Undisclosed Sri Lankan government entity
April 30, 2026
•[ cyber espionage, Shadow-Earth-053, unpatched servers ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Sri Lankan government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Taiwanese government entity
April 30, 2026
•[ espionage, state-sponsored, web shells ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Taiwanese government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Polish defense-sector organization
April 30, 2026
•[ espionage, web shells, ShadowPad ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Polish defense-sector organization by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Liberty Mutual Insurance
April 30, 2026
•[ data-extortion, data leak, personal information ]
Everest Group claimed responsibility for a data-extortion attack against Liberty Mutual Insurance on April 30, 2026 and began leaking what it claimed was more than 108 GB of stolen data, including policyholder personal, financial, and insurance information. Public reporting did not confirm encryption, deletion, or operational disruption.
Groupe 3R (Réseau Radiologique Romand)
April 30, 2026
•[ ransomware, data theft, healthcare ]
On April 30, 2026, Groupe 3R (Rseau Radiologique Romand) was hit by a ransomware attack that reduced system availability and caused some patient examinations to be rescheduled. The incident was reported to the Swiss Federal Cybersecurity Office and a criminal complaint was filed. Akira later claimed responsibility and alleged theft of 48 GB of data, including patient information, employee identification documents, payment details, and corporate records.
Florida East Coast Railway
April 30, 2026
•[ data-extortion, data leak, PII ]
PayoutsKing claimed responsibility for a data-extortion attack against Florida East Coast Railway on April 30, 2026 and threatened to leak sensitive data unless negotiations were initiated. DataBreach.com later indexed 16,668 rows associated with the breach, including names, email addresses, and phone numbers. Public sources did not confirm successful encryption or operational disruption.
Tessco Technologies
April 30, 2026
•[ ransomware, data exfiltration, data leak ]
On April 30, 2026, the ransomware group PayoutsKing claimed to have exfiltrated and encrypted 615GB of data from Tessco Technologies, a U.S. wireless communications products distributor, including contact information for over 100,000 individuals and Salesforce records for more than 500,000 customers.
Instructure
April 29, 2026
•[ unauthorized access, data leak, PII ]
Instructure detected unauthorized access to part of its Canvas environment on April 29, 2026. The incident exposed user identifying information and messages from affected institutions; Instructure stated that core learning data, course content, submissions, credentials, passwords, dates of birth, government identifiers, and financial information were not compromised.
Developers using compromised Lightning and Intercom packages
April 29, 2026
•[ software supply-chain attack, malware, credential harvesting ]
TeamPCP conducted a Mini Shai-Hulud software supply-chain attack by injecting credential-stealing malware into Lightning Python versions 2.6.2 and 2.6.3, intercom-client npm versions 7.0.4 and 7.0.5, and intercom-php 5.0.2. The malware harvested secrets from developer and CI/CD environments and created more than 1,800 GitHub repositories containing stolen credentials.
Advanta Genetics LLC
April 29, 2026
•[ data leak, healthcare, PII ]
Advanta Genetics LLC, a Texas clinical and molecular diagnostics laboratory, was listed by Aurora on April 29, 2026. Aurora claimed access to patient, provider, employee, financial, legal/regulatory, and proprietary company data. DataBreach.com indexed 280,802 rows containing Social Security numbers, birthdates, email addresses, phone numbers, names, and street addresses. Public reporting noted that Advanta had not confirmed the full scope of Aurora's claims and did not confirm encryption or operational disruption.
Vimeo
April 28, 2026
•[ extortion, data leak, third-party breach ]
In April 2026, the ShinyHunters extortion group listed Vimeo on their extortion portal as part of their "pay or leak" campaign. They subsequently published hundreds of gigabytes of data, predominantly consisting of video titles, technical data and metadata. The data also included 119k unique email addresses, sometimes accompanied by names. Vimeo attributed the exposure to a breach of Anodot, a third-party analytics vendor, and advised the incident does not include "Vimeo video content, valid user login credentials, or payment card information".
Individual Filipino pensioner
April 28, 2026
•[ vishing, phishing, malware ]
A 68-year-old Filipino pensioner received a fraudulent call claiming to be from the Social Security System and was sent a Viber link to a fake app. After installation, malware hijacked his Android phone, froze the screen and power button, and allowed thieves to drain three bank accounts and two e-wallets, stealing more than 1 million.
Vimeo
April 28, 2026
•[ unauthorized access, data leak, stolen data ]
Vimeo confirmed that an unauthorized actor accessed certain user and customer data through the Anodot breach; ShinyHunters later leaked 106GB of stolen data affecting 119,200 email addresses.
Mediaworks Hungary Zrt.
April 28, 2026
•[ data extortion, data leak, financial data ]
World Leaks claimed responsibility for a data-extortion attack against Mediaworks Hungary Zrt. and released nearly 8.5 TB of allegedly sensitive internal files on its dark web site. Local media that reviewed the material said it included payroll records, contracts, financial statements, and internal communications; public reporting did not confirm encryption, deletion, or operational disruption.
Marutake Co., Ltd.
April 28, 2026
•[ ransomware, unauthorized access, system outage ]
Marutake Co., Ltd., a Japanese pharmaceutical and medical-supplies wholesaler, confirmed that a system outage was caused by ransomware resulting from unauthorized external access. As of its May 8, 2026 third notice, some servers remained impaired, some normal operations were difficult, and full restoration was expected to take considerable time, though the company was using alternative measures to maintain stable supply. Public Japanese security reporting linked the confirmed incident to a The Gentlemen leak-site claim, but Marutake stated that external leakage of personal information had not been confirmed.
Gelatissimo
April 27, 2026
•[ data leak, ransomware, financial data ]
DragonForce listed Australian gelato franchiser Gelatissimo on its leak site around April 27, 2026 and claimed to have stolen more than 350 GB of data, with other reporting specifying 352.24 GB. The claimed data included sensitive employee data, financial details, operational information, and executive contact details, and the group threatened publication unless the company responded; reviewed reporting did not confirm encryption or operational disruption.
Asian Football Confederation
April 27, 2026
•[ data leak, Personally Identifiable Information (PII), passport scans ]
A threat actor published an alleged Asian Football Confederation and Al Nassr FC player and coach database on a cybercrime forum on April 27, 2026, exposing more than 150,000 records including passport scans, contracts, email addresses, AFC registration files, and personal details. The actor credited ShinyHunters, but public reporting did not confirm ShinyHunters carried out the breach.
Generation Life Limited
April 27, 2026
•[ cyber incident, unauthorized access, third-party service provider ]
Generation Life disclosed a contained cyber incident on April 27, 2026 involving an unauthorized party gaining access to part of its system through a third-party service provider. The company said the incident was quickly contained, core investment systems remained secure, services continued operating normally, and there was no evidence of unauthorized transactions. Qilin later claimed responsibility and alleged access to some Generation Life data, but public reporting did not confirm the scope, data types, encryption, or operational disruption.
eBay Inc
April 26, 2026
•[ DDoS attack, service disruption, hacktivism ]
eBay experienced a widespread service disruption beginning April 26, 2026, affecting search, listings, checkout, and API functionality worldwide; the hacktivist group 313 Team claimed responsibility for a DDoS attack, but eBay did not confirm the cause.
CTT
April 26, 2026
•[ data leak, personally identifiable information, postal service ]
In April 2026, data allegedly obtained from CTT, Portugals national postal service, was posted to a public hacking forum. The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history of the parcel.