CPUID (cpuid.com)
April 9, 2026
•[ malware distribution, supply chain attack, api compromise ]
CPUID confirmed that a secondary website/API feature was compromised between April 9 and April 10, 2026, causing official download links for CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor to redirect to attacker-controlled infrastructure serving malware; CPUID said its signed original files were not modified.
Athénée Royal d'Izel
April 9, 2026
•[ ransomware, encryption, service disruption ]
The local server of Athne Royal d'Izel was encrypted during a ransomware attack on the morning of April 9, 2026, affecting the online school platform for meal payments and attendance; quick isolation prevented personal data theft and restoration from backups was underway.
Saver
April 9, 2026
•[ ransomware, personal data, operational disruption ]
Saver was hit by ransomware on April 9, disrupting systems and phone lines while attackers accessed servers containing personal data.
City of Ardmore
April 8, 2026
•[ ransomware, phishing, data leak ]
On April 8, 2026, ransomware encrypted Ardmore police/internal servers after a phishing email; the incident was contained within hours, and information tied to criminal complaints and investigations, including names, addresses, and phone numbers, may have been exposed.
Rx Management
April 8, 2026
•[ ransomware, data leak, healthcare ]
INC Ransom listed Australian pharmacy management firm Rx Management on its leak site on April 8, 2026 and threatened to publish more than 180 GB of allegedly stolen data; the data types and full extent were not publicly verified.
Commune d'Anderlues
April 8, 2026
•[ cyberattack, data theft, IT shutdown ]
Anderlues suffered a municipal cyberattack resulting in data theft and a broad shutdown of communal IT systems.
Dígitro Tecnologia
April 8, 2026
•[ database leak, source code leak, internal files ]
CTIR Gov warned that databases, source-code repositories, and internal files from Dgitro Tecnologia were published by DDoSecrets.
7-Eleven
April 8, 2026
•[ extortion, data leak, ShinyHunters ]
In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters, with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers. A small number of records also contained additional exposed data fields. The company later advised the breach was limited to "certain 7-Eleven systems used to store franchisee documents", a statement consistent with the exposed data.
7-Eleven
April 8, 2026
•[ unauthorized access, data leak, ransom ]
7-Eleven discovered on April 8, 2026 that an unauthorized third party accessed systems used to store franchisee documents. ShinyHunters claimed responsibility, claimed theft of more than 600,000 Salesforce records, and leaked a 9.4 GB archive after ransom demands were not met; Have I Been Pwned identified 185,300 exposed individuals in the leaked data.
At least one DAEMON Tools user in government, scientific, manufacturing, retail, or education sectors
April 8, 2026
•[ supply chain attack, malware, trojanized installers ]
Threat actors compromised official DAEMON Tools installers distributed from the vendor website beginning April 8, 2026. The trojanized installers executed malware on infected Windows hosts, collected system information, and in selected cases deployed additional backdoor payloads. Reporting identified second-stage payloads on roughly a dozen machines in government, scientific, manufacturing, and retail organizations in Russia, Belarus, and Thailand, and QUIC RAT on one Russian educational institution. The specific perpetrator was not publicly identified.
Pitney Bowes
April 8, 2026
•[ phishing, extortion, data leak ]
Pitney Bowes identified unauthorized access to certain records in its Salesforce customer relationship management environment on April 9, 2026, after a phishing attack compromised an employee email account the previous night. ShinyHunters claimed to have obtained Pitney Bowes data as part of a broader extortion campaign and later released data containing 8.2 million unique email addresses, names, phone numbers, physical addresses, and some employee job-title records. Irish reporting separately confirmed that 137 Revenue Commissioners employees were affected through the Pitney Bowes supplier breach, with professional contact details exposed but no Revenue passwords or taxpayer data stolen.
Synergy France
April 8, 2026
•[ ransomware, data leak, cyberattack ]
The Gentlemen ransomware group claimed responsibility for a cyberattack against Synergy France on April 8, 2026 and threatened to publish sensitive data unless the company contacted the group. ComputerWeekly later described The Gentlemen as an emerging ransomware player responsible for a large volume of attacks in 2026.
My Lovely AI
April 7, 2026
•[ data breach, NSFW, AI-generated content ]
In April 2026, the NSFW AI girlfriend platform My Lovely AI suffered a data breach that exposed over 100k users. The data included user-created prompts and links to the resulting AI-generated images, along with a small number of Discord and X usernames.
ChipSoft
April 7, 2026
•[ ransomware, healthcare, data breach ]
Embargo ransomware hit ChipSoft on April 7, 2026, disrupting its website and digital healthcare services, causing hospitals to disconnect or take ChipSoft-connected systems offline, and stealing medical personal data from several Dutch healthcare institutions; ChipSoft later said the stolen data had been destroyed.
Undisclosed Australian organization
April 7, 2026
•[ ransomware, Medusa ransomware, data exfiltration ]
Microsoft reported that Storm-1175, a financially motivated cybercrime actor linked to Medusa ransomware, heavily impacted organizations in Australia, the United Kingdom, and the United States by exploiting vulnerable web-facing systems, exfiltrating data, and deploying ransomware. This row represents the undisclosed Australian victim component of the country-level coding approach.
Undisclosed United Kingdom organization
April 7, 2026
•[ ransomware, data exfiltration, cybercrime ]
Microsoft reported that Storm-1175, a financially motivated cybercrime actor linked to Medusa ransomware, heavily impacted organizations in Australia, the United Kingdom, and the United States by exploiting vulnerable web-facing systems, exfiltrating data, and deploying ransomware. This row represents the undisclosed United Kingdom victim component of the country-level coding approach.
Undisclosed United States organization
April 7, 2026
•[ ransomware, cybercrime, data exfiltration ]
Microsoft reported that Storm-1175, a financially motivated cybercrime actor linked to Medusa ransomware, heavily impacted organizations in Australia, the United Kingdom, and the United States by exploiting vulnerable web-facing systems, exfiltrating data, and deploying ransomware. This row represents the undisclosed United States victim component of the country-level coding approach.
ChipSoft
April 7, 2026
•[ ransomware, data breach, healthcare ]
ChipSoft was hit by a ransomware attack on April 7, 2026, causing hosted patient-facing and provider-facing digital services to be disconnected or taken offline while the company investigated and restored systems. ChipSoft later confirmed that personal and medical patient data from some Dutch healthcare customers had been stolen and said the stolen data was destroyed and not published.
LegionProxy
April 6, 2026
•[ data breach, email addresses, password hashes ]
In April 2026, the commercial residential and ISP proxy network LegionProxy suffered a data breach. The incident exposed 10k email addresses, bcrypt password hashes, names and purchases.
Winona County
April 6, 2026
•[ ransomware, data leak, government ]
Winona County, Minnesota experienced a ransomware attack that began April 6, 2026 and was discovered April 7. Officials took affected systems offline, declared a local emergency, requested Minnesota National Guard assistance, and notified the FBI. Later reporting confirmed cybercriminals released information taken from the county network; emergency services and 911 remained operational, while vital statistics and DMV systems were among those impacted.