Chelan County Government
May 24, 2026
•[ malware, cyberattack, network shutdown ]
Chelan County, Washington reported that malware was detected on county government systems around 10 a.m. on May 24, 2026, affecting all county departments. As a precaution, the county voluntarily shut down network access, computers, and telephone systems across departments while IT staff worked with security partners to restore systems; 911 and emergency services remained available. Public reporting did not identify the threat actor, confirm ransomware, report data theft, or confirm whether any personal data was compromised.
Undisclosed Vietnamese ministry-level agency 2
May 22, 2026
•[ data breach, cyberattack, unauthorized access ]
Vietnamese cybersecurity authorities said hackers infiltrated one of two ministry-level agency systems containing millions of user records. VNCERT investigated the incidents on May 21-22, 2026, and reported that existing SOC monitoring systems at the affected agencies failed to detect the attacks.
Koa Glass Co., Ltd.
May 17, 2026
•[ ransomware, cyberattack, encryption ]
Koa Glass Co., Ltd., a Japanese glass-container manufacturer, publicly reported on May 26, 2026 that some of its internal servers had been encrypted after a third-party ransomware cyberattack. The company said it was working with outside specialists to determine the cause, scope, and recovery path, and that it had not confirmed external data leakage at the time of disclosure. Public Japanese security reporting linked the confirmed incident to a The Gentlemen leak-site claim.
Chanhassen Dinner Theatres
May 15, 2026
•[ cyberattack, operational disruption, system outage ]
Chanhassen Dinner Theatres experienced a cyberattack affecting part of its computer network on May 15, 2026 and took systems offline while working with outside experts to restore operations. The incident disrupted internet, phone, customer-service, and operational functions and contributed to rescheduled or canceled performances, alongside a separate cast illness/norovirus disruption. Public reporting did not confirm encryption, data theft, a ransom demand, or a responsible actor.
Gas station operators
May 15, 2026
•[ operational technology, critical infrastructure, cyberattack ]
Iranian hackers reportedly accessed internet-connected automatic tank gauge systems at gas stations in multiple U.S. states. Automatic tank gauges are OT systems used to monitor physical fuel tanks, but reporting indicates the attackers altered displayed readings rather than changing actual fuel volumes or physically manipulating fuel operations.
WholeHealth Chicago
May 15, 2026
•[ data leak, PII, cyberattack ]
Cmdorganization claimed responsibility for a cyberattack against WholeHealth Chicago on May 15, 2026. DataBreach later indexed 36,409 rows allegedly tied to the breach, including dates of birth, email addresses, phone numbers, and names. Public sources did not confirm file encryption, operational disruption, or a precise intrusion vector.
Murray County Government
May 13, 2026
•[ cyberattack, government, service disruption ]
Murray County, Georgia reported that a cyberattack hit the county government network, forcing several county offices to limit services or close until network systems were restored. The Tax Commissioner, Tax Assessor, Probate Court, and Juvenile Court offices were closed, while other county offices remained open with limited functionality; 911, public safety, and primary voting continued. Public reporting did not identify a threat actor, confirm ransomware or encryption, specify the technical mechanism, report data theft, or provide a final restoration date.
Foxconn North American operations
May 11, 2026
•[ cyberattack, data theft, operational disruption ]
Nitrogen claimed responsibility for a cyberattack against Foxconn and alleged theft of roughly 8TB of data spanning more than 11 million files. Foxconn confirmed that some North American factories suffered a cyberattack and said affected factories were resuming normal production. Public reporting supports operational disruption and alleged large-scale data theft, but does not confirm file encryption, data destruction, or the specific disruption mechanism.
Direction générale de la Comptabilité publique et du Trésor
May 10, 2026
•[ cyberattack, data exfiltration, leak site ]
Senegal's Direction gnrale de la Comptabilit publique et du Trsor reported an incident affecting part of its information systems beginning May 10, 2026 and activated continuity measures. Senegalese and cyber-specialist reporting later described the incident as a cyberattack, with AuditTeam claiming exfiltration of more than 70 GB of sensitive data and listing the target on a leak site. Public reporting did not confirm the full data set, final recovery date, or whether personal data was included.
Trellix
May 5, 2026
•[ source code leakage, unauthorized access, cyberattack ]
Trellix disclosed unauthorized access to a portion of its source code repository in May 2026. RansomHouse later claimed responsibility and published screenshots as proof of access. Trellix said it had found no evidence that its source-code release or distribution process was affected or that its source code had been exploited. Public reporting did not confirm encryption, data destruction, operational disruption, or customer data exposure.
Oriental Diamond Co., Ltd.
May 4, 2026
•[ ransomware, cyberattack, data leak ]
Oriental Diamond Co., Ltd. confirmed that on May 4, 2026 a third party used ransomware in a cyberattack against a company-managed server, encrypting system data and causing business stoppage. The company reported possible leakage of names, addresses, and phone numbers, said bank account, credit card, and My Number information were not included, and stated that it would stop using the VPN path identified as the intrusion route. Public Japanese security reporting linked the confirmed incident to a The Gentlemen leak-site claim.
Standard-Examiner
May 2, 2026
•[ ransomware, data leak, cyberattack ]
Qilin listed Standard-Examiner on its leak site on May 2, 2026 and claimed responsibility for a cyberattack, threatening to release sensitive data. Separate reporting noted earlier April production difficulties at the newspaper, but the Standard-Examiner had not publicly confirmed ransomware, data theft, or a connection between the printing disruption and Qilin's claim.
Kent District Library
April 24, 2026
•[ ransomware, cyberattack, service disruption ]
Kent District Library closed all branches after a ransomware attack disrupted computer systems and network-dependent services.
South Korean Ministry of Foreign Affairs
April 17, 2026
•[ DDoS attack, service disruption, cyberattack ]
South Koreas Ministry of Foreign Affairs website was briefly disrupted by a DDoS attack and restored the same day.
Grinex
April 15, 2026
•[ cyberattack, cryptocurrency, asset theft ]
Grinex, a Kyrgyzstan-based cryptocurrency exchange linked to Russia, suspended operations after a cyberattack in which assets worth 1 billion roubles, about $13.10 million, were stolen.
Le Desk (media outlet)
April 14, 2026
•[ DDoS attack, cyberattack, media outlet ]
Le Desk was targeted by a large DDoS attack that generated 26.69 billion HTTP requests over 42 hours.
Spring Lake Park School District
April 12, 2026
•[ ransomware, system shutdown, cyberattack ]
Spring Lake Park Schools discovered on April 12, 2026 that an outside actor had accessed some district systems in a suspected ransomware incident; the district shut down systems defensively to prevent further access, causing class, childcare, community education, and after-school activity cancellations while recovery proceeded.
Synergy France
April 8, 2026
•[ ransomware, data leak, cyberattack ]
The Gentlemen ransomware group claimed responsibility for a cyberattack against Synergy France on April 8, 2026 and threatened to publish sensitive data unless the company contacted the group. ComputerWeekly later described The Gentlemen as an emerging ransomware player responsible for a large volume of attacks in 2026.
Commune d'Anderlues
April 8, 2026
•[ cyberattack, data theft, IT shutdown ]
Anderlues suffered a municipal cyberattack resulting in data theft and a broad shutdown of communal IT systems.
Signature Healthcare Brockton Hospital
April 6, 2026
•[ cyberattack, data theft, healthcare ]
A cyberattack detected on April 6, 2026 affected information systems at Signature Healthcare and Signature Healthcare Brockton Hospital, triggering downtime procedures, ambulance diversion, chemotherapy cancellations, EHR and patient portal outages, pharmacy prescription-fill disruption, lab delays, and medical-record request disruption; Anubis claimed it stole 2 TB of data, but Signature Healthcare did not confirm data theft.