Skip to content

Analysis and Reporting

Ingram Micro ransomware attack

Date of Incident: July 2-3, 2025 Overview: In July 2025, Ingram Micro experienced a ransomware attack, resulting in a data breach impacting over 42,000 individuals. The attackers deployed ransomware through phishing and exploited vulnerabilities in public-facing applications. Critical system files were encrypted, and documents containing personal information, such as Social Security numbers and government IDs,… Read More »Ingram Micro ransomware attack

CIRO Data Breach

Date of Incident: 2023-08-11 Overview: The CIRO Data Breach, reported on January 18, 2026, affected approximately 750,000 Canadian investors by exposing sensitive personal information, including dates of birth, social insurance numbers, and investment details. Occurring on August 11, 2023, the breach involved unauthorized access to CIRO’s internal systems using credential dumping techniques and included lateral… Read More »CIRO Data Breach

Grubhub Data Breach 2025

Date of Incident: 2025 Overview: In the Grubhub Data Breach of 2025, hackers from the ShinyHunters group accessed Grubhub’s systems, targeting older Salesforce and newer Zendesk data. The breach, discovered and reported in early 2026, left financial information and order history untouched. Attackers utilized MITRE ATT&CK techniques T1078 (Valid Accounts) and T1566 (Phishing) to infiltrate… Read More »Grubhub Data Breach 2025

Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 1 Jan – 6 Jan 2026

The first week of 2026 confirmed a clear trend: attackers are shifting from noisy infrastructure takeovers to trust abuse and perception manipulation. Instead of large, unambiguous “smash-and-grab” breaches, the week was shaped by: A high‑profile but non‑production NordVPN “breach” claim, weaponizing incomplete test data exposure and social perception. An escalation in Russia‑aligned UAC‑0184 espionage using… Read More »Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 1 Jan – 6 Jan 2026

Korean Air Data Breach

Date of Incident: November 2025 Overview: The Korean Air data breach, reported in December 2025, compromised the personal information of approximately 30,000 employees, including names and bank account numbers. The breach exploited vulnerabilities in the company’s ERP system, utilizing tactics such as exploitation of remote services and account access removal. This incident affected the transportation… Read More »Korean Air Data Breach