Eezy Plc
April 8, 2025
•[ ddos ]
NoName057(16) conducted a DDoS attack on employment-services provider Eezy Plc, briefly disrupting its website during the coordinated Finnish campaign on April 8 2025.
Finnish polling-place portal (äänestyspaikat.fi)
April 8, 2025
•[ ddos ]
On April 8 2025, NoName057(16) targeted Finlands polling-place website nestyspaikat.fi with a DDoS attack linked to protests over Ukraine policy, briefly disrupting voter-information access.
Czech Government – Prime Minister’s X (Twitter) Account
April 8, 2025
•[ account takeover, hacktivism, disinformation ]
On April 8 2025, hacktivists compromised the official X account of Czech Prime Minister Petr Fiala and posted fabricated messages about Russian attacks and U.S. tariffs in protest of Czech government policies. Authorities confirmed the intrusion, removed the posts, and restored control within hours. No data theft or encryption occurred.
OP Group
April 8, 2025
•[ ddos, hacktivism ]
Pro-Russian hacktivist group NoName057(16) launched DDoS attacks against OP Group, causing temporary disruption of online banking services in Finland.
Panostaja Oyj
April 8, 2025
•[ ddos, hacktivism ]
NoName057(16) hacktivists targeted Panostaja Oyjs website in a politically motivated DDoS campaign linked to Finlands ceasefire proposal on Ukraine, causing brief outages.
Taaleri Plc
April 8, 2025
•[ denial-of-service, hacktivism ]
Taaleri Plcs public website experienced temporary unavailability after a denial-of-service attack by pro-Russian hacktivist group NoName057(16) on April 8 2025.
Finnish election information portal (vaalit.fi)
April 8, 2025
•[ ddos, hacktivism, service disruption ]
Pro-Russian hacktivist group NoName057(16) carried out a DDoS attack against Finlands official election information site vaalit.fi on April 8 2025, temporarily preventing public access.
Finnish polling-place portal (äänestyspaikat.fi)
April 8, 2025
•[ DDoS attack, hacktivism, protest ]
On April 8 2025, NoName057(16) targeted Finlands polling-place website nestyspaikat.fi with a DDoS attack linked to protests over Ukraine policy, briefly disrupting voter-information access.
Integrated Orthopedics of Arizona
April 7, 2025
•[ healthcare ]
The practice first detected unauthorized activity on April 7, 2025, and began notifying affected patients and regulators on August 11.
Fall River Public Schools
April 7, 2025
•[ ransomware, data leak ]
Fall River Public Schools, Massachusetts, suffered a ransomware attack by the Medusa group that encrypted internal systems and disrupted district operations for several weeks. Attackers demanded $400,000 and claimed to have exfiltrated sensitive data, though the district has not verified theft. Recovery costs exceeded $130,000.
War & Sanctions Portal
April 7, 2025
•[ ddos, state-sponsored, disruption ]
On April 7 2025, Ukraines Main Intelligence Directorate (HUR) reported that a large-scale distributed denial-of-service (DDoS) attack targeted the War & Sanctions portal. The attack generated more than 56 million requests in 30 minutes from over 3,700 virtual machines located in at least ten countries, including Russia and China. It was attributed to Russian special services, but no specific agency was identified. The aim was to disrupt access to sanction-related information; the site remained online and suffered no data loss.
Bremanger Kraft AS
April 7, 2025
•[ hacktivism, unauthorized access, industrial control systems ]
On April 7 2025, hacktivists accessed a web-exposed control interface for Bremanger Kraft ASs hydroelectric dam in western Norway and opened a valve releasing 500 L/s of water for four hours; no casualties or structural damage reported; Norwegian authorities attributed the incident to pro-Russian hacktivists.
Toppan Next Tech
April 7, 2025
•[ ransomware, data leak, third-party breach ]
A ransomware attack on DBS Bank's third-party printing vendor Toppan Next Tech in Singapore led to the potential exposure of around 8,200 DBS customer statements and related letters, mostly for DBS Vickers trading and Cashline loan accounts. The attacker compromised Toppan's systems, leaving encrypted statement files potentially accessible, but DBS' own banking infrastructure and customer funds remained unaffected. Exposed data in the printed correspondence includes customers' names, mailing addresses and details of equity holdings or loan accounts, while passwords, government ID numbers and balances were not part of the leak. Authorities and cybersecurity agencies are assisting the investigation as DBS halts work with the vendor and notifies affected customers.
Tempo Media Group
April 6, 2025
•[ ddos, service disruption ]
From April 6 to 10, 2025, Tempo Media Groups news portals (Tempo.co, Tempo English) suffered a large-scale Distributed Denial of Service (DDoS) attack that rendered the sites inaccessible for several days. The disruption followed Tempos investigative reporting on online gambling networks. No data theft or system compromise was reported, and the perpetrators remain unidentified.
Everest Ransomware Leak Site
April 6, 2025
•[ ransomware, website defacement, hacktivism ]
The Everest ransomware groups dark web leak site was defaced on April 6 2025 by an unidentified anti-ransomware actor who replaced its content with the message Dont do crime. CRIME IS BAD. xoxo from Prague. Following the defacement, the Everest operators took the site offline. No data theft or encryption occurred.
Tri-City Cardiology Consultants (Phoenix, AZ)
April 6, 2025
•[ data leak ]
22,753 patients notified after an unauthorized third party attempted to infiltrate the network around Apr 6; PHI may have been accessed/obtained; notifications sent in May.
HighWire Press Inc.
April 5, 2025
•[ infostealer, data leak ]
On April 5 2025, Hellcat claimed access to HighWire Press systems using credentials harvested by an infostealer. Data exfiltration was listed on the Hellcat leak site. No encryption or operational disruption has been confirmed.
Individual retail investors using Japanese online brokerage platforms
April 5, 2025
•[ credential stuffing, account abuse ]
Between April 58 2025, foreign criminal actors compromised login credentials of Japanese retail investors and placed unauthorized securities trades through online brokerage portals; Japans Financial Services Agency and police launched an investigation into coordinated credential-stuffing and account abuse.
LeoVegas Group
April 5, 2025
•[ data leak, infostealer, compromised credentials ]
On April 5 2025, Hellcat listed LeoVegas Group on its leak site, claiming exfiltration of internal data through compromised Jira credentials obtained from an infostealer. Hudson Rock verified the inclusion of LeoVegas in the same credential set. No encryption confirmed.