Udemy
April 24, 2026
•[ data leak, extortion, cybercrime ]
In April 2026, online training company Udemy was the victim of a pay or leak extortion attempt perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also included names, physical addresses, phone numbers, employer information and instructor payout methods including PayPal, cheque and bank transfer.
Kent District Library
April 24, 2026
•[ ransomware, cyberattack, service disruption ]
Kent District Library closed all branches after a ransomware attack disrupted computer systems and network-dependent services.
Udemy, Inc.
April 24, 2026
•[ data leak, extortion, ShinyHunters ]
ShinyHunters listed Udemy in a pay-or-leak extortion attempt on April 24, 2026 and subsequently leaked data containing 1.4 million unique email addresses belonging to customers and instructors, along with names, physical addresses, phone numbers, employer information, and instructor payout methods. Public reporting did not confirm encryption, deletion, or operational disruption.
East Inc.
April 24, 2026
•[ unauthorized access, internal network, leak-site ]
East Inc. confirmed that it detected unauthorized third-party access to its internal network on April 24, 2026. The company reported the incident to police and relevant authorities and engaged outside security specialists, while stating that external information leakage had not been confirmed. Public Japanese security reporting later linked the confirmed incident to a The Gentlemen leak-site claim, but did not confirm data publication or operational disruption.
i.e.Smart Systems
April 23, 2026
•[ ransomware, data-extortion, data leak ]
The Gentlemen ransomware group publicly claimed responsibility for a data-extortion attack against i.e.Smart Systems, a Houston-area technology integrator, on April 23, 2026 and threatened to leak sensitive data if the company did not engage in negotiations. Public reporting did not confirm encryption, deletion, operational disruption, or the specific data volume.
Anthropic
April 21, 2026
•[ unauthorized access, third-party vendor breach, data leak ]
A private online group reportedly gained unauthorized access to Anthropics limited-release Claude Mythos Preview model through a third-party vendor environment.
Banco Rendimento
April 21, 2026
•[ security incident, unauthorized access, banking ]
Banco Rendimento identified and contained a security incident on April 21, 2026 affecting some client-access channels and accounts; the bank isolated the threat, restored operations the following day, and reported the incident to Brazilian authorities.
Mile Bluff Medical Center
April 21, 2026
•[ ransomware, data encryption, system disruption ]
Mile Bluff Medical Center experienced system disruptions after a security event that encrypted data, affecting phone and computer systems; clinical teams operated under downtime procedures while the organization investigated and engaged third-party partners.
ADT
April 20, 2026
•[ data breach, extortion, data leak ]
In April 2026, home security firm ADT confirmed a data breach by ShinyHunters, which listed the company on its website as part of a "pay or leak" extortion attempt. The breach impacted 5.5M unique email addresses along with names, phone numbers and physical addresses. ADT also advised that "in a small percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were included" and that it had contacted all affected people.
Pitney Bowes
April 20, 2026
•[ extortion, data leak, hacking collective ]
In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses, along with names, phone numbers and physical addresses. A subset of the data also included Pitney Bowes employee records with job titles.
Aman
April 20, 2026
•[ extortion, data leak, CRM breach ]
In April 2026, the ultra-luxury hotel brand Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign, with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. Whilst not present on all records, the data also included genders, physical addresses, phone numbers, nationalities, dates of birth, spouse names and VIP status codes.
Administration of Kursk region
April 20, 2026
•[ DDoS attack, government, service disruption ]
On April 20, 2026, Kursk regional authorities reported a DDoS attack against regional administration servers that made the live broadcast of a government session unavailable. Officials said the session recording would be published later on official governor and regional government resources, and corroborating reporting said the attack was localized the same day.
Mastodon (mastodon.social)
April 20, 2026
•[ DDoS attack, service disruption, 313 Team ]
Mastodons flagship mastodon.social server was hit by a DDoS attack on April 20, 2026, making the instance unusable at times and causing much of the site to become inaccessible. Mastodon implemented countermeasures by 9:05 a.m. ET and restored access within a couple of hours, while warning that instability could continue as the attack was ongoing; SC Media reported that 313 Team claimed responsibility.
Nordenta
April 20, 2026
•[ ransomware, data leak ]
The Danish dental supplier Nordenta was listed on the Kairos ransomware leak site around April 20, 2026, and Computerworld reported on April 22 that the company had been hit by ransomware. Kairos claimed to have stolen 1.68 TB of data and used the leak-site post to pressure company executives, but the specific data categories and operational impact were not confirmed in the reviewed sources.
ADT Inc.
April 20, 2026
•[ vishing, social engineering, data breach ]
ShinyHunters compromised an ADT employee Okta SSO account through vishing, used the account to access ADTs Salesforce instance, and stole personal information later assessed by Have I Been Pwned as affecting 5.5 million individuals.
BePrime
April 20, 2026
•[ unauthorized access, missing MFA, credential leak ]
BePrime, a managed cybersecurity services provider in Mexico, was breached in April 2026 after attackers accessed administrator accounts lacking MFA, exfiltrating 12.6 GB of data that included plaintext credentials, client penetration testing reports, Cisco Meraki API keys controlling 1,858 network devices, and live surveillance camera feeds from client offices.
Canada Life
April 20, 2026
•[ extortion, data leak, phishing ]
In April 2026, Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group. The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer support tickets. In their disclosure notice, Canada Life advised that "it is a small proportion of our customers who may have been impacted". In the wake of the incident, Canada Life also published an alert cautioning customers to be wary of phishing attacks, a pattern often seen after the public release of breached data.
SailPoint, Inc.
April 20, 2026
•[ unauthorized access, source code leak, third-party vulnerability ]
SailPoint disclosed unauthorized access to a subset of its GitHub repositories on April 20, 2026. The company said the unauthorized activity was quickly terminated, a vulnerability in a third-party application was remediated, and there was no evidence that customer data in production or staging environments was accessed or that services were interrupted. SailPoint did not publicly name the threat actor or disclose the type or volume of repository data that may have been compromised.
Vercel
April 19, 2026
•[ unauthorized access, OAuth compromise, third-party risk ]
Vercel confirmed unauthorized access to internal systems after a compromised third-party AI OAuth app was used to access a Vercel employee Google Workspace account.
Kelp DAO
April 19, 2026
•[ DDoS, RPC poisoning, Cryptocurrency theft ]
NGB 3rd Technical Surveillance Bureau (TraderTraitor) compromised and poisoned LayerZero RPC infrastructure, launched a DDoS to force failover to the poisoned nodes, and delivered a malicious instruction that drained 116,500 rsETH, worth roughly $292 million, from Kelp DAO.