Panera Bread
August 1, 2025
•[ data breach, unauthorized access, data leak ]
Panera Bread reportedly suffered a data breach that exposed approximately 14 million customer records after unauthorized access to an application database, with no evidence of operational disruption disclosed at the time of reporting.
Colombian Justice Minister Andres Idarraga
August 1, 2025
•[ spyware, Pegasus, surveillance ]
Colombias justice minister stated that forensic evidence indicates his phone was hacked using Israeli Pegasus spyware during the second half of 2025 while he was investigating alleged corruption in the military. He alleged the operation was ordered through the Defense Ministry using state counterintelligence structures and confidential funds. According to his statement, investigators found his phone was taken over more than 8,700 times and that 2.3 GB of data were downloaded, including sensitive corruption complaints, and that the camera/microphone were illicitly activated on numerous occasions. The incident is characterized as a targeted spyware intrusion against a senior government official with alleged state involvement.
Canada Goose
August 1, 2025
•[ data leak, third-party breach, customer records ]
BleepingComputer reported that Canada Goose was investigating after ShinyHunters leaked more than 600,000 customer records. Canada Goose said it had not found evidence its own systems were breached and believed the data related to past customer transactions. ShinyHunters told BleepingComputer the dataset was unrelated to recent SSO attacks and claimed it originated from a third-party payment processor breach and dates back to August 2025. The exposed data was described as including purchase history plus device/browser information and order values; it did not appear to include full payment card numbers.
Jabłonna Lacka Water Treatment Plant
August 1, 2025
•[ industrial control systems, ICS, critical infrastructure ]
Poland's Internal Security Agency reported that attackers breached industrial control systems at multiple water treatment facilities in 2025, including Jabonna Lacka. The attackers gained access to operational systems controlling water treatment processes and in some cases obtained the ability to modify equipment operational parameters, creating a direct risk to operational continuity and public water supply. Public reporting says the August 2025 incident nearly caused a municipality to lose its water supply before authorities intervened. Polish cybersecurity reporting linked several water-facility incidents to a pro-Russian hacktivist group, but no public source identified the specific named perpetrator for the Jabonna Lacka incident.
Qilin ransomware group
July 31, 2025
•[ ransomware, hack, leak ]
Compromise of Qilins affiliate panel by rival actors enabled access to internal systems and stolen victim files.
Foreign embassies in Moscow (multiple missions)
July 31, 2025
•[ espionage, malware, government ]
FSB-linked APT Secret Blizzard (Turla) used ISP-level access in Russia to deliver espionage malware against multiple foreign embassies in Moscow; campaign disclosed by Microsoft. Data stolen likely includes diplomatic emails/credentials; exact volume not reported.
Acea
July 31, 2025
•[ ransomware, malware, energy ]
Italian utility company Acea suffered another ransomware attack, this time claimed by World Leaks. Systems were encrypted, disrupting operations, though the exact duration and number of affected customers were not disclosed.
Ministry of iTaukei Affairs
July 31, 2025
•[ hack, government ]
The Ministry of iTaukei Affairs official Facebook page was hacked again after an April 2025 incident.
Institute Ruđer Bošković (administrative/professional services IT)
July 31, 2025
•[ ransomware, education ]
IRB was hit by a ransomware attack on July 31, 2025 via Microsoft SharePoint ToolShell vulnerabilities; administrative/professional services systems were encrypted. IRB refused to pay, isolated affected segments, and restored from backups by Aug 8; later updates confirmed full service restoration and no evidence of data exfiltration.
Fogos.pt (wildfire mapping platform)
July 31, 2025
•[ ddos, technology ]
On July 31, 2025, fogos.pt, a Portuguese volunteer-run wildfire information platform, was hit by the first of two DDoS waves, peaking at 33k requests/sec and 1.7 Gbps for 7 minutes. A second wave followed on August 1 at 31k rps / 849 Mbps for 5 minutes. Both attacks were automatically mitigated by Cloudflares Project Galileo, and the site remained available throughout, with no data loss or outages.
Undisclosed Russian pharmacy chains
July 31, 2025
•[ ransomware ]
The Record reports multiple Russian pharmacies were shut down due to a cyberattack disrupting operations and payment/services.
Thailand Ministry of Labour
July 31, 2025
•[ hacking, disruption of service ]
Thai officials said the Ministry of Labour website was hacked and later restored; the attack disrupted access to public services.
Delfingen Industry
July 31, 2025
•[ cybersecurity incident ]
Company notice references a cybersecurity incident affecting IT systems; details limited pending investigation.
Singapore traffic enforcement (dataset of offenders)
July 31, 2025
•[ data leak, government ]
AsiaOne reports that 1,300 names and addresses of traffic offenders were published online; police are investigating.
Mailchimp
July 31, 2025
•[ ransomware, data leak ]
Everest ransomware group claimed a small breach of Mailchimp systems, sharing limited details; no disruption reported.
Louis Vuitton UK (LVMH)
July 31, 2025
•[ cyberattack, data leak ]
HackRead notes a cyberattack affecting Louis Vuitton UK customers, marking the third LVMH incident in three months; details limited.
Undisclosed European ministry
July 31, 2025
•[ malware, apt, intelligence collection ]
HackRead reports DoNot APT deployed LOPTiKMod malware against a European ministry to collect intelligence; attribution aligns with prior DoNot operations.
Herbapol Lublin S.A.
July 31, 2025
•[ ransomware ]
Polish trade press reports cyberattack on Herbapol Lublin with a ransom demand; operational interruptions mentioned.
AirNet ISP (Saint Petersburg)
July 31, 2025
•[ malicious activity, outage ]
ixbt.com reports provider AirNet in St. Petersburg suffered a citywide outage linked to malicious activity.
Czech Police, Interior Ministry, and other government offices
July 31, 2025
•[ government, hacktivism ]
iRozhlas reports hackers attacked Czech police and government websites in retaliation for cooperation in Ukraine-related operations.