Abrigo
April 14, 2026
•[ extortion, data leak, fintech ]
In April 2026, the fintech software company Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group. Shortly after, data allegedly taken from the company's Salesforce instance was published publicly and contained over 700k unique email addresses belonging to both Abrigo staff and external contacts. Whilst separate from Abrigo's Salesforce compromise via the Drift application connector the previous year, the data fields described in that incident are consistent with the ShinyHunters data, namely that it was "business contact information" including "institution name, employee name, email addresses, and phone numbers".
Unimed
April 14, 2026
•[ unauthorized access, data theft, ransomware ]
Unknown attackers gained unauthorized access to parts of Unimed's IT infrastructure on April 14, 2026 and stole patient billing data processed for German hospitals and clinics. Affected institutions included university hospitals in Cologne, Freiburg, Heidelberg, Tbingen, Ulm, Dsseldorf, Mainz, Saarland, Oldenburg, Hannover, Gttingen, and others. Reporting indicated the attackers intended broader system encryption, but this was stopped; hospitals said their clinical systems and patient care were not affected.
Gastroenterology & Hepatology of CNY
April 14, 2026
•[ ransomware, data-extortion, healthcare ]
Exitium claimed responsibility for a ransomware and data-extortion attack against Gastroenterology & Hepatology of CNY on April 14, 2026, claiming it had encrypted systems and threatened to sell patient records if its demands were not met. DataBreach.com later indexed 196,959 rows associated with the leak, while other public reporting described Exitium's claim as involving approximately 167,303 patient records.
At least one compromised Iranian device
April 13, 2026
•[ spyware, cyber espionage, pegasus ]
The article reports that the US Central Intelligence Agency used Israeli-made Pegasus spyware as part of a deception campaign inside Iran during an operation to rescue a downed American airman. According to the report, Pegasus was used to send fake messages to Iranian leadership and Islamic Revolutionary Guard Corps (IRGC) operatives, making it appear the missing airman had already been located. The piece says Pegasus enabled messages to be sent through apps like WhatsApp and Signal that looked like they came from compromised devices, helping mislead Iranian forces during the rescue effort. The report also says the CIA used a separate classified system called Ghost Murmur to locate the airman by detecting a heartbeat from a distance, though experts cited in the article expressed skepticism about that capability.
Basic-Fit
April 13, 2026
•[ unauthorized access, data breach, data leak ]
Basic-Fit detected unauthorized access to the system that records member visits and stopped the intrusion within minutes, but external security experts determined that data for active members in several countries had been downloaded, affecting about 1 million members overall, including around 200,000 in the Netherlands.
Itron, Inc.
April 13, 2026
•[ unauthorized access, corporate systems, energy management ]
Itron, a provider of energy and water management solutions, detected unauthorized access to some corporate systems on April 13 2026; operations continued and no further unauthorized activity or customer impact was observed.
Marcus & Millichap
April 12, 2026
•[ hacking, extortion, data leak ]
In April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group. Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, along with names, phone numbers and employment-related information including employer, job title and physical company address. In their disclosure notice, Marcus & Millichap advised that data which may have been accessed appeared limited to "company forms, templates, marketing materials, and general contact information".
Spring Lake Park School District
April 12, 2026
•[ ransomware, system shutdown, cyberattack ]
Spring Lake Park Schools discovered on April 12, 2026 that an outside actor had accessed some district systems in a suspected ransomware incident; the district shut down systems defensively to prevent further access, causing class, childcare, community education, and after-school activity cancellations while recovery proceeded.
Morocco’s Office of Vocational Training and Employment Promotion (OFPPT)
April 12, 2026
•[ data leak, compromised account, user data ]
OFPPT disclosed that data from about 100,000 MyWay platform users was leaked after likely misuse of a compromised account.
Dialogue Logique
April 12, 2026
•[ intrusion, datacenter infrastructure, data protection ]
Dialogue Logique detected an intrusion in its datacenter infrastructure on April 12, 2026 and isolated its infrastructure from the internet to contain the incident and protect customer data.
Mytheresa
April 12, 2026
•[ extortion, data leak, ShinyHunters ]
In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group. After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date.
Rockstar Games
April 11, 2026
•[ data breach, third-party breach, SaaS breach ]
ShinyHunters claimed it stole nearly 80 million business records from Rockstar Games through a third-party SaaS/Snowflake-related breach; Rockstar said only a limited amount of non-material company information was accessed and that there was no impact on operations or players.
Autovista
April 11, 2026
•[ ransomware, service disruption, containment ]
Autovista reported a ransomware incident identified on April 11, 2026 that affected certain systems in Europe and Australia and caused service disruption for customers. The company implemented containment measures, worked with external forensic experts to validate systems before restoration, and later reported many products and services were partially or fully restored.
McGraw Hill
April 10, 2026
•[ data breach, extortion, misconfiguration ]
In April 2026, education company McGraw Hill confirmed a data breach following an extortion attempt. Attributed to a Salesforce misconfiguration, the company stated the incident exposed "a limited set of data from a webpage hosted by Salesforce on its platform". More than 100GB of data was later publicly distributed, containing 13.5M unique email addresses across multiple files, with additional fields such as name, physical address and phone number appearing inconsistently across some records.
CPUID (cpuid.com)
April 9, 2026
•[ malware distribution, supply chain attack, api compromise ]
CPUID confirmed that a secondary website/API feature was compromised between April 9 and April 10, 2026, causing official download links for CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor to redirect to attacker-controlled infrastructure serving malware; CPUID said its signed original files were not modified.
Athénée Royal d'Izel
April 9, 2026
•[ ransomware, encryption, service disruption ]
The local server of Athne Royal d'Izel was encrypted during a ransomware attack on the morning of April 9, 2026, affecting the online school platform for meal payments and attendance; quick isolation prevented personal data theft and restoration from backups was underway.
Saver
April 9, 2026
•[ ransomware, personal data, operational disruption ]
Saver was hit by ransomware on April 9, disrupting systems and phone lines while attackers accessed servers containing personal data.
City of Ardmore
April 8, 2026
•[ ransomware, phishing, data leak ]
On April 8, 2026, ransomware encrypted Ardmore police/internal servers after a phishing email; the incident was contained within hours, and information tied to criminal complaints and investigations, including names, addresses, and phone numbers, may have been exposed.
Rx Management
April 8, 2026
•[ ransomware, data leak, healthcare ]
INC Ransom listed Australian pharmacy management firm Rx Management on its leak site on April 8, 2026 and threatened to publish more than 180 GB of allegedly stolen data; the data types and full extent were not publicly verified.
Commune d'Anderlues
April 8, 2026
•[ cyberattack, data theft, IT shutdown ]
Anderlues suffered a municipal cyberattack resulting in data theft and a broad shutdown of communal IT systems.