{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "securityincident.net | Real-Time Incident Status & Milestone Timeline Index",
  "home_page_url": "https://securityincident.net/",
  "feed_url": "https://securityincident.net/feed.json",
  "description": "A neutral, high-signal index tracking real-time status and verified milestone timelines for cybersecurity incidents across the open web, powered by open weights correlation and community PR editing.",
  "icon": "https://securityincident.net/images/favicon.svg",
  "favicon": "https://securityincident.net/images/favicon.svg",
  "authors": [
    {
      "name": "securityincident.net",
      "url": "https://securityincident.net/about.html"
    }
  ],
  "items": [
    {
      "id": "https://securityincident.net/incidents/2026-09-arizona-supreme-court.html",
      "url": "https://securityincident.net/incidents/2026-09-arizona-supreme-court.html",
      "title": "[DEVELOPING] Arizona Supreme Court — A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> azcourts.gov<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 46% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-29 12:27 UTC</strong> [INDEPENDENT VERIFICATION]: Arizona Supreme Court says hackers stole residents’ personal data (<a href=\"https://therecord.media/arizona-supreme-court-says-hackers-stole-data\">The Record by Recorded Future Report</a>)</li>\n<li><strong>2026-10-07 01:32 UTC</strong> [INDEPENDENT VERIFICATION]: Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System (<a href=\"https://www.securityweek.com/personal-information-for-over-1-million-people-stolen-in-a-cyberattack-on-arizonas-court-system/\">SecurityWeek Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-arizona-supreme-court.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.",
      "date_published": "2026-09-29T00:00:00Z",
      "date_modified": "2026-10-07T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Legal",
        "investigative",
        "developing",
        "threat-intel"
      ],
      "_open_weights": {
        "score": 0.46,
        "percent": 46,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-snowflake.html",
      "url": "https://securityincident.net/incidents/2026-08-snowflake.html",
      "title": "[CONFIRMED] Snowflake — A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provide...",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> snowflake.com<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Credential Stuffing / Cloud Account Takeover<br/>\n<strong>Threat Actor:</strong> UNC5537<br/>\n<strong>Affected Population:</strong> 165,000,000 records<br/>\n<strong>Open Weights Confidence:</strong> 85% (CONFIRMED BY TARGET)<br/>\n</p>\n<p>A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provide...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-06 17:00 UTC</strong> [INDEPENDENT VERIFICATION]: Canadian Man Pleads Guilty in Snowflake Extortions (<a href=\"https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/\">Krebs on Security Report</a>)</li>\n<li><strong>2026-10-06 16:33 UTC</strong> [CONFIRMED BY TARGET]: ASOS confirms data breach after “HACKED” in-app notifications (<a href=\"https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/\">BleepingComputer Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-snowflake.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provide...",
      "date_published": "2026-08-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology",
        "investigative",
        "developing",
        "threat-intel",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.85,
        "percent": 85,
        "top_tier": "CONFIRMED BY TARGET",
        "base_weight": 0.5,
        "corroboration_bonus": 0.12,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-citrix.html",
      "url": "https://securityincident.net/incidents/2026-09-citrix.html",
      "title": "[CONFIRMED] Citrix Systems (Cloud Software Group) — Cloud Software Group and federal regulators issued emergency disclosures for two actively exploited critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5), enabling unauthenticated remote code execution and webshell deployment across 50,000+ exposed enterprise appliances worldwide.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> citrix.com<br/>\n<strong>Industry:</strong> Enterprise Software &amp; Cloud Infrastructure<br/>\n<strong>Incident Type:</strong> Zero-Day Exploitation &amp; Remote Code Execution<br/>\n<strong>Threat Actor:</strong> State-Sponsored Advanced Persistent Threat (APT)<br/>\n<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Cloud Software Group and federal regulators issued emergency disclosures for two actively exploited critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5), enabling unauthenticated remote code execution and webshell deployment across 50,000+ exposed enterprise appliances worldwide.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-27 12:00 UTC</strong> [CONFIRMED BY REGULATOR]: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway (<a href=\"https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway\">CISA Cybersecurity Advisories Report</a>)</li>\n<li><strong>2026-09-29 18:37 UTC</strong> [INDEPENDENT VERIFICATION]: Hackers exploit Citrix NetScaler zero-day to deploy web shells (<a href=\"https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/\">BleepingComputer Report</a>)</li>\n<li><strong>2026-09-28 07:21 UTC</strong> [INDEPENDENT VERIFICATION]: CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally (<a href=\"https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html\">The Hacker News Report</a>)</li>\n<li><strong>2026-09-27 07:47 UTC</strong> [INDEPENDENT VERIFICATION]: Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation (<a href=\"https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html\">The Hacker News Report</a>)</li>\n<li><strong>2026-09-29 14:19 UTC</strong> [INDEPENDENT VERIFICATION]: Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers (<a href=\"https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix\">Dark Reading Report</a>)</li>\n<li><strong>2026-09-28 12:00 UTC</strong> [CONFIRMED BY REGULATOR]: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway (<a href=\"https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway\">NCSC UK Cyber Alerts Report</a>)</li>\n<li><strong>2026-09-29 13:53 UTC</strong> [CONFIRMED BY REGULATOR]: Citrix Patches Actively Exploited NetScaler ADC &amp; NetScaler Gateway Vulnerabilities (<a href=\"https://www.hipaajournal.com/citrix-zero-day-vulnerabilities-exploited-sept-2026/\">HIPAA Journal Healthcare Breaches Report</a>)</li>\n<li><strong>2026-09-27 12:00 UTC</strong> [CONFIRMED BY REGULATOR]: CISA Adds Two Known Exploited Vulnerabilities to Catalog (<a href=\"https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog\">CISA Cybersecurity Advisories Report</a>)</li>\n<li><strong>2026-10-01 11:55 UTC</strong> [INDEPENDENT VERIFICATION]: Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed. (<a href=\"https://databreaches.net/2026/10/01/suspected-state-hackers-exploited-citrix-netscaler-for-weeks-50000-devices-may-still-be-exposed/\">DataBreaches.net Report</a>)</li>\n<li><strong>2026-10-02 16:56 UTC</strong> [INDEPENDENT VERIFICATION]: Kiteworks &amp; Citrix Incidents Show Challenges of Zero-Day Response (<a href=\"https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response\">Dark Reading Report</a>)</li>\n<li><strong>2026-10-04 12:00 UTC</strong> [CONFIRMED BY REGULATOR]: CISA Adds One Known Exploited Vulnerability to Catalog (<a href=\"https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog\">CISA Cybersecurity Advisories Report</a>)</li>\n<li><strong>2026-10-05 06:40 UTC</strong> [INDEPENDENT VERIFICATION]: New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline (<a href=\"https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html\">The Hacker News Report</a>)</li>\n<li><strong>2026-10-06 10:26 UTC</strong> [CONFIRMED BY REGULATOR]: Citrix Patches Third Actively Exploited NetScaler Zero Day (<a href=\"https://www.hipaajournal.com/citrix-patches-third-actively-exploited-netscaler-zero-day/\">HIPAA Journal Healthcare Breaches Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-citrix.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Cloud Software Group and federal regulators issued emergency disclosures for two actively exploited critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5), enabling unauthenticated remote code execution and webshell deployment across 50,000+ exposed enterprise appliances worldwide.",
      "date_published": "2026-09-27T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Enterprise Software & Cloud Infrastructure",
        "regulatory",
        "cisa-kev",
        "zero-day",
        "infrastructure",
        "enterprise-software",
        "developing",
        "threat-intel"
      ],
      "_open_weights": {
        "score": 1,
        "percent": 100,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.25,
        "unique_domains": 7
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-fbi.html",
      "url": "https://securityincident.net/incidents/2026-09-fbi.html",
      "title": "[ACKNOWLEDGED] Federal Bureau of Investigation (FBI) — Joseph Cox reports: The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical add...",
      "content_html": "<p><strong>Status:</strong> ACKNOWLEDGED<br/>\n<strong>Target Domain:</strong> fbi.gov<br/>\n<strong>Industry:</strong> Government &amp; Law Enforcement<br/>\n<strong>Incident Type:</strong> Unauthorized Portal Intrusion<br/>\n<strong>Threat Actor:</strong> Cyber Extortion Collective<br/>\n<strong>Affected Population:</strong> 85,000 records<br/>\n<strong>Open Weights Confidence:</strong> 80% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Joseph Cox reports: The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical add...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-29 12:48 UTC</strong> [INDEPENDENT VERIFICATION]: FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data (<a href=\"https://databreaches.net/2026/09/29/fbi-hackers-say-they-wont-publish-massive-trove-of-fbi-employee-data/\">DataBreaches.net Report</a>)</li>\n<li><strong>2026-09-29 20:09 UTC</strong> [INDEPENDENT VERIFICATION]: FBI tells ShinyHunters members to turn themselves in after recent arrest (<a href=\"https://www.bleepingcomputer.com/news/security/fbi-tells-shinyhunters-members-to-turn-themselves-in-after-recent-arrest/\">BleepingComputer Report</a>)</li>\n<li><strong>2026-10-02 14:06 UTC</strong> [INDEPENDENT VERIFICATION]: Mississippi mayor says ransomware incident led city to shut down systems (<a href=\"https://therecord.media/vicksburg-mississippi-government-ransomware-attack\">The Record by Recorded Future Report</a>)</li>\n<li><strong>2026-10-06 15:23 UTC</strong> [INDEPENDENT VERIFICATION]: FBI Blames Contractor’s Missed Patch for ShinyHunters Breach (<a href=\"https://databreaches.net/2026/10/06/fbi-blames-contractors-missed-patch-for-shinyhunters-breach/\">DataBreaches.net Report</a>)</li>\n<li><strong>2026-10-05 12:30 UTC</strong> [INDEPENDENT VERIFICATION]: Hackers Breached Propulsion System of U.S.-Bound Oil Tanker (<a href=\"https://databreaches.net/2026/10/05/hackers-breached-propulsion-system-of-u-s-bound-oil-tanker/\">DataBreaches.net Report</a>)</li>\n<li><strong>2026-10-06 14:15 UTC</strong> [INDEPENDENT VERIFICATION]: FBI Blames Contractor&apos;s Missed Patch for ShinyHunters Breach (<a href=\"https://www.securityweek.com/fbi-blames-contractors-missed-patch-for-shinyhunters-breach/\">SecurityWeek Report</a>)</li>\n<li><strong>2026-10-06 06:56 UTC</strong> [INDEPENDENT VERIFICATION]: FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach (<a href=\"https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html\">The Hacker News Report</a>)</li>\n<li><strong>2026-10-04 07:22 UTC</strong> [INDEPENDENT VERIFICATION]: ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members (<a href=\"https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html\">The Hacker News Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-fbi.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Joseph Cox reports: The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical add...",
      "date_published": "2026-09-29T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "ACKNOWLEDGED",
        "Government & Law Enforcement",
        "investigative",
        "emerging",
        "threat-intel",
        "developing",
        "acknowledged"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0.2,
        "unique_domains": 5
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-agri-industrial.html",
      "url": "https://securityincident.net/incidents/2026-10-agri-industrial.html",
      "title": "[EMERGING] Agri Industrial — Agri Industrial was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> agriindustrial.com<br/>\n<strong>Industry:</strong> Agriculture and Food Production<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Everest<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Agri Industrial was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 16:17 UTC</strong> [UNVERIFIED CLAIM]: Agri Industrial Listed on Everest Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/QWdyaSBJbmR1c3RyaWFsQGV2ZXJlc3Q=\">Everest Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-agri-industrial.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Agri Industrial was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Agriculture and Food Production",
        "extortion",
        "ransomware-claim",
        "everest",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-atlassian.html",
      "url": "https://securityincident.net/incidents/2026-10-atlassian.html",
      "title": "[DEVELOPING] Atlassian — Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> atlassian.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 17:34 UTC</strong> [INDEPENDENT VERIFICATION]: Atlassian warns of critical file-access flaw in Jira, Confluence (<a href=\"https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-file-access-flaw-in-jira-confluence/\">BleepingComputer Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-atlassian.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "threat-intel",
        "developing"
      ],
      "_open_weights": {
        "score": 0.35,
        "percent": 35,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-b-accountants.html",
      "url": "https://securityincident.net/incidents/2026-10-b-accountants.html",
      "title": "[EMERGING] B-accountants — B-accountants was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> baccountants.com<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Everest<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>B-accountants was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 16:17 UTC</strong> [UNVERIFIED CLAIM]: B-accountants Listed on Everest Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Qi1hY2NvdW50YW50c0BldmVyZXN0\">Everest Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-b-accountants.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "B-accountants was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "everest",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-beni-suef-technological-university-btu.html",
      "url": "https://securityincident.net/incidents/2026-10-beni-suef-technological-university-btu.html",
      "title": "[EMERGING] Beni Suef Technological University – BTU — Beni Suef Technological University – BTU was listed on the UmBra ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> benisueftechnologicaluniversitybtu.com<br/>\n<strong>Industry:</strong> Education<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> UmBra<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Beni Suef Technological University – BTU was listed on the UmBra ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 22:24 UTC</strong> [UNVERIFIED CLAIM]: Beni Suef Technological University – BTU Listed on UmBra Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/QmVuaSBTdWVmIFRlY2hub2xvZ2ljYWwgVW5pdmVyc2l0eSDigJMgQlRVQFVtQnJh\">UmBra Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-beni-suef-technological-university-btu.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Beni Suef Technological University – BTU was listed on the UmBra ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Education",
        "extortion",
        "ransomware-claim",
        "umbra",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-bnyh.html",
      "url": "https://securityincident.net/incidents/2026-10-bnyh.html",
      "title": "[EMERGING] BNYH — BNYH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> bnyh.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>BNYH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 20:19 UTC</strong> [UNVERIFIED CLAIM]: BNYH Listed on Qilin Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Qk5ZSEBxaWxpbg==\">Qilin Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-bnyh.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "BNYH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Financial Services",
        "extortion",
        "ransomware-claim",
        "qilin",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-ciftay-insaat-taahhut-ve-ticaret-anonim-sirketi.html",
      "url": "https://securityincident.net/incidents/2026-10-ciftay-insaat-taahhut-ve-ticaret-anonim-sirketi.html",
      "title": "[EMERGING] Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi — Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> ciftay.com.tr<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Third-Party Cloud Compromise<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Affected Population:</strong> 110,000,000 records<br/>\n<strong>Open Weights Confidence:</strong> 17% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 20:18 UTC</strong> [UNVERIFIED CLAIM]: Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi Listed on Qilin Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Q2lmdGF5IEluc2FhdCBUYWFoaHV0IFZlIFRpY2FyZXQgQW5vbmltIFNpcmtldGlAcWlsaW4=\">Qilin Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-ciftay-insaat-taahhut-ve-ticaret-anonim-sirketi.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "qilin",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.17,
        "percent": 17,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-corby-rock-mill.html",
      "url": "https://securityincident.net/incidents/2026-10-corby-rock-mill.html",
      "title": "[EMERGING] CORBY ROCK MILL — CORBY ROCK MILL was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> corbyrock.ie<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>CORBY ROCK MILL was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 09:03 UTC</strong> [UNVERIFIED CLAIM]: CORBY ROCK MILL Listed on Qilin Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Q09SQlkgUk9DSyBNSUxMQHFpbGlu\">Qilin Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-corby-rock-mill.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "CORBY ROCK MILL was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "qilin",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-delta-marine.html",
      "url": "https://securityincident.net/incidents/2026-10-delta-marine.html",
      "title": "[EMERGING] Delta Marine — Delta Marine was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> deltamarine.com<br/>\n<strong>Industry:</strong> Transportation<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Delta Marine was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 09:02 UTC</strong> [UNVERIFIED CLAIM]: Delta Marine Listed on Qilin Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RGVsdGEgTWFyaW5lQHFpbGlu\">Qilin Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-delta-marine.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Delta Marine was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Transportation",
        "extortion",
        "ransomware-claim",
        "qilin",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-edfelectronics.html",
      "url": "https://securityincident.net/incidents/2026-10-edfelectronics.html",
      "title": "[EMERGING] EDFelectronics — EDFelectronics was listed on the Panzer ransomware extortion leak portal. EDFelectronics.com is a Polish engineering company that develops specialized electronics and plasma technology for industrial and research applications.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> edfelectronics.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Panzer<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>EDFelectronics was listed on the Panzer ransomware extortion leak portal. EDFelectronics.com is a Polish engineering company that develops specialized electronics and plasma technology for industrial and research applications.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 22:55 UTC</strong> [UNVERIFIED CLAIM]: EDFelectronics Listed on Panzer Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RURGZWxlY3Ryb25pY3NAUGFuemVy\">Panzer Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-edfelectronics.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "EDFelectronics was listed on the Panzer ransomware extortion leak portal. EDFelectronics.com is a Polish engineering company that develops specialized electronics and plasma technology for industrial and research applications.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "panzer",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-flydubai.html",
      "url": "https://securityincident.net/incidents/2026-10-flydubai.html",
      "title": "[EMERGING] Flydubai — Flydubai was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> flydubai.com<br/>\n<strong>Industry:</strong> Transportation<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Everest<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Flydubai was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 16:15 UTC</strong> [UNVERIFIED CLAIM]: Flydubai Listed on Everest Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Rmx5ZHViYWlAZXZlcmVzdA==\">Everest Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-flydubai.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Flydubai was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Transportation",
        "extortion",
        "ransomware-claim",
        "everest",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-four-hands-llc.html",
      "url": "https://securityincident.net/incidents/2026-10-four-hands-llc.html",
      "title": "[EMERGING] Four Hands LLC — Four Hands LLC was listed on the UmBra ransomware extortion leak portal. Four Hands LLC is a global leader in lifestyle home furnishings, designing and wholesaling innovative, artisanal furniture and decor to top retailers and designers worldwide.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> fourhands.com<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> UmBra<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Four Hands LLC was listed on the UmBra ransomware extortion leak portal. Four Hands LLC is a global leader in lifestyle home furnishings, designing and wholesaling innovative, artisanal furniture and decor to top retailers and designers worldwide.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 14:54 UTC</strong> [UNVERIFIED CLAIM]: Four Hands LLC Listed on UmBra Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Rm91ciBIYW5kcyBMTENAVW1CcmE=\">UmBra Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-four-hands-llc.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Four Hands LLC was listed on the UmBra ransomware extortion leak portal. Four Hands LLC is a global leader in lifestyle home furnishings, designing and wholesaling innovative, artisanal furniture and decor to top retailers and designers worldwide.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "umbra",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-greggio-argento.html",
      "url": "https://securityincident.net/incidents/2026-10-greggio-argento.html",
      "title": "[EMERGING] Greggio Argento — Greggio Argento was listed on the Deadlock ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> greggio.com<br/>\n<strong>Industry:</strong> Agriculture and Food Production<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Deadlock<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Greggio Argento was listed on the Deadlock ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 16:21 UTC</strong> [UNVERIFIED CLAIM]: Greggio Argento Listed on Deadlock Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/R3JlZ2dpbyBBcmdlbnRvQERlYWRsb2Nr\">Deadlock Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-greggio-argento.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Greggio Argento was listed on the Deadlock ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Agriculture and Food Production",
        "extortion",
        "ransomware-claim",
        "deadlock",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-hygrade.html",
      "url": "https://securityincident.net/incidents/2026-10-hygrade.html",
      "title": "[EMERGING] Hygrade — Hygrade was listed on the Akira ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> hygrade.com<br/>\n<strong>Industry:</strong> Agriculture and Food Production<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Hygrade was listed on the Akira ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 14:52 UTC</strong> [UNVERIFIED CLAIM]: Hygrade Listed on Akira Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/SHlncmFkZUBha2lyYQ==\">Akira Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-hygrade.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Hygrade was listed on the Akira ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Agriculture and Food Production",
        "extortion",
        "ransomware-claim",
        "akira",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-j-d-financial.html",
      "url": "https://securityincident.net/incidents/2026-10-j-d-financial.html",
      "title": "[EMERGING] J&D Financial — J&D Financial was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> jdfinancial.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>J&amp;D Financial was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 09:02 UTC</strong> [UNVERIFIED CLAIM]: J&amp;D Financial Listed on Qilin Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/SiZEIEZpbmFuY2lhbEBxaWxpbg==\">Qilin Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-j-d-financial.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "J&D Financial was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Financial Services",
        "extortion",
        "ransomware-claim",
        "qilin",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-kennametal.html",
      "url": "https://securityincident.net/incidents/2026-10-kennametal.html",
      "title": "[EMERGING] Kennametal — Kennametal was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> kennametal.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Everest<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Kennametal was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 16:15 UTC</strong> [UNVERIFIED CLAIM]: Kennametal Listed on Everest Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/S2VubmFtZXRhbEBldmVyZXN0\">Everest Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-kennametal.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Kennametal was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "everest",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-kookabarra-juice.html",
      "url": "https://securityincident.net/incidents/2026-10-kookabarra-juice.html",
      "title": "[EMERGING] KOOKABARRA JUICE — KOOKABARRA JUICE was listed on the Vexy Ransomware ransomware extortion leak portal. French manufacturer specializing in fresh-pressed fruit juices, detox juices, smoothies, nectars and other fresh fruit products, serving both professionals and co...",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> kookabarra.com<br/>\n<strong>Industry:</strong> Retail &amp; E-Commerce<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Vexy Ransomware<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>KOOKABARRA JUICE was listed on the Vexy Ransomware ransomware extortion leak portal. French manufacturer specializing in fresh-pressed fruit juices, detox juices, smoothies, nectars and other fresh fruit products, serving both professionals and co...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 20:55 UTC</strong> [UNVERIFIED CLAIM]: KOOKABARRA JUICE Listed on Vexy Ransomware Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/S09PS0FCQVJSQSBKVUlDRUBWZXh5IFJhbnNvbXdhcmU=\">Vexy Ransomware Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-kookabarra-juice.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "KOOKABARRA JUICE was listed on the Vexy Ransomware ransomware extortion leak portal. French manufacturer specializing in fresh-pressed fruit juices, detox juices, smoothies, nectars and other fresh fruit products, serving both professionals and co...",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Retail & E-Commerce",
        "extortion",
        "ransomware-claim",
        "vexy ransomware",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-magnals-com.html",
      "url": "https://securityincident.net/incidents/2026-10-magnals-com.html",
      "title": "[EMERGING] magnals.com — magnals.com was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> magnals.com<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Incransom<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>magnals.com was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 17:27 UTC</strong> [UNVERIFIED CLAIM]: magnals.com Listed on Incransom Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/bWFnbmFscy5jb21AaW5jcmFuc29t\">Incransom Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-magnals-com.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "magnals.com was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "incransom",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-michael-k-shelby-cpa.html",
      "url": "https://securityincident.net/incidents/2026-10-michael-k-shelby-cpa.html",
      "title": "[EMERGING] Michael K Shelby, CPA — Michael K Shelby, CPA was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 18GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> mkshelbycpa.com<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Michael K Shelby, CPA was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 18GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 14:52 UTC</strong> [UNVERIFIED CLAIM]: Michael K Shelby, CPA Listed on Akira Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/TWljaGFlbCBLIFNoZWxieSwgQ1BBQGFraXJh\">Akira Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-michael-k-shelby-cpa.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Michael K Shelby, CPA was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 18GB of internal data files.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "akira",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-morcon-developments.html",
      "url": "https://securityincident.net/incidents/2026-10-morcon-developments.html",
      "title": "[EMERGING] Morcon Developments — Morcon Developments was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> morcondevelopments.com<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Everest<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Morcon Developments was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 16:16 UTC</strong> [UNVERIFIED CLAIM]: Morcon Developments Listed on Everest Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/TW9yY29uIERldmVsb3BtZW50c0BldmVyZXN0\">Everest Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-morcon-developments.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Morcon Developments was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "everest",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-nikkei.html",
      "url": "https://securityincident.net/incidents/2026-10-nikkei.html",
      "title": "[DEVELOPING] Nikkei — Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> nikkei.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 09:25 UTC</strong> [INDEPENDENT VERIFICATION]: Nikkei discloses breaches of employees’ Microsoft, Google email accounts (<a href=\"https://www.bleepingcomputer.com/news/security/nikkei-discloses-breaches-of-employees-microsoft-google-email-accounts/\">BleepingComputer Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-nikkei.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "threat-intel",
        "developing"
      ],
      "_open_weights": {
        "score": 0.35,
        "percent": 35,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-philander-smith-university.html",
      "url": "https://securityincident.net/incidents/2026-10-philander-smith-university.html",
      "title": "[EMERGING] Philander Smith University — Philander Smith University was listed on the EndZone ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> philander.edu<br/>\n<strong>Industry:</strong> Education<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> EndZone<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Philander Smith University was listed on the EndZone ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 07:50 UTC</strong> [UNVERIFIED CLAIM]: Philander Smith University Listed on EndZone Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/UGhpbGFuZGVyIFNtaXRoIFVuaXZlcnNpdHlARW5kWm9uZQ==\">EndZone Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-philander-smith-university.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Philander Smith University was listed on the EndZone ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Education",
        "extortion",
        "ransomware-claim",
        "endzone",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-sweetrush.html",
      "url": "https://securityincident.net/incidents/2026-10-sweetrush.html",
      "title": "[EMERGING] SweetRush — SweetRush was listed on the Panzer ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> sweetrush.com<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Panzer<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>SweetRush was listed on the Panzer ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 17:51 UTC</strong> [UNVERIFIED CLAIM]: SweetRush Listed on Panzer Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/U3dlZXRSdXNoQFBhbnplcg==\">Panzer Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-sweetrush.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "SweetRush was listed on the Panzer ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "panzer",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-wikimedia.html",
      "url": "https://securityincident.net/incidents/2026-10-wikimedia.html",
      "title": "[DEVELOPING] Wikimedia — The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. \"Th...",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> wikimedia.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. &quot;Th...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-06 11:26 UTC</strong> [INDEPENDENT VERIFICATION]: Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies (<a href=\"https://thehackernews.com/2026/10/wikimedia-says-openai-agents-tried-to.html\">The Hacker News Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-wikimedia.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. \"Th...",
      "date_published": "2026-10-06T00:00:00Z",
      "date_modified": "2026-10-06T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "threat-intel",
        "developing"
      ],
      "_open_weights": {
        "score": 0.35,
        "percent": 35,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-a-n.html",
      "url": "https://securityincident.net/incidents/2026-10-a-n.html",
      "title": "[EMERGING] A...n — A...n was listed on the SilentRansomGroup ransomware extortion leak portal. Redacted entry - full company name pending disclosure (FULL DATA TIMER active).",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> an.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> SilentRansomGroup<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>A...n was listed on the SilentRansomGroup ransomware extortion leak portal. Redacted entry - full company name pending disclosure (FULL DATA TIMER active).</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 22:27 UTC</strong> [UNVERIFIED CLAIM]: A...n Listed on SilentRansomGroup Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/QS4uLm5AU2lsZW50UmFuc29tR3JvdXA=\">SilentRansomGroup Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-a-n.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "A...n was listed on the SilentRansomGroup ransomware extortion leak portal. Redacted entry - full company name pending disclosure (FULL DATA TIMER active).",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology & Commercial",
        "extortion",
        "ransomware-claim",
        "silentransomgroup",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-advantest-america.html",
      "url": "https://securityincident.net/incidents/2026-10-advantest-america.html",
      "title": "[CONFIRMED] Advantest America — State of California Department of Justice data breach disclosure notice filed by Advantest America.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> advantestamerica.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Advantest America.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630848\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-advantest-america.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Advantest America.",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-anwo-cl.html",
      "url": "https://securityincident.net/incidents/2026-10-anwo-cl.html",
      "title": "[EMERGING] anwo.cl — anwo.cl was listed on the Safepay ransomware extortion leak portal. The company was established in 1984 by Víctor Herrmann and has developed into one of the major HVAC distribution businesses …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> anwo.cl<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>anwo.cl was listed on the Safepay ransomware extortion leak portal. The company was established in 1984 by Víctor Herrmann and has developed into one of the major HVAC distribution businesses …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 18:28 UTC</strong> [UNVERIFIED CLAIM]: anwo.cl Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/YW53by5jbEBzYWZlcGF5\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-anwo-cl.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "anwo.cl was listed on the Safepay ransomware extortion leak portal. The company was established in 1984 by Víctor Herrmann and has developed into one of the major HVAC distribution businesses …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology & Commercial",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-bwi-bau-de.html",
      "url": "https://securityincident.net/incidents/2026-10-bwi-bau-de.html",
      "title": "[EMERGING] bwi-bau.de — bwi-bau.de was listed on the Safepay ransomware extortion leak portal. The organization was established in October 1964 as a subsidiary of the Construction Industry Association of North Rhine-Westphalia. It originally …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> bwi-bau.de<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>bwi-bau.de was listed on the Safepay ransomware extortion leak portal. The organization was established in October 1964 as a subsidiary of the Construction Industry Association of North Rhine-Westphalia. It originally …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 19:36 UTC</strong> [UNVERIFIED CLAIM]: bwi-bau.de Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/YndpLWJhdS5kZUBzYWZlcGF5\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-bwi-bau-de.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "bwi-bau.de was listed on the Safepay ransomware extortion leak portal. The organization was established in October 1964 as a subsidiary of the Construction Industry Association of North Rhine-Westphalia. It originally …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-cam-group-llc.html",
      "url": "https://securityincident.net/incidents/2026-10-cam-group-llc.html",
      "title": "[EMERGING] Cam Group LLC — Cam Group LLC was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> camgroupllc.com<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Doommageddon<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Cam Group LLC was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 11:53 UTC</strong> [UNVERIFIED CLAIM]: Cam Group LLC Listed on Doommageddon Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Q2FtIEdyb3VwIExMQ0BEb29tbWFnZWRkb24=\">Doommageddon Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-cam-group-llc.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Cam Group LLC was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "doommageddon",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-daiwa-securities.html",
      "url": "https://securityincident.net/incidents/2026-10-daiwa-securities.html",
      "title": "[DEVELOPING] Daiwa Securities — Takashi Nakamichi and Ryo Horiuchi report that Daiwa Securities, Japan's second-largest brokerage and investment banking firm, is responding to a breach at one of its vendors. Daiwa Securities Group said information on as many as 110,000 clients m...",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> daiwasecurities.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Takashi Nakamichi and Ryo Horiuchi report that Daiwa Securities, Japan&apos;s second-largest brokerage and investment banking firm, is responding to a breach at one of its vendors. Daiwa Securities Group said information on as many as 110,000 clients m...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 12:30 UTC</strong> [INDEPENDENT VERIFICATION]: Daiwa Securities says info on 110,000 clients may have been leaked in vendor incident (<a href=\"https://databreaches.net/2026/10/05/daiwa-securities-says-info-on-110000-clients-may-have-been-leaked-in-vendor-incident/\">DataBreaches.net Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-daiwa-securities.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Takashi Nakamichi and Ryo Horiuchi report that Daiwa Securities, Japan's second-largest brokerage and investment banking firm, is responding to a breach at one of its vendors. Daiwa Securities Group said information on as many as 110,000 clients m...",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "investigative",
        "developing"
      ],
      "_open_weights": {
        "score": 0.35,
        "percent": 35,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-dd-automation-ch.html",
      "url": "https://securityincident.net/incidents/2026-10-dd-automation-ch.html",
      "title": "[EMERGING] dd-automation.ch — dd-automation.ch was listed on the Safepay ransomware extortion leak portal. The company was entered into the Swiss commercial register in 1997 and specializes in electrical engineering, automation systems, conveyor technology, …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> dd-automation.ch<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>dd-automation.ch was listed on the Safepay ransomware extortion leak portal. The company was entered into the Swiss commercial register in 1997 and specializes in electrical engineering, automation systems, conveyor technology, …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 19:39 UTC</strong> [UNVERIFIED CLAIM]: dd-automation.ch Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/ZGQtYXV0b21hdGlvbi5jaEBzYWZlcGF5\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-dd-automation-ch.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "dd-automation.ch was listed on the Safepay ransomware extortion leak portal. The company was entered into the Swiss commercial register in 1997 and specializes in electrical engineering, automation systems, conveyor technology, …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-denmark-population-registry.html",
      "url": "https://securityincident.net/incidents/2026-10-denmark-population-registry.html",
      "title": "[DEVELOPING] Denmark population registry — Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> denmarkpopulationregistry.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Denmark&apos;s Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 15:21 UTC</strong> [INDEPENDENT VERIFICATION]: Denmark population registry data breach affects 8.8 million people (<a href=\"https://www.bleepingcomputer.com/news/security/denmark-population-registry-data-breach-affects-88-million-people/\">BleepingComputer Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-denmark-population-registry.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "threat-intel",
        "developing"
      ],
      "_open_weights": {
        "score": 0.39,
        "percent": 39,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-duhaas-sk.html",
      "url": "https://securityincident.net/incidents/2026-10-duhaas-sk.html",
      "title": "[EMERGING] duhaas.sk — duhaas.sk was listed on the Safepay ransomware extortion leak portal. The company was subsequently transformed into a limited liability company in 1992 and established as a joint-stock company in 1994. …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> duhaas.sk<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>duhaas.sk was listed on the Safepay ransomware extortion leak portal. The company was subsequently transformed into a limited liability company in 1992 and established as a joint-stock company in 1994. …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 18:27 UTC</strong> [UNVERIFIED CLAIM]: duhaas.sk Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/ZHVoYWFzLnNrQHNhZmVwYXk=\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-duhaas-sk.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "duhaas.sk was listed on the Safepay ransomware extortion leak portal. The company was subsequently transformed into a limited liability company in 1992 and established as a joint-stock company in 1994. …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-enka-schools.html",
      "url": "https://securityincident.net/incidents/2026-10-enka-schools.html",
      "title": "[EMERGING] ENKA Schools — ENKA Schools was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> enka.k12.tr<br/>\n<strong>Industry:</strong> Education<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Doommageddon<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>ENKA Schools was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 11:53 UTC</strong> [UNVERIFIED CLAIM]: ENKA Schools Listed on Doommageddon Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RU5LQSBTY2hvb2xzQERvb21tYWdlZGRvbg==\">Doommageddon Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-enka-schools.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "ENKA Schools was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Education",
        "extortion",
        "ransomware-claim",
        "doommageddon",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-global-security-concepts.html",
      "url": "https://securityincident.net/incidents/2026-10-global-security-concepts.html",
      "title": "[EMERGING] Global Security Concepts — Global Security Concepts was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> gscsecurity.com<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Global Security Concepts was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 21:04 UTC</strong> [UNVERIFIED CLAIM]: Global Security Concepts Listed on Qilin Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/R2xvYmFsIFNlY3VyaXR5IENvbmNlcHRzQHFpbGlu\">Qilin Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-global-security-concepts.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Global Security Concepts was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "qilin",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-grundens-com.html",
      "url": "https://securityincident.net/incidents/2026-10-grundens-com.html",
      "title": "[EMERGING] grundens.com — grundens.com was listed on the Safepay ransomware extortion leak portal. The company's origins can be traced to 1911, when Carl A. Grundén, the son of a fisherman from Grundsund on …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> grundens.com<br/>\n<strong>Industry:</strong> Retail &amp; E-Commerce<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>grundens.com was listed on the Safepay ransomware extortion leak portal. The company&apos;s origins can be traced to 1911, when Carl A. Grundén, the son of a fisherman from Grundsund on …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 19:35 UTC</strong> [UNVERIFIED CLAIM]: grundens.com Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Z3J1bmRlbnMuY29tQHNhZmVwYXk=\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-grundens-com.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "grundens.com was listed on the Safepay ransomware extortion leak portal. The company's origins can be traced to 1911, when Carl A. Grundén, the son of a fisherman from Grundsund on …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Retail & E-Commerce",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-h-l-manufacturing.html",
      "url": "https://securityincident.net/incidents/2026-10-h-l-manufacturing.html",
      "title": "[EMERGING] H&L Manufacturing — H&L Manufacturing was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> https:hlmanufacturing.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Interlock<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>H&amp;L Manufacturing was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 15:59 UTC</strong> [UNVERIFIED CLAIM]: H&amp;L Manufacturing Listed on Interlock Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/SCZMIE1hbnVmYWN0dXJpbmdAaW50ZXJsb2Nr\">Interlock Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-h-l-manufacturing.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "H&L Manufacturing was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "interlock",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-halservice-it.html",
      "url": "https://securityincident.net/incidents/2026-10-halservice-it.html",
      "title": "[EMERGING] halservice.it — halservice.it was listed on the Safepay ransomware extortion leak portal. Established in 1990, the company initially focused on system integration and information-technology services and later expanded into telecommunications following the …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> halservice.it<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>halservice.it was listed on the Safepay ransomware extortion leak portal. Established in 1990, the company initially focused on system integration and information-technology services and later expanded into telecommunications following the …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 19:36 UTC</strong> [UNVERIFIED CLAIM]: halservice.it Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/aGFsc2VydmljZS5pdEBzYWZlcGF5\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-halservice-it.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "halservice.it was listed on the Safepay ransomware extortion leak portal. Established in 1990, the company initially focused on system integration and information-technology services and later expanded into telecommunications following the …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-ikhasas-com.html",
      "url": "https://securityincident.net/incidents/2026-10-ikhasas-com.html",
      "title": "[EMERGING] ikhasas.com — ikhasas.com was listed on the Safepay ransomware extortion leak portal. The group was incorporated as iKHASAS Sdn. Bhd. in 2008 and subsequently expanded beyond construction into property development, hospitality, plantation, …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> ikhasas.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>ikhasas.com was listed on the Safepay ransomware extortion leak portal. The group was incorporated as iKHASAS Sdn. Bhd. in 2008 and subsequently expanded beyond construction into property development, hospitality, plantation, …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 18:26 UTC</strong> [UNVERIFIED CLAIM]: ikhasas.com Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/aWtoYXNhcy5jb21Ac2FmZXBheQ==\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-ikhasas-com.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "ikhasas.com was listed on the Safepay ransomware extortion leak portal. The group was incorporated as iKHASAS Sdn. Bhd. in 2008 and subsequently expanded beyond construction into property development, hospitality, plantation, …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology & Commercial",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-millensys.html",
      "url": "https://securityincident.net/incidents/2026-10-millensys.html",
      "title": "[EMERGING] Millensys — Millensys was listed on the Medusalocker ransomware extortion leak portal. Organization with 2 emails extracted. Domain: millensys.com",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> millensys.com<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Medusalocker<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Millensys was listed on the Medusalocker ransomware extortion leak portal. Organization with 2 emails extracted. Domain: millensys.com</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 11:08 UTC</strong> [UNVERIFIED CLAIM]: Millensys Listed on Medusalocker Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/TWlsbGVuc3lzQG1lZHVzYWxvY2tlcg==\">Medusalocker Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-millensys.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Millensys was listed on the Medusalocker ransomware extortion leak portal. Organization with 2 emails extracted. Domain: millensys.com",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology",
        "extortion",
        "ransomware-claim",
        "medusalocker",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-nelson-mullins-riley-scarborough.html",
      "url": "https://securityincident.net/incidents/2026-10-nelson-mullins-riley-scarborough.html",
      "title": "[EMERGING] Nelson Mullins Riley & Scarborough — Nelson Mullins Riley & Scarborough was listed on the SilentRansomGroup ransomware extortion leak portal. They offered $8.000.000 to keep the data from being published.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> nelsonmullinsrileyscarborough.com<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> SilentRansomGroup<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Nelson Mullins Riley &amp; Scarborough was listed on the SilentRansomGroup ransomware extortion leak portal. They offered $8.000.000 to keep the data from being published.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 19:25 UTC</strong> [UNVERIFIED CLAIM]: Nelson Mullins Riley &amp; Scarborough Listed on SilentRansomGroup Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/TmVsc29uIE11bGxpbnMgUmlsZXkgJiBTY2FyYm9yb3VnaEBTaWxlbnRSYW5zb21Hcm91cA==\">SilentRansomGroup Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-nelson-mullins-riley-scarborough.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Nelson Mullins Riley & Scarborough was listed on the SilentRansomGroup ransomware extortion leak portal. They offered $8.000.000 to keep the data from being published.",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "silentransomgroup",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-o2-dental-group.html",
      "url": "https://securityincident.net/incidents/2026-10-o2-dental-group.html",
      "title": "[EMERGING] O2 Dental Group — O2 Dental Group was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> o2smiles.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Interlock<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>O2 Dental Group was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 15:01 UTC</strong> [UNVERIFIED CLAIM]: O2 Dental Group Listed on Interlock Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/TzIgRGVudGFsIEdyb3VwQGludGVybG9jaw==\">Interlock Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-o2-dental-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "O2 Dental Group was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Healthcare",
        "extortion",
        "ransomware-claim",
        "interlock",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-onsemi.html",
      "url": "https://securityincident.net/incidents/2026-10-onsemi.html",
      "title": "[EMERGING] Onsemi — Onsemi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> onsemi.com<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Onsemi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 13:15 UTC</strong> [UNVERIFIED CLAIM]: Onsemi Listed on Qilin Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/T25zZW1pQHFpbGlu\">Qilin Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-onsemi.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Onsemi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology",
        "extortion",
        "ransomware-claim",
        "qilin",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-sheppard-mullin-richter-hampto.html",
      "url": "https://securityincident.net/incidents/2026-10-sheppard-mullin-richter-hampto.html",
      "title": "[CONFIRMED] Sheppard, Mullin, Richter & Hampton — State of California Department of Justice data breach disclosure notice filed by Sheppard, Mullin, Richter & Hampton.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> sheppardmullinrichterhampto.com<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> SilentRansomGroup<br/>\n<strong>Open Weights Confidence:</strong> 92% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Sheppard, Mullin, Richter &amp; Hampton.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630779\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-10-05 19:25 UTC</strong> [UNVERIFIED CLAIM]: Sheppard, Mullin, Richter &amp; Hampton Listed on SilentRansomGroup Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/U2hlcHBhcmQsIE11bGxpbiwgUmljaHRlciAmIEhhbXB0b25AU2lsZW50UmFuc29tR3JvdXA=\">SilentRansomGroup Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-sheppard-mullin-richter-hampto.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Sheppard, Mullin, Richter & Hampton.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Professional Services",
        "regulatory",
        "state-ag",
        "california",
        "confirmed",
        "extortion",
        "ransomware-claim",
        "silentransomgroup",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.92,
        "percent": 92,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.12,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-sterrer-net.html",
      "url": "https://securityincident.net/incidents/2026-10-sterrer-net.html",
      "title": "[EMERGING] sterrer.net — sterrer.net was listed on the Safepay ransomware extortion leak portal. The company has operated since 1979 and combines agricultural production with technical services for commercial poultry farms. Its activities include …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> sterrer.net<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>sterrer.net was listed on the Safepay ransomware extortion leak portal. The company has operated since 1979 and combines agricultural production with technical services for commercial poultry farms. Its activities include …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 18:26 UTC</strong> [UNVERIFIED CLAIM]: sterrer.net Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/c3RlcnJlci5uZXRAc2FmZXBheQ==\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-sterrer-net.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "sterrer.net was listed on the Safepay ransomware extortion leak portal. The company has operated since 1979 and combines agricultural production with technical services for commercial poultry farms. Its activities include …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-stuecheli-ch.html",
      "url": "https://securityincident.net/incidents/2026-10-stuecheli-ch.html",
      "title": "[EMERGING] stuecheli.ch — stuecheli.ch was listed on the Safepay ransomware extortion leak portal. The firm was founded by architect Werner Stücheli in 1946 and has developed into a third-generation architectural practice. It is …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> stuecheli.ch<br/>\n<strong>Industry:</strong> Retail &amp; E-Commerce<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>stuecheli.ch was listed on the Safepay ransomware extortion leak portal. The firm was founded by architect Werner Stücheli in 1946 and has developed into a third-generation architectural practice. It is …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 19:37 UTC</strong> [UNVERIFIED CLAIM]: stuecheli.ch Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/c3R1ZWNoZWxpLmNoQHNhZmVwYXk=\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-stuecheli-ch.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "stuecheli.ch was listed on the Safepay ransomware extortion leak portal. The firm was founded by architect Werner Stücheli in 1946 and has developed into a third-generation architectural practice. It is …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Retail & E-Commerce",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-t-systems-com.html",
      "url": "https://securityincident.net/incidents/2026-10-t-systems-com.html",
      "title": "[EMERGING] t-systems.com — t-systems.com was listed on the Safepay ransomware extortion leak portal. Headquartered in Germany, the company operates internationally and has locations in 26 countries, employing more than 26,000 people. T-Systems specializes …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> t-systems.com<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>t-systems.com was listed on the Safepay ransomware extortion leak portal. Headquartered in Germany, the company operates internationally and has locations in 26 countries, employing more than 26,000 people. T-Systems specializes …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 19:34 UTC</strong> [UNVERIFIED CLAIM]: t-systems.com Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/dC1zeXN0ZW1zLmNvbUBzYWZlcGF5\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-t-systems-com.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "t-systems.com was listed on the Safepay ransomware extortion leak portal. Headquartered in Germany, the company operates internationally and has locations in 26 countries, employing more than 26,000 people. T-Systems specializes …",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-turn5.html",
      "url": "https://securityincident.net/incidents/2026-10-turn5.html",
      "title": "[EMERGING] Turn5 — Turn5 was listed on the Global Secret Group ransomware extortion leak portal. Threat actor claims exfiltration of 328 GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> turn5.com<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Global Secret Group<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Turn5 was listed on the Global Secret Group ransomware extortion leak portal. Threat actor claims exfiltration of 328 GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-05 18:53 UTC</strong> [UNVERIFIED CLAIM]: Turn5 Listed on Global Secret Group Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/VHVybjVAR2xvYmFsIFNlY3JldCBHcm91cA==\">Global Secret Group Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-turn5.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Turn5 was listed on the Global Secret Group ransomware extortion leak portal. Threat actor claims exfiltration of 328 GB of internal data files.",
      "date_published": "2026-10-05T00:00:00Z",
      "date_modified": "2026-10-05T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "global secret group",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-automovil-club-del-ecuador-aneta.html",
      "url": "https://securityincident.net/incidents/2026-10-automovil-club-del-ecuador-aneta.html",
      "title": "[EMERGING] Automovil Club del Ecuador ANETA — Automovil Club del Ecuador ANETA was listed on the Barracuda ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> aneta.org.ec<br/>\n<strong>Industry:</strong> Transportation<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Barracuda<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Automovil Club del Ecuador ANETA was listed on the Barracuda ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 04:50 UTC</strong> [UNVERIFIED CLAIM]: Automovil Club del Ecuador ANETA Listed on Barracuda Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/QXV0b21vdmlsIENsdWIgZGVsIEVjdWFkb3IgQU5FVEFAQmFycmFjdWRh\">Barracuda Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-automovil-club-del-ecuador-aneta.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Automovil Club del Ecuador ANETA was listed on the Barracuda ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Transportation",
        "extortion",
        "ransomware-claim",
        "barracuda",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-edgeendo-usa.html",
      "url": "https://securityincident.net/incidents/2026-10-edgeendo-usa.html",
      "title": "[EMERGING] EdgeEndo® USA — EdgeEndo® USA was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 103 GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> edgeendo.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Booba Project<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>EdgeEndo® USA was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 103 GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 12:50 UTC</strong> [UNVERIFIED CLAIM]: EdgeEndo® USA Listed on Booba Project Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RWRnZUVuZG/CriBVU0FAQm9vYmEgUHJvamVjdA==\">Booba Project Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-edgeendo-usa.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "EdgeEndo® USA was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 103 GB of internal data files.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Healthcare",
        "extortion",
        "ransomware-claim",
        "booba project",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-far-west-contractors.html",
      "url": "https://securityincident.net/incidents/2026-10-far-west-contractors.html",
      "title": "[EMERGING] Far West Contractors — Far West Contractors was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> farwestcontractors.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Deadlock<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Far West Contractors was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 07:50 UTC</strong> [UNVERIFIED CLAIM]: Far West Contractors Listed on Deadlock Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RmFyIFdlc3QgQ29udHJhY3RvcnNARGVhZGxvY2s=\">Deadlock Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-far-west-contractors.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Far West Contractors was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "deadlock",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-fragomen-del-rey-bernsen-loewy.html",
      "url": "https://securityincident.net/incidents/2026-10-fragomen-del-rey-bernsen-loewy.html",
      "title": "[CONFIRMED] Fragomen, Del Rey, Bernsen & Loewy — State of California Department of Justice data breach disclosure notice filed by Fragomen, Del Rey, Bernsen & Loewy.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> fragomendelreybernsenloewy.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Fragomen, Del Rey, Bernsen &amp; Loewy.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630760\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-fragomen-del-rey-bernsen-loewy.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Fragomen, Del Rey, Bernsen & Loewy.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-inova-semiconductors-gmbh.html",
      "url": "https://securityincident.net/incidents/2026-10-inova-semiconductors-gmbh.html",
      "title": "[EMERGING] Inova Semiconductors GmbH — Inova Semiconductors GmbH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> inova-semiconductors.de<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Inova Semiconductors GmbH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 14:04 UTC</strong> [UNVERIFIED CLAIM]: Inova Semiconductors GmbH Listed on Qilin Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/SW5vdmEgU2VtaWNvbmR1Y3RvcnMgR21iSEBxaWxpbg==\">Qilin Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-inova-semiconductors-gmbh.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Inova Semiconductors GmbH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "qilin",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-jampac-alimentos.html",
      "url": "https://securityincident.net/incidents/2026-10-jampac-alimentos.html",
      "title": "[EMERGING] Jampac Alimentos — Jampac Alimentos was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 35GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> jampacalimentos.com<br/>\n<strong>Industry:</strong> Agriculture and Food Production<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Affected Population:</strong> 500 records<br/>\n<strong>Open Weights Confidence:</strong> 13% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Jampac Alimentos was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 35GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 14:59 UTC</strong> [UNVERIFIED CLAIM]: Jampac Alimentos Listed on Akira Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/SmFtcGFjIEFsaW1lbnRvc0Bha2lyYQ==\">Akira Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-jampac-alimentos.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Jampac Alimentos was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 35GB of internal data files.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Agriculture and Food Production",
        "extortion",
        "ransomware-claim",
        "akira",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.13,
        "percent": 13,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-main-place-mall.html",
      "url": "https://securityincident.net/incidents/2026-10-main-place-mall.html",
      "title": "[EMERGING] Main Place Mall — Main Place Mall was listed on the Netrunner ransomware extortion leak portal. Main Place is part of a mixed development that combines residence, leisure, retail and dining to bring you the ultimate city-suburban lifestyle.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> mainplace.com.my<br/>\n<strong>Industry:</strong> Retail &amp; E-Commerce<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Netrunner<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Main Place Mall was listed on the Netrunner ransomware extortion leak portal. Main Place is part of a mixed development that combines residence, leisure, retail and dining to bring you the ultimate city-suburban lifestyle.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 00:05 UTC</strong> [UNVERIFIED CLAIM]: Main Place Mall Listed on Netrunner Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/TWFpbiBQbGFjZSBNYWxsQG5ldHJ1bm5lcg==\">Netrunner Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-main-place-mall.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Main Place Mall was listed on the Netrunner ransomware extortion leak portal. Main Place is part of a mixed development that combines residence, leisure, retail and dining to bring you the ultimate city-suburban lifestyle.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Retail & E-Commerce",
        "extortion",
        "ransomware-claim",
        "netrunner",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-pacific-tank-lines.html",
      "url": "https://securityincident.net/incidents/2026-10-pacific-tank-lines.html",
      "title": "[EMERGING] Pacific Tank Lines — Pacific Tank Lines was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 13GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> pacifictanklines.com<br/>\n<strong>Industry:</strong> Transportation<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Affected Population:</strong> 118 records<br/>\n<strong>Open Weights Confidence:</strong> 13% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Pacific Tank Lines was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 13GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 14:24 UTC</strong> [UNVERIFIED CLAIM]: Pacific Tank Lines Listed on Akira Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/UGFjaWZpYyBUYW5rIExpbmVzQGFraXJh\">Akira Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-pacific-tank-lines.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Pacific Tank Lines was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 13GB of internal data files.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Transportation",
        "extortion",
        "ransomware-claim",
        "akira",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.13,
        "percent": 13,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-raleigh-family-medicine.html",
      "url": "https://securityincident.net/incidents/2026-10-raleigh-family-medicine.html",
      "title": "[EMERGING] Raleigh Family Medicine — Raleigh Family Medicine was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 1 GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> rfppa.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Booba Project<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Raleigh Family Medicine was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 1 GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 12:51 UTC</strong> [UNVERIFIED CLAIM]: Raleigh Family Medicine Listed on Booba Project Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/UmFsZWlnaCBGYW1pbHkgTWVkaWNpbmVAQm9vYmEgUHJvamVjdA==\">Booba Project Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-raleigh-family-medicine.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Raleigh Family Medicine was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 1 GB of internal data files.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Healthcare",
        "extortion",
        "ransomware-claim",
        "booba project",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-sangre-de-cristo-electric-association.html",
      "url": "https://securityincident.net/incidents/2026-10-sangre-de-cristo-electric-association.html",
      "title": "[EMERGING] Sangre de Cristo Electric Association — Sangre de Cristo Electric Association was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> myelectric.coop<br/>\n<strong>Industry:</strong> Energy &amp; Utilities<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Incransom<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Sangre de Cristo Electric Association was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 01:33 UTC</strong> [UNVERIFIED CLAIM]: Sangre de Cristo Electric Association Listed on Incransom Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/U2FuZ3JlIGRlIENyaXN0byBFbGVjdHJpYyBBc3NvY2lhdGlvbkBpbmNyYW5zb20=\">Incransom Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-sangre-de-cristo-electric-association.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Sangre de Cristo Electric Association was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Energy & Utilities",
        "extortion",
        "ransomware-claim",
        "incransom",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-soni-medical-centre.html",
      "url": "https://securityincident.net/incidents/2026-10-soni-medical-centre.html",
      "title": "[EMERGING] Soni Medical Centre — Soni Medical Centre was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 5.5 GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> lakewoodmedical.ca<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Booba Project<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Soni Medical Centre was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 5.5 GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 12:50 UTC</strong> [UNVERIFIED CLAIM]: Soni Medical Centre Listed on Booba Project Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/U29uaSBNZWRpY2FsIENlbnRyZUBCb29iYSBQcm9qZWN0\">Booba Project Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-soni-medical-centre.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Soni Medical Centre was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 5.5 GB of internal data files.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Healthcare",
        "extortion",
        "ransomware-claim",
        "booba project",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-the-official-college-of-architects-of-leon-coal.html",
      "url": "https://securityincident.net/incidents/2026-10-the-official-college-of-architects-of-leon-coal.html",
      "title": "[EMERGING] The Official College of Architects of León (COAL) — The Official College of Architects of León (COAL) was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 77GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> theofficialcollegeofarchitectsofleoncoal.com<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>The Official College of Architects of León (COAL) was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 77GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 14:59 UTC</strong> [UNVERIFIED CLAIM]: The Official College of Architects of León (COAL) Listed on Akira Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/VGhlIE9mZmljaWFsIENvbGxlZ2Ugb2YgQXJjaGl0ZWN0cyBvZiBMZcOzbiAoQ09BTClAYWtpcmE=\">Akira Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-the-official-college-of-architects-of-leon-coal.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "The Official College of Architects of León (COAL) was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 77GB of internal data files.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "akira",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-tronex-a-s.html",
      "url": "https://securityincident.net/incidents/2026-10-tronex-a-s.html",
      "title": "[EMERGING] Tronex A/S — Tronex A/S was listed on the Wallstreet ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> tronexas.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Wallstreet<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Tronex A/S was listed on the Wallstreet ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 11:55 UTC</strong> [UNVERIFIED CLAIM]: Tronex A/S Listed on Wallstreet Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/VHJvbmV4IEEvU0BXYWxsc3RyZWV0\">Wallstreet Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-tronex-a-s.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Tronex A/S was listed on the Wallstreet ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "wallstreet",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-union-fa.html",
      "url": "https://securityincident.net/incidents/2026-10-union-fa.html",
      "title": "[EMERGING] UNION FA — UNION FA was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> rogdianakis.gr<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Deadlock<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>UNION FA was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 07:50 UTC</strong> [UNVERIFIED CLAIM]: UNION FA Listed on Deadlock Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/VU5JT04gRkFARGVhZGxvY2s=\">Deadlock Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-union-fa.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "UNION FA was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "deadlock",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-university-of-illinois-chicago.html",
      "url": "https://securityincident.net/incidents/2026-10-university-of-illinois-chicago.html",
      "title": "[EMERGING] University of Illinois Chicago — University of Illinois Chicago was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 344 GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> uic.edu<br/>\n<strong>Industry:</strong> Education<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Booba Project<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>University of Illinois Chicago was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 344 GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 12:50 UTC</strong> [UNVERIFIED CLAIM]: University of Illinois Chicago Listed on Booba Project Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/VW5pdmVyc2l0eSBvZiBJbGxpbm9pcyBDaGljYWdvQEJvb2JhIFByb2plY3Q=\">Booba Project Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-university-of-illinois-chicago.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "University of Illinois Chicago was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 344 GB of internal data files.",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Education",
        "extortion",
        "ransomware-claim",
        "booba project",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-www-kres-cz.html",
      "url": "https://securityincident.net/incidents/2026-10-www-kres-cz.html",
      "title": "[EMERGING] www.kres.cz — www.kres.cz was listed on the Krybit ransomware extortion leak portal. KRES spol. s r.o. is a Czech company headquartered in Krnov, Moravskoslezský Region, Czech Republic, specializing in wh...",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> kres.cz<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Krybit<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>www.kres.cz was listed on the Krybit ransomware extortion leak portal. KRES spol. s r.o. is a Czech company headquartered in Krnov, Moravskoslezský Region, Czech Republic, specializing in wh...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 09:31 UTC</strong> [UNVERIFIED CLAIM]: www.kres.cz Listed on Krybit Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/d3d3LmtyZXMuY3pAa3J5Yml0\">Krybit Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-www-kres-cz.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "www.kres.cz was listed on the Krybit ransomware extortion leak portal. KRES spol. s r.o. is a Czech company headquartered in Krnov, Moravskoslezský Region, Czech Republic, specializing in wh...",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology & Commercial",
        "extortion",
        "ransomware-claim",
        "krybit",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-www-pierrefeu-fr.html",
      "url": "https://securityincident.net/incidents/2026-10-www-pierrefeu-fr.html",
      "title": "[EMERGING] www.pierrefeu.fr — www.pierrefeu.fr was listed on the Krybit ransomware extortion leak portal. Pierrefeu Immobilier is an independent French real estate agency founded in 1963, headquartered in Tarare, in the Nord-O...",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> pierrefeu.fr<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Krybit<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>www.pierrefeu.fr was listed on the Krybit ransomware extortion leak portal. Pierrefeu Immobilier is an independent French real estate agency founded in 1963, headquartered in Tarare, in the Nord-O...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 09:30 UTC</strong> [UNVERIFIED CLAIM]: www.pierrefeu.fr Listed on Krybit Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/d3d3LnBpZXJyZWZldS5mckBrcnliaXQ=\">Krybit Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-www-pierrefeu-fr.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "www.pierrefeu.fr was listed on the Krybit ransomware extortion leak portal. Pierrefeu Immobilier is an independent French real estate agency founded in 1963, headquartered in Tarare, in the Nord-O...",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "krybit",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-www-raajratna-com.html",
      "url": "https://securityincident.net/incidents/2026-10-www-raajratna-com.html",
      "title": "[EMERGING] www.raajratna.com — www.raajratna.com was listed on the Krybit ransomware extortion leak portal. Raajratna Metal Industries Limited (RMIL) is a leading Indian public limited company incorporated on May 9, 1988, headqu...",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> raajratna.com<br/>\n<strong>Industry:</strong> Retail &amp; E-Commerce<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Krybit<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>www.raajratna.com was listed on the Krybit ransomware extortion leak portal. Raajratna Metal Industries Limited (RMIL) is a leading Indian public limited company incorporated on May 9, 1988, headqu...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-02 09:31 UTC</strong> [UNVERIFIED CLAIM]: www.raajratna.com Listed on Krybit Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/d3d3LnJhYWpyYXRuYS5jb21Aa3J5Yml0\">Krybit Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-www-raajratna-com.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "www.raajratna.com was listed on the Krybit ransomware extortion leak portal. Raajratna Metal Industries Limited (RMIL) is a leading Indian public limited company incorporated on May 9, 1988, headqu...",
      "date_published": "2026-10-02T00:00:00Z",
      "date_modified": "2026-10-02T00:00:00Z",
      "tags": [
        "EMERGING",
        "Retail & E-Commerce",
        "extortion",
        "ransomware-claim",
        "krybit",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2024-01-microsoft-midnight-blizzard.html",
      "url": "https://securityincident.net/incidents/2024-01-microsoft-midnight-blizzard.html",
      "title": "[CONFIRMED] Microsoft — Microsoft disclosed an intrusion by Russian foreign intelligence threat group Midnight Blizzard (APT29), accessing senior leadership corporate emails and source code.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> microsoft.com<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Nation-State Password Spray &amp; Cloud Access<br/>\n<strong>Threat Actor:</strong> Midnight Blizzard (APT29)<br/>\n<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Microsoft disclosed an intrusion by Russian foreign intelligence threat group Midnight Blizzard (APT29), accessing senior leadership corporate emails and source code.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2024-01-12 18:00 UTC</strong> [CONFIRMED BY TARGET]: Microsoft security team detects Russian state-sponsored threat actor Midnight Blizzard accessing corporate email systems via legacy OAuth tenant test account. (<a href=\"https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/\">Microsoft Security Response Center (MSRC) Advisory</a>)</li>\n<li><strong>2024-01-19 21:00 UTC</strong> [CONFIRMED BY REGULATOR]: Microsoft files Form 8-K Item 1.05 detailing Midnight Blizzard intrusion into senior executive email accounts and cybersecurity staff communications. (<a href=\"https://www.sec.gov/Archives/edgar/data/789019/000078901924000004/msft-20240119.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0000789019-24-000004)</a>)</li>\n<li><strong>2024-03-08 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: Microsoft Form 8-K update discloses threat actor used exfiltrated email secrets to gain unauthorized access to internal source code repositories. (<a href=\"https://www.sec.gov/Archives/edgar/data/789019/000078901924000008/msft-20240308.htm\">SEC EDGAR 8-K Item 1.05 Update (Adsh 0000789019-24-000008)</a>)</li>\n<li><strong>2026-10-01 19:32 UTC</strong> [INDEPENDENT VERIFICATION]: Microsoft says threat actors are ahead in the early AI race (<a href=\"https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/\">BleepingComputer Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2024-01-microsoft-midnight-blizzard.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Microsoft disclosed an intrusion by Russian foreign intelligence threat group Midnight Blizzard (APT29), accessing senior leadership corporate emails and source code.",
      "date_published": "2024-01-12T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology",
        "regulatory",
        "sec-8k",
        "nation-state",
        "apt29",
        "confirmed",
        "threat-intel",
        "developing"
      ],
      "_open_weights": {
        "score": 1,
        "percent": 100,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.17,
        "unique_domains": 3
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-bitget.html",
      "url": "https://securityincident.net/incidents/2026-09-bitget.html",
      "title": "[CONFIRMED] Bitget — Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> bitget.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 74% (CONFIRMED BY TARGET)<br/>\n</p>\n<p>Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-28 09:25 UTC</strong> [INDEPENDENT VERIFICATION]: Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist (<a href=\"https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/\">BleepingComputer Report</a>)</li>\n<li><strong>2026-09-28 17:42 UTC</strong> [INDEPENDENT VERIFICATION]: Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M (<a href=\"https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html\">The Hacker News Intelligence Notice</a>)</li>\n<li><strong>2026-09-25 10:35 UTC</strong> [INDEPENDENT VERIFICATION]: Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise (<a href=\"https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html\">The Hacker News Intelligence Notice</a>)</li>\n<li><strong>2026-09-30 11:11 UTC</strong> [INDEPENDENT VERIFICATION]: Bitget hacked via zero-day in third-party security products (<a href=\"https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/\">BleepingComputer Report</a>)</li>\n<li><strong>2026-10-01 05:21 UTC</strong> [CONFIRMED BY TARGET]: Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft (<a href=\"https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html\">The Hacker News Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-bitget.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]",
      "date_published": "2026-09-25T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "threat-intel",
        "developing"
      ],
      "_open_weights": {
        "score": 0.74,
        "percent": 74,
        "top_tier": "CONFIRMED BY TARGET",
        "base_weight": 0.5,
        "corroboration_bonus": 0.12,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-divd.html",
      "url": "https://securityincident.net/incidents/2026-09-divd.html",
      "title": "[DEVELOPING] DIVD — The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> divd.nl<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 42% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-30 19:49 UTC</strong> [INDEPENDENT VERIFICATION]: DIVD says Zammad zero-days enabled AI-driven network breach (<a href=\"https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/\">BleepingComputer Report</a>)</li>\n<li><strong>2026-10-01 10:42 UTC</strong> [INDEPENDENT VERIFICATION]: Zammad Zero-Days Exploited in AI-Powered DIVD Hack (<a href=\"https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/\">SecurityWeek Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-divd.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]",
      "date_published": "2026-09-30T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "threat-intel",
        "developing"
      ],
      "_open_weights": {
        "score": 0.42,
        "percent": 42,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-greenberg-traurig.html",
      "url": "https://securityincident.net/incidents/2026-09-greenberg-traurig.html",
      "title": "[CONFIRMED] Greenberg Traurig — Global law firm Greenberg Traurig was compromised by Silent Ransom Group, resulting in the exfiltration and notification of over 126,000 individuals.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> gtlaw.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> RansomHub<br/>\n<strong>Affected Population:</strong> 145,000 records<br/>\n<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Global law firm Greenberg Traurig was compromised by Silent Ransom Group, resulting in the exfiltration and notification of over 126,000 individuals.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-14 11:30 UTC</strong> [INDEPENDENT VERIFICATION]: Silent Ransom Group lists Greenberg Traurig on extortion site; forensic investigation confirms 126k individuals affected. (<a href=\"https://databreaches.net/2026/09/14/silent-ransom-group-hacked-greenberg-traurig-who-notifies-the-126k-affected/\">DataBreaches.net Incident Audit</a>)</li>\n<li><strong>2026-09-09 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629493\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-10-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630659\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-greenberg-traurig.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Global law firm Greenberg Traurig was compromised by Silent Ransom Group, resulting in the exfiltration and notification of over 126,000 individuals.",
      "date_published": "2026-09-09T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "investigative",
        "legal",
        "ransomware-claim",
        "developing",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 1,
        "percent": 100,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.12,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-us-dod-pentagon.html",
      "url": "https://securityincident.net/incidents/2026-09-us-dod-pentagon.html",
      "title": "[DEVELOPING] U.S. Department of Defense (Pentagon) — Sean Lyngaas and Davis Winkie report: A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national s...",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> defense.gov<br/>\n<strong>Industry:</strong> Government &amp; Defense<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 240,000 records<br/>\n<strong>Open Weights Confidence:</strong> 70% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Sean Lyngaas and Davis Winkie report: A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national s...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-26 11:47 UTC</strong> [INDEPENDENT VERIFICATION]: Pentagon data breach of military personnel raises national security concerns (<a href=\"https://databreaches.net/2026/09/26/pentagon-data-breach-of-military-personnel-raises-national-security-concerns/\">DataBreaches.net Report</a>)</li>\n<li><strong>2026-09-29 12:25 UTC</strong> [INDEPENDENT VERIFICATION]: Pentagon Personnel Agency Data Breach Impacts 3 Million People (<a href=\"https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/\">SecurityWeek Intelligence Notice</a>)</li>\n<li><strong>2026-10-01 09:44 UTC</strong> [INDEPENDENT VERIFICATION]: Hackers stole Pentagon personnel records of over 3 million people (<a href=\"https://www.bleepingcomputer.com/news/security/hackers-breach-pentagon-human-resources-management-system-steal-data-of-nearly-3-million-people/\">BleepingComputer Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-us-dod-pentagon.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Sean Lyngaas and Davis Winkie report: A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national s...",
      "date_published": "2026-09-26T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Government & Defense",
        "investigative",
        "developing",
        "threat-intel"
      ],
      "_open_weights": {
        "score": 0.7,
        "percent": 70,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0.12,
        "unique_domains": 3
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-aldrich-services.html",
      "url": "https://securityincident.net/incidents/2026-10-aldrich-services.html",
      "title": "[CONFIRMED] Aldrich Services — State of California Department of Justice data breach disclosure notice filed by Aldrich Services.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> aldrichservices.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Aldrich Services.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630682\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-aldrich-services.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Aldrich Services.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-associated-gastroenterologists-of-central-new.html",
      "url": "https://securityincident.net/incidents/2026-10-associated-gastroenterologists-of-central-new.html",
      "title": "[EMERGING] ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C — ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 70 GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> gastrocny.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Booba Project<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 70 GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 14:50 UTC</strong> [UNVERIFIED CLAIM]: ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C Listed on Booba Project Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/QVNTT0NJQVRFRCBHQVNUUk9FTlRFUk9MT0dJU1RTIE9GIENFTlRSQUwgTkVXIFlPUkssIFAuQ0BCb29iYSBQcm9qZWN0\">Booba Project Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-associated-gastroenterologists-of-central-new.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 70 GB of internal data files.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Healthcare",
        "extortion",
        "ransomware-claim",
        "booba project",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-c-ro-nty-es.html",
      "url": "https://securityincident.net/incidents/2026-10-c-ro-nty-es.html",
      "title": "[EMERGING] C*ro *nty *es — C*ro *nty *es was listed on the Nightspire ransomware extortion leak portal. Data is not available now.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> crontyes.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Nightspire<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>C*ro *nty *es was listed on the Nightspire ransomware extortion leak portal. Data is not available now.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 13:35 UTC</strong> [UNVERIFIED CLAIM]: C*ro *nty *es Listed on Nightspire Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/QypybyAqbnR5ICplc0BuaWdodHNwaXJl\">Nightspire Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-c-ro-nty-es.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "C*ro *nty *es was listed on the Nightspire ransomware extortion leak portal. Data is not available now.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology & Commercial",
        "extortion",
        "ransomware-claim",
        "nightspire",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-den-hartog-industries.html",
      "url": "https://securityincident.net/incidents/2026-10-den-hartog-industries.html",
      "title": "[EMERGING] Den Hartog Industries — Den Hartog Industries was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> denhartogindustries.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Incransom<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Den Hartog Industries was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 11:29 UTC</strong> [UNVERIFIED CLAIM]: Den Hartog Industries Listed on Incransom Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RGVuIEhhcnRvZyBJbmR1c3RyaWVzQGluY3JhbnNvbQ==\">Incransom Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-den-hartog-industries.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Den Hartog Industries was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "incransom",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-disk-precision-group-diskprecision-com.html",
      "url": "https://securityincident.net/incidents/2026-10-disk-precision-group-diskprecision-com.html",
      "title": "[EMERGING] DISK PRECISION GROUP - diskprecision.com — DISK PRECISION GROUP - diskprecision.com was listed on the Krybit ransomware extortion leak portal. - Disk Precision Industries Pte Ltd (Singapore, est. 1986)   - Spacetech Industrial Pte Ltd (Singapore)   - Niteac Eng...",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> disk precision group - diskprecision.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Krybit<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>DISK PRECISION GROUP - diskprecision.com was listed on the Krybit ransomware extortion leak portal. - Disk Precision Industries Pte Ltd (Singapore, est. 1986)   - Spacetech Industrial Pte Ltd (Singapore)   - Niteac Eng...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 14:59 UTC</strong> [UNVERIFIED CLAIM]: DISK PRECISION GROUP - diskprecision.com Listed on Krybit Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RElTSyBQUkVDSVNJT04gR1JPVVAgLSBkaXNrcHJlY2lzaW9uLmNvbUBrcnliaXQ=\">Krybit Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-disk-precision-group-diskprecision-com.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "DISK PRECISION GROUP - diskprecision.com was listed on the Krybit ransomware extortion leak portal. - Disk Precision Industries Pte Ltd (Singapore, est. 1986)   - Spacetech Industrial Pte Ltd (Singapore)   - Niteac Eng...",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "krybit",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-dpl-group.html",
      "url": "https://securityincident.net/incidents/2026-10-dpl-group.html",
      "title": "[EMERGING] DPL Group — DPL Group was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 8GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> dplgroup.com<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>DPL Group was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 8GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 13:27 UTC</strong> [UNVERIFIED CLAIM]: DPL Group Listed on Akira Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RFBMIEdyb3VwQGFraXJh\">Akira Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-dpl-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "DPL Group was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 8GB of internal data files.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "akira",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-dynamic-office-solutions.html",
      "url": "https://securityincident.net/incidents/2026-10-dynamic-office-solutions.html",
      "title": "[EMERGING] Dynamic Office Solutions — Dynamic Office Solutions was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> dynamicos.co.uk<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Dynamic Office Solutions was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 09:04 UTC</strong> [UNVERIFIED CLAIM]: Dynamic Office Solutions Listed on Qilin Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RHluYW1pYyBPZmZpY2UgU29sdXRpb25zQHFpbGlu\">Qilin Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-dynamic-office-solutions.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Dynamic Office Solutions was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "qilin",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-euroditel-resotelecom.html",
      "url": "https://securityincident.net/incidents/2026-10-euroditel-resotelecom.html",
      "title": "[EMERGING] EURODITEL/RESOTELECOM — EURODITEL/RESOTELECOM was listed on the Krybit ransomware extortion leak portal. Euroditel is a French managed services provider (MSP) specializing in telephony and unified communications. Based in th...",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> euroditel.com<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Krybit<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>EURODITEL/RESOTELECOM was listed on the Krybit ransomware extortion leak portal. Euroditel is a French managed services provider (MSP) specializing in telephony and unified communications. Based in th...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 21:33 UTC</strong> [UNVERIFIED CLAIM]: EURODITEL/RESOTELECOM Listed on Krybit Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RVVST0RJVEVML1JFU09URUxFQ09NQGtyeWJpdA==\">Krybit Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-euroditel-resotelecom.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "EURODITEL/RESOTELECOM was listed on the Krybit ransomware extortion leak portal. Euroditel is a French managed services provider (MSP) specializing in telephony and unified communications. Based in th...",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology",
        "extortion",
        "ransomware-claim",
        "krybit",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-fortinet.html",
      "url": "https://securityincident.net/incidents/2026-10-fortinet.html",
      "title": "[DEVELOPING] Fortinet — Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> fortinet.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 22:42 UTC</strong> [INDEPENDENT VERIFICATION]: Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (<a href=\"https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/\">BleepingComputer Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-fortinet.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "threat-intel",
        "developing"
      ],
      "_open_weights": {
        "score": 0.35,
        "percent": 35,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-funap-fundacao-prof-dr-manoel-pedro-pimentel.html",
      "url": "https://securityincident.net/incidents/2026-10-funap-fundacao-prof-dr-manoel-pedro-pimentel.html",
      "title": "[EMERGING] FUNAP - Fundação \"Prof. Dr. Manoel Pedro Pimentel\" — FUNAP - Fundação \"Prof. Dr. Manoel Pedro Pimentel\" was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 26 GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> funap.sp.gov.br<br/>\n<strong>Industry:</strong> Government &amp; Defense<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Booba Project<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>FUNAP - Fundação &quot;Prof. Dr. Manoel Pedro Pimentel&quot; was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 26 GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 14:50 UTC</strong> [UNVERIFIED CLAIM]: FUNAP - Fundação &quot;Prof. Dr. Manoel Pedro Pimentel&quot; Listed on Booba Project Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/RlVOQVAgLSBGdW5kYcOnw6NvICJQcm9mLiBEci4gTWFub2VsIFBlZHJvIFBpbWVudGVsIkBCb29iYSBQcm9qZWN0\">Booba Project Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-funap-fundacao-prof-dr-manoel-pedro-pimentel.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "FUNAP - Fundação \"Prof. Dr. Manoel Pedro Pimentel\" was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 26 GB of internal data files.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Government & Defense",
        "extortion",
        "ransomware-claim",
        "booba project",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-graybar-electric-company-inc.html",
      "url": "https://securityincident.net/incidents/2026-10-graybar-electric-company-inc.html",
      "title": "[EMERGING] Graybar Electric Company, Inc. — Graybar Electric Company, Inc. was listed on the Redact ransomware extortion leak portal. Sector: Electrical Equipment | Revenue: $11B USD",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> graybarelectriccompanyinc.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Redact<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Graybar Electric Company, Inc. was listed on the Redact ransomware extortion leak portal. Sector: Electrical Equipment | Revenue: $11B USD</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 12:55 UTC</strong> [UNVERIFIED CLAIM]: Graybar Electric Company, Inc. Listed on Redact Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/R3JheWJhciBFbGVjdHJpYyBDb21wYW55LCBJbmMuQFJlZGFjdA==\">Redact Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-graybar-electric-company-inc.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Graybar Electric Company, Inc. was listed on the Redact ransomware extortion leak portal. Sector: Electrical Equipment | Revenue: $11B USD",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "redact",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-guardian-pharmacy-llc.html",
      "url": "https://securityincident.net/incidents/2026-10-guardian-pharmacy-llc.html",
      "title": "[EMERGING] Guardian Pharmacy LLC — Guardian Pharmacy LLC was listed on the Incransom ransomware extortion leak portal. Hacked; more news coming soon. . .",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> guardianpharmacyllc.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Incransom<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Guardian Pharmacy LLC was listed on the Incransom ransomware extortion leak portal. Hacked; more news coming soon. . .</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 11:30 UTC</strong> [UNVERIFIED CLAIM]: Guardian Pharmacy LLC Listed on Incransom Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/R3VhcmRpYW4gUGhhcm1hY3kgTExDQGluY3JhbnNvbQ==\">Incransom Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-guardian-pharmacy-llc.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Guardian Pharmacy LLC was listed on the Incransom ransomware extortion leak portal. Hacked; more news coming soon. . .",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Healthcare",
        "extortion",
        "ransomware-claim",
        "incransom",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-krycler-ervin-taubman-kaminsky.html",
      "url": "https://securityincident.net/incidents/2026-10-krycler-ervin-taubman-kaminsky.html",
      "title": "[EMERGING] Krycler, Ervin, Taubman & Kaminsky — Krycler, Ervin, Taubman & Kaminsky was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 88GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> kryclerervintaubmankaminsky.com<br/>\n<strong>Industry:</strong> Professional Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Krycler, Ervin, Taubman &amp; Kaminsky was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 88GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 12:56 UTC</strong> [UNVERIFIED CLAIM]: Krycler, Ervin, Taubman &amp; Kaminsky Listed on Akira Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/S3J5Y2xlciwgRXJ2aW4sIFRhdWJtYW4gJiBLYW1pbnNreUBha2lyYQ==\">Akira Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-krycler-ervin-taubman-kaminsky.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Krycler, Ervin, Taubman & Kaminsky was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 88GB of internal data files.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Professional Services",
        "extortion",
        "ransomware-claim",
        "akira",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-la-ponderosa.html",
      "url": "https://securityincident.net/incidents/2026-10-la-ponderosa.html",
      "title": "[EMERGING] LA PONDEROSA — LA PONDEROSA was listed on the Emperador ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> laponderosa.com<br/>\n<strong>Industry:</strong> Agriculture and Food Production<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Emperador<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>LA PONDEROSA was listed on the Emperador ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 09:51 UTC</strong> [UNVERIFIED CLAIM]: LA PONDEROSA Listed on Emperador Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/TEEgUE9OREVST1NBQGVtcGVyYWRvcg==\">Emperador Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-la-ponderosa.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "LA PONDEROSA was listed on the Emperador ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Agriculture and Food Production",
        "extortion",
        "ransomware-claim",
        "emperador",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-laboratorios-roemmers-saicf.html",
      "url": "https://securityincident.net/incidents/2026-10-laboratorios-roemmers-saicf.html",
      "title": "[EMERGING] Laboratorios Roemmers SAICF — Laboratorios Roemmers SAICF was listed on the Aurora ransomware extortion leak portal. Threat actor claims exfiltration of 82 GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> roemmers.com.ar<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Aurora<br/>\n<strong>Affected Population:</strong> 6,890 records<br/>\n<strong>Open Weights Confidence:</strong> 13% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Laboratorios Roemmers SAICF was listed on the Aurora ransomware extortion leak portal. Threat actor claims exfiltration of 82 GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 06:55 UTC</strong> [UNVERIFIED CLAIM]: Laboratorios Roemmers SAICF Listed on Aurora Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/TGFib3JhdG9yaW9zIFJvZW1tZXJzIFNBSUNGQGF1cm9yYQ==\">Aurora Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-laboratorios-roemmers-saicf.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Laboratorios Roemmers SAICF was listed on the Aurora ransomware extortion leak portal. Threat actor claims exfiltration of 82 GB of internal data files.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Healthcare",
        "extortion",
        "ransomware-claim",
        "aurora",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.13,
        "percent": 13,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-lincoln-property-company-comme.html",
      "url": "https://securityincident.net/incidents/2026-10-lincoln-property-company-comme.html",
      "title": "[CONFIRMED] Lincoln Property Company Commercial — State of California Department of Justice data breach disclosure notice filed by Lincoln Property Company Commercial.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> lincolnpropertycompanycomme.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Lincoln Property Company Commercial.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630678\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-lincoln-property-company-comme.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Lincoln Property Company Commercial.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-marana-health-center.html",
      "url": "https://securityincident.net/incidents/2026-10-marana-health-center.html",
      "title": "[CONFIRMED] Marana Health Center — State of California Department of Justice data breach disclosure notice filed by Marana Health Center.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> maranahealthcenter.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Marana Health Center.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630668\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-marana-health-center.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Marana Health Center.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-northern-counties-health-care.html",
      "url": "https://securityincident.net/incidents/2026-10-northern-counties-health-care.html",
      "title": "[EMERGING] Northern Counties Health Care — Northern Counties Health Care was listed on the Incransom ransomware extortion leak portal. With five community Health Centers, two dental centers, and a certified Home Health Care & Hospice division, NCHC provides health care services to patients...",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> nchcvt.org<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Incransom<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Northern Counties Health Care was listed on the Incransom ransomware extortion leak portal. With five community Health Centers, two dental centers, and a certified Home Health Care &amp; Hospice division, NCHC provides health care services to patients...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 11:29 UTC</strong> [UNVERIFIED CLAIM]: Northern Counties Health Care Listed on Incransom Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Tm9ydGhlcm4gQ291bnRpZXMgSGVhbHRoIENhcmVAaW5jcmFuc29t\">Incransom Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-northern-counties-health-care.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Northern Counties Health Care was listed on the Incransom ransomware extortion leak portal. With five community Health Centers, two dental centers, and a certified Home Health Care & Hospice division, NCHC provides health care services to patients...",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Healthcare",
        "extortion",
        "ransomware-claim",
        "incransom",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-post-metal-recycling.html",
      "url": "https://securityincident.net/incidents/2026-10-post-metal-recycling.html",
      "title": "[EMERGING] Post Metal Recycling — Post Metal Recycling was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> postmetalrecycling.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Incransom<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Post Metal Recycling was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 11:29 UTC</strong> [UNVERIFIED CLAIM]: Post Metal Recycling Listed on Incransom Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/UG9zdCBNZXRhbCBSZWN5Y2xpbmdAaW5jcmFuc29t\">Incransom Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-post-metal-recycling.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Post Metal Recycling was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "incransom",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-rimrock-foundation.html",
      "url": "https://securityincident.net/incidents/2026-10-rimrock-foundation.html",
      "title": "[EMERGING] Rimrock Foundation — Rimrock Foundation was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> rimrock.org<br/>\n<strong>Industry:</strong> Other<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Incransom<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Rimrock Foundation was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 12:31 UTC</strong> [UNVERIFIED CLAIM]: Rimrock Foundation Listed on Incransom Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/Umltcm9jayBGb3VuZGF0aW9uQGluY3JhbnNvbQ==\">Incransom Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-rimrock-foundation.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Rimrock Foundation was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Other",
        "extortion",
        "ransomware-claim",
        "incransom",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-superior-plating-technology-co.html",
      "url": "https://securityincident.net/incidents/2026-10-superior-plating-technology-co.html",
      "title": "[EMERGING] Superior Plating Technology CO — Superior Plating Technology CO was listed on the Morpheus ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> superiorplatingtechnologyco.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Morpheus<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Superior Plating Technology CO was listed on the Morpheus ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 14:30 UTC</strong> [UNVERIFIED CLAIM]: Superior Plating Technology CO Listed on Morpheus Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/U3VwZXJpb3IgUGxhdGluZyBUZWNobm9sb2d5IENPQG1vcnBoZXVz\">Morpheus Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-superior-plating-technology-co.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Superior Plating Technology CO was listed on the Morpheus ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "morpheus",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-10-wesmar.html",
      "url": "https://securityincident.net/incidents/2026-10-wesmar.html",
      "title": "[EMERGING] Wesmar — Wesmar was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 66GB of internal data files.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> wesmar.com<br/>\n<strong>Industry:</strong> Manufacturing<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Wesmar was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 66GB of internal data files.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-10-01 13:27 UTC</strong> [UNVERIFIED CLAIM]: Wesmar Listed on Akira Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/V2VzbWFyQGFraXJh\">Akira Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-10-wesmar.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Wesmar was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 66GB of internal data files.",
      "date_published": "2026-10-01T00:00:00Z",
      "date_modified": "2026-10-01T00:00:00Z",
      "tags": [
        "EMERGING",
        "Manufacturing",
        "extortion",
        "ransomware-claim",
        "akira",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-american-family-connect-insura.html",
      "url": "https://securityincident.net/incidents/2026-09-american-family-connect-insura.html",
      "title": "[CONFIRMED] American Family Connect Insurance Company — State of California Department of Justice data breach disclosure notice filed by American Family Connect Insurance Company.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> americanfamilyconnectinsura.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by American Family Connect Insurance Company.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-30 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630618\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-american-family-connect-insura.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by American Family Connect Insurance Company.",
      "date_published": "2026-09-30T00:00:00Z",
      "date_modified": "2026-09-30T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-drivewealth.html",
      "url": "https://securityincident.net/incidents/2026-09-drivewealth.html",
      "title": "[CONFIRMED] DriveWealth — State of California Department of Justice data breach disclosure notice filed by DriveWealth.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> drivewealth.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by DriveWealth.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-30 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630619\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-drivewealth.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by DriveWealth.",
      "date_published": "2026-09-30T00:00:00Z",
      "date_modified": "2026-09-30T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-houston-thyroid-endocrine-specialists.html",
      "url": "https://securityincident.net/incidents/2026-09-houston-thyroid-endocrine-specialists.html",
      "title": "[EMERGING] Houston Thyroid & Endocrine Specialists — Houston Thyroid & Endocrine Specialists was listed on the N0n ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> houstonthyroidendocrinespecialists.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> N0n<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Houston Thyroid &amp; Endocrine Specialists was listed on the N0n ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-30 22:53 UTC</strong> [UNVERIFIED CLAIM]: Houston Thyroid &amp; Endocrine Specialists Listed on N0n Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/SG91c3RvbiBUaHlyb2lkICYgRW5kb2NyaW5lIFNwZWNpYWxpc3RzQE4wbg==\">N0n Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-houston-thyroid-endocrine-specialists.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Houston Thyroid & Endocrine Specialists was listed on the N0n ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-09-30T00:00:00Z",
      "date_modified": "2026-09-30T00:00:00Z",
      "tags": [
        "EMERGING",
        "Healthcare",
        "extortion",
        "ransomware-claim",
        "n0n",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-nishiyamato-academy.html",
      "url": "https://securityincident.net/incidents/2026-09-nishiyamato-academy.html",
      "title": "[CONFIRMED] Nishiyamato Academy — State of California Department of Justice data breach disclosure notice filed by Nishiyamato Academy.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> nishiyamatoacademy.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Nishiyamato Academy.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-30 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630609\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-nishiyamato-academy.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Nishiyamato Academy.",
      "date_published": "2026-09-30T00:00:00Z",
      "date_modified": "2026-09-30T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-procamps.html",
      "url": "https://securityincident.net/incidents/2026-09-procamps.html",
      "title": "[CONFIRMED] ProCamps — State of California Department of Justice data breach disclosure notice filed by ProCamps.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> procamps.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by ProCamps.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-30 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630604\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-procamps.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by ProCamps.",
      "date_published": "2026-09-30T00:00:00Z",
      "date_modified": "2026-09-30T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.8,
        "percent": 80,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-summit-electric-supply.html",
      "url": "https://securityincident.net/incidents/2026-09-summit-electric-supply.html",
      "title": "[EMERGING] Summit Electric Supply — Summit Electric Supply was listed on the Vexy Ransomware ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> summit.com<br/>\n<strong>Industry:</strong> Energy &amp; Utilities<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Vexy Ransomware<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Summit Electric Supply was listed on the Vexy Ransomware ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-30 20:55 UTC</strong> [UNVERIFIED CLAIM]: Summit Electric Supply Listed on Vexy Ransomware Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/U3VtbWl0IEVsZWN0cmljIFN1cHBseUBWZXh5IFJhbnNvbXdhcmU=\">Vexy Ransomware Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-summit-electric-supply.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Summit Electric Supply was listed on the Vexy Ransomware ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.",
      "date_published": "2026-09-30T00:00:00Z",
      "date_modified": "2026-09-30T00:00:00Z",
      "tags": [
        "EMERGING",
        "Energy & Utilities",
        "extortion",
        "ransomware-claim",
        "vexy ransomware",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-wolfusofsky-de.html",
      "url": "https://securityincident.net/incidents/2026-09-wolfusofsky-de.html",
      "title": "[EMERGING] wolfusofsky.de — wolfusofsky.de was listed on the Safepay ransomware extortion leak portal. The group provides a broad range of construction and infrastructure services to public and private clients in Rhineland-Palatinate, Saarland, neighboring …",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> wolfusofsky.de<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Safepay<br/>\n<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>wolfusofsky.de was listed on the Safepay ransomware extortion leak portal. The group provides a broad range of construction and infrastructure services to public and private clients in Rhineland-Palatinate, Saarland, neighboring …</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-30 20:11 UTC</strong> [UNVERIFIED CLAIM]: wolfusofsky.de Listed on Safepay Ransomware Extortion Portal (<a href=\"https://www.ransomware.live/id/d29sZnVzb2Zza3kuZGVAc2FmZXBheQ==\">Safepay Ransomware Leak Site Claim</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-wolfusofsky-de.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "wolfusofsky.de was listed on the Safepay ransomware extortion leak portal. The group provides a broad range of construction and infrastructure services to public and private clients in Rhineland-Palatinate, Saarland, neighboring …",
      "date_published": "2026-09-30T00:00:00Z",
      "date_modified": "2026-09-30T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology & Commercial",
        "extortion",
        "ransomware-claim",
        "safepay",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.09,
        "percent": 9,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-challenge-financial-services.html",
      "url": "https://securityincident.net/incidents/2026-09-challenge-financial-services.html",
      "title": "[CONFIRMED] Challenge Financial Services — State of California Department of Justice data breach disclosure notice filed by Challenge Financial Services.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> challengefinancialservices.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Challenge Financial Services.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630536\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-challenge-financial-services.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Challenge Financial Services.",
      "date_published": "2026-09-29T00:00:00Z",
      "date_modified": "2026-09-29T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.68,
        "percent": 68,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-city-of-mcminnville.html",
      "url": "https://securityincident.net/incidents/2026-09-city-of-mcminnville.html",
      "title": "[CONFIRMED] City of McMinnville — State of California Department of Justice data breach disclosure notice filed by City of McMinnville.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> cityofmcminnville.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by City of McMinnville.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630525\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-city-of-mcminnville.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by City of McMinnville.",
      "date_published": "2026-09-29T00:00:00Z",
      "date_modified": "2026-09-29T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.68,
        "percent": 68,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-dodo-pizza.html",
      "url": "https://securityincident.net/incidents/2026-09-dodo-pizza.html",
      "title": "[CONFIRMED] Dodo Brands (Dodo Pizza) — Andrey Mihayloff reports: Dodo Pizza has confirmed a cyberattack on its IT systems, admitting that attackers may have accessed personal data of a portion of its customer base. The company reported the breach to Roskomnadzor and stated that access...",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> dodopizza.com<br/>\n<strong>Industry:</strong> Retail &amp; Consumer Goods<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 64% (CONFIRMED BY TARGET)<br/>\n</p>\n<p>Andrey Mihayloff reports: Dodo Pizza has confirmed a cyberattack on its IT systems, admitting that attackers may have accessed personal data of a portion of its customer base. The company reported the breach to Roskomnadzor and stated that access...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-29 12:43 UTC</strong> [CONFIRMED BY TARGET]: Russian pizza restaurant chain confirms cyberattack: Hackers claim 68 million users exposed (<a href=\"https://databreaches.net/2026/09/29/russian-pizza-restaurant-chain-confirms-cyberattack-hackers-claim-68-million-users-exposed/\">DataBreaches.net Report</a>)</li>\n<li><strong>2026-09-29 12:34 UTC</strong> [CONFIRMED BY TARGET]: Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims (<a href=\"https://therecord.media/russian-pizza-chain-dodo-confirms-data-breach\">The Record by Recorded Future Intelligence Notice</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-dodo-pizza.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Andrey Mihayloff reports: Dodo Pizza has confirmed a cyberattack on its IT systems, admitting that attackers may have accessed personal data of a portion of its customer base. The company reported the breach to Roskomnadzor and stated that access...",
      "date_published": "2026-09-29T00:00:00Z",
      "date_modified": "2026-09-29T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Retail & Consumer Goods",
        "investigative",
        "developing"
      ],
      "_open_weights": {
        "score": 0.64,
        "percent": 64,
        "top_tier": "CONFIRMED BY TARGET",
        "base_weight": 0.5,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-dutch-police-politie.html",
      "url": "https://securityincident.net/incidents/2026-09-dutch-police-politie.html",
      "title": "[DEVELOPING] Dutch Police (Politie) — Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining Sh...",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> politie.nl<br/>\n<strong>Industry:</strong> Government &amp; Law Enforcement<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Exfiltration<br/>\n<strong>Threat Actor:</strong> ShinyHunters<br/>\n<strong>Affected Population:</strong> 65,000 records<br/>\n<strong>Open Weights Confidence:</strong> 62% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect&apos;s arrest, remaining Sh...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-28 15:08 UTC</strong> [INDEPENDENT VERIFICATION]: Dutch Police Arrest &apos;Reformed&apos; Hacker in Shiny Hunters Investigation (<a href=\"https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/\">Krebs on Security Report</a>)</li>\n<li><strong>2026-09-29 11:01 UTC</strong> [INDEPENDENT VERIFICATION]: Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation (<a href=\"https://www.securityweek.com/dutch-police-arrest-convicted-hacker-in-shinyhunters-investigation/\">SecurityWeek Intelligence Notice</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-dutch-police-politie.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining Sh...",
      "date_published": "2026-09-28T00:00:00Z",
      "date_modified": "2026-09-29T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Government & Law Enforcement",
        "investigative",
        "developing"
      ],
      "_open_weights": {
        "score": 0.62,
        "percent": 62,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-lamb-weston.html",
      "url": "https://securityincident.net/incidents/2026-09-lamb-weston.html",
      "title": "[CONFIRMED] Lamb Weston — Oregon Department of Justice formal data breach disclosure notice filed by Lamb Weston affecting 7,175 Oregon residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> lambweston.com<br/>\n<strong>Industry:</strong> Food &amp; Agriculture<br/>\n<strong>Incident Type:</strong> Data Breach<br/>\n<strong>Affected Population:</strong> 7,175 records<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Oregon Department of Justice formal data breach disclosure notice filed by Lamb Weston affecting 7,175 Oregon residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: Oregon Department of Justice Breach Notice (<a href=\"https://justice.oregon.gov/consumer/databreach/\">Oregon Department of Justice Breach Notice</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-lamb-weston.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Oregon Department of Justice formal data breach disclosure notice filed by Lamb Weston affecting 7,175 Oregon residents.",
      "date_published": "2026-09-29T00:00:00Z",
      "date_modified": "2026-09-29T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Food & Agriculture",
        "regulatory",
        "state-ag",
        "oregon",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-poppins-payroll-company.html",
      "url": "https://securityincident.net/incidents/2026-09-poppins-payroll-company.html",
      "title": "[CONFIRMED] Poppins Payroll Company — State of California Department of Justice data breach disclosure notice filed by Poppins Payroll Company.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> poppinspayrollcompany.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Poppins Payroll Company.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630541\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-poppins-payroll-company.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Poppins Payroll Company.",
      "date_published": "2026-09-29T00:00:00Z",
      "date_modified": "2026-09-29T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.68,
        "percent": 68,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-at-t.html",
      "url": "https://securityincident.net/incidents/2026-09-at-t.html",
      "title": "[DEVELOPING] AT&T — A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered...",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> att.com<br/>\n<strong>Industry:</strong> Telecommunications<br/>\n<strong>Incident Type:</strong> Third-Party Cloud Compromise<br/>\n<strong>Threat Actor:</strong> ShinyHunters / UNC5537<br/>\n<strong>Affected Population:</strong> 110,000,000 records<br/>\n<strong>Open Weights Confidence:</strong> 62% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&amp;T customers in 2024 was sentenced to 70 months in federal prison today and ordered...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-25 21:44 UTC</strong> [INDEPENDENT VERIFICATION]: U.S. Soldier Gets 70 Months in Prison for AT&amp;T, Verizon Extortions (<a href=\"https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/\">Krebs on Security Report</a>)</li>\n<li><strong>2026-09-28 12:36 UTC</strong> [INDEPENDENT VERIFICATION]: Prison Sentence for Former US Soldier Who Hacked AT&amp;T and Verizon (<a href=\"https://www.securityweek.com/prison-sentence-for-former-us-soldier-who-hacked-att-and-verizon/\">SecurityWeek Intelligence Notice</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-at-t.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered...",
      "date_published": "2026-09-25T00:00:00Z",
      "date_modified": "2026-09-28T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Telecommunications",
        "investigative",
        "developing"
      ],
      "_open_weights": {
        "score": 0.62,
        "percent": 62,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-hogan-lovells.html",
      "url": "https://securityincident.net/incidents/2026-09-hogan-lovells.html",
      "title": "[DEVELOPING] Hogan Lovells — Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG's recent attacks on Hogan Lovells Cadwalader. Yes, that's \"attacks,\" plural. When New York City's oldest law firm, C...",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> hoganlovells.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Silent Ransom Group<br/>\n<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG&apos;s recent attacks on Hogan Lovells Cadwalader. Yes, that&apos;s &quot;attacks,&quot; plural. When New York City&apos;s oldest law firm, C...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-28 17:07 UTC</strong> [INDEPENDENT VERIFICATION]: Hogan Lovells Cadwalader hacked by Silent Ransom Group; re-attacked after they wouldn&apos;t pay (<a href=\"https://databreaches.net/2026/09/28/hogan-lovells-cadwalader-hacked-by-silent-ransom-group-re-attacked-after-they-wouldnt-pay/\">DataBreaches.net Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-hogan-lovells.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG's recent attacks on Hogan Lovells Cadwalader. Yes, that's \"attacks,\" plural. When New York City's oldest law firm, C...",
      "date_published": "2026-09-28T00:00:00Z",
      "date_modified": "2026-09-28T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Legal",
        "investigative",
        "developing"
      ],
      "_open_weights": {
        "score": 0.39,
        "percent": 39,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-keio-corp.html",
      "url": "https://securityincident.net/incidents/2026-09-keio-corp.html",
      "title": "[CONFIRMED] Keio Corporation — Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> keio.co.jp<br/>\n<strong>Industry:</strong> Transportation &amp; Logistics<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 57% (CONFIRMED BY TARGET)<br/>\n</p>\n<p>Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-28 20:56 UTC</strong> [CONFIRMED BY TARGET]: Japan&apos;s Keio confirms ransomware attack disrupted business systems (<a href=\"https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/\">BleepingComputer Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-keio-corp.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]",
      "date_published": "2026-09-28T00:00:00Z",
      "date_modified": "2026-09-28T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Transportation & Logistics",
        "threat-intel",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.57,
        "percent": 57,
        "top_tier": "CONFIRMED BY TARGET",
        "base_weight": 0.5,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-san-bernardino-county-on-behal.html",
      "url": "https://securityincident.net/incidents/2026-09-san-bernardino-county-on-behal.html",
      "title": "[CONFIRMED] San Bernardino County on behalf of Arrowhead Regional Medical Center — State of California Department of Justice data breach disclosure notice filed by San Bernardino County on behalf of Arrowhead Regional Medical Center.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> sanbernardinocountyonbehal.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by San Bernardino County on behalf of Arrowhead Regional Medical Center.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-28 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630484\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-san-bernardino-county-on-behal.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by San Bernardino County on behalf of Arrowhead Regional Medical Center.",
      "date_published": "2026-09-28T00:00:00Z",
      "date_modified": "2026-09-28T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.68,
        "percent": 68,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-times-car.html",
      "url": "https://securityincident.net/incidents/2026-09-times-car.html",
      "title": "[CONFIRMED] Times Car — Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> timescar.jp<br/>\n<strong>Industry:</strong> Transportation &amp; Logistics<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 57% (CONFIRMED BY TARGET)<br/>\n</p>\n<p>Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-28 20:31 UTC</strong> [CONFIRMED BY TARGET]: Times Car confirms data breach affecting 6.6 million user accounts (<a href=\"https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/\">BleepingComputer Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-times-car.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]",
      "date_published": "2026-09-28T00:00:00Z",
      "date_modified": "2026-09-28T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Transportation & Logistics",
        "threat-intel",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.57,
        "percent": 57,
        "top_tier": "CONFIRMED BY TARGET",
        "base_weight": 0.5,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-upbound-group.html",
      "url": "https://securityincident.net/incidents/2026-07-upbound-group.html",
      "title": "[CONFIRMED] Upbound Group — Upbound Group disclosed unauthorized acquisition of customer records and internal documents subsequently leveraged in fraudulent attempts.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> upbound.com<br/>\n<strong>Industry:</strong> Retail &amp; Consumer Goods<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Affected Population:</strong> 76,327 records<br/>\n<strong>Open Weights Confidence:</strong> 95% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Upbound Group disclosed unauthorized acquisition of customer records and internal documents subsequently leveraged in fraudulent attempts.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-22 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 8.01 Disclosure: Upbound Group reveals unauthorized acquisition of non-sensitive customer records and corporate documents. (<a href=\"https://www.sec.gov/Archives/edgar/data/933036/000119312526310605/0001193125-26-310605-index.htm\">SEC EDGAR 8-K Item 8.01 (Adsh 0001193125-26-310605)</a>)</li>\n<li><strong>2026-09-27 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630390\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-upbound-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Upbound Group disclosed unauthorized acquisition of customer records and internal documents subsequently leveraged in fraudulent attempts.",
      "date_published": "2026-07-22T00:00:00Z",
      "date_modified": "2026-09-27T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Retail & Consumer Goods",
        "regulatory",
        "sec-8k",
        "retail",
        "confirmed",
        "state-ag",
        "california"
      ],
      "_open_weights": {
        "score": 0.95,
        "percent": 95,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-nhs-england.html",
      "url": "https://securityincident.net/incidents/2026-09-nhs-england.html",
      "title": "[DEVELOPING] NHS England — Tom McArthur and Louise Parry report: Ten NHS staff have been removed from duty or suspended after a data breach involving the digital medical records of three-year-old Noah Woods. Launching an \"urgent\" investigation, Dr Martin Mansfield, deputy c...",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> nhs.uk<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> Qilin<br/>\n<strong>Affected Population:</strong> 3,000,000 records<br/>\n<strong>Open Weights Confidence:</strong> 55% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Tom McArthur and Louise Parry report: Ten NHS staff have been removed from duty or suspended after a data breach involving the digital medical records of three-year-old Noah Woods. Launching an &quot;urgent&quot; investigation, Dr Martin Mansfield, deputy c...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-27 13:22 UTC</strong> [INDEPENDENT VERIFICATION]: UK: Ten NHS staff removed over Noah Woods data breach (<a href=\"https://databreaches.net/2026/09/27/uk-ten-nhs-staff-removed-over-noah-woods-data-breach/\">DataBreaches.net Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-nhs-england.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Tom McArthur and Louise Parry report: Ten NHS staff have been removed from duty or suspended after a data breach involving the digital medical records of three-year-old Noah Woods. Launching an \"urgent\" investigation, Dr Martin Mansfield, deputy c...",
      "date_published": "2026-09-27T00:00:00Z",
      "date_modified": "2026-09-27T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Healthcare",
        "investigative",
        "developing"
      ],
      "_open_weights": {
        "score": 0.55,
        "percent": 55,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-cloudflare.html",
      "url": "https://securityincident.net/incidents/2026-09-cloudflare.html",
      "title": "[DEVELOPING] Cloudflare — The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which desc...",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> cloudflare.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which desc...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-26 18:22 UTC</strong> [INDEPENDENT VERIFICATION]: Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials (<a href=\"https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html\">The Hacker News Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-cloudflare.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which desc...",
      "date_published": "2026-09-26T00:00:00Z",
      "date_modified": "2026-09-26T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "threat-intel",
        "developing"
      ],
      "_open_weights": {
        "score": 0.39,
        "percent": 39,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-labcorp.html",
      "url": "https://securityincident.net/incidents/2026-09-labcorp.html",
      "title": "[DEVELOPING] Labcorp — Suzanne Smiley reports another update on litigation stemming from the American Medical Collection Agency breach. A bipartisan coalition of 44 state attorneys general on Thursday announced that they settled a lawsuit against Labcorp in exchange for...",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> labcorp.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Unauthorized Cloud Access<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Suzanne Smiley reports another update on litigation stemming from the American Medical Collection Agency breach. A bipartisan coalition of 44 state attorneys general on Thursday announced that they settled a lawsuit against Labcorp in exchange for...</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-26 10:49 UTC</strong> [INDEPENDENT VERIFICATION]: Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings (<a href=\"https://databreaches.net/2026/09/26/labcorp-to-overhaul-data-security-practices-pay-2-3-million-fine-for-cybersecurity-failings/\">DataBreaches.net Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-labcorp.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Suzanne Smiley reports another update on litigation stemming from the American Medical Collection Agency breach. A bipartisan coalition of 44 state attorneys general on Thursday announced that they settled a lawsuit against Labcorp in exchange for...",
      "date_published": "2026-09-26T00:00:00Z",
      "date_modified": "2026-09-26T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Healthcare",
        "investigative",
        "developing"
      ],
      "_open_weights": {
        "score": 0.39,
        "percent": 39,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-financial-administrative-suppo.html",
      "url": "https://securityincident.net/incidents/2026-09-financial-administrative-suppo.html",
      "title": "[CONFIRMED] Financial Administrative Support Services — State of California Department of Justice data breach disclosure notice filed by Financial Administrative Support Services.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> financialadministrativesuppo.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Financial Administrative Support Services.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630351\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-financial-administrative-suppo.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Financial Administrative Support Services.",
      "date_published": "2026-09-25T00:00:00Z",
      "date_modified": "2026-09-25T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.68,
        "percent": 68,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-gallagher-transport-international.html",
      "url": "https://securityincident.net/incidents/2026-09-gallagher-transport-international.html",
      "title": "[CONFIRMED] Gallagher Transport International — State of California Department of Justice data breach disclosure notice filed by Gallagher Transport International.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> gallaghertransport.com<br/>\n<strong>Industry:</strong> Transportation &amp; Logistics<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Gallagher Transport International.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630300\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-gallagher-transport-international.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Gallagher Transport International.",
      "date_published": "2026-09-25T00:00:00Z",
      "date_modified": "2026-09-25T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Transportation & Logistics",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-kings-united-way.html",
      "url": "https://securityincident.net/incidents/2026-09-kings-united-way.html",
      "title": "[CONFIRMED] Kings United Way — State of California Department of Justice data breach disclosure notice filed by Kings United Way.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> kingsunitedway.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Kings United Way.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630314\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-kings-united-way.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Kings United Way.",
      "date_published": "2026-09-25T00:00:00Z",
      "date_modified": "2026-09-25T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-medimpact-healthcare-systems.html",
      "url": "https://securityincident.net/incidents/2026-09-medimpact-healthcare-systems.html",
      "title": "[CONFIRMED] MedImpact Healthcare Systems — State of California Department of Justice data breach disclosure notice filed by MedImpact Healthcare Systems.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> medimpacthealthcaresystems.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Affected Population:</strong> 327,082 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by MedImpact Healthcare Systems.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630343\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-medimpact-healthcare-systems.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by MedImpact Healthcare Systems.",
      "date_published": "2026-09-25T00:00:00Z",
      "date_modified": "2026-09-25T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-onemain-financial-group.html",
      "url": "https://securityincident.net/incidents/2026-09-onemain-financial-group.html",
      "title": "[CONFIRMED] OneMain Financial Group — State of California Department of Justice data breach disclosure notice filed by OneMain Financial Group.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> onemainfinancialgroup.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Credential Stuffing &amp; Account Takeover<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 42,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by OneMain Financial Group.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630345\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-onemain-financial-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by OneMain Financial Group.",
      "date_published": "2026-09-25T00:00:00Z",
      "date_modified": "2026-09-25T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-5star-life-insurance-company.html",
      "url": "https://securityincident.net/incidents/2026-09-5star-life-insurance-company.html",
      "title": "[CONFIRMED] 5Star Life Insurance Company — State of California Department of Justice data breach disclosure notice filed by 5Star Life Insurance Company.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> 5starlifeinsurancecompany.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by 5Star Life Insurance Company.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630231\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-5star-life-insurance-company.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by 5Star Life Insurance Company.",
      "date_published": "2026-09-24T00:00:00Z",
      "date_modified": "2026-09-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-blanchard-training-development.html",
      "url": "https://securityincident.net/incidents/2026-09-blanchard-training-development.html",
      "title": "[CONFIRMED] Blanchard Training & Development — State of California Department of Justice data breach disclosure notice filed by Blanchard Training & Development.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> blanchardtrainingdevelopment.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Blanchard Training &amp; Development.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630239\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-blanchard-training-development.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Blanchard Training & Development.",
      "date_published": "2026-09-24T00:00:00Z",
      "date_modified": "2026-09-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-hilt-trust-2020-a-and-its-unde.html",
      "url": "https://securityincident.net/incidents/2026-09-hilt-trust-2020-a-and-its-unde.html",
      "title": "[CONFIRMED] HILT-Trust 2020-A and its underlying trusts and affiliates — State of California Department of Justice data breach disclosure notice filed by HILT-Trust 2020-A and its underlying trusts and affiliates.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> hilttrust2020aanditsunde.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by HILT-Trust 2020-A and its underlying trusts and affiliates.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630200\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-hilt-trust-2020-a-and-its-unde.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by HILT-Trust 2020-A and its underlying trusts and affiliates.",
      "date_published": "2026-09-24T00:00:00Z",
      "date_modified": "2026-09-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.68,
        "percent": 68,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-nse-insurance-agencies.html",
      "url": "https://securityincident.net/incidents/2026-09-nse-insurance-agencies.html",
      "title": "[CONFIRMED] NSE Insurance Agencies — State of California Department of Justice data breach disclosure notice filed by NSE Insurance Agencies.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> nseinsuranceagencies.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by NSE Insurance Agencies.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630194\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-nse-insurance-agencies.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by NSE Insurance Agencies.",
      "date_published": "2026-09-24T00:00:00Z",
      "date_modified": "2026-09-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-pena-and-bromberg.html",
      "url": "https://securityincident.net/incidents/2026-09-pena-and-bromberg.html",
      "title": "[CONFIRMED] Peña and Bromberg — State of California Department of Justice data breach disclosure notice filed by Peña and Bromberg.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> penabromberg.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Peña and Bromberg.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630232\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-pena-and-bromberg.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Peña and Bromberg.",
      "date_published": "2026-09-24T00:00:00Z",
      "date_modified": "2026-09-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-astrana-health.html",
      "url": "https://securityincident.net/incidents/2026-09-astrana-health.html",
      "title": "[CONFIRMED] Astrana Health — Healthcare management company Astrana Health filed Form 8-K Item 1.05 disclosing a cybersecurity intrusion at its Astrana Health Management subsidiary.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> astranahealth.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> RansomHub<br/>\n<strong>Affected Population:</strong> 92,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Healthcare management company Astrana Health filed Form 8-K Item 1.05 disclosing a cybersecurity intrusion at its Astrana Health Management subsidiary.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-23 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Astrana Health discloses cybersecurity incident impacting management subsidiary environments. (<a href=\"https://www.sec.gov/Archives/edgar/data/1083446/000110465926109813/0001104659-26-109813-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001104659-26-109813)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-astrana-health.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Healthcare management company Astrana Health filed Form 8-K Item 1.05 disclosing a cybersecurity intrusion at its Astrana Health Management subsidiary.",
      "date_published": "2026-09-23T00:00:00Z",
      "date_modified": "2026-09-23T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "sec-8k",
        "healthcare",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-fairwinds-credit-union.html",
      "url": "https://securityincident.net/incidents/2026-09-fairwinds-credit-union.html",
      "title": "[CONFIRMED] Fairwinds Credit Union — State of California Department of Justice data breach disclosure notice filed by Fairwinds Credit Union.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> fairwindscreditunion.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Third-Party Vendor Cloud Compromise<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 65,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Fairwinds Credit Union.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-23 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630165\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-fairwinds-credit-union.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Fairwinds Credit Union.",
      "date_published": "2026-09-23T00:00:00Z",
      "date_modified": "2026-09-23T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-modoc-medical-center.html",
      "url": "https://securityincident.net/incidents/2026-09-modoc-medical-center.html",
      "title": "[CONFIRMED] Modoc Medical Center — State of California Department of Justice data breach disclosure notice filed by Modoc Medical Center.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> modocmedicalcenter.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Ransomware &amp; Network Intrusion<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Affected Population:</strong> 8,400 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Modoc Medical Center.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-22 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630126\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-modoc-medical-center.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Modoc Medical Center.",
      "date_published": "2026-09-22T00:00:00Z",
      "date_modified": "2026-09-22T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-ethan-conrad-properties.html",
      "url": "https://securityincident.net/incidents/2026-09-ethan-conrad-properties.html",
      "title": "[CONFIRMED] Ethan Conrad Properties — State of California Department of Justice data breach disclosure notice filed by Ethan Conrad Properties.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> ethanconradproperties.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Ethan Conrad Properties.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630085\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-ethan-conrad-properties.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Ethan Conrad Properties.",
      "date_published": "2026-09-21T00:00:00Z",
      "date_modified": "2026-09-21T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-friesen-group.html",
      "url": "https://securityincident.net/incidents/2026-09-friesen-group.html",
      "title": "[CONFIRMED] Friesen Group — State of California Department of Justice data breach disclosure notice filed by Friesen Group.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> friesengroup.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Friesen Group.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630087\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-friesen-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Friesen Group.",
      "date_published": "2026-09-21T00:00:00Z",
      "date_modified": "2026-09-21T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-fun-for-less-tours.html",
      "url": "https://securityincident.net/incidents/2026-09-fun-for-less-tours.html",
      "title": "[CONFIRMED] Fun For Less Tours — State of California Department of Justice data breach disclosure notice filed by Fun For Less Tours.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> funforlesstours.com<br/>\n<strong>Industry:</strong> Retail &amp; Consumer Goods<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Fun For Less Tours.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630062\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-fun-for-less-tours.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Fun For Less Tours.",
      "date_published": "2026-09-21T00:00:00Z",
      "date_modified": "2026-09-21T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Retail & Consumer Goods",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-ridgeway-pharmacy.html",
      "url": "https://securityincident.net/incidents/2026-09-ridgeway-pharmacy.html",
      "title": "[CONFIRMED] Ridgeway Pharmacy — State of California Department of Justice data breach disclosure notice filed by Ridgeway Pharmacy.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> ridgewaypharmacy.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Ridgeway Pharmacy.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630056\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-ridgeway-pharmacy.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Ridgeway Pharmacy.",
      "date_published": "2026-09-21T00:00:00Z",
      "date_modified": "2026-09-21T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-united-underwriters.html",
      "url": "https://securityincident.net/incidents/2026-09-united-underwriters.html",
      "title": "[CONFIRMED] United Underwriters — State of California Department of Justice data breach disclosure notice filed by United Underwriters.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> unitedunderwriters.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by United Underwriters.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-630066\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-united-underwriters.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by United Underwriters.",
      "date_published": "2026-09-21T00:00:00Z",
      "date_modified": "2026-09-21T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-los-angeles-city-attorney.html",
      "url": "https://securityincident.net/incidents/2026-09-los-angeles-city-attorney.html",
      "title": "[CONFIRMED] Office of the Los Angeles City Attorney — State of California Department of Justice data breach disclosure notice filed by The Office of the Los Angeles City.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> lacityattorney.org<br/>\n<strong>Industry:</strong> Government &amp; Legal<br/>\n<strong>Incident Type:</strong> File Transfer Server Compromise<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 11,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by The Office of the Los Angeles City.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-18 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629957\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-los-angeles-city-attorney.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by The Office of the Los Angeles City.",
      "date_published": "2026-09-18T00:00:00Z",
      "date_modified": "2026-09-18T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Legal",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-opportune.html",
      "url": "https://securityincident.net/incidents/2026-09-opportune.html",
      "title": "[CONFIRMED] Opportune — State of California Department of Justice data breach disclosure notice filed by Opportune.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> opportune.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Opportune.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-18 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629948\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-opportune.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Opportune.",
      "date_published": "2026-09-18T00:00:00Z",
      "date_modified": "2026-09-18T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-seyfarth-shaw.html",
      "url": "https://securityincident.net/incidents/2026-09-seyfarth-shaw.html",
      "title": "[CONFIRMED] Seyfarth Shaw — State of California Department of Justice data breach disclosure notice filed by Seyfarth Shaw.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> seyfarthshaw.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Seyfarth Shaw.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-18 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629966\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-seyfarth-shaw.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Seyfarth Shaw.",
      "date_published": "2026-09-18T00:00:00Z",
      "date_modified": "2026-09-18T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-callondoc.html",
      "url": "https://securityincident.net/incidents/2026-09-callondoc.html",
      "title": "[CONFIRMED] CallonDoc — State of California Department of Justice data breach disclosure notice filed by CallonDoc.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> callondoc.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by CallonDoc.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-17 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629887\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-callondoc.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by CallonDoc.",
      "date_published": "2026-09-17T00:00:00Z",
      "date_modified": "2026-09-17T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-gyazo.html",
      "url": "https://securityincident.net/incidents/2026-09-gyazo.html",
      "title": "[CONFIRMED] Gyazo — Screen capture platform Gyazo suffered a major data breach exposing 23.62 million user account records and 490 million image metadata entries.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> gyazo.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 57% (CONFIRMED BY TARGET)<br/>\n</p>\n<p>Screen capture platform Gyazo suffered a major data breach exposing 23.62 million user account records and 490 million image metadata entries.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-17 14:00 UTC</strong> [CONFIRMED BY TARGET]: Gyazo confirms data breach affecting 23.62M user accounts and resets all session tokens and user API keys. (<a href=\"https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html\">The Hacker News Investigation Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-gyazo.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Screen capture platform Gyazo suffered a major data breach exposing 23.62 million user account records and 490 million image metadata entries.",
      "date_published": "2026-09-17T00:00:00Z",
      "date_modified": "2026-09-17T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "threat-intel",
        "credential-breach",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.57,
        "percent": 57,
        "top_tier": "CONFIRMED BY TARGET",
        "base_weight": 0.5,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-partnership-healthplan-california.html",
      "url": "https://securityincident.net/incidents/2026-09-partnership-healthplan-california.html",
      "title": "[CONFIRMED] Partnership HealthPlan of California — State of California Department of Justice data breach disclosure notice filed by Partnership HealthPlan of California.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> partnershiphp.net<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> Hive / Successor Affiliate<br/>\n<strong>Affected Population:</strong> 854,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Partnership HealthPlan of California.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-17 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629908\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-partnership-healthplan-california.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Partnership HealthPlan of California.",
      "date_published": "2026-09-17T00:00:00Z",
      "date_modified": "2026-09-17T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-alliance-environmental-group.html",
      "url": "https://securityincident.net/incidents/2026-09-alliance-environmental-group.html",
      "title": "[CONFIRMED] Alliance Environmental Group — State of California Department of Justice data breach disclosure notice filed by Alliance Environmental Group.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> allianceenvironmentalgroup.com<br/>\n<strong>Industry:</strong> Manufacturing &amp; Construction<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Alliance Environmental Group.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-15 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629776\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-alliance-environmental-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Alliance Environmental Group.",
      "date_published": "2026-09-15T00:00:00Z",
      "date_modified": "2026-09-15T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Manufacturing & Construction",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-leggett-platt-benefits.html",
      "url": "https://securityincident.net/incidents/2026-09-leggett-platt-benefits.html",
      "title": "[CONFIRMED] Leggett & Platt Employee Benefits Plan — State of California Department of Justice data breach disclosure notice filed by Leggett & Platt,  Employee Benefits Plan.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> leggett.com<br/>\n<strong>Industry:</strong> Manufacturing &amp; Construction<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Leggett &amp; Platt,  Employee Benefits Plan.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-15 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629789\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-leggett-platt-benefits.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Leggett & Platt,  Employee Benefits Plan.",
      "date_published": "2026-09-15T00:00:00Z",
      "date_modified": "2026-09-15T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Manufacturing & Construction",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-tarter-krinsky-drogin.html",
      "url": "https://securityincident.net/incidents/2026-09-tarter-krinsky-drogin.html",
      "title": "[CONFIRMED] Tarter Krinsky & Drogin — State of California Department of Justice data breach disclosure notice filed by Tarter Krinsky & Drogin.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> tarterkrinskydrogin.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Tarter Krinsky &amp; Drogin.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-15 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629786\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-tarter-krinsky-drogin.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Tarter Krinsky & Drogin.",
      "date_published": "2026-09-15T00:00:00Z",
      "date_modified": "2026-09-15T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-accela.html",
      "url": "https://securityincident.net/incidents/2026-09-accela.html",
      "title": "[CONFIRMED] Accela — State of California Department of Justice data breach disclosure notice filed by Accela.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> accela.com<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Cloud Misconfiguration &amp; Unauthorized Access<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 52,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Accela.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-14 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629676\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-accela.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Accela.",
      "date_published": "2026-09-14T00:00:00Z",
      "date_modified": "2026-09-14T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-cambridge-mercantile.html",
      "url": "https://securityincident.net/incidents/2026-09-cambridge-mercantile.html",
      "title": "[CONFIRMED] Cambridge Mercantile — State of California Department of Justice data breach disclosure notice filed by Cambridge Mercantile.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> cambridgemercantile.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Cambridge Mercantile.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-14 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629696\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-cambridge-mercantile.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Cambridge Mercantile.",
      "date_published": "2026-09-14T00:00:00Z",
      "date_modified": "2026-09-14T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-paradigm-healthcare-services.html",
      "url": "https://securityincident.net/incidents/2026-09-paradigm-healthcare-services.html",
      "title": "[CONFIRMED] Paradigm Healthcare Services — State of California Department of Justice data breach disclosure notice filed by Paradigm Healthcare Services.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> paradigmhealthcareservices.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Paradigm Healthcare Services.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-14 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629754\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-paradigm-healthcare-services.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Paradigm Healthcare Services.",
      "date_published": "2026-09-14T00:00:00Z",
      "date_modified": "2026-09-14T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-nutex-health.html",
      "url": "https://securityincident.net/incidents/2026-08-nutex-health.html",
      "title": "[CONFIRMED] Nutex Health — Nutex Health disclosed an unauthorized cybersecurity incident involving corporate data environments, triggering formal Item 1.05 notification.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> nutexhealth.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Nutex Health disclosed an unauthorized cybersecurity incident involving corporate data environments, triggering formal Item 1.05 notification.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-31 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Nutex Health confirms unauthorized data exfiltration following prior Item 8.01 investigation notice. (<a href=\"https://www.sec.gov/Archives/edgar/data/1479681/000162828026059602/0001628280-26-059602-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001628280-26-059602)</a>)</li>\n<li><strong>2026-09-11 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 8.01 Supplemental: Nutex Health provides containment verification and reports clinical operations remain fully operational. (<a href=\"https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/0001628280-26-061432-index.htm\">SEC EDGAR 8-K Item 8.01 (Adsh 0001628280-26-061432)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-nutex-health.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Nutex Health disclosed an unauthorized cybersecurity incident involving corporate data environments, triggering formal Item 1.05 notification.",
      "date_published": "2026-08-31T00:00:00Z",
      "date_modified": "2026-09-11T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "sec-8k",
        "healthcare",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-catalyst-physician-group.html",
      "url": "https://securityincident.net/incidents/2026-09-catalyst-physician-group.html",
      "title": "[CONFIRMED] Catalyst Physician Group — State of California Department of Justice data breach disclosure notice filed by Catalyst Physician Group.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> catalystphysiciangroup.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Catalyst Physician Group.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-11 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629605\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-catalyst-physician-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Catalyst Physician Group.",
      "date_published": "2026-09-11T00:00:00Z",
      "date_modified": "2026-09-11T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-cornerstone-staffing-solutions.html",
      "url": "https://securityincident.net/incidents/2026-09-cornerstone-staffing-solutions.html",
      "title": "[CONFIRMED] Cornerstone Staffing Solutions — State of California Department of Justice data breach disclosure notice filed by Cornerstone Staffing Solutions.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> cornerstonestaffingsolutions.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Cornerstone Staffing Solutions.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-11 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629595\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-09-11 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42777.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-cornerstone-staffing-solutions.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Cornerstone Staffing Solutions.",
      "date_published": "2026-09-11T00:00:00Z",
      "date_modified": "2026-09-11T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed",
        "washington"
      ],
      "_open_weights": {
        "score": 0.91,
        "percent": 91,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-suffolk-federal-credit-union.html",
      "url": "https://securityincident.net/incidents/2026-09-suffolk-federal-credit-union.html",
      "title": "[CONFIRMED] Suffolk Federal Credit Union — State of California Department of Justice data breach disclosure notice filed by Suffolk Federal Credit Union.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> suffolkfederalcreditunion.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Third-Party Service Provider Breach<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 28,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Suffolk Federal Credit Union.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-11 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629581\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-suffolk-federal-credit-union.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Suffolk Federal Credit Union.",
      "date_published": "2026-09-11T00:00:00Z",
      "date_modified": "2026-09-11T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-zhealth.html",
      "url": "https://securityincident.net/incidents/2026-09-zhealth.html",
      "title": "[CONFIRMED] zHealth — State of California Department of Justice data breach disclosure notice filed by zHealth.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> zhealth.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by zHealth.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-11 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629559\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-09-11 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42768.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-zhealth.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by zHealth.",
      "date_published": "2026-09-11T00:00:00Z",
      "date_modified": "2026-09-11T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "california",
        "confirmed",
        "washington"
      ],
      "_open_weights": {
        "score": 0.91,
        "percent": 91,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-quatrro-business-support.html",
      "url": "https://securityincident.net/incidents/2026-09-quatrro-business-support.html",
      "title": "[CONFIRMED] Quatrro Business Support Services — State of California Department of Justice data breach disclosure notice filed by Quatrro Business Support Services.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> quatrrobss.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Quatrro Business Support Services.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-09 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629483\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-09-09 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42741.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-quatrro-business-support.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Quatrro Business Support Services.",
      "date_published": "2026-09-09T00:00:00Z",
      "date_modified": "2026-09-09T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed",
        "washington"
      ],
      "_open_weights": {
        "score": 0.91,
        "percent": 91,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-boston-scientific.html",
      "url": "https://securityincident.net/incidents/2026-09-boston-scientific.html",
      "title": "[CONFIRMED] Boston Scientific — Medical manufacturer Boston Scientific Corporation filed Form 8-K Item 1.05 formalizing disclosure of an unauthorized intrusion into corporate IT environments.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> bostonscientific.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Unauthorized Network Intrusion<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Affected Population:</strong> 48,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Medical manufacturer Boston Scientific Corporation filed Form 8-K Item 1.05 formalizing disclosure of an unauthorized intrusion into corporate IT environments.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-08 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Boston Scientific formalizes disclosure of unauthorized access detected in August 2026. (<a href=\"https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/0000885725-26-000059-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0000885725-26-000059)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-boston-scientific.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Medical manufacturer Boston Scientific Corporation filed Form 8-K Item 1.05 formalizing disclosure of an unauthorized intrusion into corporate IT environments.",
      "date_published": "2026-09-08T00:00:00Z",
      "date_modified": "2026-09-08T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "sec-8k",
        "healthcare",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-hibbett-retail.html",
      "url": "https://securityincident.net/incidents/2026-09-hibbett-retail.html",
      "title": "[CONFIRMED] Hibbett Retail — State of California Department of Justice data breach disclosure notice filed by Hibbett Retail.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> hibbettretail.com<br/>\n<strong>Industry:</strong> Retail &amp; Consumer Goods<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Hibbett Retail.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-08 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629439\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-09-08 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42734.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-hibbett-retail.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Hibbett Retail.",
      "date_published": "2026-09-08T00:00:00Z",
      "date_modified": "2026-09-08T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Retail & Consumer Goods",
        "regulatory",
        "state-ag",
        "california",
        "confirmed",
        "washington"
      ],
      "_open_weights": {
        "score": 0.91,
        "percent": 91,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-june-2026-healthcare-data.html",
      "url": "https://securityincident.net/incidents/2026-09-june-2026-healthcare-data.html",
      "title": "[CONFIRMED] June 2026 Healthcare Data — Healthcare data breach disclosure submitted to federal regulators by June 2026 Healthcare Data.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> june2026healthcaredata.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Protected Health Information (PHI) Breach<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Healthcare data breach disclosure submitted to federal regulators by June 2026 Healthcare Data.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-07 15:00 UTC</strong> [CONFIRMED BY REGULATOR]: HHS OCR Healthcare Data Breach Disclosure: June 2026 Healthcare Data Breach Report (<a href=\"https://www.hipaajournal.com/june-2026-healthcare-data-breach-report/\">HHS OCR Regulatory Healthcare Breach Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-june-2026-healthcare-data.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Healthcare data breach disclosure submitted to federal regulators by June 2026 Healthcare Data.",
      "date_published": "2026-09-07T00:00:00Z",
      "date_modified": "2026-09-07T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "hhs-ocr",
        "healthcare",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-bimbo-bakeries-usa.html",
      "url": "https://securityincident.net/incidents/2026-09-bimbo-bakeries-usa.html",
      "title": "[CONFIRMED] Bimbo Bakeries USA — State of California Department of Justice data breach disclosure notice filed by Bimbo Bakeries USA.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> bimbobakeriesusa.com<br/>\n<strong>Industry:</strong> Manufacturing &amp; Consumer Goods<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> BlackSuit<br/>\n<strong>Affected Population:</strong> 18,500 records<br/>\n<strong>Open Weights Confidence:</strong> 95% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Bimbo Bakeries USA.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-04 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629294\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-09-04 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42696.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-bimbo-bakeries-usa.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Bimbo Bakeries USA.",
      "date_published": "2026-09-04T00:00:00Z",
      "date_modified": "2026-09-04T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Manufacturing & Consumer Goods",
        "regulatory",
        "state-ag",
        "california",
        "confirmed",
        "washington"
      ],
      "_open_weights": {
        "score": 0.95,
        "percent": 95,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-catalyst-brands.html",
      "url": "https://securityincident.net/incidents/2026-09-catalyst-brands.html",
      "title": "[CONFIRMED] Catalyst Brands — State of California Department of Justice data breach disclosure notice filed by Catalyst Brands.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> catalystbrands.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Catalyst Brands.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-04 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629314\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-09-04 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42702.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-catalyst-brands.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Catalyst Brands.",
      "date_published": "2026-09-04T00:00:00Z",
      "date_modified": "2026-09-04T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed",
        "washington"
      ],
      "_open_weights": {
        "score": 0.91,
        "percent": 91,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-elixir-medical.html",
      "url": "https://securityincident.net/incidents/2026-09-elixir-medical.html",
      "title": "[CONFIRMED] Elixir Medical — State of California Department of Justice data breach disclosure notice filed by Elixir Medical.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> elixirmedical.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Elixir Medical.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-04 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629325\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-elixir-medical.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Elixir Medical.",
      "date_published": "2026-09-04T00:00:00Z",
      "date_modified": "2026-09-04T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-lhc-group.html",
      "url": "https://securityincident.net/incidents/2026-09-lhc-group.html",
      "title": "[CONFIRMED] LHC Group — Washington State Attorney General formal data breach disclosure notice filed by LHC Group affecting 6602 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> lhcgroup.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by LHC Group affecting 6602 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-04 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42695.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-lhc-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by LHC Group affecting 6602 residents.",
      "date_published": "2026-09-04T00:00:00Z",
      "date_modified": "2026-09-04T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-virta-health-and-virta-medical.html",
      "url": "https://securityincident.net/incidents/2026-08-virta-health-and-virta-medical.html",
      "title": "[CONFIRMED] Virta Health  and Virta Medical — State of California Department of Justice data breach disclosure notice filed by Virta Health  and Virta Medical.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> virtahealthandvirtamedical.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Third-Party Cloud Repository Compromise<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 36,000 records<br/>\n<strong>Open Weights Confidence:</strong> 95% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Virta Health  and Virta Medical.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-31 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629093\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-09-03 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42682.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-virta-health-and-virta-medical.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Virta Health  and Virta Medical.",
      "date_published": "2026-08-31T00:00:00Z",
      "date_modified": "2026-09-03T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "california",
        "confirmed",
        "washington"
      ],
      "_open_weights": {
        "score": 0.95,
        "percent": 95,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-mogren-glessner-ahrens-p-s.html",
      "url": "https://securityincident.net/incidents/2026-09-mogren-glessner-ahrens-p-s.html",
      "title": "[CONFIRMED] Mogren, Glessner & Ahrens, P.S — Washington State Attorney General formal data breach disclosure notice filed by Mogren, Glessner & Ahrens, P.S affecting 1379 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> mogrenglessnerahrensps.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Mogren, Glessner &amp; Ahrens, P.S affecting 1379 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-03 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42675.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-mogren-glessner-ahrens-p-s.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Mogren, Glessner & Ahrens, P.S affecting 1379 residents.",
      "date_published": "2026-09-03T00:00:00Z",
      "date_modified": "2026-09-03T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-the-lighthouse-for-the-blind.html",
      "url": "https://securityincident.net/incidents/2026-09-the-lighthouse-for-the-blind.html",
      "title": "[CONFIRMED] The Lighthouse for the Blind — Washington State Attorney General formal data breach disclosure notice filed by The Lighthouse for the Blind affecting 520 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> thelighthousefortheblind.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by The Lighthouse for the Blind affecting 520 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-03 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42680.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-the-lighthouse-for-the-blind.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by The Lighthouse for the Blind affecting 520 residents.",
      "date_published": "2026-09-03T00:00:00Z",
      "date_modified": "2026-09-03T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-thomson-reuters.html",
      "url": "https://securityincident.net/incidents/2026-09-thomson-reuters.html",
      "title": "[DEVELOPING] Thomson Reuters — A vulnerability in Thomson Reuters court management software exposed sensitive sealed court filings and Social Security numbers across multiple jurisdictions.",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> thomsonreuters.com<br/>\n<strong>Industry:</strong> Legal Technology<br/>\n<strong>Incident Type:</strong> Zero-Day Vulnerability Exposure<br/>\n<strong>Threat Actor:</strong> Independent Researcher Disclosure<br/>\n<strong>Affected Population:</strong> 350,000 records<br/>\n<strong>Open Weights Confidence:</strong> 55% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>A vulnerability in Thomson Reuters court management software exposed sensitive sealed court filings and Social Security numbers across multiple jurisdictions.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-03 15:45 UTC</strong> [INDEPENDENT VERIFICATION]: Security researchers discover unauthorized exposure of sealed court records and PII in court software systems. (<a href=\"https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html\">The Hacker News Telemetry Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-thomson-reuters.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "A vulnerability in Thomson Reuters court management software exposed sensitive sealed court filings and Social Security numbers across multiple jurisdictions.",
      "date_published": "2026-09-03T00:00:00Z",
      "date_modified": "2026-09-03T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Legal Technology",
        "threat-intel",
        "legal",
        "court-systems",
        "developing"
      ],
      "_open_weights": {
        "score": 0.55,
        "percent": 55,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-fiesta-insurance-franchise.html",
      "url": "https://securityincident.net/incidents/2026-09-fiesta-insurance-franchise.html",
      "title": "[CONFIRMED] Fiesta Insurance Franchise — State of California Department of Justice data breach disclosure notice filed by Fiesta Insurance Franchise.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> fiestainsurancefranchise.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Fiesta Insurance Franchise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629220\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-fiesta-insurance-franchise.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Fiesta Insurance Franchise.",
      "date_published": "2026-09-02T00:00:00Z",
      "date_modified": "2026-09-02T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-fishbrain-ab.html",
      "url": "https://securityincident.net/incidents/2026-09-fishbrain-ab.html",
      "title": "[CONFIRMED] Fishbrain AB — State of California Department of Justice data breach disclosure notice filed by Fishbrain AB.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> fishbrainab.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Fishbrain AB.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629190\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-fishbrain-ab.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Fishbrain AB.",
      "date_published": "2026-09-02T00:00:00Z",
      "date_modified": "2026-09-02T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-humanedge.html",
      "url": "https://securityincident.net/incidents/2026-09-humanedge.html",
      "title": "[CONFIRMED] HumanEdge — State of California Department of Justice data breach disclosure notice filed by HumanEdge.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> humanedge.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by HumanEdge.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629213\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-humanedge.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by HumanEdge.",
      "date_published": "2026-09-02T00:00:00Z",
      "date_modified": "2026-09-02T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-knowledge-research-center.html",
      "url": "https://securityincident.net/incidents/2026-09-knowledge-research-center.html",
      "title": "[CONFIRMED] Knowledge Research Center — State of California Department of Justice data breach disclosure notice filed by Knowledge Research Center.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> knowledgeresearchcenter.com<br/>\n<strong>Industry:</strong> Education &amp; Research<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Knowledge Research Center.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629199\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-knowledge-research-center.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Knowledge Research Center.",
      "date_published": "2026-09-02T00:00:00Z",
      "date_modified": "2026-09-02T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Education & Research",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-see-s-candies.html",
      "url": "https://securityincident.net/incidents/2026-09-see-s-candies.html",
      "title": "[CONFIRMED] See’s Candies — State of California Department of Justice data breach disclosure notice filed by See’s Candies.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> seescandies.com<br/>\n<strong>Industry:</strong> Retail &amp; Consumer Goods<br/>\n<strong>Incident Type:</strong> E-commerce Skimming &amp; Credential Theft<br/>\n<strong>Threat Actor:</strong> Magecart / E-commerce Skimmer<br/>\n<strong>Affected Population:</strong> 12,500 records<br/>\n<strong>Open Weights Confidence:</strong> 95% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by See’s Candies.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629221\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n<li><strong>2026-09-02 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42672.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-see-s-candies.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by See’s Candies.",
      "date_published": "2026-09-02T00:00:00Z",
      "date_modified": "2026-09-02T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Retail & Consumer Goods",
        "regulatory",
        "state-ag",
        "california",
        "confirmed",
        "washington"
      ],
      "_open_weights": {
        "score": 0.95,
        "percent": 95,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-youlend-us.html",
      "url": "https://securityincident.net/incidents/2026-09-youlend-us.html",
      "title": "[CONFIRMED] YouLend US — State of California Department of Justice data breach disclosure notice filed by YouLend US.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> youlendus.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by YouLend US.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629202\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-youlend-us.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by YouLend US.",
      "date_published": "2026-09-02T00:00:00Z",
      "date_modified": "2026-09-02T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-demera-demera-cameron.html",
      "url": "https://securityincident.net/incidents/2026-09-demera-demera-cameron.html",
      "title": "[CONFIRMED] DeMera DeMera Cameron — State of California Department of Justice data breach disclosure notice filed by DeMera DeMera Cameron.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> demerademeracameron.com<br/>\n<strong>Industry:</strong> Government &amp; Public Sector<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by DeMera DeMera Cameron.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629160\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-demera-demera-cameron.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by DeMera DeMera Cameron.",
      "date_published": "2026-09-01T00:00:00Z",
      "date_modified": "2026-09-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Government & Public Sector",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-kaniksu-community-health.html",
      "url": "https://securityincident.net/incidents/2026-09-kaniksu-community-health.html",
      "title": "[CONFIRMED] Kaniksu Community Health — State of California Department of Justice data breach disclosure notice filed by Kaniksu Community Health.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> kaniksucommunityhealth.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 19,200 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Kaniksu Community Health.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629145\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-kaniksu-community-health.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Kaniksu Community Health.",
      "date_published": "2026-09-01T00:00:00Z",
      "date_modified": "2026-09-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-novocure.html",
      "url": "https://securityincident.net/incidents/2026-09-novocure.html",
      "title": "[CONFIRMED] NovoCure — Oncology medical device company NovoCure disclosed unauthorized access to subsidiary information systems detected in mid-August 2026.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> novocure.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Unauthorized Network Intrusion<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Affected Population:</strong> 18,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Oncology medical device company NovoCure disclosed unauthorized access to subsidiary information systems detected in mid-August 2026.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-01 16:45 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 8.01 Filing: NovoCure reports containment of unauthorized access to subsidiary IT systems with no impact on patient therapy. (<a href=\"https://www.sec.gov/Archives/edgar/data/1645113/000164511326000065/0001645113-26-000065-index.htm\">SEC EDGAR 8-K Item 8.01 (Adsh 0001645113-26-000065)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-novocure.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Oncology medical device company NovoCure disclosed unauthorized access to subsidiary information systems detected in mid-August 2026.",
      "date_published": "2026-09-01T00:00:00Z",
      "date_modified": "2026-09-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "sec-8k",
        "medical-device",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-09-park-dental-partners.html",
      "url": "https://securityincident.net/incidents/2026-09-park-dental-partners.html",
      "title": "[CONFIRMED] Park Dental Partners — Dental support organization Park Dental Partners filed Form 8-K Item 1.05 disclosing network disruption and forensic containment efforts.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> parkdental.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Ransomware<br/>\n<strong>Threat Actor:</strong> Akira<br/>\n<strong>Affected Population:</strong> 62,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Dental support organization Park Dental Partners filed Form 8-K Item 1.05 disclosing network disruption and forensic containment efforts.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-09-01 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Park Dental Partners confirms unauthorized network activity and initiates third-party forensic containment. (<a href=\"https://www.sec.gov/Archives/edgar/data/2069604/000110465926104300/0001104659-26-104300-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001104659-26-104300)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-09-park-dental-partners.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Dental support organization Park Dental Partners filed Form 8-K Item 1.05 disclosing network disruption and forensic containment efforts.",
      "date_published": "2026-09-01T00:00:00Z",
      "date_modified": "2026-09-01T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "sec-8k",
        "healthcare",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-berkeley-research-group.html",
      "url": "https://securityincident.net/incidents/2026-08-berkeley-research-group.html",
      "title": "[CONFIRMED] Berkeley Research Group — State of California Department of Justice data breach disclosure notice filed by Berkeley Research Group.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> berkeleyresearchgroup.com<br/>\n<strong>Industry:</strong> Education &amp; Research<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Berkeley Research Group.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-31 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-629096\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-berkeley-research-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Berkeley Research Group.",
      "date_published": "2026-08-31T00:00:00Z",
      "date_modified": "2026-08-31T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Education & Research",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-bennett-college.html",
      "url": "https://securityincident.net/incidents/2026-08-bennett-college.html",
      "title": "[CONFIRMED] Bennett College — State of California Department of Justice data breach disclosure notice filed by Bennett College.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> bennettcollege.com<br/>\n<strong>Industry:</strong> Education &amp; Research<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>State of California Department of Justice data breach disclosure notice filed by Bennett College.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-28 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href=\"https://oag.ca.gov/ecrime/databreach/reports/sb24-628990\">California Attorney General Data Breach Notice (SB-24)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-bennett-college.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "State of California Department of Justice data breach disclosure notice filed by Bennett College.",
      "date_published": "2026-08-28T00:00:00Z",
      "date_modified": "2026-08-28T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Education & Research",
        "regulatory",
        "state-ag",
        "california",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-rb-american-group.html",
      "url": "https://securityincident.net/incidents/2026-08-rb-american-group.html",
      "title": "[CONFIRMED] RB American Group — Washington State Attorney General formal data breach disclosure notice filed by RB American Group affecting 974 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> rbamericangroup.com<br/>\n<strong>Industry:</strong> Retail &amp; Food Services<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> RansomHub<br/>\n<strong>Affected Population:</strong> 98,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by RB American Group affecting 974 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-28 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42591.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-rb-american-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by RB American Group affecting 974 residents.",
      "date_published": "2026-08-28T00:00:00Z",
      "date_modified": "2026-08-28T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Retail & Food Services",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-greystar-real-estate-partners.html",
      "url": "https://securityincident.net/incidents/2026-08-greystar-real-estate-partners.html",
      "title": "[CONFIRMED] Greystar Real Estate Partners — Washington State Attorney General formal data breach disclosure notice filed by Greystar Real Estate Partners affecting 333 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> greystarrealestatepartners.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Greystar Real Estate Partners affecting 333 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-27 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42570.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-greystar-real-estate-partners.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Greystar Real Estate Partners affecting 333 residents.",
      "date_published": "2026-08-27T00:00:00Z",
      "date_modified": "2026-08-27T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-cascade-coffee.html",
      "url": "https://securityincident.net/incidents/2026-08-cascade-coffee.html",
      "title": "[CONFIRMED] Cascade Coffee — Washington State Attorney General formal data breach disclosure notice filed by Cascade Coffee affecting 610 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> cascadecoffee.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Cascade Coffee affecting 610 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-26 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42548.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-cascade-coffee.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Cascade Coffee affecting 610 residents.",
      "date_published": "2026-08-26T00:00:00Z",
      "date_modified": "2026-08-26T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-murfreesboro-medical-clinic.html",
      "url": "https://securityincident.net/incidents/2026-08-murfreesboro-medical-clinic.html",
      "title": "[CONFIRMED] Murfreesboro Medical Clinic — Washington State Attorney General formal data breach disclosure notice filed by Murfreesboro Medical Clinic affecting 845 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> murfreesboromedicalclinic.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Murfreesboro Medical Clinic affecting 845 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-26 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42565.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-murfreesboro-medical-clinic.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Murfreesboro Medical Clinic affecting 845 residents.",
      "date_published": "2026-08-26T00:00:00Z",
      "date_modified": "2026-08-26T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-news-uk-ireland-limited.html",
      "url": "https://securityincident.net/incidents/2026-08-news-uk-ireland-limited.html",
      "title": "[CONFIRMED] News  UK & Ireland Limited — Washington State Attorney General formal data breach disclosure notice filed by News  UK & Ireland Limited affecting 3304 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> newsukirelandlimited.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by News  UK &amp; Ireland Limited affecting 3304 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-26 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42560.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-news-uk-ireland-limited.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by News  UK & Ireland Limited affecting 3304 residents.",
      "date_published": "2026-08-26T00:00:00Z",
      "date_modified": "2026-08-26T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-pan-american-group.html",
      "url": "https://securityincident.net/incidents/2026-08-pan-american-group.html",
      "title": "[CONFIRMED] Pan American Group — Washington State Attorney General formal data breach disclosure notice filed by Pan American Group affecting 12309 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> panamericangroup.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Pan American Group affecting 12309 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-24 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42509.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-pan-american-group.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Pan American Group affecting 12309 residents.",
      "date_published": "2026-08-24T00:00:00Z",
      "date_modified": "2026-08-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-asos-us-sales.html",
      "url": "https://securityincident.net/incidents/2026-08-asos-us-sales.html",
      "title": "[CONFIRMED] ASOS US Sales — Washington State Attorney General formal data breach disclosure notice filed by ASOS US Sales affecting 1929 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> asosussales.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by ASOS US Sales affecting 1929 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-21 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42451.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-asos-us-sales.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by ASOS US Sales affecting 1929 residents.",
      "date_published": "2026-08-21T00:00:00Z",
      "date_modified": "2026-08-21T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-rockwood-retirement-communities.html",
      "url": "https://securityincident.net/incidents/2026-08-rockwood-retirement-communities.html",
      "title": "[CONFIRMED] Rockwood Retirement Communities — Washington State Attorney General formal data breach disclosure notice filed by Rockwood Retirement Communities affecting 7136 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> rockwoodretirement.org<br/>\n<strong>Industry:</strong> Healthcare &amp; Senior Living<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 6,200 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Rockwood Retirement Communities affecting 7136 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-20 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42441.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-rockwood-retirement-communities.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Rockwood Retirement Communities affecting 7136 residents.",
      "date_published": "2026-08-20T00:00:00Z",
      "date_modified": "2026-08-20T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare & Senior Living",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-southern-illinois-university.html",
      "url": "https://securityincident.net/incidents/2026-08-southern-illinois-university.html",
      "title": "[CONFIRMED] Southern Illinois University — Washington State Attorney General formal data breach disclosure notice filed by Southern Illinois University affecting 552 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> southernillinoisuniversity.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Southern Illinois University affecting 552 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-20 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42450.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-southern-illinois-university.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Southern Illinois University affecting 552 residents.",
      "date_published": "2026-08-20T00:00:00Z",
      "date_modified": "2026-08-20T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-nebraska-orthopaedic-center.html",
      "url": "https://securityincident.net/incidents/2026-08-nebraska-orthopaedic-center.html",
      "title": "[CONFIRMED] Nebraska Orthopaedic Center — Washington State Attorney General formal data breach disclosure notice filed by Nebraska Orthopaedic Center affecting 992 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> nebraskaorthopaediccenter.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Nebraska Orthopaedic Center affecting 992 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-19 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42412.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-nebraska-orthopaedic-center.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Nebraska Orthopaedic Center affecting 992 residents.",
      "date_published": "2026-08-19T00:00:00Z",
      "date_modified": "2026-08-19T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-apple-american-group-and-apple.html",
      "url": "https://securityincident.net/incidents/2026-08-apple-american-group-and-apple.html",
      "title": "[CONFIRMED] Apple American Group  and Apple American Group II — Washington State Attorney General formal data breach disclosure notice filed by Apple American Group  and Apple American Group II affecting 20653 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> appleamericangroupandapple.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Apple American Group  and Apple American Group II affecting 20653 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-18 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42400.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-apple-american-group-and-apple.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Apple American Group  and Apple American Group II affecting 20653 residents.",
      "date_published": "2026-08-18T00:00:00Z",
      "date_modified": "2026-08-18T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.68,
        "percent": 68,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-turner-construction-company.html",
      "url": "https://securityincident.net/incidents/2026-08-turner-construction-company.html",
      "title": "[CONFIRMED] Turner Construction Company — Washington State Attorney General formal data breach disclosure notice filed by Turner Construction Company affecting 3401 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> turnerconstructioncompany.com<br/>\n<strong>Industry:</strong> Manufacturing &amp; Construction<br/>\n<strong>Incident Type:</strong> Business Email Compromise (BEC)<br/>\n<strong>Threat Actor:</strong> Unattributed<br/>\n<strong>Affected Population:</strong> 34,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Turner Construction Company affecting 3401 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-18 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42399.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-turner-construction-company.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Turner Construction Company affecting 3401 residents.",
      "date_published": "2026-08-18T00:00:00Z",
      "date_modified": "2026-08-18T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Manufacturing & Construction",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-taxact.html",
      "url": "https://securityincident.net/incidents/2026-08-taxact.html",
      "title": "[DEVELOPING] TaxAct — Tax preparation provider TaxAct investigated unauthorized acquisition of over 2 million user records following sample leaks on illicit forums.",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> taxact.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Tax preparation provider TaxAct investigated unauthorized acquisition of over 2 million user records following sample leaks on illicit forums.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-17 13:15 UTC</strong> [INDEPENDENT VERIFICATION]: Threat actor leaks 450k tax preparation sample records, claiming access to 2 million customer files. (<a href=\"https://databreaches.net/2026/08/17/more-than-2-million-user-records-from-taxact-allegedly-acquired-450k-already-leaked/\">DataBreaches.net Telemetry Audit</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-taxact.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Tax preparation provider TaxAct investigated unauthorized acquisition of over 2 million user records following sample leaks on illicit forums.",
      "date_published": "2026-08-17T00:00:00Z",
      "date_modified": "2026-08-17T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "investigative",
        "tax-data",
        "leak-site",
        "developing"
      ],
      "_open_weights": {
        "score": 0.39,
        "percent": 39,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-fairlife.html",
      "url": "https://securityincident.net/incidents/2026-08-fairlife.html",
      "title": "[EMERGING] Fairlife — Dairy brand Fairlife suffered an Anubis ransomware cyberattack compromising 500 network hosts and resulting in 1 TB of exfiltrated operational data.",
      "content_html": "<p><strong>Status:</strong> EMERGING<br/>\n<strong>Target Domain:</strong> fairlife.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> Anubis<br/>\n<strong>Open Weights Confidence:</strong> 8% (UNVERIFIED CLAIM)<br/>\n</p>\n<p>Dairy brand Fairlife suffered an Anubis ransomware cyberattack compromising 500 network hosts and resulting in 1 TB of exfiltrated operational data.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-16 19:20 UTC</strong> [UNVERIFIED CLAIM]: Anubis ransomware gang publishes technical telemetry detailing compromise of 500 internal hosts at Fairlife. (<a href=\"https://databreaches.net/2026/08/16/500-hosts-1-tb-and-no-negotiation-anubis-provides-details-on-the-fairlife-attack/\">DataBreaches.net Extortion Watch</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-fairlife.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Dairy brand Fairlife suffered an Anubis ransomware cyberattack compromising 500 network hosts and resulting in 1 TB of exfiltrated operational data.",
      "date_published": "2026-08-16T00:00:00Z",
      "date_modified": "2026-08-16T00:00:00Z",
      "tags": [
        "EMERGING",
        "Technology & Commercial",
        "investigative",
        "ransomware",
        "industrial",
        "emerging"
      ],
      "_open_weights": {
        "score": 0.08,
        "percent": 8,
        "top_tier": "UNVERIFIED CLAIM",
        "base_weight": 0.06,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-adapthealth.html",
      "url": "https://securityincident.net/incidents/2026-07-adapthealth.html",
      "title": "[CONFIRMED] AdaptHealth — Healthcare solutions provider AdaptHealth Corp disclosed an external threat actor gained unauthorized access to internal systems and exfiltrated company data.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> adapthealth.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Healthcare solutions provider AdaptHealth Corp disclosed an external threat actor gained unauthorized access to internal systems and exfiltrated company data.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-02 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: AdaptHealth confirms threat actor breached company systems and exfiltrated files. (<a href=\"https://www.sec.gov/Archives/edgar/data/1725255/000110465926080297/0001104659-26-080297-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001104659-26-080297)</a>)</li>\n<li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42340.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-adapthealth.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Healthcare solutions provider AdaptHealth Corp disclosed an external threat actor gained unauthorized access to internal systems and exfiltrated company data.",
      "date_published": "2026-07-02T00:00:00Z",
      "date_modified": "2026-08-14T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "sec-8k",
        "healthcare",
        "confirmed",
        "state-ag",
        "washington"
      ],
      "_open_weights": {
        "score": 0.91,
        "percent": 91,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-baylor-genetics.html",
      "url": "https://securityincident.net/incidents/2026-08-baylor-genetics.html",
      "title": "[CONFIRMED] Baylor Genetics — Washington State Attorney General formal data breach disclosure notice filed by Baylor Genetics affecting 27243 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> baylorgenetics.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Baylor Genetics affecting 27243 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42352.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-baylor-genetics.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Baylor Genetics affecting 27243 residents.",
      "date_published": "2026-08-14T00:00:00Z",
      "date_modified": "2026-08-14T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-lennar-mortgage.html",
      "url": "https://securityincident.net/incidents/2026-08-lennar-mortgage.html",
      "title": "[CONFIRMED] Lennar Mortgage — Washington State Attorney General formal data breach disclosure notice filed by Lennar Mortgage affecting 11417 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> lennarmortgage.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Lennar Mortgage affecting 11417 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42347.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-lennar-mortgage.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Lennar Mortgage affecting 11417 residents.",
      "date_published": "2026-08-14T00:00:00Z",
      "date_modified": "2026-08-14T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-paylogix.html",
      "url": "https://securityincident.net/incidents/2026-08-paylogix.html",
      "title": "[CONFIRMED] Paylogix — Washington State Attorney General formal data breach disclosure notice filed by Paylogix affecting 28449 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> paylogix.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Paylogix affecting 28449 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42351.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-paylogix.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Paylogix affecting 28449 residents.",
      "date_published": "2026-08-14T00:00:00Z",
      "date_modified": "2026-08-14T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-quantum-health.html",
      "url": "https://securityincident.net/incidents/2026-08-quantum-health.html",
      "title": "[CONFIRMED] Quantum Health — Washington State Attorney General formal data breach disclosure notice filed by Quantum Health affecting 5909 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> quantumhealth.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Quantum Health affecting 5909 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42356.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-quantum-health.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Quantum Health affecting 5909 residents.",
      "date_published": "2026-08-14T00:00:00Z",
      "date_modified": "2026-08-14T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-chelan-county-wa.html",
      "url": "https://securityincident.net/incidents/2026-08-chelan-county-wa.html",
      "title": "[CONFIRMED] Chelan County, WA — Washington State Attorney General formal data breach disclosure notice filed by Chelan County, WA.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> chelancountywa.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Chelan County, WA.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-11 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42288.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-chelan-county-wa.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Chelan County, WA.",
      "date_published": "2026-08-11T00:00:00Z",
      "date_modified": "2026-08-11T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-kovack-financial.html",
      "url": "https://securityincident.net/incidents/2026-08-kovack-financial.html",
      "title": "[CONFIRMED] Kovack Financial — Washington State Attorney General formal data breach disclosure notice filed by Kovack Financial affecting 657 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> kovackfinancial.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Kovack Financial affecting 657 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-10 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42272.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-kovack-financial.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Kovack Financial affecting 657 residents.",
      "date_published": "2026-08-10T00:00:00Z",
      "date_modified": "2026-08-10T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-american-addiction-centers.html",
      "url": "https://securityincident.net/incidents/2026-08-american-addiction-centers.html",
      "title": "[CONFIRMED] American Addiction Centers — Washington State Attorney General formal data breach disclosure notice filed by American Addiction Centers affecting 1155 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> americanaddictioncenters.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by American Addiction Centers affecting 1155 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-07 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42250.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-american-addiction-centers.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by American Addiction Centers affecting 1155 residents.",
      "date_published": "2026-08-07T00:00:00Z",
      "date_modified": "2026-08-07T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-golden-opportunities-and-local.html",
      "url": "https://securityincident.net/incidents/2026-08-golden-opportunities-and-local.html",
      "title": "[CONFIRMED] Golden Opportunities And Local Support — Washington State Attorney General formal data breach disclosure notice filed by Golden Opportunities And Local Support.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> goldenopportunitiesandlocal.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Golden Opportunities And Local Support.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-07 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42237.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-golden-opportunities-and-local.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Golden Opportunities And Local Support.",
      "date_published": "2026-08-07T00:00:00Z",
      "date_modified": "2026-08-07T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-aesto.html",
      "url": "https://securityincident.net/incidents/2026-08-aesto.html",
      "title": "[CONFIRMED] Aesto — Washington State Attorney General formal data breach disclosure notice filed by Aesto affecting 37253 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> aesto.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Aesto affecting 37253 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-04 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42154.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-aesto.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Aesto affecting 37253 residents.",
      "date_published": "2026-08-04T00:00:00Z",
      "date_modified": "2026-08-04T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-08-cts-journey.html",
      "url": "https://securityincident.net/incidents/2026-08-cts-journey.html",
      "title": "[CONFIRMED] CTS Journey — Washington State Attorney General formal data breach disclosure notice filed by CTS Journey affecting 2226 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> ctsjourney.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by CTS Journey affecting 2226 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-08-03 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42137.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-08-cts-journey.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by CTS Journey affecting 2226 residents.",
      "date_published": "2026-08-03T00:00:00Z",
      "date_modified": "2026-08-03T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.68,
        "percent": 68,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-amgen.html",
      "url": "https://securityincident.net/incidents/2026-07-amgen.html",
      "title": "[CONFIRMED] Amgen — Biotechnology company Amgen filed Form 8-K Item 1.05 disclosing unauthorized cyber activity detected in July 2026.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> amgen.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Biotechnology company Amgen filed Form 8-K Item 1.05 disclosing unauthorized cyber activity detected in July 2026.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-31 16:15 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Amgen discloses detection of unauthorized access to corporate IT systems and initiates incident response. (<a href=\"https://www.sec.gov/Archives/edgar/data/318154/000031815426000119/0000318154-26-000119-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0000318154-26-000119)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-amgen.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Biotechnology company Amgen filed Form 8-K Item 1.05 disclosing unauthorized cyber activity detected in July 2026.",
      "date_published": "2026-07-31T00:00:00Z",
      "date_modified": "2026-07-31T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology & Commercial",
        "regulatory",
        "sec-8k",
        "biotech",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-everside-health.html",
      "url": "https://securityincident.net/incidents/2026-07-everside-health.html",
      "title": "[CONFIRMED] Everside Health — Washington State Attorney General formal data breach disclosure notice filed by Everside Health affecting 21308 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> eversidehealth.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Everside Health affecting 21308 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-31 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42089.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-everside-health.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Everside Health affecting 21308 residents.",
      "date_published": "2026-07-31T00:00:00Z",
      "date_modified": "2026-07-31T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-microcode.html",
      "url": "https://securityincident.net/incidents/2026-07-microcode.html",
      "title": "[CONFIRMED] Microcode — Washington State Attorney General formal data breach disclosure notice filed by Microcode affecting 4096 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> microcode.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Microcode affecting 4096 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-30 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42069.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-microcode.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Microcode affecting 4096 residents.",
      "date_published": "2026-07-30T00:00:00Z",
      "date_modified": "2026-07-30T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-river-financial.html",
      "url": "https://securityincident.net/incidents/2026-07-river-financial.html",
      "title": "[CONFIRMED] River Financial — River Financial Corporation (parent of River Bank & Trust) disclosed an unauthorized intrusion into its banking network involving corporate data exfiltration.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> riverbankandtrust.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 87% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>River Financial Corporation (parent of River Bank &amp; Trust) disclosed an unauthorized intrusion into its banking network involving corporate data exfiltration.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-06 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Initial Disclosure: River Financial detects unauthorized network intrusion and begins forensic investigation. (<a href=\"https://www.sec.gov/Archives/edgar/data/1641601/000119312526295704/0001193125-26-295704-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001193125-26-295704)</a>)</li>\n<li><strong>2026-07-10 18:30 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Amendment: Confirms unauthorized threat actor accessed internal systems and exfiltrated sensitive data files. (<a href=\"https://www.sec.gov/Archives/edgar/data/1641601/000119312526300763/0001193125-26-300763-index.htm\">SEC EDGAR 8-K/A Item 1.05 (Adsh 0001193125-26-300763)</a>)</li>\n<li><strong>2026-07-17 16:45 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Update: Details containment milestones, ongoing litigation tracking, and customer notification procedures. (<a href=\"https://www.sec.gov/Archives/edgar/data/1641601/000119312526307288/0001193125-26-307288-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001193125-26-307288)</a>)</li>\n<li><strong>2026-07-30 19:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Status Conclusion: Confirms core network restoration, enhanced multi-factor controls, and complete containment. (<a href=\"https://www.sec.gov/Archives/edgar/data/1641601/000119312526325324/0001193125-26-325324-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001193125-26-325324)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-river-financial.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "River Financial Corporation (parent of River Bank & Trust) disclosed an unauthorized intrusion into its banking network involving corporate data exfiltration.",
      "date_published": "2026-07-06T00:00:00Z",
      "date_modified": "2026-07-30T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "sec-8k",
        "banking",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.87,
        "percent": 87,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-adt.html",
      "url": "https://securityincident.net/incidents/2026-07-adt.html",
      "title": "[CONFIRMED] ADT — Washington State Attorney General formal data breach disclosure notice filed by ADT affecting 5129 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> adt.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by ADT affecting 5129 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-28 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42014.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-adt.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by ADT affecting 5129 residents.",
      "date_published": "2026-07-28T00:00:00Z",
      "date_modified": "2026-07-28T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-jrk-property.html",
      "url": "https://securityincident.net/incidents/2026-07-jrk-property.html",
      "title": "[CONFIRMED] JRK Property — Washington State Attorney General formal data breach disclosure notice filed by JRK Property affecting 5667 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> jrkproperty.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by JRK Property affecting 5667 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-27 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42008.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-jrk-property.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by JRK Property affecting 5667 residents.",
      "date_published": "2026-07-27T00:00:00Z",
      "date_modified": "2026-07-27T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-spay-dba-stack-sports.html",
      "url": "https://securityincident.net/incidents/2026-07-spay-dba-stack-sports.html",
      "title": "[CONFIRMED] SPay  dba Stack Sports — Washington State Attorney General formal data breach disclosure notice filed by SPay  dba Stack Sports affecting 1190 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> spaydbastacksports.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by SPay  dba Stack Sports affecting 1190 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-27 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42002.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-spay-dba-stack-sports.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by SPay  dba Stack Sports affecting 1190 residents.",
      "date_published": "2026-07-27T00:00:00Z",
      "date_modified": "2026-07-27T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-anmed-health.html",
      "url": "https://securityincident.net/incidents/2026-07-anmed-health.html",
      "title": "[CONFIRMED] AnMed Health — South Carolina healthcare system AnMed Health experienced extensive IT and telecommunications outages across all hospital campuses.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> anmed.org<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 57% (CONFIRMED BY TARGET)<br/>\n</p>\n<p>South Carolina healthcare system AnMed Health experienced extensive IT and telecommunications outages across all hospital campuses.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-26 14:00 UTC</strong> [CONFIRMED BY TARGET]: AnMed Health confirms widespread network and phone outages affecting all facilities, maintaining emergency room triage. (<a href=\"https://databreaches.net/2026/07/26/developing-anmed-reports-phone-and-internet-outage-impacting-all-hospital-locations-ers-remain-open/\">DataBreaches.net Telemetry Alert</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-anmed-health.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "South Carolina healthcare system AnMed Health experienced extensive IT and telecommunications outages across all hospital campuses.",
      "date_published": "2026-07-26T00:00:00Z",
      "date_modified": "2026-07-26T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "investigative",
        "healthcare",
        "outage",
        "acknowledged"
      ],
      "_open_weights": {
        "score": 0.57,
        "percent": 57,
        "top_tier": "CONFIRMED BY TARGET",
        "base_weight": 0.5,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-tribeca-film-festival.html",
      "url": "https://securityincident.net/incidents/2026-07-tribeca-film-festival.html",
      "title": "[DEVELOPING] Tribeca Film Festival — Confidential attendee records, contact information, and travel itineraries for celebrity directors and actors leaked from Tribeca Festival systems.",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> tribecafilm.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Business Email Compromise (BEC)<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Confidential attendee records, contact information, and travel itineraries for celebrity directors and actors leaked from Tribeca Festival systems.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-26 16:30 UTC</strong> [INDEPENDENT VERIFICATION]: Independent audit confirms exposure of internal filmmaker directories and high-profile attendee rosters. (<a href=\"https://databreaches.net/2026/07/26/a-list-directors-actors-and-celebrities-exposed-in-tribeca-film-festival-data-leak/\">DataBreaches.net Security Report</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-tribeca-film-festival.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Confidential attendee records, contact information, and travel itineraries for celebrity directors and actors leaked from Tribeca Festival systems.",
      "date_published": "2026-07-26T00:00:00Z",
      "date_modified": "2026-07-26T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Technology & Commercial",
        "investigative",
        "entertainment",
        "data-leak",
        "developing"
      ],
      "_open_weights": {
        "score": 0.39,
        "percent": 39,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-bridgeway-benefit-technologies.html",
      "url": "https://securityincident.net/incidents/2026-07-bridgeway-benefit-technologies.html",
      "title": "[CONFIRMED] Bridgeway Benefit Technologies — Washington State Attorney General formal data breach disclosure notice filed by Bridgeway Benefit Technologies affecting 640 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> bridgewaybenefittechnologies.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Bridgeway Benefit Technologies affecting 640 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-24 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41982.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-bridgeway-benefit-technologies.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Bridgeway Benefit Technologies affecting 640 residents.",
      "date_published": "2026-07-24T00:00:00Z",
      "date_modified": "2026-07-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-carecloud.html",
      "url": "https://securityincident.net/incidents/2026-07-carecloud.html",
      "title": "[CONFIRMED] CareCloud — Washington State Attorney General formal data breach disclosure notice filed by CareCloud affecting 20706 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> carecloud.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Unauthorized Cloud Access<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by CareCloud affecting 20706 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-24 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachM25126.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-carecloud.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by CareCloud affecting 20706 residents.",
      "date_published": "2026-07-24T00:00:00Z",
      "date_modified": "2026-07-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-crime-stoppers-usa.html",
      "url": "https://securityincident.net/incidents/2026-07-crime-stoppers-usa.html",
      "title": "[DEVELOPING] Crime Stoppers USA — Over 1 million confidential crime tip records intended to remain strictly anonymous were exposed through an unsecured online system.",
      "content_html": "<p><strong>Status:</strong> DEVELOPING<br/>\n<strong>Target Domain:</strong> crimestoppersusa.org<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Affected Population:</strong> 1,000,000 records<br/>\n<strong>Open Weights Confidence:</strong> 43% (INDEPENDENT VERIFICATION)<br/>\n</p>\n<p>Over 1 million confidential crime tip records intended to remain strictly anonymous were exposed through an unsecured online system.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-24 18:00 UTC</strong> [INDEPENDENT VERIFICATION]: Investigative audit reveals misconfigured repository leaking over 1 million anonymous tipster reports. (<a href=\"https://databreaches.net/2026/07/24/crime-stoppers-assured-people-their-tips-would-be-anonymous-then-more-than-1-million-tips-leaked/\">DataBreaches.net Investigation</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-crime-stoppers-usa.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Over 1 million confidential crime tip records intended to remain strictly anonymous were exposed through an unsecured online system.",
      "date_published": "2026-07-24T00:00:00Z",
      "date_modified": "2026-07-24T00:00:00Z",
      "tags": [
        "DEVELOPING",
        "Legal",
        "investigative",
        "law-enforcement",
        "exposure",
        "developing"
      ],
      "_open_weights": {
        "score": 0.43,
        "percent": 43,
        "top_tier": "INDEPENDENT VERIFICATION",
        "base_weight": 0.32,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-eyemart-express.html",
      "url": "https://securityincident.net/incidents/2026-07-eyemart-express.html",
      "title": "[CONFIRMED] Eyemart Express — Washington State Attorney General formal data breach disclosure notice filed by Eyemart Express affecting 1704 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> eyemartexpress.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Eyemart Express affecting 1704 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-24 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41958.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-eyemart-express.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Eyemart Express affecting 1704 residents.",
      "date_published": "2026-07-24T00:00:00Z",
      "date_modified": "2026-07-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-safetyfirst-systems.html",
      "url": "https://securityincident.net/incidents/2026-07-safetyfirst-systems.html",
      "title": "[CONFIRMED] Safetyfirst Systems — Washington State Attorney General formal data breach disclosure notice filed by Safetyfirst Systems affecting 1157 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> safetyfirstsystems.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Safetyfirst Systems affecting 1157 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-23 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41934.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-safetyfirst-systems.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Safetyfirst Systems affecting 1157 residents.",
      "date_published": "2026-07-23T00:00:00Z",
      "date_modified": "2026-07-23T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-the-moody-bible-institute.html",
      "url": "https://securityincident.net/incidents/2026-07-the-moody-bible-institute.html",
      "title": "[CONFIRMED] The Moody Bible Institute of Chicago — Washington State Attorney General formal data breach disclosure notice filed by The Moody Bible Institute of Chicago affecting 8955 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> moodybible.org<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by The Moody Bible Institute of Chicago affecting 8955 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-23 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41947.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-the-moody-bible-institute.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by The Moody Bible Institute of Chicago affecting 8955 residents.",
      "date_published": "2026-07-23T00:00:00Z",
      "date_modified": "2026-07-23T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-kootenai-county-idaho.html",
      "url": "https://securityincident.net/incidents/2026-07-kootenai-county-idaho.html",
      "title": "[CONFIRMED] Kootenai County, Idaho — Washington State Attorney General formal data breach disclosure notice filed by Kootenai County, Idaho affecting 746 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> kootenaicountyidaho.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Kootenai County, Idaho affecting 746 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-22 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41917.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-kootenai-county-idaho.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Kootenai County, Idaho affecting 746 residents.",
      "date_published": "2026-07-22T00:00:00Z",
      "date_modified": "2026-07-22T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-unlimited-technology-systems.html",
      "url": "https://securityincident.net/incidents/2026-07-unlimited-technology-systems.html",
      "title": "[CONFIRMED] Unlimited Technology Systems — Washington State Attorney General formal data breach disclosure notice filed by Unlimited Technology Systems affecting 724 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> unlimitedtechnologysystems.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Unlimited Technology Systems affecting 724 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-21 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41907.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-unlimited-technology-systems.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Unlimited Technology Systems affecting 724 residents.",
      "date_published": "2026-07-21T00:00:00Z",
      "date_modified": "2026-07-21T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-the-estee-lauder-companies.html",
      "url": "https://securityincident.net/incidents/2026-07-the-estee-lauder-companies.html",
      "title": "[CONFIRMED] The Estée Lauder Companies — Washington State Attorney General formal data breach disclosure notice filed by The Estée Lauder Companies affecting 2110 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> theesteelaudercompanies.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by The Estée Lauder Companies affecting 2110 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-17 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41847.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-the-estee-lauder-companies.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by The Estée Lauder Companies affecting 2110 residents.",
      "date_published": "2026-07-17T00:00:00Z",
      "date_modified": "2026-07-17T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-zenpatient.html",
      "url": "https://securityincident.net/incidents/2026-07-zenpatient.html",
      "title": "[CONFIRMED] ZenPatient — Washington State Attorney General formal data breach disclosure notice filed by ZenPatient affecting 651 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> zenpatient.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by ZenPatient affecting 651 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-17 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41853.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-zenpatient.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by ZenPatient affecting 651 residents.",
      "date_published": "2026-07-17T00:00:00Z",
      "date_modified": "2026-07-17T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-dentaquest.html",
      "url": "https://securityincident.net/incidents/2026-07-dentaquest.html",
      "title": "[CONFIRMED] DentaQuest — Washington State Attorney General formal data breach disclosure notice filed by DentaQuest affecting 148300 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> dentaquest.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by DentaQuest affecting 148300 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-16 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41829.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-dentaquest.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by DentaQuest affecting 148300 residents.",
      "date_published": "2026-07-16T00:00:00Z",
      "date_modified": "2026-07-16T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-fox-rothschild.html",
      "url": "https://securityincident.net/incidents/2026-07-fox-rothschild.html",
      "title": "[CONFIRMED] Fox Rothschild — Washington State Attorney General formal data breach disclosure notice filed by Fox Rothschild affecting 1891 residents.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> foxrothschild.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Data Exfiltration<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Washington State Attorney General formal data breach disclosure notice filed by Fox Rothschild affecting 1891 residents.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-16 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href=\"https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41834.pdf\">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-fox-rothschild.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Washington State Attorney General formal data breach disclosure notice filed by Fox Rothschild affecting 1891 residents.",
      "date_published": "2026-07-16T00:00:00Z",
      "date_modified": "2026-07-16T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "state-ag",
        "washington",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-synopsys.html",
      "url": "https://securityincident.net/incidents/2026-07-synopsys.html",
      "title": "[REFUTED] Synopsys — Threat actor extortion claims asserting an intrusion into Synopsys systems were formally audited and disproven with no evidence of compromise.",
      "content_html": "<p><strong>Status:</strong> REFUTED<br/>\n<strong>Target Domain:</strong> synopsys.com<br/>\n<strong>Industry:</strong> Technology &amp; Commercial<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 0% (REFUTED)<br/>\n</p>\n<p>Threat actor extortion claims asserting an intrusion into Synopsys systems were formally audited and disproven with no evidence of compromise.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-14 12:00 UTC</strong> [REFUTED]: Synopsys completes comprehensive forensic review and confirms threat actor claims are false with no breach of corporate data. (<a href=\"https://databreaches.net/2026/07/14/synopsys-finds-no-evidence-of-data-breach-amid-bosch-hack-claims/\">DataBreaches.net Forensic Verification Notice</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-synopsys.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Threat actor extortion claims asserting an intrusion into Synopsys systems were formally audited and disproven with no evidence of compromise.",
      "date_published": "2026-07-14T00:00:00Z",
      "date_modified": "2026-07-14T00:00:00Z",
      "tags": [
        "REFUTED",
        "Technology & Commercial",
        "investigative",
        "semiconductors",
        "refuted"
      ],
      "_open_weights": {
        "score": 0,
        "percent": 0,
        "top_tier": "REFUTED",
        "base_weight": 0,
        "corroboration_bonus": 0,
        "unique_domains": 0
      }
    },
    {
      "id": "https://securityincident.net/incidents/2026-07-navient.html",
      "url": "https://securityincident.net/incidents/2026-07-navient.html",
      "title": "[CONFIRMED] Navient — Student loan servicer Navient disclosed a third-party ransomware attack affecting legal service provider systems containing Navient corporate data.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> navient.com<br/>\n<strong>Industry:</strong> Legal<br/>\n<strong>Incident Type:</strong> Ransomware Extortion<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Student loan servicer Navient disclosed a third-party ransomware attack affecting legal service provider systems containing Navient corporate data.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2026-07-02 17:30 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Navient discloses ransomware breach at third-party law firm impacting company data. (<a href=\"https://www.sec.gov/Archives/edgar/data/1593538/000114036126027441/0001140361-26-027441-index.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001140361-26-027441)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2026-07-navient.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Student loan servicer Navient disclosed a third-party ransomware attack affecting legal service provider systems containing Navient corporate data.",
      "date_published": "2026-07-02T00:00:00Z",
      "date_modified": "2026-07-02T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Legal",
        "regulatory",
        "sec-8k",
        "third-party",
        "financial",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.84,
        "percent": 84,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0,
        "unique_domains": 1
      }
    },
    {
      "id": "https://securityincident.net/incidents/2024-02-change-healthcare.html",
      "url": "https://securityincident.net/incidents/2024-02-change-healthcare.html",
      "title": "[CONFIRMED] Change Healthcare — Change Healthcare (UnitedHealth Group) suffered a devastating ALPHV / BlackCat ransomware extortion attack halting healthcare clearinghouse networks nationwide and impacting 100M individuals.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> changehealthcare.com<br/>\n<strong>Industry:</strong> Healthcare<br/>\n<strong>Incident Type:</strong> Ransomware Extortion &amp; Healthcare Pipeline Disruption<br/>\n<strong>Threat Actor:</strong> ALPHV / BlackCat<br/>\n<strong>Affected Population:</strong> 100,000,000 records<br/>\n<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Change Healthcare (UnitedHealth Group) suffered a devastating ALPHV / BlackCat ransomware extortion attack halting healthcare clearinghouse networks nationwide and impacting 100M individuals.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2024-02-21 14:00 UTC</strong> [CONFIRMED BY TARGET]: Change Healthcare confirms widespread network disruption to prescription routing, claims processing, and clinical operations. (<a href=\"https://www.unitedhealthgroup.com/changehealthcarecyberresponse\">UnitedHealth Group Official Disruption Bulletin</a>)</li>\n<li><strong>2024-02-22 17:30 UTC</strong> [CONFIRMED BY REGULATOR]: UnitedHealth Group files SEC Form 8-K Item 1.05 disclosing suspected cybercrime intrusion into Change Healthcare IT environments. (<a href=\"https://www.sec.gov/Archives/edgar/data/731766/000073176624000010/uhg-20240221.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0000731766-24-000010)</a>)</li>\n<li><strong>2024-02-28 19:00 UTC</strong> [INDEPENDENT VERIFICATION]: ALPHV / BlackCat ransomware extortion gang claims responsibility, stating 6 TB of sensitive patient and financial records were exfiltrated. (<a href=\"https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a\">CISA &amp; FBI Joint Cybersecurity Advisory (AA24-060A)</a>)</li>\n<li><strong>2024-10-24 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: HHS OCR breach portal registers confirmed affected population of approximately 100,000,000 individuals. (<a href=\"https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf\">HHS OCR Data Breach Portal Entry (Change Healthcare)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2024-02-change-healthcare.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Change Healthcare (UnitedHealth Group) suffered a devastating ALPHV / BlackCat ransomware extortion attack halting healthcare clearinghouse networks nationwide and impacting 100M individuals.",
      "date_published": "2024-02-21T00:00:00Z",
      "date_modified": "2024-10-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Healthcare",
        "regulatory",
        "sec-8k",
        "hhs-ocr",
        "healthcare",
        "ransomware",
        "confirmed"
      ],
      "_open_weights": {
        "score": 1,
        "percent": 100,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.21,
        "unique_domains": 4
      }
    },
    {
      "id": "https://securityincident.net/incidents/2024-08-halliburton.html",
      "url": "https://securityincident.net/incidents/2024-08-halliburton.html",
      "title": "[CONFIRMED] Halliburton — Oilfield services corporation Halliburton filed Form 8-K Item 1.05 disclosing an unauthorized intrusion by RansomHub that forced the company to take global systems offline.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> halliburton.com<br/>\n<strong>Industry:</strong> Energy &amp; Oil Field Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Ransomware<br/>\n<strong>Threat Actor:</strong> RansomHub<br/>\n<strong>Open Weights Confidence:</strong> 94% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Oilfield services corporation Halliburton filed Form 8-K Item 1.05 disclosing an unauthorized intrusion by RansomHub that forced the company to take global systems offline.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2024-08-21 16:00 UTC</strong> [CONFIRMED BY TARGET]: Energy giant Halliburton detects unauthorized third-party access to corporate systems and activates incident response protocols. (<a href=\"https://www.halliburton.com/en/about-us/corporate-governance\">Halliburton Incident Advisory</a>)</li>\n<li><strong>2024-08-23 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: Halliburton files Form 8-K Item 1.05 disclosing material disruption to business operations and systems shutdown. (<a href=\"https://www.sec.gov/Archives/edgar/data/45012/000004501224000067/hal-20240823.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0000045012-24-000067)</a>)</li>\n<li><strong>2024-09-03 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 8.01 supplemental filing confirms company is restoring operational capabilities and remediating core IT environments. (<a href=\"https://www.sec.gov/Archives/edgar/data/45012/000004501224000072/hal-20240903.htm\">SEC EDGAR 8-K Item 8.01 (Adsh 0000045012-24-000072)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2024-08-halliburton.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Oilfield services corporation Halliburton filed Form 8-K Item 1.05 disclosing an unauthorized intrusion by RansomHub that forced the company to take global systems offline.",
      "date_published": "2024-08-21T00:00:00Z",
      "date_modified": "2024-09-03T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Energy & Oil Field Services",
        "regulatory",
        "sec-8k",
        "energy",
        "oil-gas",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.94,
        "percent": 94,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2024-06-cdk-global.html",
      "url": "https://securityincident.net/incidents/2024-06-cdk-global.html",
      "title": "[CONFIRMED] CDK Global — Dealership software giant CDK Global suffered an operational paralysis cyberattack by the BlackSuit ransomware group, shutting down 15,000 auto dealerships nationwide.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> cdkglobal.com<br/>\n<strong>Industry:</strong> Automotive &amp; Software Services<br/>\n<strong>Incident Type:</strong> Ransomware Extortion &amp; Software Outage<br/>\n<strong>Threat Actor:</strong> BlackSuit<br/>\n<strong>Affected Population:</strong> 15,000,000 records<br/>\n<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY TARGET)<br/>\n</p>\n<p>Dealership software giant CDK Global suffered an operational paralysis cyberattack by the BlackSuit ransomware group, shutting down 15,000 auto dealerships nationwide.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2024-06-19 14:00 UTC</strong> [CONFIRMED BY TARGET]: CDK Global shuts down all core dealership management systems following massive cyberattack disrupting 15,000 car dealerships nationwide. (<a href=\"https://www.cdkglobal.com/outage-update\">CDK Global Customer Advisory Bulletin</a>)</li>\n<li><strong>2024-06-21 16:30 UTC</strong> [INDEPENDENT VERIFICATION]: BlackSuit ransomware collective demands $25M ransom; second intrusion detected during restoration attempt. (<a href=\"https://www.bleepingcomputer.com/news/security/cdk-global-cyberattack-dealership-outage-details/\">BleepingComputer Cybersecurity Investigation</a>)</li>\n<li><strong>2024-07-02 18:00 UTC</strong> [CONFIRMED BY TARGET]: CDK confirms phased restoration of dealer management system (DMS) for core dealership clients nationwide. (<a href=\"https://www.cdkglobal.com/news-insights\">CDK Global Restoration Announcement</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2024-06-cdk-global.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Dealership software giant CDK Global suffered an operational paralysis cyberattack by the BlackSuit ransomware group, shutting down 15,000 auto dealerships nationwide.",
      "date_published": "2024-06-19T00:00:00Z",
      "date_modified": "2024-07-02T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Automotive & Software Services",
        "investigative",
        "automotive",
        "software",
        "ransomware",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.88,
        "percent": 88,
        "top_tier": "CONFIRMED BY TARGET",
        "base_weight": 0.5,
        "corroboration_bonus": 0.12,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2024-06-advance-auto-parts.html",
      "url": "https://securityincident.net/incidents/2024-06-advance-auto-parts.html",
      "title": "[CONFIRMED] Advance Auto Parts — Automotive retailer Advance Auto Parts filed Form 8-K Item 1.05 after cybercriminals compromised its cloud database tenant, stealing 380 million customer profiles.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> advanceautoparts.com<br/>\n<strong>Industry:</strong> Retail &amp; Consumer Goods<br/>\n<strong>Incident Type:</strong> Third-Party Cloud Account Takeover<br/>\n<strong>Threat Actor:</strong> UNC5537<br/>\n<strong>Affected Population:</strong> 380,000,000 records<br/>\n<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Automotive retailer Advance Auto Parts filed Form 8-K Item 1.05 after cybercriminals compromised its cloud database tenant, stealing 380 million customer profiles.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2024-05-23 16:30 UTC</strong> [CONFIRMED BY TARGET]: Unauthorized actor accesses company&apos;s cloud data environment via stolen contractor credentials. (<a href=\"https://corp.advanceautoparts.com/investors\">Advance Auto Parts Security Notice</a>)</li>\n<li><strong>2024-06-04 18:00 UTC</strong> [INDEPENDENT VERIFICATION]: Threat actor offers 380 million customer records for sale on dark web breach forums for $1.5 million. (<a href=\"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft\">Mandiant Threat Intelligence Audit (UNC5537)</a>)</li>\n<li><strong>2024-06-05 17:30 UTC</strong> [CONFIRMED BY REGULATOR]: Advance Auto Parts files Form 8-K Item 1.05 confirming exfiltration of customer and employee data files. (<a href=\"https://www.sec.gov/Archives/edgar/data/1158449/000115844924000163/aap-20240605.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001158449-24-000163)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2024-06-advance-auto-parts.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Automotive retailer Advance Auto Parts filed Form 8-K Item 1.05 after cybercriminals compromised its cloud database tenant, stealing 380 million customer profiles.",
      "date_published": "2024-05-23T00:00:00Z",
      "date_modified": "2024-06-05T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Retail & Consumer Goods",
        "regulatory",
        "sec-8k",
        "retail",
        "snowflake-cloud",
        "confirmed"
      ],
      "_open_weights": {
        "score": 1,
        "percent": 100,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.17,
        "unique_domains": 3
      }
    },
    {
      "id": "https://securityincident.net/incidents/2024-02-prudential-financial.html",
      "url": "https://securityincident.net/incidents/2024-02-prudential-financial.html",
      "title": "[CONFIRMED] Prudential Financial — Prudential Financial filed Form 8-K Item 1.05 following an administrative system intrusion by the ALPHV / BlackCat ransomware group compromising employee and user data.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> prudential.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Administrative Cloud Intrusion<br/>\n<strong>Threat Actor:</strong> ALPHV / BlackCat<br/>\n<strong>Affected Population:</strong> 32,183 records<br/>\n<strong>Open Weights Confidence:</strong> 98% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Prudential Financial filed Form 8-K Item 1.05 following an administrative system intrusion by the ALPHV / BlackCat ransomware group compromising employee and user data.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2024-02-05 16:00 UTC</strong> [CONFIRMED BY TARGET]: Threat actor breaches internal administrative network environments and exfiltrates corporate data files. (<a href=\"https://www.prudential.com/links/security\">Prudential Information Security Bulletin</a>)</li>\n<li><strong>2024-02-13 18:30 UTC</strong> [CONFIRMED BY REGULATOR]: Prudential files Form 8-K Item 1.05 disclosing unauthorized access to administrative and internal user directories. (<a href=\"https://www.sec.gov/Archives/edgar/data/1137774/000113777424000012/pru-20240212.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001137774-24-000012)</a>)</li>\n<li><strong>2024-03-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 1.05 amendment updates scope to confirm 32,183 individuals impacted by exfiltration. (<a href=\"https://www.sec.gov/Archives/edgar/data/1137774/000113777424000028/pru-20240329.htm\">SEC EDGAR 8-K/A Item 1.05 (Adsh 0001137774-24-000028)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2024-02-prudential-financial.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Prudential Financial filed Form 8-K Item 1.05 following an administrative system intrusion by the ALPHV / BlackCat ransomware group compromising employee and user data.",
      "date_published": "2024-02-05T00:00:00Z",
      "date_modified": "2024-03-29T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "sec-8k",
        "financial",
        "insurance",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.98,
        "percent": 98,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2024-01-hewlett-packard-enterprise.html",
      "url": "https://securityincident.net/incidents/2024-01-hewlett-packard-enterprise.html",
      "title": "[CONFIRMED] Hewlett Packard Enterprise — Hewlett Packard Enterprise filed Form 8-K Item 1.05 disclosing that nation-state actor Midnight Blizzard compromised its cloud-based Office 365 email environment.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> hpe.com<br/>\n<strong>Industry:</strong> Technology<br/>\n<strong>Incident Type:</strong> Nation-State Cloud Intrusion<br/>\n<strong>Threat Actor:</strong> Midnight Blizzard (APT29)<br/>\n<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>Hewlett Packard Enterprise filed Form 8-K Item 1.05 disclosing that nation-state actor Midnight Blizzard compromised its cloud-based Office 365 email environment.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2024-01-19 16:30 UTC</strong> [CONFIRMED BY TARGET]: HPE notified that nation-state actor Midnight Blizzard gained unauthorized access to Office 365 cloud email environment. (<a href=\"https://www.hpe.com/us/en/newsroom/press-releases/2024/01/hpe-security-update.html\">HPE Press &amp; Security Disclosure Notice</a>)</li>\n<li><strong>2024-01-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: HPE files Form 8-K Item 1.05 disclosing data exfiltration from cybersecurity, legal, and operational team mailboxes dating back to May 2023. (<a href=\"https://www.sec.gov/Archives/edgar/data/1645590/000164559024000003/hpe-20240119.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001645590-24-000003)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2024-01-hewlett-packard-enterprise.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "Hewlett Packard Enterprise filed Form 8-K Item 1.05 disclosing that nation-state actor Midnight Blizzard compromised its cloud-based Office 365 email environment.",
      "date_published": "2024-01-19T00:00:00Z",
      "date_modified": "2024-01-24T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Technology",
        "regulatory",
        "sec-8k",
        "technology",
        "nation-state",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.91,
        "percent": 91,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2024-01-loandepot.html",
      "url": "https://securityincident.net/incidents/2024-01-loandepot.html",
      "title": "[CONFIRMED] LoanDepot — LoanDepot filed Form 8-K Item 1.05 disclosing a major ransomware extortion attack encrypting mortgage servicing systems and compromising 16.6 million customers.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> loandepot.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Ransomware Extortion &amp; Encryption<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Affected Population:</strong> 16,600,000 records<br/>\n<strong>Open Weights Confidence:</strong> 98% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>LoanDepot filed Form 8-K Item 1.05 disclosing a major ransomware extortion attack encrypting mortgage servicing systems and compromising 16.6 million customers.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2024-01-08 15:00 UTC</strong> [CONFIRMED BY TARGET]: LoanDepot detects unauthorized cyber incident that encrypted company systems and took loan servicing portals offline. (<a href=\"https://www.loandepot.com/cybersecurity-notice\">LoanDepot Cybersecurity Response Bulletin</a>)</li>\n<li><strong>2024-01-11 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: LoanDepot files Form 8-K Item 1.05 confirming unauthorized third-party access and ransomware encryption. (<a href=\"https://www.sec.gov/Archives/edgar/data/1831631/000183163124000002/lndi-20240108.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001831631-24-000002)</a>)</li>\n<li><strong>2024-01-22 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 1.05 amendment confirms sensitive personal data of approximately 16.6 million individuals was exfiltrated. (<a href=\"https://www.sec.gov/Archives/edgar/data/1831631/000183163124000004/lndi-20240122.htm\">SEC EDGAR 8-K/A Item 1.05 (Adsh 0001831631-24-000004)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2024-01-loandepot.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "LoanDepot filed Form 8-K Item 1.05 disclosing a major ransomware extortion attack encrypting mortgage servicing systems and compromising 16.6 million customers.",
      "date_published": "2024-01-08T00:00:00Z",
      "date_modified": "2024-01-22T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "sec-8k",
        "financial",
        "mortgage",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.98,
        "percent": 98,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2023-12-vf-corporation.html",
      "url": "https://securityincident.net/incidents/2023-12-vf-corporation.html",
      "title": "[CONFIRMED] VF Corporation — VF Corporation (parent of Vans, The North Face, and Timberland) filed Form 8-K Item 1.05 following an ALPHV ransomware attack compromising 35.5 million customer records.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> vfc.com<br/>\n<strong>Industry:</strong> Retail &amp; Consumer Goods<br/>\n<strong>Incident Type:</strong> Ransomware Extortion &amp; Encryption<br/>\n<strong>Threat Actor:</strong> ALPHV / BlackCat<br/>\n<strong>Affected Population:</strong> 35,500,000 records<br/>\n<strong>Open Weights Confidence:</strong> 98% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>VF Corporation (parent of Vans, The North Face, and Timberland) filed Form 8-K Item 1.05 following an ALPHV ransomware attack compromising 35.5 million customer records.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2023-12-13 19:00 UTC</strong> [CONFIRMED BY TARGET]: Threat actor encrypts operational IT systems and exfiltrates corporate data from apparel conglomerate VF Corp. (<a href=\"https://www.vfc.com/news\">VF Corporation Incident Briefing</a>)</li>\n<li><strong>2023-12-18 17:30 UTC</strong> [CONFIRMED BY REGULATOR]: VF Corp files Form 8-K Item 1.05 disclosing material disruption to retail logistics and e-commerce order processing. (<a href=\"https://www.sec.gov/Archives/edgar/data/103379/000010337923000039/vfc-20231215.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0000103379-23-000039)</a>)</li>\n<li><strong>2024-01-18 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 1.05 update confirms 35.5 million individual customer records compromised during the intrusion. (<a href=\"https://www.sec.gov/Archives/edgar/data/103379/000010337924000003/vfc-20240118.htm\">SEC EDGAR 8-K Item 1.05 Update (Adsh 0000103379-24-000003)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2023-12-vf-corporation.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "VF Corporation (parent of Vans, The North Face, and Timberland) filed Form 8-K Item 1.05 following an ALPHV ransomware attack compromising 35.5 million customer records.",
      "date_published": "2023-12-13T00:00:00Z",
      "date_modified": "2024-01-18T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Retail & Consumer Goods",
        "regulatory",
        "sec-8k",
        "retail",
        "ransomware",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.98,
        "percent": 98,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    },
    {
      "id": "https://securityincident.net/incidents/2023-12-first-american-financial.html",
      "url": "https://securityincident.net/incidents/2023-12-first-american-financial.html",
      "title": "[CONFIRMED] First American Financial — First American Financial filed the very first SEC Form 8-K Item 1.05 disclosure under the SEC mandate following an unauthorized network intrusion that disabled title portals.",
      "content_html": "<p><strong>Status:</strong> CONFIRMED<br/>\n<strong>Target Domain:</strong> firstam.com<br/>\n<strong>Industry:</strong> Financial Services<br/>\n<strong>Incident Type:</strong> Network Intrusion &amp; Disruption<br/>\n<strong>Threat Actor:</strong> Unknown / Unattributed<br/>\n<strong>Affected Population:</strong> 44,000 records<br/>\n<strong>Open Weights Confidence:</strong> 98% (CONFIRMED BY REGULATOR)<br/>\n</p>\n<p>First American Financial filed the very first SEC Form 8-K Item 1.05 disclosure under the SEC mandate following an unauthorized network intrusion that disabled title portals.</p>\n<h3>Milestone Timeline</h3>\n<ul>\n<li><strong>2023-12-20 18:00 UTC</strong> [CONFIRMED BY TARGET]: First American detects unauthorized cybersecurity activity and isolates systems, taking email, title production, and web portals offline. (<a href=\"https://www.firstam.com/update\">First American Cybersecurity Advisory</a>)</li>\n<li><strong>2023-12-22 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: First American files SEC Form 8-K Item 1.05—marking the landmark first-ever disclosure under the SEC&apos;s material cybersecurity disclosure mandate. (<a href=\"https://www.sec.gov/Archives/edgar/data/1472787/000147278723000072/faf-20231220.htm\">SEC EDGAR 8-K Item 1.05 (Adsh 0001472787-23-000072)</a>)</li>\n<li><strong>2024-01-16 16:45 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 1.05 amendment confirms core title and escrow transaction systems are restored and operational. (<a href=\"https://www.sec.gov/Archives/edgar/data/1472787/000147278724000003/faf-20240116.htm\">SEC EDGAR 8-K/A Item 1.05 (Adsh 0001472787-24-000003)</a>)</li>\n</ul>\n<p><a href=\"https://securityincident.net/incidents/2023-12-first-american-financial.html\">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>",
      "summary": "First American Financial filed the very first SEC Form 8-K Item 1.05 disclosure under the SEC mandate following an unauthorized network intrusion that disabled title portals.",
      "date_published": "2023-12-20T00:00:00Z",
      "date_modified": "2024-01-16T00:00:00Z",
      "tags": [
        "CONFIRMED",
        "Financial Services",
        "regulatory",
        "sec-8k",
        "financial",
        "title-insurance",
        "confirmed"
      ],
      "_open_weights": {
        "score": 0.98,
        "percent": 98,
        "top_tier": "CONFIRMED BY REGULATOR",
        "base_weight": 0.65,
        "corroboration_bonus": 0.07,
        "unique_domains": 2
      }
    }
  ]
}