exploitation, web shells ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Myanmar government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Malaysian government entity
April 30, 2026
•[ espionage, vulnerability exploitation, unpatched software ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Malaysian government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Sri Lankan government entity
April 30, 2026
•[ cyber espionage, Shadow-Earth-053, unpatched servers ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Sri Lankan government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Taiwanese government entity
April 30, 2026
•[ espionage, state-sponsored, web shells ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Taiwanese government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Polish defense-sector organization
April 30, 2026
•[ espionage, web shells, ShadowPad ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Polish defense-sector organization by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Liberty Mutual Insurance
April 30, 2026
•[ data-extortion, data leak, personal information ]
Everest Group claimed responsibility for a data-extortion attack against Liberty Mutual Insurance on April 30, 2026 and began leaking what it claimed was more than 108 GB of stolen data, including policyholder personal, financial, and insurance information. Public reporting did not confirm encryption, deletion, or operational disruption.
Groupe 3R (Réseau Radiologique Romand)
April 30, 2026
•[ ransomware, data theft, healthcare ]
On April 30, 2026, Groupe 3R (Rseau Radiologique Romand) was hit by a ransomware attack that reduced system availability and caused some patient examinations to be rescheduled. The incident was reported to the Swiss Federal Cybersecurity Office and a criminal complaint was filed. Akira later claimed responsibility and alleged theft of 48 GB of data, including patient information, employee identification documents, payment details, and corporate records.
Florida East Coast Railway
April 30, 2026
•[ data-extortion, data leak, PII ]
PayoutsKing claimed responsibility for a data-extortion attack against Florida East Coast Railway on April 30, 2026 and threatened to leak sensitive data unless negotiations were initiated. DataBreach.com later indexed 16,668 rows associated with the breach, including names, email addresses, and phone numbers. Public sources did not confirm successful encryption or operational disruption.