<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>securityincident.net | Real-Time Incident Status &amp; Milestone Timeline Index</title>
    <link>https://securityincident.net/</link>
    <description>A neutral, high-signal index tracking real-time status and verified milestone timelines for cybersecurity incidents across the open web, powered by open weights correlation and community PR editing.</description>
    <language>en-us</language>
    <lastBuildDate>Thu, 08 Oct 2026 02:45:39 GMT</lastBuildDate>
    <atom:link href="https://securityincident.net/feed.xml" rel="self" type="application/rss+xml"/>
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>securityincident.net static generator</generator>
    <item>
      <title>[DEVELOPING] Arizona Supreme Court — A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.</title>
      <link>https://securityincident.net/incidents/2026-09-arizona-supreme-court.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-arizona-supreme-court.html</guid>
      <pubDate>Tue, 29 Sep 2026 12:27:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> azcourts.gov<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 46% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-29<br/>
<strong>Last Updated:</strong> 2026-10-07</p>
<p>A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-29 12:27 UTC</strong> [INDEPENDENT VERIFICATION]: Arizona Supreme Court says hackers stole residents’ personal data (<a href="https://therecord.media/arizona-supreme-court-says-hackers-stole-data">The Record by Recorded Future Report</a>)</li>
  <li><strong>2026-10-07 01:32 UTC</strong> [INDEPENDENT VERIFICATION]: Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System (<a href="https://www.securityweek.com/personal-information-for-over-1-million-people-stolen-in-a-cyberattack-on-arizonas-court-system/">SecurityWeek Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-arizona-supreme-court.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>developing</category>
      <category>threat-intel</category>
    </item>
    <item>
      <title>[CONFIRMED] Snowflake — A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provide...</title>
      <link>https://securityincident.net/incidents/2026-08-snowflake.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-snowflake.html</guid>
      <pubDate>Thu, 06 Aug 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> snowflake.com<br/>
<strong>Threat Actor:</strong> UNC5537<br/>
<strong>Open Weights Confidence:</strong> 85% (CONFIRMED BY TARGET)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-08-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provide...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-06 17:00 UTC</strong> [INDEPENDENT VERIFICATION]: Canadian Man Pleads Guilty in Snowflake Extortions (<a href="https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/">Krebs on Security Report</a>)</li>
  <li><strong>2026-10-06 16:33 UTC</strong> [CONFIRMED BY TARGET]: ASOS confirms data breach after “HACKED” in-app notifications (<a href="https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/">BleepingComputer Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-snowflake.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>investigative</category>
      <category>developing</category>
      <category>threat-intel</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Citrix Systems (Cloud Software Group) — Cloud Software Group and federal regulators issued emergency disclosures for two actively exploited critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5), enabling unauthenticated remote code execution and webshell deployment across 50,000+ exposed enterprise appliances worldwide.</title>
      <link>https://securityincident.net/incidents/2026-09-citrix.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-citrix.html</guid>
      <pubDate>Sun, 27 Sep 2026 12:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> citrix.com<br/>
<strong>Threat Actor:</strong> State-Sponsored Advanced Persistent Threat (APT)<br/>
<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 7<br/>
<strong>First Seen:</strong> 2026-09-27<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Cloud Software Group and federal regulators issued emergency disclosures for two actively exploited critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5), enabling unauthenticated remote code execution and webshell deployment across 50,000+ exposed enterprise appliances worldwide.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-27 12:00 UTC</strong> [CONFIRMED BY REGULATOR]: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway (<a href="https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway">CISA Cybersecurity Advisories Report</a>)</li>
  <li><strong>2026-09-29 18:37 UTC</strong> [INDEPENDENT VERIFICATION]: Hackers exploit Citrix NetScaler zero-day to deploy web shells (<a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-citrix-netscaler-zero-day-to-deploy-web-shells/">BleepingComputer Report</a>)</li>
  <li><strong>2026-09-28 07:21 UTC</strong> [INDEPENDENT VERIFICATION]: CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally (<a href="https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html">The Hacker News Report</a>)</li>
  <li><strong>2026-09-27 07:47 UTC</strong> [INDEPENDENT VERIFICATION]: Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation (<a href="https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html">The Hacker News Report</a>)</li>
  <li><strong>2026-09-29 14:19 UTC</strong> [INDEPENDENT VERIFICATION]: Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers (<a href="https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix">Dark Reading Report</a>)</li>
  <li><strong>2026-09-28 12:00 UTC</strong> [CONFIRMED BY REGULATOR]: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway (<a href="https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway">NCSC UK Cyber Alerts Report</a>)</li>
  <li><strong>2026-09-29 13:53 UTC</strong> [CONFIRMED BY REGULATOR]: Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities (<a href="https://www.hipaajournal.com/citrix-zero-day-vulnerabilities-exploited-sept-2026/">HIPAA Journal Healthcare Breaches Report</a>)</li>
  <li><strong>2026-09-27 12:00 UTC</strong> [CONFIRMED BY REGULATOR]: CISA Adds Two Known Exploited Vulnerabilities to Catalog (<a href="https://www.cisa.gov/news-events/alerts/2026/09/27/cisa-adds-two-known-exploited-vulnerabilities-catalog">CISA Cybersecurity Advisories Report</a>)</li>
  <li><strong>2026-10-01 11:55 UTC</strong> [INDEPENDENT VERIFICATION]: Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed. (<a href="https://databreaches.net/2026/10/01/suspected-state-hackers-exploited-citrix-netscaler-for-weeks-50000-devices-may-still-be-exposed/">DataBreaches.net Report</a>)</li>
  <li><strong>2026-10-02 16:56 UTC</strong> [INDEPENDENT VERIFICATION]: Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response (<a href="https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response">Dark Reading Report</a>)</li>
  <li><strong>2026-10-04 12:00 UTC</strong> [CONFIRMED BY REGULATOR]: CISA Adds One Known Exploited Vulnerability to Catalog (<a href="https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog">CISA Cybersecurity Advisories Report</a>)</li>
  <li><strong>2026-10-05 06:40 UTC</strong> [INDEPENDENT VERIFICATION]: New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline (<a href="https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html">The Hacker News Report</a>)</li>
  <li><strong>2026-10-06 10:26 UTC</strong> [CONFIRMED BY REGULATOR]: Citrix Patches Third Actively Exploited NetScaler Zero Day (<a href="https://www.hipaajournal.com/citrix-patches-third-actively-exploited-netscaler-zero-day/">HIPAA Journal Healthcare Breaches Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-citrix.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>cisa-kev</category>
      <category>zero-day</category>
      <category>infrastructure</category>
      <category>enterprise-software</category>
      <category>developing</category>
      <category>threat-intel</category>
    </item>
    <item>
      <title>[ACKNOWLEDGED] Federal Bureau of Investigation (FBI) — Joseph Cox reports: The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical add...</title>
      <link>https://securityincident.net/incidents/2026-09-fbi.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-fbi.html</guid>
      <pubDate>Tue, 29 Sep 2026 12:48:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> ACKNOWLEDGED<br/>
<strong>Target Domain:</strong> fbi.gov<br/>
<strong>Threat Actor:</strong> Cyber Extortion Collective<br/>
<strong>Open Weights Confidence:</strong> 80% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 5<br/>
<strong>First Seen:</strong> 2026-09-29<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Joseph Cox reports: The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical add...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-29 12:48 UTC</strong> [INDEPENDENT VERIFICATION]: FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data (<a href="https://databreaches.net/2026/09/29/fbi-hackers-say-they-wont-publish-massive-trove-of-fbi-employee-data/">DataBreaches.net Report</a>)</li>
  <li><strong>2026-09-29 20:09 UTC</strong> [INDEPENDENT VERIFICATION]: FBI tells ShinyHunters members to turn themselves in after recent arrest (<a href="https://www.bleepingcomputer.com/news/security/fbi-tells-shinyhunters-members-to-turn-themselves-in-after-recent-arrest/">BleepingComputer Report</a>)</li>
  <li><strong>2026-10-02 14:06 UTC</strong> [INDEPENDENT VERIFICATION]: Mississippi mayor says ransomware incident led city to shut down systems (<a href="https://therecord.media/vicksburg-mississippi-government-ransomware-attack">The Record by Recorded Future Report</a>)</li>
  <li><strong>2026-10-06 15:23 UTC</strong> [INDEPENDENT VERIFICATION]: FBI Blames Contractor’s Missed Patch for ShinyHunters Breach (<a href="https://databreaches.net/2026/10/06/fbi-blames-contractors-missed-patch-for-shinyhunters-breach/">DataBreaches.net Report</a>)</li>
  <li><strong>2026-10-05 12:30 UTC</strong> [INDEPENDENT VERIFICATION]: Hackers Breached Propulsion System of U.S.-Bound Oil Tanker (<a href="https://databreaches.net/2026/10/05/hackers-breached-propulsion-system-of-u-s-bound-oil-tanker/">DataBreaches.net Report</a>)</li>
  <li><strong>2026-10-06 14:15 UTC</strong> [INDEPENDENT VERIFICATION]: FBI Blames Contractor's Missed Patch for ShinyHunters Breach (<a href="https://www.securityweek.com/fbi-blames-contractors-missed-patch-for-shinyhunters-breach/">SecurityWeek Report</a>)</li>
  <li><strong>2026-10-06 06:56 UTC</strong> [INDEPENDENT VERIFICATION]: FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach (<a href="https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html">The Hacker News Report</a>)</li>
  <li><strong>2026-10-04 07:22 UTC</strong> [INDEPENDENT VERIFICATION]: ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members (<a href="https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html">The Hacker News Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-fbi.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>ACKNOWLEDGED</category>
      <category>investigative</category>
      <category>emerging</category>
      <category>threat-intel</category>
      <category>developing</category>
      <category>acknowledged</category>
    </item>
    <item>
      <title>[EMERGING] Agri Industrial — Agri Industrial was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-agri-industrial.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-agri-industrial.html</guid>
      <pubDate>Tue, 06 Oct 2026 16:17:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> agriindustrial.com<br/>
<strong>Threat Actor:</strong> Everest<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Agri Industrial was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 16:17 UTC</strong> [UNVERIFIED CLAIM]: Agri Industrial Listed on Everest Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/QWdyaSBJbmR1c3RyaWFsQGV2ZXJlc3Q=">Everest Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-agri-industrial.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>everest</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[DEVELOPING] Atlassian — Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]</title>
      <link>https://securityincident.net/incidents/2026-10-atlassian.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-atlassian.html</guid>
      <pubDate>Tue, 06 Oct 2026 17:34:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> atlassian.com<br/>
<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 17:34 UTC</strong> [INDEPENDENT VERIFICATION]: Atlassian warns of critical file-access flaw in Jira, Confluence (<a href="https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-file-access-flaw-in-jira-confluence/">BleepingComputer Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-atlassian.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>threat-intel</category>
      <category>developing</category>
    </item>
    <item>
      <title>[EMERGING] B-accountants — B-accountants was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-b-accountants.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-b-accountants.html</guid>
      <pubDate>Tue, 06 Oct 2026 16:17:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> baccountants.com<br/>
<strong>Threat Actor:</strong> Everest<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>B-accountants was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 16:17 UTC</strong> [UNVERIFIED CLAIM]: B-accountants Listed on Everest Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Qi1hY2NvdW50YW50c0BldmVyZXN0">Everest Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-b-accountants.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>everest</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Beni Suef Technological University – BTU — Beni Suef Technological University – BTU was listed on the UmBra ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-beni-suef-technological-university-btu.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-beni-suef-technological-university-btu.html</guid>
      <pubDate>Tue, 06 Oct 2026 22:24:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> benisueftechnologicaluniversitybtu.com<br/>
<strong>Threat Actor:</strong> UmBra<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Beni Suef Technological University – BTU was listed on the UmBra ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 22:24 UTC</strong> [UNVERIFIED CLAIM]: Beni Suef Technological University – BTU Listed on UmBra Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/QmVuaSBTdWVmIFRlY2hub2xvZ2ljYWwgVW5pdmVyc2l0eSDigJMgQlRVQFVtQnJh">UmBra Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-beni-suef-technological-university-btu.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>umbra</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] BNYH — BNYH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-bnyh.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-bnyh.html</guid>
      <pubDate>Tue, 06 Oct 2026 20:19:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> bnyh.com<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>BNYH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 20:19 UTC</strong> [UNVERIFIED CLAIM]: BNYH Listed on Qilin Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Qk5ZSEBxaWxpbg==">Qilin Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-bnyh.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>qilin</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi — Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-ciftay-insaat-taahhut-ve-ticaret-anonim-sirketi.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-ciftay-insaat-taahhut-ve-ticaret-anonim-sirketi.html</guid>
      <pubDate>Tue, 06 Oct 2026 20:18:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> ciftay.com.tr<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 17% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 20:18 UTC</strong> [UNVERIFIED CLAIM]: Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi Listed on Qilin Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Q2lmdGF5IEluc2FhdCBUYWFoaHV0IFZlIFRpY2FyZXQgQW5vbmltIFNpcmtldGlAcWlsaW4=">Qilin Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-ciftay-insaat-taahhut-ve-ticaret-anonim-sirketi.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>qilin</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] CORBY ROCK MILL — CORBY ROCK MILL was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-corby-rock-mill.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-corby-rock-mill.html</guid>
      <pubDate>Tue, 06 Oct 2026 09:03:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> corbyrock.ie<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>CORBY ROCK MILL was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 09:03 UTC</strong> [UNVERIFIED CLAIM]: CORBY ROCK MILL Listed on Qilin Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Q09SQlkgUk9DSyBNSUxMQHFpbGlu">Qilin Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-corby-rock-mill.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>qilin</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Delta Marine — Delta Marine was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-delta-marine.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-delta-marine.html</guid>
      <pubDate>Tue, 06 Oct 2026 09:02:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> deltamarine.com<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Delta Marine was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 09:02 UTC</strong> [UNVERIFIED CLAIM]: Delta Marine Listed on Qilin Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RGVsdGEgTWFyaW5lQHFpbGlu">Qilin Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-delta-marine.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>qilin</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] EDFelectronics — EDFelectronics was listed on the Panzer ransomware extortion leak portal. EDFelectronics.com is a Polish engineering company that develops specialized electronics and plasma technology for industrial and research applications.</title>
      <link>https://securityincident.net/incidents/2026-10-edfelectronics.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-edfelectronics.html</guid>
      <pubDate>Tue, 06 Oct 2026 22:55:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> edfelectronics.com<br/>
<strong>Threat Actor:</strong> Panzer<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>EDFelectronics was listed on the Panzer ransomware extortion leak portal. EDFelectronics.com is a Polish engineering company that develops specialized electronics and plasma technology for industrial and research applications.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 22:55 UTC</strong> [UNVERIFIED CLAIM]: EDFelectronics Listed on Panzer Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RURGZWxlY3Ryb25pY3NAUGFuemVy">Panzer Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-edfelectronics.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>panzer</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Flydubai — Flydubai was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-flydubai.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-flydubai.html</guid>
      <pubDate>Tue, 06 Oct 2026 16:15:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> flydubai.com<br/>
<strong>Threat Actor:</strong> Everest<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Flydubai was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 16:15 UTC</strong> [UNVERIFIED CLAIM]: Flydubai Listed on Everest Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Rmx5ZHViYWlAZXZlcmVzdA==">Everest Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-flydubai.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>everest</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Four Hands LLC — Four Hands LLC was listed on the UmBra ransomware extortion leak portal. Four Hands LLC is a global leader in lifestyle home furnishings, designing and wholesaling innovative, artisanal furniture and decor to top retailers and designers worldwide.</title>
      <link>https://securityincident.net/incidents/2026-10-four-hands-llc.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-four-hands-llc.html</guid>
      <pubDate>Tue, 06 Oct 2026 14:54:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> fourhands.com<br/>
<strong>Threat Actor:</strong> UmBra<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Four Hands LLC was listed on the UmBra ransomware extortion leak portal. Four Hands LLC is a global leader in lifestyle home furnishings, designing and wholesaling innovative, artisanal furniture and decor to top retailers and designers worldwide.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 14:54 UTC</strong> [UNVERIFIED CLAIM]: Four Hands LLC Listed on UmBra Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Rm91ciBIYW5kcyBMTENAVW1CcmE=">UmBra Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-four-hands-llc.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>umbra</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Greggio Argento — Greggio Argento was listed on the Deadlock ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-greggio-argento.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-greggio-argento.html</guid>
      <pubDate>Tue, 06 Oct 2026 16:21:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> greggio.com<br/>
<strong>Threat Actor:</strong> Deadlock<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Greggio Argento was listed on the Deadlock ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 16:21 UTC</strong> [UNVERIFIED CLAIM]: Greggio Argento Listed on Deadlock Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/R3JlZ2dpbyBBcmdlbnRvQERlYWRsb2Nr">Deadlock Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-greggio-argento.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>deadlock</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Hygrade — Hygrade was listed on the Akira ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-hygrade.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-hygrade.html</guid>
      <pubDate>Tue, 06 Oct 2026 14:52:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> hygrade.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Hygrade was listed on the Akira ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 14:52 UTC</strong> [UNVERIFIED CLAIM]: Hygrade Listed on Akira Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/SHlncmFkZUBha2lyYQ==">Akira Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-hygrade.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>akira</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] J&amp;D Financial — J&amp;D Financial was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-j-d-financial.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-j-d-financial.html</guid>
      <pubDate>Tue, 06 Oct 2026 09:02:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> jdfinancial.com<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>J&D Financial was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 09:02 UTC</strong> [UNVERIFIED CLAIM]: J&D Financial Listed on Qilin Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/SiZEIEZpbmFuY2lhbEBxaWxpbg==">Qilin Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-j-d-financial.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>qilin</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Kennametal — Kennametal was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-kennametal.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-kennametal.html</guid>
      <pubDate>Tue, 06 Oct 2026 16:15:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> kennametal.com<br/>
<strong>Threat Actor:</strong> Everest<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Kennametal was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 16:15 UTC</strong> [UNVERIFIED CLAIM]: Kennametal Listed on Everest Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/S2VubmFtZXRhbEBldmVyZXN0">Everest Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-kennametal.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>everest</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] KOOKABARRA JUICE — KOOKABARRA JUICE was listed on the Vexy Ransomware ransomware extortion leak portal. French manufacturer specializing in fresh-pressed fruit juices, detox juices, smoothies, nectars and other fresh fruit products, serving both professionals and co...</title>
      <link>https://securityincident.net/incidents/2026-10-kookabarra-juice.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-kookabarra-juice.html</guid>
      <pubDate>Tue, 06 Oct 2026 20:55:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> kookabarra.com<br/>
<strong>Threat Actor:</strong> Vexy Ransomware<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>KOOKABARRA JUICE was listed on the Vexy Ransomware ransomware extortion leak portal. French manufacturer specializing in fresh-pressed fruit juices, detox juices, smoothies, nectars and other fresh fruit products, serving both professionals and co...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 20:55 UTC</strong> [UNVERIFIED CLAIM]: KOOKABARRA JUICE Listed on Vexy Ransomware Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/S09PS0FCQVJSQSBKVUlDRUBWZXh5IFJhbnNvbXdhcmU=">Vexy Ransomware Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-kookabarra-juice.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>vexy ransomware</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] magnals.com — magnals.com was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-magnals-com.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-magnals-com.html</guid>
      <pubDate>Tue, 06 Oct 2026 17:27:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> magnals.com<br/>
<strong>Threat Actor:</strong> Incransom<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>magnals.com was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 17:27 UTC</strong> [UNVERIFIED CLAIM]: magnals.com Listed on Incransom Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/bWFnbmFscy5jb21AaW5jcmFuc29t">Incransom Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-magnals-com.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>incransom</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Michael K Shelby, CPA — Michael K Shelby, CPA was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 18GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-michael-k-shelby-cpa.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-michael-k-shelby-cpa.html</guid>
      <pubDate>Tue, 06 Oct 2026 14:52:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> mkshelbycpa.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Michael K Shelby, CPA was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 18GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 14:52 UTC</strong> [UNVERIFIED CLAIM]: Michael K Shelby, CPA Listed on Akira Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/TWljaGFlbCBLIFNoZWxieSwgQ1BBQGFraXJh">Akira Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-michael-k-shelby-cpa.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>akira</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Morcon Developments — Morcon Developments was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-morcon-developments.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-morcon-developments.html</guid>
      <pubDate>Tue, 06 Oct 2026 16:16:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> morcondevelopments.com<br/>
<strong>Threat Actor:</strong> Everest<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Morcon Developments was listed on the Everest ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 16:16 UTC</strong> [UNVERIFIED CLAIM]: Morcon Developments Listed on Everest Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/TW9yY29uIERldmVsb3BtZW50c0BldmVyZXN0">Everest Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-morcon-developments.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>everest</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[DEVELOPING] Nikkei — Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]</title>
      <link>https://securityincident.net/incidents/2026-10-nikkei.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-nikkei.html</guid>
      <pubDate>Tue, 06 Oct 2026 09:25:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> nikkei.com<br/>
<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 09:25 UTC</strong> [INDEPENDENT VERIFICATION]: Nikkei discloses breaches of employees’ Microsoft, Google email accounts (<a href="https://www.bleepingcomputer.com/news/security/nikkei-discloses-breaches-of-employees-microsoft-google-email-accounts/">BleepingComputer Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-nikkei.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>threat-intel</category>
      <category>developing</category>
    </item>
    <item>
      <title>[EMERGING] Philander Smith University — Philander Smith University was listed on the EndZone ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-philander-smith-university.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-philander-smith-university.html</guid>
      <pubDate>Tue, 06 Oct 2026 07:50:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> philander.edu<br/>
<strong>Threat Actor:</strong> EndZone<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>Philander Smith University was listed on the EndZone ransomware extortion leak portal. Threat actor claims exfiltration of 500GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 07:50 UTC</strong> [UNVERIFIED CLAIM]: Philander Smith University Listed on EndZone Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/UGhpbGFuZGVyIFNtaXRoIFVuaXZlcnNpdHlARW5kWm9uZQ==">EndZone Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-philander-smith-university.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>endzone</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] SweetRush — SweetRush was listed on the Panzer ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-sweetrush.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-sweetrush.html</guid>
      <pubDate>Tue, 06 Oct 2026 17:51:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> sweetrush.com<br/>
<strong>Threat Actor:</strong> Panzer<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>SweetRush was listed on the Panzer ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 17:51 UTC</strong> [UNVERIFIED CLAIM]: SweetRush Listed on Panzer Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/U3dlZXRSdXNoQFBhbnplcg==">Panzer Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-sweetrush.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>panzer</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[DEVELOPING] Wikimedia — The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. &quot;Th...</title>
      <link>https://securityincident.net/incidents/2026-10-wikimedia.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-wikimedia.html</guid>
      <pubDate>Tue, 06 Oct 2026 11:26:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> wikimedia.com<br/>
<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-06<br/>
<strong>Last Updated:</strong> 2026-10-06</p>
<p>The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "Th...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-06 11:26 UTC</strong> [INDEPENDENT VERIFICATION]: Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies (<a href="https://thehackernews.com/2026/10/wikimedia-says-openai-agents-tried-to.html">The Hacker News Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-wikimedia.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>threat-intel</category>
      <category>developing</category>
    </item>
    <item>
      <title>[EMERGING] A...n — A...n was listed on the SilentRansomGroup ransomware extortion leak portal. Redacted entry - full company name pending disclosure (FULL DATA TIMER active).</title>
      <link>https://securityincident.net/incidents/2026-10-a-n.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-a-n.html</guid>
      <pubDate>Mon, 05 Oct 2026 22:27:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> an.com<br/>
<strong>Threat Actor:</strong> SilentRansomGroup<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>A...n was listed on the SilentRansomGroup ransomware extortion leak portal. Redacted entry - full company name pending disclosure (FULL DATA TIMER active).</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 22:27 UTC</strong> [UNVERIFIED CLAIM]: A...n Listed on SilentRansomGroup Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/QS4uLm5AU2lsZW50UmFuc29tR3JvdXA=">SilentRansomGroup Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-a-n.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>silentransomgroup</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[CONFIRMED] Advantest America — State of California Department of Justice data breach disclosure notice filed by Advantest America.</title>
      <link>https://securityincident.net/incidents/2026-10-advantest-america.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-advantest-america.html</guid>
      <pubDate>Mon, 05 Oct 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> advantestamerica.com<br/>
<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>State of California Department of Justice data breach disclosure notice filed by Advantest America.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630848">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-advantest-america.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[EMERGING] anwo.cl — anwo.cl was listed on the Safepay ransomware extortion leak portal. The company was established in 1984 by Víctor Herrmann and has developed into one of the major HVAC distribution businesses …</title>
      <link>https://securityincident.net/incidents/2026-10-anwo-cl.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-anwo-cl.html</guid>
      <pubDate>Mon, 05 Oct 2026 18:28:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> anwo.cl<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>anwo.cl was listed on the Safepay ransomware extortion leak portal. The company was established in 1984 by Víctor Herrmann and has developed into one of the major HVAC distribution businesses …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 18:28 UTC</strong> [UNVERIFIED CLAIM]: anwo.cl Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/YW53by5jbEBzYWZlcGF5">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-anwo-cl.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] bwi-bau.de — bwi-bau.de was listed on the Safepay ransomware extortion leak portal. The organization was established in October 1964 as a subsidiary of the Construction Industry Association of North Rhine-Westphalia. It originally …</title>
      <link>https://securityincident.net/incidents/2026-10-bwi-bau-de.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-bwi-bau-de.html</guid>
      <pubDate>Mon, 05 Oct 2026 19:36:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> bwi-bau.de<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>bwi-bau.de was listed on the Safepay ransomware extortion leak portal. The organization was established in October 1964 as a subsidiary of the Construction Industry Association of North Rhine-Westphalia. It originally …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 19:36 UTC</strong> [UNVERIFIED CLAIM]: bwi-bau.de Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/YndpLWJhdS5kZUBzYWZlcGF5">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-bwi-bau-de.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Cam Group LLC — Cam Group LLC was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z</title>
      <link>https://securityincident.net/incidents/2026-10-cam-group-llc.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-cam-group-llc.html</guid>
      <pubDate>Mon, 05 Oct 2026 11:53:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> camgroupllc.com<br/>
<strong>Threat Actor:</strong> Doommageddon<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>Cam Group LLC was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 11:53 UTC</strong> [UNVERIFIED CLAIM]: Cam Group LLC Listed on Doommageddon Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Q2FtIEdyb3VwIExMQ0BEb29tbWFnZWRkb24=">Doommageddon Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-cam-group-llc.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>doommageddon</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[DEVELOPING] Daiwa Securities — Takashi Nakamichi and Ryo Horiuchi report that Daiwa Securities, Japan&apos;s second-largest brokerage and investment banking firm, is responding to a breach at one of its vendors. Daiwa Securities Group said information on as many as 110,000 clients m...</title>
      <link>https://securityincident.net/incidents/2026-10-daiwa-securities.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-daiwa-securities.html</guid>
      <pubDate>Mon, 05 Oct 2026 12:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> daiwasecurities.com<br/>
<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>Takashi Nakamichi and Ryo Horiuchi report that Daiwa Securities, Japan's second-largest brokerage and investment banking firm, is responding to a breach at one of its vendors. Daiwa Securities Group said information on as many as 110,000 clients m...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 12:30 UTC</strong> [INDEPENDENT VERIFICATION]: Daiwa Securities says info on 110,000 clients may have been leaked in vendor incident (<a href="https://databreaches.net/2026/10/05/daiwa-securities-says-info-on-110000-clients-may-have-been-leaked-in-vendor-incident/">DataBreaches.net Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-daiwa-securities.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>developing</category>
    </item>
    <item>
      <title>[EMERGING] dd-automation.ch — dd-automation.ch was listed on the Safepay ransomware extortion leak portal. The company was entered into the Swiss commercial register in 1997 and specializes in electrical engineering, automation systems, conveyor technology, …</title>
      <link>https://securityincident.net/incidents/2026-10-dd-automation-ch.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-dd-automation-ch.html</guid>
      <pubDate>Mon, 05 Oct 2026 19:39:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> dd-automation.ch<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>dd-automation.ch was listed on the Safepay ransomware extortion leak portal. The company was entered into the Swiss commercial register in 1997 and specializes in electrical engineering, automation systems, conveyor technology, …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 19:39 UTC</strong> [UNVERIFIED CLAIM]: dd-automation.ch Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/ZGQtYXV0b21hdGlvbi5jaEBzYWZlcGF5">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-dd-automation-ch.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[DEVELOPING] Denmark population registry — Denmark&apos;s Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]</title>
      <link>https://securityincident.net/incidents/2026-10-denmark-population-registry.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-denmark-population-registry.html</guid>
      <pubDate>Mon, 05 Oct 2026 15:21:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> denmarkpopulationregistry.com<br/>
<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 15:21 UTC</strong> [INDEPENDENT VERIFICATION]: Denmark population registry data breach affects 8.8 million people (<a href="https://www.bleepingcomputer.com/news/security/denmark-population-registry-data-breach-affects-88-million-people/">BleepingComputer Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-denmark-population-registry.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>threat-intel</category>
      <category>developing</category>
    </item>
    <item>
      <title>[EMERGING] duhaas.sk — duhaas.sk was listed on the Safepay ransomware extortion leak portal. The company was subsequently transformed into a limited liability company in 1992 and established as a joint-stock company in 1994. …</title>
      <link>https://securityincident.net/incidents/2026-10-duhaas-sk.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-duhaas-sk.html</guid>
      <pubDate>Mon, 05 Oct 2026 18:27:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> duhaas.sk<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>duhaas.sk was listed on the Safepay ransomware extortion leak portal. The company was subsequently transformed into a limited liability company in 1992 and established as a joint-stock company in 1994. …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 18:27 UTC</strong> [UNVERIFIED CLAIM]: duhaas.sk Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/ZHVoYWFzLnNrQHNhZmVwYXk=">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-duhaas-sk.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] ENKA Schools — ENKA Schools was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z</title>
      <link>https://securityincident.net/incidents/2026-10-enka-schools.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-enka-schools.html</guid>
      <pubDate>Mon, 05 Oct 2026 11:53:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> enka.k12.tr<br/>
<strong>Threat Actor:</strong> Doommageddon<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>ENKA Schools was listed on the Doommageddon ransomware extortion leak portal. Status: upcoming | Deadline: 2026-10-15T00:00:00Z</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 11:53 UTC</strong> [UNVERIFIED CLAIM]: ENKA Schools Listed on Doommageddon Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RU5LQSBTY2hvb2xzQERvb21tYWdlZGRvbg==">Doommageddon Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-enka-schools.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>doommageddon</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Global Security Concepts — Global Security Concepts was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-global-security-concepts.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-global-security-concepts.html</guid>
      <pubDate>Mon, 05 Oct 2026 21:04:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> gscsecurity.com<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>Global Security Concepts was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 21:04 UTC</strong> [UNVERIFIED CLAIM]: Global Security Concepts Listed on Qilin Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/R2xvYmFsIFNlY3VyaXR5IENvbmNlcHRzQHFpbGlu">Qilin Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-global-security-concepts.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>qilin</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] grundens.com — grundens.com was listed on the Safepay ransomware extortion leak portal. The company&apos;s origins can be traced to 1911, when Carl A. Grundén, the son of a fisherman from Grundsund on …</title>
      <link>https://securityincident.net/incidents/2026-10-grundens-com.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-grundens-com.html</guid>
      <pubDate>Mon, 05 Oct 2026 19:35:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> grundens.com<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>grundens.com was listed on the Safepay ransomware extortion leak portal. The company's origins can be traced to 1911, when Carl A. Grundén, the son of a fisherman from Grundsund on …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 19:35 UTC</strong> [UNVERIFIED CLAIM]: grundens.com Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Z3J1bmRlbnMuY29tQHNhZmVwYXk=">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-grundens-com.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] H&amp;L Manufacturing — H&amp;L Manufacturing was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-h-l-manufacturing.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-h-l-manufacturing.html</guid>
      <pubDate>Mon, 05 Oct 2026 15:59:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> https:hlmanufacturing.com<br/>
<strong>Threat Actor:</strong> Interlock<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>H&L Manufacturing was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 15:59 UTC</strong> [UNVERIFIED CLAIM]: H&L Manufacturing Listed on Interlock Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/SCZMIE1hbnVmYWN0dXJpbmdAaW50ZXJsb2Nr">Interlock Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-h-l-manufacturing.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>interlock</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] halservice.it — halservice.it was listed on the Safepay ransomware extortion leak portal. Established in 1990, the company initially focused on system integration and information-technology services and later expanded into telecommunications following the …</title>
      <link>https://securityincident.net/incidents/2026-10-halservice-it.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-halservice-it.html</guid>
      <pubDate>Mon, 05 Oct 2026 19:36:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> halservice.it<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>halservice.it was listed on the Safepay ransomware extortion leak portal. Established in 1990, the company initially focused on system integration and information-technology services and later expanded into telecommunications following the …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 19:36 UTC</strong> [UNVERIFIED CLAIM]: halservice.it Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/aGFsc2VydmljZS5pdEBzYWZlcGF5">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-halservice-it.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] ikhasas.com — ikhasas.com was listed on the Safepay ransomware extortion leak portal. The group was incorporated as iKHASAS Sdn. Bhd. in 2008 and subsequently expanded beyond construction into property development, hospitality, plantation, …</title>
      <link>https://securityincident.net/incidents/2026-10-ikhasas-com.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-ikhasas-com.html</guid>
      <pubDate>Mon, 05 Oct 2026 18:26:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> ikhasas.com<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>ikhasas.com was listed on the Safepay ransomware extortion leak portal. The group was incorporated as iKHASAS Sdn. Bhd. in 2008 and subsequently expanded beyond construction into property development, hospitality, plantation, …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 18:26 UTC</strong> [UNVERIFIED CLAIM]: ikhasas.com Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/aWtoYXNhcy5jb21Ac2FmZXBheQ==">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-ikhasas-com.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Millensys — Millensys was listed on the Medusalocker ransomware extortion leak portal. Organization with 2 emails extracted. Domain: millensys.com</title>
      <link>https://securityincident.net/incidents/2026-10-millensys.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-millensys.html</guid>
      <pubDate>Mon, 05 Oct 2026 11:08:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> millensys.com<br/>
<strong>Threat Actor:</strong> Medusalocker<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>Millensys was listed on the Medusalocker ransomware extortion leak portal. Organization with 2 emails extracted. Domain: millensys.com</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 11:08 UTC</strong> [UNVERIFIED CLAIM]: Millensys Listed on Medusalocker Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/TWlsbGVuc3lzQG1lZHVzYWxvY2tlcg==">Medusalocker Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-millensys.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>medusalocker</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Nelson Mullins Riley &amp; Scarborough — Nelson Mullins Riley &amp; Scarborough was listed on the SilentRansomGroup ransomware extortion leak portal. They offered $8.000.000 to keep the data from being published.</title>
      <link>https://securityincident.net/incidents/2026-10-nelson-mullins-riley-scarborough.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-nelson-mullins-riley-scarborough.html</guid>
      <pubDate>Mon, 05 Oct 2026 19:25:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> nelsonmullinsrileyscarborough.com<br/>
<strong>Threat Actor:</strong> SilentRansomGroup<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>Nelson Mullins Riley & Scarborough was listed on the SilentRansomGroup ransomware extortion leak portal. They offered $8.000.000 to keep the data from being published.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 19:25 UTC</strong> [UNVERIFIED CLAIM]: Nelson Mullins Riley & Scarborough Listed on SilentRansomGroup Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/TmVsc29uIE11bGxpbnMgUmlsZXkgJiBTY2FyYm9yb3VnaEBTaWxlbnRSYW5zb21Hcm91cA==">SilentRansomGroup Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-nelson-mullins-riley-scarborough.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>silentransomgroup</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] O2 Dental Group — O2 Dental Group was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-o2-dental-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-o2-dental-group.html</guid>
      <pubDate>Mon, 05 Oct 2026 15:01:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> o2smiles.com<br/>
<strong>Threat Actor:</strong> Interlock<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>O2 Dental Group was listed on the Interlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 15:01 UTC</strong> [UNVERIFIED CLAIM]: O2 Dental Group Listed on Interlock Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/TzIgRGVudGFsIEdyb3VwQGludGVybG9jaw==">Interlock Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-o2-dental-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>interlock</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Onsemi — Onsemi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-onsemi.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-onsemi.html</guid>
      <pubDate>Mon, 05 Oct 2026 13:15:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> onsemi.com<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>Onsemi was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 13:15 UTC</strong> [UNVERIFIED CLAIM]: Onsemi Listed on Qilin Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/T25zZW1pQHFpbGlu">Qilin Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-onsemi.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>qilin</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[CONFIRMED] Sheppard, Mullin, Richter &amp; Hampton — State of California Department of Justice data breach disclosure notice filed by Sheppard, Mullin, Richter &amp; Hampton.</title>
      <link>https://securityincident.net/incidents/2026-10-sheppard-mullin-richter-hampto.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-sheppard-mullin-richter-hampto.html</guid>
      <pubDate>Fri, 02 Oct 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> sheppardmullinrichterhampto.com<br/>
<strong>Threat Actor:</strong> SilentRansomGroup<br/>
<strong>Open Weights Confidence:</strong> 92% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>State of California Department of Justice data breach disclosure notice filed by Sheppard, Mullin, Richter & Hampton.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630779">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-10-05 19:25 UTC</strong> [UNVERIFIED CLAIM]: Sheppard, Mullin, Richter & Hampton Listed on SilentRansomGroup Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/U2hlcHBhcmQsIE11bGxpbiwgUmljaHRlciAmIEhhbXB0b25AU2lsZW50UmFuc29tR3JvdXA=">SilentRansomGroup Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-sheppard-mullin-richter-hampto.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>silentransomgroup</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] sterrer.net — sterrer.net was listed on the Safepay ransomware extortion leak portal. The company has operated since 1979 and combines agricultural production with technical services for commercial poultry farms. Its activities include …</title>
      <link>https://securityincident.net/incidents/2026-10-sterrer-net.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-sterrer-net.html</guid>
      <pubDate>Mon, 05 Oct 2026 18:26:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> sterrer.net<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>sterrer.net was listed on the Safepay ransomware extortion leak portal. The company has operated since 1979 and combines agricultural production with technical services for commercial poultry farms. Its activities include …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 18:26 UTC</strong> [UNVERIFIED CLAIM]: sterrer.net Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/c3RlcnJlci5uZXRAc2FmZXBheQ==">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-sterrer-net.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] stuecheli.ch — stuecheli.ch was listed on the Safepay ransomware extortion leak portal. The firm was founded by architect Werner Stücheli in 1946 and has developed into a third-generation architectural practice. It is …</title>
      <link>https://securityincident.net/incidents/2026-10-stuecheli-ch.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-stuecheli-ch.html</guid>
      <pubDate>Mon, 05 Oct 2026 19:37:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> stuecheli.ch<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>stuecheli.ch was listed on the Safepay ransomware extortion leak portal. The firm was founded by architect Werner Stücheli in 1946 and has developed into a third-generation architectural practice. It is …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 19:37 UTC</strong> [UNVERIFIED CLAIM]: stuecheli.ch Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/c3R1ZWNoZWxpLmNoQHNhZmVwYXk=">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-stuecheli-ch.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] t-systems.com — t-systems.com was listed on the Safepay ransomware extortion leak portal. Headquartered in Germany, the company operates internationally and has locations in 26 countries, employing more than 26,000 people. T-Systems specializes …</title>
      <link>https://securityincident.net/incidents/2026-10-t-systems-com.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-t-systems-com.html</guid>
      <pubDate>Mon, 05 Oct 2026 19:34:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> t-systems.com<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>t-systems.com was listed on the Safepay ransomware extortion leak portal. Headquartered in Germany, the company operates internationally and has locations in 26 countries, employing more than 26,000 people. T-Systems specializes …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 19:34 UTC</strong> [UNVERIFIED CLAIM]: t-systems.com Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/dC1zeXN0ZW1zLmNvbUBzYWZlcGF5">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-t-systems-com.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Turn5 — Turn5 was listed on the Global Secret Group ransomware extortion leak portal. Threat actor claims exfiltration of 328 GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-turn5.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-turn5.html</guid>
      <pubDate>Mon, 05 Oct 2026 18:53:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> turn5.com<br/>
<strong>Threat Actor:</strong> Global Secret Group<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-05<br/>
<strong>Last Updated:</strong> 2026-10-05</p>
<p>Turn5 was listed on the Global Secret Group ransomware extortion leak portal. Threat actor claims exfiltration of 328 GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-05 18:53 UTC</strong> [UNVERIFIED CLAIM]: Turn5 Listed on Global Secret Group Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/VHVybjVAR2xvYmFsIFNlY3JldCBHcm91cA==">Global Secret Group Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-turn5.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>global secret group</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Automovil Club del Ecuador ANETA — Automovil Club del Ecuador ANETA was listed on the Barracuda ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-automovil-club-del-ecuador-aneta.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-automovil-club-del-ecuador-aneta.html</guid>
      <pubDate>Fri, 02 Oct 2026 04:50:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> aneta.org.ec<br/>
<strong>Threat Actor:</strong> Barracuda<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Automovil Club del Ecuador ANETA was listed on the Barracuda ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 04:50 UTC</strong> [UNVERIFIED CLAIM]: Automovil Club del Ecuador ANETA Listed on Barracuda Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/QXV0b21vdmlsIENsdWIgZGVsIEVjdWFkb3IgQU5FVEFAQmFycmFjdWRh">Barracuda Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-automovil-club-del-ecuador-aneta.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>barracuda</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] EdgeEndo® USA — EdgeEndo® USA was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 103 GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-edgeendo-usa.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-edgeendo-usa.html</guid>
      <pubDate>Fri, 02 Oct 2026 12:50:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> edgeendo.com<br/>
<strong>Threat Actor:</strong> Booba Project<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>EdgeEndo® USA was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 103 GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 12:50 UTC</strong> [UNVERIFIED CLAIM]: EdgeEndo® USA Listed on Booba Project Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RWRnZUVuZG/CriBVU0FAQm9vYmEgUHJvamVjdA==">Booba Project Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-edgeendo-usa.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>booba project</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Far West Contractors — Far West Contractors was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-far-west-contractors.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-far-west-contractors.html</guid>
      <pubDate>Fri, 02 Oct 2026 07:50:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> farwestcontractors.com<br/>
<strong>Threat Actor:</strong> Deadlock<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Far West Contractors was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 07:50 UTC</strong> [UNVERIFIED CLAIM]: Far West Contractors Listed on Deadlock Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RmFyIFdlc3QgQ29udHJhY3RvcnNARGVhZGxvY2s=">Deadlock Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-far-west-contractors.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>deadlock</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[CONFIRMED] Fragomen, Del Rey, Bernsen &amp; Loewy — State of California Department of Justice data breach disclosure notice filed by Fragomen, Del Rey, Bernsen &amp; Loewy.</title>
      <link>https://securityincident.net/incidents/2026-10-fragomen-del-rey-bernsen-loewy.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-fragomen-del-rey-bernsen-loewy.html</guid>
      <pubDate>Fri, 02 Oct 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> fragomendelreybernsenloewy.com<br/>
<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>State of California Department of Justice data breach disclosure notice filed by Fragomen, Del Rey, Bernsen & Loewy.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630760">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-fragomen-del-rey-bernsen-loewy.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[EMERGING] Inova Semiconductors GmbH — Inova Semiconductors GmbH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-inova-semiconductors-gmbh.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-inova-semiconductors-gmbh.html</guid>
      <pubDate>Fri, 02 Oct 2026 14:04:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> inova-semiconductors.de<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Inova Semiconductors GmbH was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 14:04 UTC</strong> [UNVERIFIED CLAIM]: Inova Semiconductors GmbH Listed on Qilin Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/SW5vdmEgU2VtaWNvbmR1Y3RvcnMgR21iSEBxaWxpbg==">Qilin Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-inova-semiconductors-gmbh.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>qilin</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Jampac Alimentos — Jampac Alimentos was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 35GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-jampac-alimentos.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-jampac-alimentos.html</guid>
      <pubDate>Fri, 02 Oct 2026 14:59:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> jampacalimentos.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 13% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Jampac Alimentos was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 35GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 14:59 UTC</strong> [UNVERIFIED CLAIM]: Jampac Alimentos Listed on Akira Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/SmFtcGFjIEFsaW1lbnRvc0Bha2lyYQ==">Akira Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-jampac-alimentos.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>akira</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Main Place Mall — Main Place Mall was listed on the Netrunner ransomware extortion leak portal. Main Place is part of a mixed development that combines residence, leisure, retail and dining to bring you the ultimate city-suburban lifestyle.</title>
      <link>https://securityincident.net/incidents/2026-10-main-place-mall.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-main-place-mall.html</guid>
      <pubDate>Fri, 02 Oct 2026 00:05:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> mainplace.com.my<br/>
<strong>Threat Actor:</strong> Netrunner<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Main Place Mall was listed on the Netrunner ransomware extortion leak portal. Main Place is part of a mixed development that combines residence, leisure, retail and dining to bring you the ultimate city-suburban lifestyle.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 00:05 UTC</strong> [UNVERIFIED CLAIM]: Main Place Mall Listed on Netrunner Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/TWFpbiBQbGFjZSBNYWxsQG5ldHJ1bm5lcg==">Netrunner Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-main-place-mall.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>netrunner</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Pacific Tank Lines — Pacific Tank Lines was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 13GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-pacific-tank-lines.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-pacific-tank-lines.html</guid>
      <pubDate>Fri, 02 Oct 2026 14:24:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> pacifictanklines.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 13% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Pacific Tank Lines was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 13GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 14:24 UTC</strong> [UNVERIFIED CLAIM]: Pacific Tank Lines Listed on Akira Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/UGFjaWZpYyBUYW5rIExpbmVzQGFraXJh">Akira Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-pacific-tank-lines.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>akira</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Raleigh Family Medicine — Raleigh Family Medicine was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 1 GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-raleigh-family-medicine.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-raleigh-family-medicine.html</guid>
      <pubDate>Fri, 02 Oct 2026 12:51:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> rfppa.com<br/>
<strong>Threat Actor:</strong> Booba Project<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Raleigh Family Medicine was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 1 GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 12:51 UTC</strong> [UNVERIFIED CLAIM]: Raleigh Family Medicine Listed on Booba Project Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/UmFsZWlnaCBGYW1pbHkgTWVkaWNpbmVAQm9vYmEgUHJvamVjdA==">Booba Project Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-raleigh-family-medicine.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>booba project</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Sangre de Cristo Electric Association — Sangre de Cristo Electric Association was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-sangre-de-cristo-electric-association.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-sangre-de-cristo-electric-association.html</guid>
      <pubDate>Fri, 02 Oct 2026 01:33:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> myelectric.coop<br/>
<strong>Threat Actor:</strong> Incransom<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Sangre de Cristo Electric Association was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 01:33 UTC</strong> [UNVERIFIED CLAIM]: Sangre de Cristo Electric Association Listed on Incransom Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/U2FuZ3JlIGRlIENyaXN0byBFbGVjdHJpYyBBc3NvY2lhdGlvbkBpbmNyYW5zb20=">Incransom Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-sangre-de-cristo-electric-association.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>incransom</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Soni Medical Centre — Soni Medical Centre was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 5.5 GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-soni-medical-centre.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-soni-medical-centre.html</guid>
      <pubDate>Fri, 02 Oct 2026 12:50:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> lakewoodmedical.ca<br/>
<strong>Threat Actor:</strong> Booba Project<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Soni Medical Centre was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 5.5 GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 12:50 UTC</strong> [UNVERIFIED CLAIM]: Soni Medical Centre Listed on Booba Project Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/U29uaSBNZWRpY2FsIENlbnRyZUBCb29iYSBQcm9qZWN0">Booba Project Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-soni-medical-centre.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>booba project</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] The Official College of Architects of León (COAL) — The Official College of Architects of León (COAL) was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 77GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-the-official-college-of-architects-of-leon-coal.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-the-official-college-of-architects-of-leon-coal.html</guid>
      <pubDate>Fri, 02 Oct 2026 14:59:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> theofficialcollegeofarchitectsofleoncoal.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>The Official College of Architects of León (COAL) was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 77GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 14:59 UTC</strong> [UNVERIFIED CLAIM]: The Official College of Architects of León (COAL) Listed on Akira Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/VGhlIE9mZmljaWFsIENvbGxlZ2Ugb2YgQXJjaGl0ZWN0cyBvZiBMZcOzbiAoQ09BTClAYWtpcmE=">Akira Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-the-official-college-of-architects-of-leon-coal.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>akira</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Tronex A/S — Tronex A/S was listed on the Wallstreet ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-tronex-a-s.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-tronex-a-s.html</guid>
      <pubDate>Fri, 02 Oct 2026 11:55:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> tronexas.com<br/>
<strong>Threat Actor:</strong> Wallstreet<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>Tronex A/S was listed on the Wallstreet ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 11:55 UTC</strong> [UNVERIFIED CLAIM]: Tronex A/S Listed on Wallstreet Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/VHJvbmV4IEEvU0BXYWxsc3RyZWV0">Wallstreet Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-tronex-a-s.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>wallstreet</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] UNION FA — UNION FA was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-union-fa.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-union-fa.html</guid>
      <pubDate>Fri, 02 Oct 2026 07:50:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> rogdianakis.gr<br/>
<strong>Threat Actor:</strong> Deadlock<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>UNION FA was listed on the Deadlock ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 07:50 UTC</strong> [UNVERIFIED CLAIM]: UNION FA Listed on Deadlock Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/VU5JT04gRkFARGVhZGxvY2s=">Deadlock Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-union-fa.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>deadlock</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] University of Illinois Chicago — University of Illinois Chicago was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 344 GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-university-of-illinois-chicago.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-university-of-illinois-chicago.html</guid>
      <pubDate>Fri, 02 Oct 2026 12:50:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> uic.edu<br/>
<strong>Threat Actor:</strong> Booba Project<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>University of Illinois Chicago was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 344 GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 12:50 UTC</strong> [UNVERIFIED CLAIM]: University of Illinois Chicago Listed on Booba Project Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/VW5pdmVyc2l0eSBvZiBJbGxpbm9pcyBDaGljYWdvQEJvb2JhIFByb2plY3Q=">Booba Project Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-university-of-illinois-chicago.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>booba project</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] www.kres.cz — www.kres.cz was listed on the Krybit ransomware extortion leak portal. KRES spol. s r.o. is a Czech company headquartered in Krnov, Moravskoslezský Region, Czech Republic, specializing in wh...</title>
      <link>https://securityincident.net/incidents/2026-10-www-kres-cz.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-www-kres-cz.html</guid>
      <pubDate>Fri, 02 Oct 2026 09:31:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> kres.cz<br/>
<strong>Threat Actor:</strong> Krybit<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>www.kres.cz was listed on the Krybit ransomware extortion leak portal. KRES spol. s r.o. is a Czech company headquartered in Krnov, Moravskoslezský Region, Czech Republic, specializing in wh...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 09:31 UTC</strong> [UNVERIFIED CLAIM]: www.kres.cz Listed on Krybit Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/d3d3LmtyZXMuY3pAa3J5Yml0">Krybit Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-www-kres-cz.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>krybit</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] www.pierrefeu.fr — www.pierrefeu.fr was listed on the Krybit ransomware extortion leak portal. Pierrefeu Immobilier is an independent French real estate agency founded in 1963, headquartered in Tarare, in the Nord-O...</title>
      <link>https://securityincident.net/incidents/2026-10-www-pierrefeu-fr.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-www-pierrefeu-fr.html</guid>
      <pubDate>Fri, 02 Oct 2026 09:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> pierrefeu.fr<br/>
<strong>Threat Actor:</strong> Krybit<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>www.pierrefeu.fr was listed on the Krybit ransomware extortion leak portal. Pierrefeu Immobilier is an independent French real estate agency founded in 1963, headquartered in Tarare, in the Nord-O...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 09:30 UTC</strong> [UNVERIFIED CLAIM]: www.pierrefeu.fr Listed on Krybit Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/d3d3LnBpZXJyZWZldS5mckBrcnliaXQ=">Krybit Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-www-pierrefeu-fr.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>krybit</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] www.raajratna.com — www.raajratna.com was listed on the Krybit ransomware extortion leak portal. Raajratna Metal Industries Limited (RMIL) is a leading Indian public limited company incorporated on May 9, 1988, headqu...</title>
      <link>https://securityincident.net/incidents/2026-10-www-raajratna-com.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-www-raajratna-com.html</guid>
      <pubDate>Fri, 02 Oct 2026 09:31:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> raajratna.com<br/>
<strong>Threat Actor:</strong> Krybit<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-02<br/>
<strong>Last Updated:</strong> 2026-10-02</p>
<p>www.raajratna.com was listed on the Krybit ransomware extortion leak portal. Raajratna Metal Industries Limited (RMIL) is a leading Indian public limited company incorporated on May 9, 1988, headqu...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-02 09:31 UTC</strong> [UNVERIFIED CLAIM]: www.raajratna.com Listed on Krybit Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/d3d3LnJhYWpyYXRuYS5jb21Aa3J5Yml0">Krybit Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-www-raajratna-com.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>krybit</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[CONFIRMED] Microsoft — Microsoft disclosed an intrusion by Russian foreign intelligence threat group Midnight Blizzard (APT29), accessing senior leadership corporate emails and source code.</title>
      <link>https://securityincident.net/incidents/2024-01-microsoft-midnight-blizzard.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2024-01-microsoft-midnight-blizzard.html</guid>
      <pubDate>Fri, 12 Jan 2024 18:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> microsoft.com<br/>
<strong>Threat Actor:</strong> Midnight Blizzard (APT29)<br/>
<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 3<br/>
<strong>First Seen:</strong> 2024-01-12<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Microsoft disclosed an intrusion by Russian foreign intelligence threat group Midnight Blizzard (APT29), accessing senior leadership corporate emails and source code.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2024-01-12 18:00 UTC</strong> [CONFIRMED BY TARGET]: Microsoft security team detects Russian state-sponsored threat actor Midnight Blizzard accessing corporate email systems via legacy OAuth tenant test account. (<a href="https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/">Microsoft Security Response Center (MSRC) Advisory</a>)</li>
  <li><strong>2024-01-19 21:00 UTC</strong> [CONFIRMED BY REGULATOR]: Microsoft files Form 8-K Item 1.05 detailing Midnight Blizzard intrusion into senior executive email accounts and cybersecurity staff communications. (<a href="https://www.sec.gov/Archives/edgar/data/789019/000078901924000004/msft-20240119.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0000789019-24-000004)</a>)</li>
  <li><strong>2024-03-08 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: Microsoft Form 8-K update discloses threat actor used exfiltrated email secrets to gain unauthorized access to internal source code repositories. (<a href="https://www.sec.gov/Archives/edgar/data/789019/000078901924000008/msft-20240308.htm">SEC EDGAR 8-K Item 1.05 Update (Adsh 0000789019-24-000008)</a>)</li>
  <li><strong>2026-10-01 19:32 UTC</strong> [INDEPENDENT VERIFICATION]: Microsoft says threat actors are ahead in the early AI race (<a href="https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/">BleepingComputer Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2024-01-microsoft-midnight-blizzard.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>nation-state</category>
      <category>apt29</category>
      <category>confirmed</category>
      <category>threat-intel</category>
      <category>developing</category>
    </item>
    <item>
      <title>[CONFIRMED] Bitget — Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]</title>
      <link>https://securityincident.net/incidents/2026-09-bitget.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-bitget.html</guid>
      <pubDate>Mon, 28 Sep 2026 09:25:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> bitget.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 74% (CONFIRMED BY TARGET)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-25<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-28 09:25 UTC</strong> [INDEPENDENT VERIFICATION]: Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist (<a href="https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/">BleepingComputer Report</a>)</li>
  <li><strong>2026-09-28 17:42 UTC</strong> [INDEPENDENT VERIFICATION]: Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M (<a href="https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html">The Hacker News Intelligence Notice</a>)</li>
  <li><strong>2026-09-25 10:35 UTC</strong> [INDEPENDENT VERIFICATION]: Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise (<a href="https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html">The Hacker News Intelligence Notice</a>)</li>
  <li><strong>2026-09-30 11:11 UTC</strong> [INDEPENDENT VERIFICATION]: Bitget hacked via zero-day in third-party security products (<a href="https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/">BleepingComputer Report</a>)</li>
  <li><strong>2026-10-01 05:21 UTC</strong> [CONFIRMED BY TARGET]: Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft (<a href="https://thehackernews.com/2026/10/bitget-confirms-third-party-zero-day.html">The Hacker News Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-bitget.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>threat-intel</category>
      <category>developing</category>
    </item>
    <item>
      <title>[DEVELOPING] DIVD — The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]</title>
      <link>https://securityincident.net/incidents/2026-09-divd.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-divd.html</guid>
      <pubDate>Wed, 30 Sep 2026 19:49:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> divd.nl<br/>
<strong>Open Weights Confidence:</strong> 42% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-30<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-30 19:49 UTC</strong> [INDEPENDENT VERIFICATION]: DIVD says Zammad zero-days enabled AI-driven network breach (<a href="https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/">BleepingComputer Report</a>)</li>
  <li><strong>2026-10-01 10:42 UTC</strong> [INDEPENDENT VERIFICATION]: Zammad Zero-Days Exploited in AI-Powered DIVD Hack (<a href="https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/">SecurityWeek Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-divd.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>threat-intel</category>
      <category>developing</category>
    </item>
    <item>
      <title>[CONFIRMED] Greenberg Traurig — Global law firm Greenberg Traurig was compromised by Silent Ransom Group, resulting in the exfiltration and notification of over 126,000 individuals.</title>
      <link>https://securityincident.net/incidents/2026-09-greenberg-traurig.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-greenberg-traurig.html</guid>
      <pubDate>Mon, 14 Sep 2026 11:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> gtlaw.com<br/>
<strong>Threat Actor:</strong> RansomHub<br/>
<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-09<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Global law firm Greenberg Traurig was compromised by Silent Ransom Group, resulting in the exfiltration and notification of over 126,000 individuals.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-14 11:30 UTC</strong> [INDEPENDENT VERIFICATION]: Silent Ransom Group lists Greenberg Traurig on extortion site; forensic investigation confirms 126k individuals affected. (<a href="https://databreaches.net/2026/09/14/silent-ransom-group-hacked-greenberg-traurig-who-notifies-the-126k-affected/">DataBreaches.net Incident Audit</a>)</li>
  <li><strong>2026-09-09 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629493">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-10-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630659">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-greenberg-traurig.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>investigative</category>
      <category>legal</category>
      <category>ransomware-claim</category>
      <category>developing</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[DEVELOPING] U.S. Department of Defense (Pentagon) — Sean Lyngaas and Davis Winkie report: A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national s...</title>
      <link>https://securityincident.net/incidents/2026-09-us-dod-pentagon.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-us-dod-pentagon.html</guid>
      <pubDate>Sat, 26 Sep 2026 11:47:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> defense.gov<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 70% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 3<br/>
<strong>First Seen:</strong> 2026-09-26<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Sean Lyngaas and Davis Winkie report: A data breach at the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national s...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-26 11:47 UTC</strong> [INDEPENDENT VERIFICATION]: Pentagon data breach of military personnel raises national security concerns (<a href="https://databreaches.net/2026/09/26/pentagon-data-breach-of-military-personnel-raises-national-security-concerns/">DataBreaches.net Report</a>)</li>
  <li><strong>2026-09-29 12:25 UTC</strong> [INDEPENDENT VERIFICATION]: Pentagon Personnel Agency Data Breach Impacts 3 Million People (<a href="https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/">SecurityWeek Intelligence Notice</a>)</li>
  <li><strong>2026-10-01 09:44 UTC</strong> [INDEPENDENT VERIFICATION]: Hackers stole Pentagon personnel records of over 3 million people (<a href="https://www.bleepingcomputer.com/news/security/hackers-breach-pentagon-human-resources-management-system-steal-data-of-nearly-3-million-people/">BleepingComputer Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-us-dod-pentagon.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>developing</category>
      <category>threat-intel</category>
    </item>
    <item>
      <title>[CONFIRMED] Aldrich Services — State of California Department of Justice data breach disclosure notice filed by Aldrich Services.</title>
      <link>https://securityincident.net/incidents/2026-10-aldrich-services.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-aldrich-services.html</guid>
      <pubDate>Thu, 01 Oct 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> aldrichservices.com<br/>
<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>State of California Department of Justice data breach disclosure notice filed by Aldrich Services.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630682">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-aldrich-services.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[EMERGING] ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C — ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 70 GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-associated-gastroenterologists-of-central-new.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-associated-gastroenterologists-of-central-new.html</guid>
      <pubDate>Thu, 01 Oct 2026 14:50:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> gastrocny.com<br/>
<strong>Threat Actor:</strong> Booba Project<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 70 GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 14:50 UTC</strong> [UNVERIFIED CLAIM]: ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C Listed on Booba Project Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/QVNTT0NJQVRFRCBHQVNUUk9FTlRFUk9MT0dJU1RTIE9GIENFTlRSQUwgTkVXIFlPUkssIFAuQ0BCb29iYSBQcm9qZWN0">Booba Project Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-associated-gastroenterologists-of-central-new.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>booba project</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] C*ro *nty *es — C*ro *nty *es was listed on the Nightspire ransomware extortion leak portal. Data is not available now.</title>
      <link>https://securityincident.net/incidents/2026-10-c-ro-nty-es.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-c-ro-nty-es.html</guid>
      <pubDate>Thu, 01 Oct 2026 13:35:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> crontyes.com<br/>
<strong>Threat Actor:</strong> Nightspire<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>C*ro *nty *es was listed on the Nightspire ransomware extortion leak portal. Data is not available now.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 13:35 UTC</strong> [UNVERIFIED CLAIM]: C*ro *nty *es Listed on Nightspire Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/QypybyAqbnR5ICplc0BuaWdodHNwaXJl">Nightspire Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-c-ro-nty-es.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>nightspire</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Den Hartog Industries — Den Hartog Industries was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-den-hartog-industries.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-den-hartog-industries.html</guid>
      <pubDate>Thu, 01 Oct 2026 11:29:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> denhartogindustries.com<br/>
<strong>Threat Actor:</strong> Incransom<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Den Hartog Industries was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 11:29 UTC</strong> [UNVERIFIED CLAIM]: Den Hartog Industries Listed on Incransom Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RGVuIEhhcnRvZyBJbmR1c3RyaWVzQGluY3JhbnNvbQ==">Incransom Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-den-hartog-industries.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>incransom</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] DISK PRECISION GROUP - diskprecision.com — DISK PRECISION GROUP - diskprecision.com was listed on the Krybit ransomware extortion leak portal. - Disk Precision Industries Pte Ltd (Singapore, est. 1986)   - Spacetech Industrial Pte Ltd (Singapore)   - Niteac Eng...</title>
      <link>https://securityincident.net/incidents/2026-10-disk-precision-group-diskprecision-com.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-disk-precision-group-diskprecision-com.html</guid>
      <pubDate>Thu, 01 Oct 2026 14:59:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> disk precision group - diskprecision.com<br/>
<strong>Threat Actor:</strong> Krybit<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>DISK PRECISION GROUP - diskprecision.com was listed on the Krybit ransomware extortion leak portal. - Disk Precision Industries Pte Ltd (Singapore, est. 1986)   - Spacetech Industrial Pte Ltd (Singapore)   - Niteac Eng...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 14:59 UTC</strong> [UNVERIFIED CLAIM]: DISK PRECISION GROUP - diskprecision.com Listed on Krybit Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RElTSyBQUkVDSVNJT04gR1JPVVAgLSBkaXNrcHJlY2lzaW9uLmNvbUBrcnliaXQ=">Krybit Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-disk-precision-group-diskprecision-com.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>krybit</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] DPL Group — DPL Group was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 8GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-dpl-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-dpl-group.html</guid>
      <pubDate>Thu, 01 Oct 2026 13:27:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> dplgroup.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>DPL Group was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 8GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 13:27 UTC</strong> [UNVERIFIED CLAIM]: DPL Group Listed on Akira Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RFBMIEdyb3VwQGFraXJh">Akira Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-dpl-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>akira</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Dynamic Office Solutions — Dynamic Office Solutions was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-dynamic-office-solutions.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-dynamic-office-solutions.html</guid>
      <pubDate>Thu, 01 Oct 2026 09:04:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> dynamicos.co.uk<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Dynamic Office Solutions was listed on the Qilin ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 09:04 UTC</strong> [UNVERIFIED CLAIM]: Dynamic Office Solutions Listed on Qilin Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RHluYW1pYyBPZmZpY2UgU29sdXRpb25zQHFpbGlu">Qilin Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-dynamic-office-solutions.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>qilin</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] EURODITEL/RESOTELECOM — EURODITEL/RESOTELECOM was listed on the Krybit ransomware extortion leak portal. Euroditel is a French managed services provider (MSP) specializing in telephony and unified communications. Based in th...</title>
      <link>https://securityincident.net/incidents/2026-10-euroditel-resotelecom.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-euroditel-resotelecom.html</guid>
      <pubDate>Thu, 01 Oct 2026 21:33:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> euroditel.com<br/>
<strong>Threat Actor:</strong> Krybit<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>EURODITEL/RESOTELECOM was listed on the Krybit ransomware extortion leak portal. Euroditel is a French managed services provider (MSP) specializing in telephony and unified communications. Based in th...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 21:33 UTC</strong> [UNVERIFIED CLAIM]: EURODITEL/RESOTELECOM Listed on Krybit Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RVVST0RJVEVML1JFU09URUxFQ09NQGtyeWJpdA==">Krybit Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-euroditel-resotelecom.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>krybit</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[DEVELOPING] Fortinet — Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]</title>
      <link>https://securityincident.net/incidents/2026-10-fortinet.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-fortinet.html</guid>
      <pubDate>Thu, 01 Oct 2026 22:42:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> fortinet.com<br/>
<strong>Open Weights Confidence:</strong> 35% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 22:42 UTC</strong> [INDEPENDENT VERIFICATION]: Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (<a href="https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/">BleepingComputer Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-fortinet.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>threat-intel</category>
      <category>developing</category>
    </item>
    <item>
      <title>[EMERGING] FUNAP - Fundação &quot;Prof. Dr. Manoel Pedro Pimentel&quot; — FUNAP - Fundação &quot;Prof. Dr. Manoel Pedro Pimentel&quot; was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 26 GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-funap-fundacao-prof-dr-manoel-pedro-pimentel.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-funap-fundacao-prof-dr-manoel-pedro-pimentel.html</guid>
      <pubDate>Thu, 01 Oct 2026 14:50:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> funap.sp.gov.br<br/>
<strong>Threat Actor:</strong> Booba Project<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" was listed on the Booba Project ransomware extortion leak portal. Threat actor claims exfiltration of 26 GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 14:50 UTC</strong> [UNVERIFIED CLAIM]: FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" Listed on Booba Project Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/RlVOQVAgLSBGdW5kYcOnw6NvICJQcm9mLiBEci4gTWFub2VsIFBlZHJvIFBpbWVudGVsIkBCb29iYSBQcm9qZWN0">Booba Project Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-funap-fundacao-prof-dr-manoel-pedro-pimentel.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>booba project</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Graybar Electric Company, Inc. — Graybar Electric Company, Inc. was listed on the Redact ransomware extortion leak portal. Sector: Electrical Equipment | Revenue: $11B USD</title>
      <link>https://securityincident.net/incidents/2026-10-graybar-electric-company-inc.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-graybar-electric-company-inc.html</guid>
      <pubDate>Thu, 01 Oct 2026 12:55:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> graybarelectriccompanyinc.com<br/>
<strong>Threat Actor:</strong> Redact<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Graybar Electric Company, Inc. was listed on the Redact ransomware extortion leak portal. Sector: Electrical Equipment | Revenue: $11B USD</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 12:55 UTC</strong> [UNVERIFIED CLAIM]: Graybar Electric Company, Inc. Listed on Redact Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/R3JheWJhciBFbGVjdHJpYyBDb21wYW55LCBJbmMuQFJlZGFjdA==">Redact Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-graybar-electric-company-inc.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>redact</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Guardian Pharmacy LLC — Guardian Pharmacy LLC was listed on the Incransom ransomware extortion leak portal. Hacked; more news coming soon. . .</title>
      <link>https://securityincident.net/incidents/2026-10-guardian-pharmacy-llc.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-guardian-pharmacy-llc.html</guid>
      <pubDate>Thu, 01 Oct 2026 11:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> guardianpharmacyllc.com<br/>
<strong>Threat Actor:</strong> Incransom<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Guardian Pharmacy LLC was listed on the Incransom ransomware extortion leak portal. Hacked; more news coming soon. . .</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 11:30 UTC</strong> [UNVERIFIED CLAIM]: Guardian Pharmacy LLC Listed on Incransom Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/R3VhcmRpYW4gUGhhcm1hY3kgTExDQGluY3JhbnNvbQ==">Incransom Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-guardian-pharmacy-llc.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>incransom</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Krycler, Ervin, Taubman &amp; Kaminsky — Krycler, Ervin, Taubman &amp; Kaminsky was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 88GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-krycler-ervin-taubman-kaminsky.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-krycler-ervin-taubman-kaminsky.html</guid>
      <pubDate>Thu, 01 Oct 2026 12:56:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> kryclerervintaubmankaminsky.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Krycler, Ervin, Taubman & Kaminsky was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 88GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 12:56 UTC</strong> [UNVERIFIED CLAIM]: Krycler, Ervin, Taubman & Kaminsky Listed on Akira Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/S3J5Y2xlciwgRXJ2aW4sIFRhdWJtYW4gJiBLYW1pbnNreUBha2lyYQ==">Akira Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-krycler-ervin-taubman-kaminsky.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>akira</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] LA PONDEROSA — LA PONDEROSA was listed on the Emperador ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-la-ponderosa.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-la-ponderosa.html</guid>
      <pubDate>Thu, 01 Oct 2026 09:51:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> laponderosa.com<br/>
<strong>Threat Actor:</strong> Emperador<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>LA PONDEROSA was listed on the Emperador ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 09:51 UTC</strong> [UNVERIFIED CLAIM]: LA PONDEROSA Listed on Emperador Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/TEEgUE9OREVST1NBQGVtcGVyYWRvcg==">Emperador Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-la-ponderosa.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>emperador</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Laboratorios Roemmers SAICF — Laboratorios Roemmers SAICF was listed on the Aurora ransomware extortion leak portal. Threat actor claims exfiltration of 82 GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-laboratorios-roemmers-saicf.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-laboratorios-roemmers-saicf.html</guid>
      <pubDate>Thu, 01 Oct 2026 06:55:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> roemmers.com.ar<br/>
<strong>Threat Actor:</strong> Aurora<br/>
<strong>Open Weights Confidence:</strong> 13% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Laboratorios Roemmers SAICF was listed on the Aurora ransomware extortion leak portal. Threat actor claims exfiltration of 82 GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 06:55 UTC</strong> [UNVERIFIED CLAIM]: Laboratorios Roemmers SAICF Listed on Aurora Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/TGFib3JhdG9yaW9zIFJvZW1tZXJzIFNBSUNGQGF1cm9yYQ==">Aurora Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-laboratorios-roemmers-saicf.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>aurora</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[CONFIRMED] Lincoln Property Company Commercial — State of California Department of Justice data breach disclosure notice filed by Lincoln Property Company Commercial.</title>
      <link>https://securityincident.net/incidents/2026-10-lincoln-property-company-comme.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-lincoln-property-company-comme.html</guid>
      <pubDate>Thu, 01 Oct 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> lincolnpropertycompanycomme.com<br/>
<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>State of California Department of Justice data breach disclosure notice filed by Lincoln Property Company Commercial.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630678">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-lincoln-property-company-comme.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Marana Health Center — State of California Department of Justice data breach disclosure notice filed by Marana Health Center.</title>
      <link>https://securityincident.net/incidents/2026-10-marana-health-center.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-marana-health-center.html</guid>
      <pubDate>Thu, 01 Oct 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> maranahealthcenter.com<br/>
<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>State of California Department of Justice data breach disclosure notice filed by Marana Health Center.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630668">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-marana-health-center.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[EMERGING] Northern Counties Health Care — Northern Counties Health Care was listed on the Incransom ransomware extortion leak portal. With five community Health Centers, two dental centers, and a certified Home Health Care &amp; Hospice division, NCHC provides health care services to patients...</title>
      <link>https://securityincident.net/incidents/2026-10-northern-counties-health-care.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-northern-counties-health-care.html</guid>
      <pubDate>Thu, 01 Oct 2026 11:29:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> nchcvt.org<br/>
<strong>Threat Actor:</strong> Incransom<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Northern Counties Health Care was listed on the Incransom ransomware extortion leak portal. With five community Health Centers, two dental centers, and a certified Home Health Care & Hospice division, NCHC provides health care services to patients...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 11:29 UTC</strong> [UNVERIFIED CLAIM]: Northern Counties Health Care Listed on Incransom Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Tm9ydGhlcm4gQ291bnRpZXMgSGVhbHRoIENhcmVAaW5jcmFuc29t">Incransom Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-northern-counties-health-care.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>incransom</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Post Metal Recycling — Post Metal Recycling was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-post-metal-recycling.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-post-metal-recycling.html</guid>
      <pubDate>Thu, 01 Oct 2026 11:29:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> postmetalrecycling.com<br/>
<strong>Threat Actor:</strong> Incransom<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Post Metal Recycling was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 11:29 UTC</strong> [UNVERIFIED CLAIM]: Post Metal Recycling Listed on Incransom Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/UG9zdCBNZXRhbCBSZWN5Y2xpbmdAaW5jcmFuc29t">Incransom Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-post-metal-recycling.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>incransom</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Rimrock Foundation — Rimrock Foundation was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-rimrock-foundation.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-rimrock-foundation.html</guid>
      <pubDate>Thu, 01 Oct 2026 12:31:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> rimrock.org<br/>
<strong>Threat Actor:</strong> Incransom<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Rimrock Foundation was listed on the Incransom ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 12:31 UTC</strong> [UNVERIFIED CLAIM]: Rimrock Foundation Listed on Incransom Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/Umltcm9jayBGb3VuZGF0aW9uQGluY3JhbnNvbQ==">Incransom Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-rimrock-foundation.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>incransom</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Superior Plating Technology CO — Superior Plating Technology CO was listed on the Morpheus ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-10-superior-plating-technology-co.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-superior-plating-technology-co.html</guid>
      <pubDate>Thu, 01 Oct 2026 14:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> superiorplatingtechnologyco.com<br/>
<strong>Threat Actor:</strong> Morpheus<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Superior Plating Technology CO was listed on the Morpheus ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 14:30 UTC</strong> [UNVERIFIED CLAIM]: Superior Plating Technology CO Listed on Morpheus Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/U3VwZXJpb3IgUGxhdGluZyBUZWNobm9sb2d5IENPQG1vcnBoZXVz">Morpheus Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-superior-plating-technology-co.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>morpheus</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] Wesmar — Wesmar was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 66GB of internal data files.</title>
      <link>https://securityincident.net/incidents/2026-10-wesmar.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-10-wesmar.html</guid>
      <pubDate>Thu, 01 Oct 2026 13:27:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> wesmar.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-10-01<br/>
<strong>Last Updated:</strong> 2026-10-01</p>
<p>Wesmar was listed on the Akira ransomware extortion leak portal. Threat actor claims exfiltration of 66GB of internal data files.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-10-01 13:27 UTC</strong> [UNVERIFIED CLAIM]: Wesmar Listed on Akira Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/V2VzbWFyQGFraXJh">Akira Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-10-wesmar.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>akira</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[CONFIRMED] American Family Connect Insurance Company — State of California Department of Justice data breach disclosure notice filed by American Family Connect Insurance Company.</title>
      <link>https://securityincident.net/incidents/2026-09-american-family-connect-insura.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-american-family-connect-insura.html</guid>
      <pubDate>Wed, 30 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> americanfamilyconnectinsura.com<br/>
<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-30<br/>
<strong>Last Updated:</strong> 2026-09-30</p>
<p>State of California Department of Justice data breach disclosure notice filed by American Family Connect Insurance Company.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-30 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630618">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-american-family-connect-insura.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] DriveWealth — State of California Department of Justice data breach disclosure notice filed by DriveWealth.</title>
      <link>https://securityincident.net/incidents/2026-09-drivewealth.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-drivewealth.html</guid>
      <pubDate>Wed, 30 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> drivewealth.com<br/>
<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-30<br/>
<strong>Last Updated:</strong> 2026-09-30</p>
<p>State of California Department of Justice data breach disclosure notice filed by DriveWealth.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-30 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630619">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-drivewealth.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[EMERGING] Houston Thyroid &amp; Endocrine Specialists — Houston Thyroid &amp; Endocrine Specialists was listed on the N0n ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-09-houston-thyroid-endocrine-specialists.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-houston-thyroid-endocrine-specialists.html</guid>
      <pubDate>Wed, 30 Sep 2026 22:53:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> houstonthyroidendocrinespecialists.com<br/>
<strong>Threat Actor:</strong> N0n<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-30<br/>
<strong>Last Updated:</strong> 2026-09-30</p>
<p>Houston Thyroid & Endocrine Specialists was listed on the N0n ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-30 22:53 UTC</strong> [UNVERIFIED CLAIM]: Houston Thyroid & Endocrine Specialists Listed on N0n Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/SG91c3RvbiBUaHlyb2lkICYgRW5kb2NyaW5lIFNwZWNpYWxpc3RzQE4wbg==">N0n Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-houston-thyroid-endocrine-specialists.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>n0n</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[CONFIRMED] Nishiyamato Academy — State of California Department of Justice data breach disclosure notice filed by Nishiyamato Academy.</title>
      <link>https://securityincident.net/incidents/2026-09-nishiyamato-academy.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-nishiyamato-academy.html</guid>
      <pubDate>Wed, 30 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> nishiyamatoacademy.com<br/>
<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-30<br/>
<strong>Last Updated:</strong> 2026-09-30</p>
<p>State of California Department of Justice data breach disclosure notice filed by Nishiyamato Academy.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-30 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630609">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-nishiyamato-academy.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] ProCamps — State of California Department of Justice data breach disclosure notice filed by ProCamps.</title>
      <link>https://securityincident.net/incidents/2026-09-procamps.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-procamps.html</guid>
      <pubDate>Wed, 30 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> procamps.com<br/>
<strong>Open Weights Confidence:</strong> 80% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-30<br/>
<strong>Last Updated:</strong> 2026-09-30</p>
<p>State of California Department of Justice data breach disclosure notice filed by ProCamps.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-30 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630604">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-procamps.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[EMERGING] Summit Electric Supply — Summit Electric Supply was listed on the Vexy Ransomware ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</title>
      <link>https://securityincident.net/incidents/2026-09-summit-electric-supply.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-summit-electric-supply.html</guid>
      <pubDate>Wed, 30 Sep 2026 20:55:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> summit.com<br/>
<strong>Threat Actor:</strong> Vexy Ransomware<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-30<br/>
<strong>Last Updated:</strong> 2026-09-30</p>
<p>Summit Electric Supply was listed on the Vexy Ransomware ransomware extortion leak portal. Unverified extortion claim alleging unauthorized network access and data compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-30 20:55 UTC</strong> [UNVERIFIED CLAIM]: Summit Electric Supply Listed on Vexy Ransomware Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/U3VtbWl0IEVsZWN0cmljIFN1cHBseUBWZXh5IFJhbnNvbXdhcmU=">Vexy Ransomware Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-summit-electric-supply.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>vexy ransomware</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[EMERGING] wolfusofsky.de — wolfusofsky.de was listed on the Safepay ransomware extortion leak portal. The group provides a broad range of construction and infrastructure services to public and private clients in Rhineland-Palatinate, Saarland, neighboring …</title>
      <link>https://securityincident.net/incidents/2026-09-wolfusofsky-de.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-wolfusofsky-de.html</guid>
      <pubDate>Wed, 30 Sep 2026 20:11:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> wolfusofsky.de<br/>
<strong>Threat Actor:</strong> Safepay<br/>
<strong>Open Weights Confidence:</strong> 9% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-30<br/>
<strong>Last Updated:</strong> 2026-09-30</p>
<p>wolfusofsky.de was listed on the Safepay ransomware extortion leak portal. The group provides a broad range of construction and infrastructure services to public and private clients in Rhineland-Palatinate, Saarland, neighboring …</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-30 20:11 UTC</strong> [UNVERIFIED CLAIM]: wolfusofsky.de Listed on Safepay Ransomware Extortion Portal (<a href="https://www.ransomware.live/id/d29sZnVzb2Zza3kuZGVAc2FmZXBheQ==">Safepay Ransomware Leak Site Claim</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-wolfusofsky-de.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>extortion</category>
      <category>ransomware-claim</category>
      <category>safepay</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[CONFIRMED] Challenge Financial Services — State of California Department of Justice data breach disclosure notice filed by Challenge Financial Services.</title>
      <link>https://securityincident.net/incidents/2026-09-challenge-financial-services.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-challenge-financial-services.html</guid>
      <pubDate>Tue, 29 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> challengefinancialservices.com<br/>
<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-29<br/>
<strong>Last Updated:</strong> 2026-09-29</p>
<p>State of California Department of Justice data breach disclosure notice filed by Challenge Financial Services.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630536">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-challenge-financial-services.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] City of McMinnville — State of California Department of Justice data breach disclosure notice filed by City of McMinnville.</title>
      <link>https://securityincident.net/incidents/2026-09-city-of-mcminnville.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-city-of-mcminnville.html</guid>
      <pubDate>Tue, 29 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> cityofmcminnville.com<br/>
<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-29<br/>
<strong>Last Updated:</strong> 2026-09-29</p>
<p>State of California Department of Justice data breach disclosure notice filed by City of McMinnville.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630525">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-city-of-mcminnville.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Dodo Brands (Dodo Pizza) — Andrey Mihayloff reports: Dodo Pizza has confirmed a cyberattack on its IT systems, admitting that attackers may have accessed personal data of a portion of its customer base. The company reported the breach to Roskomnadzor and stated that access...</title>
      <link>https://securityincident.net/incidents/2026-09-dodo-pizza.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-dodo-pizza.html</guid>
      <pubDate>Tue, 29 Sep 2026 12:43:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> dodopizza.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 64% (CONFIRMED BY TARGET)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-29<br/>
<strong>Last Updated:</strong> 2026-09-29</p>
<p>Andrey Mihayloff reports: Dodo Pizza has confirmed a cyberattack on its IT systems, admitting that attackers may have accessed personal data of a portion of its customer base. The company reported the breach to Roskomnadzor and stated that access...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-29 12:43 UTC</strong> [CONFIRMED BY TARGET]: Russian pizza restaurant chain confirms cyberattack: Hackers claim 68 million users exposed (<a href="https://databreaches.net/2026/09/29/russian-pizza-restaurant-chain-confirms-cyberattack-hackers-claim-68-million-users-exposed/">DataBreaches.net Report</a>)</li>
  <li><strong>2026-09-29 12:34 UTC</strong> [CONFIRMED BY TARGET]: Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims (<a href="https://therecord.media/russian-pizza-chain-dodo-confirms-data-breach">The Record by Recorded Future Intelligence Notice</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-dodo-pizza.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>investigative</category>
      <category>developing</category>
    </item>
    <item>
      <title>[DEVELOPING] Dutch Police (Politie) — Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect&apos;s arrest, remaining Sh...</title>
      <link>https://securityincident.net/incidents/2026-09-dutch-police-politie.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-dutch-police-politie.html</guid>
      <pubDate>Mon, 28 Sep 2026 15:08:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> politie.nl<br/>
<strong>Threat Actor:</strong> ShinyHunters<br/>
<strong>Open Weights Confidence:</strong> 62% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-28<br/>
<strong>Last Updated:</strong> 2026-09-29</p>
<p>Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining Sh...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-28 15:08 UTC</strong> [INDEPENDENT VERIFICATION]: Dutch Police Arrest 'Reformed' Hacker in Shiny Hunters Investigation (<a href="https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/">Krebs on Security Report</a>)</li>
  <li><strong>2026-09-29 11:01 UTC</strong> [INDEPENDENT VERIFICATION]: Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation (<a href="https://www.securityweek.com/dutch-police-arrest-convicted-hacker-in-shinyhunters-investigation/">SecurityWeek Intelligence Notice</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-dutch-police-politie.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>developing</category>
    </item>
    <item>
      <title>[CONFIRMED] Lamb Weston — Oregon Department of Justice formal data breach disclosure notice filed by Lamb Weston affecting 7,175 Oregon residents.</title>
      <link>https://securityincident.net/incidents/2026-09-lamb-weston.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-lamb-weston.html</guid>
      <pubDate>Tue, 29 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> lambweston.com<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-29<br/>
<strong>Last Updated:</strong> 2026-09-29</p>
<p>Oregon Department of Justice formal data breach disclosure notice filed by Lamb Weston affecting 7,175 Oregon residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: Oregon Department of Justice Breach Notice (<a href="https://justice.oregon.gov/consumer/databreach/">Oregon Department of Justice Breach Notice</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-lamb-weston.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>oregon</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Poppins Payroll Company — State of California Department of Justice data breach disclosure notice filed by Poppins Payroll Company.</title>
      <link>https://securityincident.net/incidents/2026-09-poppins-payroll-company.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-poppins-payroll-company.html</guid>
      <pubDate>Tue, 29 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> poppinspayrollcompany.com<br/>
<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-29<br/>
<strong>Last Updated:</strong> 2026-09-29</p>
<p>State of California Department of Justice data breach disclosure notice filed by Poppins Payroll Company.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630541">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-poppins-payroll-company.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[DEVELOPING] AT&amp;T — A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&amp;T customers in 2024 was sentenced to 70 months in federal prison today and ordered...</title>
      <link>https://securityincident.net/incidents/2026-09-at-t.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-at-t.html</guid>
      <pubDate>Fri, 25 Sep 2026 21:44:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> att.com<br/>
<strong>Threat Actor:</strong> ShinyHunters / UNC5537<br/>
<strong>Open Weights Confidence:</strong> 62% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-25<br/>
<strong>Last Updated:</strong> 2026-09-28</p>
<p>A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-25 21:44 UTC</strong> [INDEPENDENT VERIFICATION]: U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions (<a href="https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/">Krebs on Security Report</a>)</li>
  <li><strong>2026-09-28 12:36 UTC</strong> [INDEPENDENT VERIFICATION]: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon (<a href="https://www.securityweek.com/prison-sentence-for-former-us-soldier-who-hacked-att-and-verizon/">SecurityWeek Intelligence Notice</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-at-t.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>developing</category>
    </item>
    <item>
      <title>[DEVELOPING] Hogan Lovells — Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG&apos;s recent attacks on Hogan Lovells Cadwalader. Yes, that&apos;s &quot;attacks,&quot; plural. When New York City&apos;s oldest law firm, C...</title>
      <link>https://securityincident.net/incidents/2026-09-hogan-lovells.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-hogan-lovells.html</guid>
      <pubDate>Mon, 28 Sep 2026 17:07:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> hoganlovells.com<br/>
<strong>Threat Actor:</strong> Silent Ransom Group<br/>
<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-28<br/>
<strong>Last Updated:</strong> 2026-09-28</p>
<p>Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG's recent attacks on Hogan Lovells Cadwalader. Yes, that's "attacks," plural. When New York City's oldest law firm, C...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-28 17:07 UTC</strong> [INDEPENDENT VERIFICATION]: Hogan Lovells Cadwalader hacked by Silent Ransom Group; re-attacked after they wouldn't pay (<a href="https://databreaches.net/2026/09/28/hogan-lovells-cadwalader-hacked-by-silent-ransom-group-re-attacked-after-they-wouldnt-pay/">DataBreaches.net Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-hogan-lovells.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>developing</category>
    </item>
    <item>
      <title>[CONFIRMED] Keio Corporation — Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]</title>
      <link>https://securityincident.net/incidents/2026-09-keio-corp.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-keio-corp.html</guid>
      <pubDate>Mon, 28 Sep 2026 20:56:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> keio.co.jp<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 57% (CONFIRMED BY TARGET)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-28<br/>
<strong>Last Updated:</strong> 2026-09-28</p>
<p>Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-28 20:56 UTC</strong> [CONFIRMED BY TARGET]: Japan's Keio confirms ransomware attack disrupted business systems (<a href="https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/">BleepingComputer Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-keio-corp.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>threat-intel</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] San Bernardino County on behalf of Arrowhead Regional Medical Center — State of California Department of Justice data breach disclosure notice filed by San Bernardino County on behalf of Arrowhead Regional Medical Center.</title>
      <link>https://securityincident.net/incidents/2026-09-san-bernardino-county-on-behal.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-san-bernardino-county-on-behal.html</guid>
      <pubDate>Mon, 28 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> sanbernardinocountyonbehal.com<br/>
<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-28<br/>
<strong>Last Updated:</strong> 2026-09-28</p>
<p>State of California Department of Justice data breach disclosure notice filed by San Bernardino County on behalf of Arrowhead Regional Medical Center.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-28 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630484">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-san-bernardino-county-on-behal.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Times Car — Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]</title>
      <link>https://securityincident.net/incidents/2026-09-times-car.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-times-car.html</guid>
      <pubDate>Mon, 28 Sep 2026 20:31:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> timescar.jp<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 57% (CONFIRMED BY TARGET)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-28<br/>
<strong>Last Updated:</strong> 2026-09-28</p>
<p>Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-28 20:31 UTC</strong> [CONFIRMED BY TARGET]: Times Car confirms data breach affecting 6.6 million user accounts (<a href="https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/">BleepingComputer Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-times-car.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>threat-intel</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Upbound Group — Upbound Group disclosed unauthorized acquisition of customer records and internal documents subsequently leveraged in fraudulent attempts.</title>
      <link>https://securityincident.net/incidents/2026-07-upbound-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-upbound-group.html</guid>
      <pubDate>Wed, 22 Jul 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> upbound.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 95% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-07-22<br/>
<strong>Last Updated:</strong> 2026-09-27</p>
<p>Upbound Group disclosed unauthorized acquisition of customer records and internal documents subsequently leveraged in fraudulent attempts.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-22 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 8.01 Disclosure: Upbound Group reveals unauthorized acquisition of non-sensitive customer records and corporate documents. (<a href="https://www.sec.gov/Archives/edgar/data/933036/000119312526310605/0001193125-26-310605-index.htm">SEC EDGAR 8-K Item 8.01 (Adsh 0001193125-26-310605)</a>)</li>
  <li><strong>2026-09-27 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630390">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-upbound-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>retail</category>
      <category>confirmed</category>
      <category>state-ag</category>
      <category>california</category>
    </item>
    <item>
      <title>[DEVELOPING] NHS England — Tom McArthur and Louise Parry report: Ten NHS staff have been removed from duty or suspended after a data breach involving the digital medical records of three-year-old Noah Woods. Launching an &quot;urgent&quot; investigation, Dr Martin Mansfield, deputy c...</title>
      <link>https://securityincident.net/incidents/2026-09-nhs-england.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-nhs-england.html</guid>
      <pubDate>Sun, 27 Sep 2026 13:22:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> nhs.uk<br/>
<strong>Threat Actor:</strong> Qilin<br/>
<strong>Open Weights Confidence:</strong> 55% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-27<br/>
<strong>Last Updated:</strong> 2026-09-27</p>
<p>Tom McArthur and Louise Parry report: Ten NHS staff have been removed from duty or suspended after a data breach involving the digital medical records of three-year-old Noah Woods. Launching an "urgent" investigation, Dr Martin Mansfield, deputy c...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-27 13:22 UTC</strong> [INDEPENDENT VERIFICATION]: UK: Ten NHS staff removed over Noah Woods data breach (<a href="https://databreaches.net/2026/09/27/uk-ten-nhs-staff-removed-over-noah-woods-data-breach/">DataBreaches.net Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-nhs-england.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>developing</category>
    </item>
    <item>
      <title>[DEVELOPING] Cloudflare — The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which desc...</title>
      <link>https://securityincident.net/incidents/2026-09-cloudflare.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-cloudflare.html</guid>
      <pubDate>Sat, 26 Sep 2026 18:22:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> cloudflare.com<br/>
<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-26<br/>
<strong>Last Updated:</strong> 2026-09-26</p>
<p>The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which desc...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-26 18:22 UTC</strong> [INDEPENDENT VERIFICATION]: Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials (<a href="https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html">The Hacker News Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-cloudflare.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>threat-intel</category>
      <category>developing</category>
    </item>
    <item>
      <title>[DEVELOPING] Labcorp — Suzanne Smiley reports another update on litigation stemming from the American Medical Collection Agency breach. A bipartisan coalition of 44 state attorneys general on Thursday announced that they settled a lawsuit against Labcorp in exchange for...</title>
      <link>https://securityincident.net/incidents/2026-09-labcorp.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-labcorp.html</guid>
      <pubDate>Sat, 26 Sep 2026 10:49:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> labcorp.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-26<br/>
<strong>Last Updated:</strong> 2026-09-26</p>
<p>Suzanne Smiley reports another update on litigation stemming from the American Medical Collection Agency breach. A bipartisan coalition of 44 state attorneys general on Thursday announced that they settled a lawsuit against Labcorp in exchange for...</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-26 10:49 UTC</strong> [INDEPENDENT VERIFICATION]: Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings (<a href="https://databreaches.net/2026/09/26/labcorp-to-overhaul-data-security-practices-pay-2-3-million-fine-for-cybersecurity-failings/">DataBreaches.net Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-labcorp.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>developing</category>
    </item>
    <item>
      <title>[CONFIRMED] Financial Administrative Support Services — State of California Department of Justice data breach disclosure notice filed by Financial Administrative Support Services.</title>
      <link>https://securityincident.net/incidents/2026-09-financial-administrative-suppo.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-financial-administrative-suppo.html</guid>
      <pubDate>Fri, 25 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> financialadministrativesuppo.com<br/>
<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-25<br/>
<strong>Last Updated:</strong> 2026-09-25</p>
<p>State of California Department of Justice data breach disclosure notice filed by Financial Administrative Support Services.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630351">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-financial-administrative-suppo.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Gallagher Transport International — State of California Department of Justice data breach disclosure notice filed by Gallagher Transport International.</title>
      <link>https://securityincident.net/incidents/2026-09-gallagher-transport-international.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-gallagher-transport-international.html</guid>
      <pubDate>Fri, 25 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> gallaghertransport.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-25<br/>
<strong>Last Updated:</strong> 2026-09-25</p>
<p>State of California Department of Justice data breach disclosure notice filed by Gallagher Transport International.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630300">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-gallagher-transport-international.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Kings United Way — State of California Department of Justice data breach disclosure notice filed by Kings United Way.</title>
      <link>https://securityincident.net/incidents/2026-09-kings-united-way.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-kings-united-way.html</guid>
      <pubDate>Fri, 25 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> kingsunitedway.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-25<br/>
<strong>Last Updated:</strong> 2026-09-25</p>
<p>State of California Department of Justice data breach disclosure notice filed by Kings United Way.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630314">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-kings-united-way.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] MedImpact Healthcare Systems — State of California Department of Justice data breach disclosure notice filed by MedImpact Healthcare Systems.</title>
      <link>https://securityincident.net/incidents/2026-09-medimpact-healthcare-systems.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-medimpact-healthcare-systems.html</guid>
      <pubDate>Fri, 25 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> medimpacthealthcaresystems.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-25<br/>
<strong>Last Updated:</strong> 2026-09-25</p>
<p>State of California Department of Justice data breach disclosure notice filed by MedImpact Healthcare Systems.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630343">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-medimpact-healthcare-systems.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] OneMain Financial Group — State of California Department of Justice data breach disclosure notice filed by OneMain Financial Group.</title>
      <link>https://securityincident.net/incidents/2026-09-onemain-financial-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-onemain-financial-group.html</guid>
      <pubDate>Fri, 25 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> onemainfinancialgroup.com<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-25<br/>
<strong>Last Updated:</strong> 2026-09-25</p>
<p>State of California Department of Justice data breach disclosure notice filed by OneMain Financial Group.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-25 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630345">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-onemain-financial-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] 5Star Life Insurance Company — State of California Department of Justice data breach disclosure notice filed by 5Star Life Insurance Company.</title>
      <link>https://securityincident.net/incidents/2026-09-5star-life-insurance-company.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-5star-life-insurance-company.html</guid>
      <pubDate>Thu, 24 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> 5starlifeinsurancecompany.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-24<br/>
<strong>Last Updated:</strong> 2026-09-24</p>
<p>State of California Department of Justice data breach disclosure notice filed by 5Star Life Insurance Company.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630231">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-5star-life-insurance-company.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Blanchard Training &amp; Development — State of California Department of Justice data breach disclosure notice filed by Blanchard Training &amp; Development.</title>
      <link>https://securityincident.net/incidents/2026-09-blanchard-training-development.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-blanchard-training-development.html</guid>
      <pubDate>Thu, 24 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> blanchardtrainingdevelopment.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-24<br/>
<strong>Last Updated:</strong> 2026-09-24</p>
<p>State of California Department of Justice data breach disclosure notice filed by Blanchard Training & Development.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630239">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-blanchard-training-development.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] HILT-Trust 2020-A and its underlying trusts and affiliates — State of California Department of Justice data breach disclosure notice filed by HILT-Trust 2020-A and its underlying trusts and affiliates.</title>
      <link>https://securityincident.net/incidents/2026-09-hilt-trust-2020-a-and-its-unde.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-hilt-trust-2020-a-and-its-unde.html</guid>
      <pubDate>Thu, 24 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> hilttrust2020aanditsunde.com<br/>
<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-24<br/>
<strong>Last Updated:</strong> 2026-09-24</p>
<p>State of California Department of Justice data breach disclosure notice filed by HILT-Trust 2020-A and its underlying trusts and affiliates.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Notice (SB-24) (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630200">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-hilt-trust-2020-a-and-its-unde.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] NSE Insurance Agencies — State of California Department of Justice data breach disclosure notice filed by NSE Insurance Agencies.</title>
      <link>https://securityincident.net/incidents/2026-09-nse-insurance-agencies.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-nse-insurance-agencies.html</guid>
      <pubDate>Thu, 24 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> nseinsuranceagencies.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-24<br/>
<strong>Last Updated:</strong> 2026-09-24</p>
<p>State of California Department of Justice data breach disclosure notice filed by NSE Insurance Agencies.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630194">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-nse-insurance-agencies.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Peña and Bromberg — State of California Department of Justice data breach disclosure notice filed by Peña and Bromberg.</title>
      <link>https://securityincident.net/incidents/2026-09-pena-and-bromberg.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-pena-and-bromberg.html</guid>
      <pubDate>Thu, 24 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> penabromberg.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-24<br/>
<strong>Last Updated:</strong> 2026-09-24</p>
<p>State of California Department of Justice data breach disclosure notice filed by Peña and Bromberg.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630232">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-pena-and-bromberg.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Astrana Health — Healthcare management company Astrana Health filed Form 8-K Item 1.05 disclosing a cybersecurity intrusion at its Astrana Health Management subsidiary.</title>
      <link>https://securityincident.net/incidents/2026-09-astrana-health.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-astrana-health.html</guid>
      <pubDate>Wed, 23 Sep 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> astranahealth.com<br/>
<strong>Threat Actor:</strong> RansomHub<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-23<br/>
<strong>Last Updated:</strong> 2026-09-23</p>
<p>Healthcare management company Astrana Health filed Form 8-K Item 1.05 disclosing a cybersecurity intrusion at its Astrana Health Management subsidiary.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-23 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Astrana Health discloses cybersecurity incident impacting management subsidiary environments. (<a href="https://www.sec.gov/Archives/edgar/data/1083446/000110465926109813/0001104659-26-109813-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001104659-26-109813)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-astrana-health.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>healthcare</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Fairwinds Credit Union — State of California Department of Justice data breach disclosure notice filed by Fairwinds Credit Union.</title>
      <link>https://securityincident.net/incidents/2026-09-fairwinds-credit-union.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-fairwinds-credit-union.html</guid>
      <pubDate>Wed, 23 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> fairwindscreditunion.com<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-23<br/>
<strong>Last Updated:</strong> 2026-09-23</p>
<p>State of California Department of Justice data breach disclosure notice filed by Fairwinds Credit Union.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-23 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630165">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-fairwinds-credit-union.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Modoc Medical Center — State of California Department of Justice data breach disclosure notice filed by Modoc Medical Center.</title>
      <link>https://securityincident.net/incidents/2026-09-modoc-medical-center.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-modoc-medical-center.html</guid>
      <pubDate>Tue, 22 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> modocmedicalcenter.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-22<br/>
<strong>Last Updated:</strong> 2026-09-22</p>
<p>State of California Department of Justice data breach disclosure notice filed by Modoc Medical Center.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-22 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630126">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-modoc-medical-center.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Ethan Conrad Properties — State of California Department of Justice data breach disclosure notice filed by Ethan Conrad Properties.</title>
      <link>https://securityincident.net/incidents/2026-09-ethan-conrad-properties.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-ethan-conrad-properties.html</guid>
      <pubDate>Mon, 21 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> ethanconradproperties.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-21<br/>
<strong>Last Updated:</strong> 2026-09-21</p>
<p>State of California Department of Justice data breach disclosure notice filed by Ethan Conrad Properties.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630085">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-ethan-conrad-properties.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Friesen Group — State of California Department of Justice data breach disclosure notice filed by Friesen Group.</title>
      <link>https://securityincident.net/incidents/2026-09-friesen-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-friesen-group.html</guid>
      <pubDate>Mon, 21 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> friesengroup.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-21<br/>
<strong>Last Updated:</strong> 2026-09-21</p>
<p>State of California Department of Justice data breach disclosure notice filed by Friesen Group.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630087">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-friesen-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Fun For Less Tours — State of California Department of Justice data breach disclosure notice filed by Fun For Less Tours.</title>
      <link>https://securityincident.net/incidents/2026-09-fun-for-less-tours.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-fun-for-less-tours.html</guid>
      <pubDate>Mon, 21 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> funforlesstours.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-21<br/>
<strong>Last Updated:</strong> 2026-09-21</p>
<p>State of California Department of Justice data breach disclosure notice filed by Fun For Less Tours.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630062">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-fun-for-less-tours.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Ridgeway Pharmacy — State of California Department of Justice data breach disclosure notice filed by Ridgeway Pharmacy.</title>
      <link>https://securityincident.net/incidents/2026-09-ridgeway-pharmacy.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-ridgeway-pharmacy.html</guid>
      <pubDate>Mon, 21 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> ridgewaypharmacy.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-21<br/>
<strong>Last Updated:</strong> 2026-09-21</p>
<p>State of California Department of Justice data breach disclosure notice filed by Ridgeway Pharmacy.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630056">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-ridgeway-pharmacy.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] United Underwriters — State of California Department of Justice data breach disclosure notice filed by United Underwriters.</title>
      <link>https://securityincident.net/incidents/2026-09-united-underwriters.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-united-underwriters.html</guid>
      <pubDate>Mon, 21 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> unitedunderwriters.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-21<br/>
<strong>Last Updated:</strong> 2026-09-21</p>
<p>State of California Department of Justice data breach disclosure notice filed by United Underwriters.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-21 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-630066">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-united-underwriters.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Office of the Los Angeles City Attorney — State of California Department of Justice data breach disclosure notice filed by The Office of the Los Angeles City.</title>
      <link>https://securityincident.net/incidents/2026-09-los-angeles-city-attorney.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-los-angeles-city-attorney.html</guid>
      <pubDate>Fri, 18 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> lacityattorney.org<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-18<br/>
<strong>Last Updated:</strong> 2026-09-18</p>
<p>State of California Department of Justice data breach disclosure notice filed by The Office of the Los Angeles City.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-18 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629957">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-los-angeles-city-attorney.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Opportune — State of California Department of Justice data breach disclosure notice filed by Opportune.</title>
      <link>https://securityincident.net/incidents/2026-09-opportune.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-opportune.html</guid>
      <pubDate>Fri, 18 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> opportune.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-18<br/>
<strong>Last Updated:</strong> 2026-09-18</p>
<p>State of California Department of Justice data breach disclosure notice filed by Opportune.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-18 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629948">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-opportune.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Seyfarth Shaw — State of California Department of Justice data breach disclosure notice filed by Seyfarth Shaw.</title>
      <link>https://securityincident.net/incidents/2026-09-seyfarth-shaw.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-seyfarth-shaw.html</guid>
      <pubDate>Fri, 18 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> seyfarthshaw.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-18<br/>
<strong>Last Updated:</strong> 2026-09-18</p>
<p>State of California Department of Justice data breach disclosure notice filed by Seyfarth Shaw.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-18 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629966">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-seyfarth-shaw.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] CallonDoc — State of California Department of Justice data breach disclosure notice filed by CallonDoc.</title>
      <link>https://securityincident.net/incidents/2026-09-callondoc.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-callondoc.html</guid>
      <pubDate>Thu, 17 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> callondoc.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-17<br/>
<strong>Last Updated:</strong> 2026-09-17</p>
<p>State of California Department of Justice data breach disclosure notice filed by CallonDoc.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-17 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629887">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-callondoc.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Gyazo — Screen capture platform Gyazo suffered a major data breach exposing 23.62 million user account records and 490 million image metadata entries.</title>
      <link>https://securityincident.net/incidents/2026-09-gyazo.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-gyazo.html</guid>
      <pubDate>Thu, 17 Sep 2026 14:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> gyazo.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 57% (CONFIRMED BY TARGET)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-17<br/>
<strong>Last Updated:</strong> 2026-09-17</p>
<p>Screen capture platform Gyazo suffered a major data breach exposing 23.62 million user account records and 490 million image metadata entries.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-17 14:00 UTC</strong> [CONFIRMED BY TARGET]: Gyazo confirms data breach affecting 23.62M user accounts and resets all session tokens and user API keys. (<a href="https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html">The Hacker News Investigation Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-gyazo.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>threat-intel</category>
      <category>credential-breach</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Partnership HealthPlan of California — State of California Department of Justice data breach disclosure notice filed by Partnership HealthPlan of California.</title>
      <link>https://securityincident.net/incidents/2026-09-partnership-healthplan-california.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-partnership-healthplan-california.html</guid>
      <pubDate>Thu, 17 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> partnershiphp.net<br/>
<strong>Threat Actor:</strong> Hive / Successor Affiliate<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-17<br/>
<strong>Last Updated:</strong> 2026-09-17</p>
<p>State of California Department of Justice data breach disclosure notice filed by Partnership HealthPlan of California.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-17 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629908">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-partnership-healthplan-california.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Alliance Environmental Group — State of California Department of Justice data breach disclosure notice filed by Alliance Environmental Group.</title>
      <link>https://securityincident.net/incidents/2026-09-alliance-environmental-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-alliance-environmental-group.html</guid>
      <pubDate>Tue, 15 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> allianceenvironmentalgroup.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-15<br/>
<strong>Last Updated:</strong> 2026-09-15</p>
<p>State of California Department of Justice data breach disclosure notice filed by Alliance Environmental Group.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-15 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629776">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-alliance-environmental-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Leggett &amp; Platt Employee Benefits Plan — State of California Department of Justice data breach disclosure notice filed by Leggett &amp; Platt,  Employee Benefits Plan.</title>
      <link>https://securityincident.net/incidents/2026-09-leggett-platt-benefits.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-leggett-platt-benefits.html</guid>
      <pubDate>Tue, 15 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> leggett.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-15<br/>
<strong>Last Updated:</strong> 2026-09-15</p>
<p>State of California Department of Justice data breach disclosure notice filed by Leggett & Platt,  Employee Benefits Plan.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-15 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629789">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-leggett-platt-benefits.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Tarter Krinsky &amp; Drogin — State of California Department of Justice data breach disclosure notice filed by Tarter Krinsky &amp; Drogin.</title>
      <link>https://securityincident.net/incidents/2026-09-tarter-krinsky-drogin.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-tarter-krinsky-drogin.html</guid>
      <pubDate>Tue, 15 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> tarterkrinskydrogin.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-15<br/>
<strong>Last Updated:</strong> 2026-09-15</p>
<p>State of California Department of Justice data breach disclosure notice filed by Tarter Krinsky & Drogin.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-15 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629786">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-tarter-krinsky-drogin.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Accela — State of California Department of Justice data breach disclosure notice filed by Accela.</title>
      <link>https://securityincident.net/incidents/2026-09-accela.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-accela.html</guid>
      <pubDate>Mon, 14 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> accela.com<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-14<br/>
<strong>Last Updated:</strong> 2026-09-14</p>
<p>State of California Department of Justice data breach disclosure notice filed by Accela.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-14 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629676">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-accela.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Cambridge Mercantile — State of California Department of Justice data breach disclosure notice filed by Cambridge Mercantile.</title>
      <link>https://securityincident.net/incidents/2026-09-cambridge-mercantile.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-cambridge-mercantile.html</guid>
      <pubDate>Mon, 14 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> cambridgemercantile.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-14<br/>
<strong>Last Updated:</strong> 2026-09-14</p>
<p>State of California Department of Justice data breach disclosure notice filed by Cambridge Mercantile.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-14 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629696">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-cambridge-mercantile.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Paradigm Healthcare Services — State of California Department of Justice data breach disclosure notice filed by Paradigm Healthcare Services.</title>
      <link>https://securityincident.net/incidents/2026-09-paradigm-healthcare-services.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-paradigm-healthcare-services.html</guid>
      <pubDate>Mon, 14 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> paradigmhealthcareservices.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-14<br/>
<strong>Last Updated:</strong> 2026-09-14</p>
<p>State of California Department of Justice data breach disclosure notice filed by Paradigm Healthcare Services.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-14 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629754">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-paradigm-healthcare-services.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Nutex Health — Nutex Health disclosed an unauthorized cybersecurity incident involving corporate data environments, triggering formal Item 1.05 notification.</title>
      <link>https://securityincident.net/incidents/2026-08-nutex-health.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-nutex-health.html</guid>
      <pubDate>Mon, 31 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> nutexhealth.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-31<br/>
<strong>Last Updated:</strong> 2026-09-11</p>
<p>Nutex Health disclosed an unauthorized cybersecurity incident involving corporate data environments, triggering formal Item 1.05 notification.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-31 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Nutex Health confirms unauthorized data exfiltration following prior Item 8.01 investigation notice. (<a href="https://www.sec.gov/Archives/edgar/data/1479681/000162828026059602/0001628280-26-059602-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001628280-26-059602)</a>)</li>
  <li><strong>2026-09-11 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 8.01 Supplemental: Nutex Health provides containment verification and reports clinical operations remain fully operational. (<a href="https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/0001628280-26-061432-index.htm">SEC EDGAR 8-K Item 8.01 (Adsh 0001628280-26-061432)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-nutex-health.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>healthcare</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Catalyst Physician Group — State of California Department of Justice data breach disclosure notice filed by Catalyst Physician Group.</title>
      <link>https://securityincident.net/incidents/2026-09-catalyst-physician-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-catalyst-physician-group.html</guid>
      <pubDate>Fri, 11 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> catalystphysiciangroup.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-11<br/>
<strong>Last Updated:</strong> 2026-09-11</p>
<p>State of California Department of Justice data breach disclosure notice filed by Catalyst Physician Group.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-11 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629605">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-catalyst-physician-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Cornerstone Staffing Solutions — State of California Department of Justice data breach disclosure notice filed by Cornerstone Staffing Solutions.</title>
      <link>https://securityincident.net/incidents/2026-09-cornerstone-staffing-solutions.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-cornerstone-staffing-solutions.html</guid>
      <pubDate>Fri, 11 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> cornerstonestaffingsolutions.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-11<br/>
<strong>Last Updated:</strong> 2026-09-11</p>
<p>State of California Department of Justice data breach disclosure notice filed by Cornerstone Staffing Solutions.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-11 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629595">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-09-11 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42777.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-cornerstone-staffing-solutions.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
      <category>washington</category>
    </item>
    <item>
      <title>[CONFIRMED] Suffolk Federal Credit Union — State of California Department of Justice data breach disclosure notice filed by Suffolk Federal Credit Union.</title>
      <link>https://securityincident.net/incidents/2026-09-suffolk-federal-credit-union.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-suffolk-federal-credit-union.html</guid>
      <pubDate>Fri, 11 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> suffolkfederalcreditunion.com<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-11<br/>
<strong>Last Updated:</strong> 2026-09-11</p>
<p>State of California Department of Justice data breach disclosure notice filed by Suffolk Federal Credit Union.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-11 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629581">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-suffolk-federal-credit-union.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] zHealth — State of California Department of Justice data breach disclosure notice filed by zHealth.</title>
      <link>https://securityincident.net/incidents/2026-09-zhealth.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-zhealth.html</guid>
      <pubDate>Fri, 11 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> zhealth.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-11<br/>
<strong>Last Updated:</strong> 2026-09-11</p>
<p>State of California Department of Justice data breach disclosure notice filed by zHealth.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-11 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629559">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-09-11 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42768.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-zhealth.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
      <category>washington</category>
    </item>
    <item>
      <title>[CONFIRMED] Quatrro Business Support Services — State of California Department of Justice data breach disclosure notice filed by Quatrro Business Support Services.</title>
      <link>https://securityincident.net/incidents/2026-09-quatrro-business-support.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-quatrro-business-support.html</guid>
      <pubDate>Wed, 09 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> quatrrobss.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-09<br/>
<strong>Last Updated:</strong> 2026-09-09</p>
<p>State of California Department of Justice data breach disclosure notice filed by Quatrro Business Support Services.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-09 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629483">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-09-09 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42741.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-quatrro-business-support.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
      <category>washington</category>
    </item>
    <item>
      <title>[CONFIRMED] Boston Scientific — Medical manufacturer Boston Scientific Corporation filed Form 8-K Item 1.05 formalizing disclosure of an unauthorized intrusion into corporate IT environments.</title>
      <link>https://securityincident.net/incidents/2026-09-boston-scientific.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-boston-scientific.html</guid>
      <pubDate>Tue, 08 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> bostonscientific.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-08<br/>
<strong>Last Updated:</strong> 2026-09-08</p>
<p>Medical manufacturer Boston Scientific Corporation filed Form 8-K Item 1.05 formalizing disclosure of an unauthorized intrusion into corporate IT environments.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-08 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Boston Scientific formalizes disclosure of unauthorized access detected in August 2026. (<a href="https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/0000885725-26-000059-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0000885725-26-000059)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-boston-scientific.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>healthcare</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Hibbett Retail — State of California Department of Justice data breach disclosure notice filed by Hibbett Retail.</title>
      <link>https://securityincident.net/incidents/2026-09-hibbett-retail.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-hibbett-retail.html</guid>
      <pubDate>Tue, 08 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> hibbettretail.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-08<br/>
<strong>Last Updated:</strong> 2026-09-08</p>
<p>State of California Department of Justice data breach disclosure notice filed by Hibbett Retail.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-08 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629439">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-09-08 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42734.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-hibbett-retail.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
      <category>washington</category>
    </item>
    <item>
      <title>[CONFIRMED] June 2026 Healthcare Data — Healthcare data breach disclosure submitted to federal regulators by June 2026 Healthcare Data.</title>
      <link>https://securityincident.net/incidents/2026-09-june-2026-healthcare-data.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-june-2026-healthcare-data.html</guid>
      <pubDate>Mon, 07 Sep 2026 15:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> june2026healthcaredata.com<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-07<br/>
<strong>Last Updated:</strong> 2026-09-07</p>
<p>Healthcare data breach disclosure submitted to federal regulators by June 2026 Healthcare Data.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-07 15:00 UTC</strong> [CONFIRMED BY REGULATOR]: HHS OCR Healthcare Data Breach Disclosure: June 2026 Healthcare Data Breach Report (<a href="https://www.hipaajournal.com/june-2026-healthcare-data-breach-report/">HHS OCR Regulatory Healthcare Breach Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-june-2026-healthcare-data.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>hhs-ocr</category>
      <category>healthcare</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Bimbo Bakeries USA — State of California Department of Justice data breach disclosure notice filed by Bimbo Bakeries USA.</title>
      <link>https://securityincident.net/incidents/2026-09-bimbo-bakeries-usa.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-bimbo-bakeries-usa.html</guid>
      <pubDate>Fri, 04 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> bimbobakeriesusa.com<br/>
<strong>Threat Actor:</strong> BlackSuit<br/>
<strong>Open Weights Confidence:</strong> 95% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-04<br/>
<strong>Last Updated:</strong> 2026-09-04</p>
<p>State of California Department of Justice data breach disclosure notice filed by Bimbo Bakeries USA.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-04 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629294">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-09-04 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42696.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-bimbo-bakeries-usa.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
      <category>washington</category>
    </item>
    <item>
      <title>[CONFIRMED] Catalyst Brands — State of California Department of Justice data breach disclosure notice filed by Catalyst Brands.</title>
      <link>https://securityincident.net/incidents/2026-09-catalyst-brands.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-catalyst-brands.html</guid>
      <pubDate>Fri, 04 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> catalystbrands.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-04<br/>
<strong>Last Updated:</strong> 2026-09-04</p>
<p>State of California Department of Justice data breach disclosure notice filed by Catalyst Brands.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-04 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629314">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-09-04 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42702.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-catalyst-brands.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
      <category>washington</category>
    </item>
    <item>
      <title>[CONFIRMED] Elixir Medical — State of California Department of Justice data breach disclosure notice filed by Elixir Medical.</title>
      <link>https://securityincident.net/incidents/2026-09-elixir-medical.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-elixir-medical.html</guid>
      <pubDate>Fri, 04 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> elixirmedical.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-04<br/>
<strong>Last Updated:</strong> 2026-09-04</p>
<p>State of California Department of Justice data breach disclosure notice filed by Elixir Medical.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-04 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629325">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-elixir-medical.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] LHC Group — Washington State Attorney General formal data breach disclosure notice filed by LHC Group affecting 6602 residents.</title>
      <link>https://securityincident.net/incidents/2026-09-lhc-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-lhc-group.html</guid>
      <pubDate>Fri, 04 Sep 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> lhcgroup.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-04<br/>
<strong>Last Updated:</strong> 2026-09-04</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by LHC Group affecting 6602 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-04 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42695.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-lhc-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Virta Health  and Virta Medical — State of California Department of Justice data breach disclosure notice filed by Virta Health  and Virta Medical.</title>
      <link>https://securityincident.net/incidents/2026-08-virta-health-and-virta-medical.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-virta-health-and-virta-medical.html</guid>
      <pubDate>Mon, 31 Aug 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> virtahealthandvirtamedical.com<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 95% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-08-31<br/>
<strong>Last Updated:</strong> 2026-09-03</p>
<p>State of California Department of Justice data breach disclosure notice filed by Virta Health  and Virta Medical.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-31 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629093">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-09-03 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42682.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-virta-health-and-virta-medical.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
      <category>washington</category>
    </item>
    <item>
      <title>[CONFIRMED] Mogren, Glessner &amp; Ahrens, P.S — Washington State Attorney General formal data breach disclosure notice filed by Mogren, Glessner &amp; Ahrens, P.S affecting 1379 residents.</title>
      <link>https://securityincident.net/incidents/2026-09-mogren-glessner-ahrens-p-s.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-mogren-glessner-ahrens-p-s.html</guid>
      <pubDate>Thu, 03 Sep 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> mogrenglessnerahrensps.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-03<br/>
<strong>Last Updated:</strong> 2026-09-03</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Mogren, Glessner & Ahrens, P.S affecting 1379 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-03 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42675.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-mogren-glessner-ahrens-p-s.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] The Lighthouse for the Blind — Washington State Attorney General formal data breach disclosure notice filed by The Lighthouse for the Blind affecting 520 residents.</title>
      <link>https://securityincident.net/incidents/2026-09-the-lighthouse-for-the-blind.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-the-lighthouse-for-the-blind.html</guid>
      <pubDate>Thu, 03 Sep 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> thelighthousefortheblind.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-03<br/>
<strong>Last Updated:</strong> 2026-09-03</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by The Lighthouse for the Blind affecting 520 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-03 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42680.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-the-lighthouse-for-the-blind.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[DEVELOPING] Thomson Reuters — A vulnerability in Thomson Reuters court management software exposed sensitive sealed court filings and Social Security numbers across multiple jurisdictions.</title>
      <link>https://securityincident.net/incidents/2026-09-thomson-reuters.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-thomson-reuters.html</guid>
      <pubDate>Thu, 03 Sep 2026 15:45:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> thomsonreuters.com<br/>
<strong>Threat Actor:</strong> Independent Researcher Disclosure<br/>
<strong>Open Weights Confidence:</strong> 55% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-03<br/>
<strong>Last Updated:</strong> 2026-09-03</p>
<p>A vulnerability in Thomson Reuters court management software exposed sensitive sealed court filings and Social Security numbers across multiple jurisdictions.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-03 15:45 UTC</strong> [INDEPENDENT VERIFICATION]: Security researchers discover unauthorized exposure of sealed court records and PII in court software systems. (<a href="https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html">The Hacker News Telemetry Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-thomson-reuters.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>threat-intel</category>
      <category>legal</category>
      <category>court-systems</category>
      <category>developing</category>
    </item>
    <item>
      <title>[CONFIRMED] Fiesta Insurance Franchise — State of California Department of Justice data breach disclosure notice filed by Fiesta Insurance Franchise.</title>
      <link>https://securityincident.net/incidents/2026-09-fiesta-insurance-franchise.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-fiesta-insurance-franchise.html</guid>
      <pubDate>Wed, 02 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> fiestainsurancefranchise.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-02<br/>
<strong>Last Updated:</strong> 2026-09-02</p>
<p>State of California Department of Justice data breach disclosure notice filed by Fiesta Insurance Franchise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629220">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-fiesta-insurance-franchise.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Fishbrain AB — State of California Department of Justice data breach disclosure notice filed by Fishbrain AB.</title>
      <link>https://securityincident.net/incidents/2026-09-fishbrain-ab.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-fishbrain-ab.html</guid>
      <pubDate>Wed, 02 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> fishbrainab.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-02<br/>
<strong>Last Updated:</strong> 2026-09-02</p>
<p>State of California Department of Justice data breach disclosure notice filed by Fishbrain AB.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629190">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-fishbrain-ab.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] HumanEdge — State of California Department of Justice data breach disclosure notice filed by HumanEdge.</title>
      <link>https://securityincident.net/incidents/2026-09-humanedge.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-humanedge.html</guid>
      <pubDate>Wed, 02 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> humanedge.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-02<br/>
<strong>Last Updated:</strong> 2026-09-02</p>
<p>State of California Department of Justice data breach disclosure notice filed by HumanEdge.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629213">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-humanedge.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Knowledge Research Center — State of California Department of Justice data breach disclosure notice filed by Knowledge Research Center.</title>
      <link>https://securityincident.net/incidents/2026-09-knowledge-research-center.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-knowledge-research-center.html</guid>
      <pubDate>Wed, 02 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> knowledgeresearchcenter.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-02<br/>
<strong>Last Updated:</strong> 2026-09-02</p>
<p>State of California Department of Justice data breach disclosure notice filed by Knowledge Research Center.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629199">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-knowledge-research-center.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] See’s Candies — State of California Department of Justice data breach disclosure notice filed by See’s Candies.</title>
      <link>https://securityincident.net/incidents/2026-09-see-s-candies.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-see-s-candies.html</guid>
      <pubDate>Wed, 02 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> seescandies.com<br/>
<strong>Threat Actor:</strong> Magecart / E-commerce Skimmer<br/>
<strong>Open Weights Confidence:</strong> 95% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-09-02<br/>
<strong>Last Updated:</strong> 2026-09-02</p>
<p>State of California Department of Justice data breach disclosure notice filed by See’s Candies.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629221">California Attorney General Data Breach Notice (SB-24)</a>)</li>
  <li><strong>2026-09-02 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42672.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-see-s-candies.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
      <category>washington</category>
    </item>
    <item>
      <title>[CONFIRMED] YouLend US — State of California Department of Justice data breach disclosure notice filed by YouLend US.</title>
      <link>https://securityincident.net/incidents/2026-09-youlend-us.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-youlend-us.html</guid>
      <pubDate>Wed, 02 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> youlendus.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-02<br/>
<strong>Last Updated:</strong> 2026-09-02</p>
<p>State of California Department of Justice data breach disclosure notice filed by YouLend US.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-02 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629202">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-youlend-us.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] DeMera DeMera Cameron — State of California Department of Justice data breach disclosure notice filed by DeMera DeMera Cameron.</title>
      <link>https://securityincident.net/incidents/2026-09-demera-demera-cameron.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-demera-demera-cameron.html</guid>
      <pubDate>Tue, 01 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> demerademeracameron.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-01<br/>
<strong>Last Updated:</strong> 2026-09-01</p>
<p>State of California Department of Justice data breach disclosure notice filed by DeMera DeMera Cameron.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629160">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-demera-demera-cameron.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Kaniksu Community Health — State of California Department of Justice data breach disclosure notice filed by Kaniksu Community Health.</title>
      <link>https://securityincident.net/incidents/2026-09-kaniksu-community-health.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-kaniksu-community-health.html</guid>
      <pubDate>Tue, 01 Sep 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> kaniksucommunityhealth.com<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-01<br/>
<strong>Last Updated:</strong> 2026-09-01</p>
<p>State of California Department of Justice data breach disclosure notice filed by Kaniksu Community Health.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-01 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629145">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-kaniksu-community-health.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] NovoCure — Oncology medical device company NovoCure disclosed unauthorized access to subsidiary information systems detected in mid-August 2026.</title>
      <link>https://securityincident.net/incidents/2026-09-novocure.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-novocure.html</guid>
      <pubDate>Tue, 01 Sep 2026 16:45:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> novocure.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-01<br/>
<strong>Last Updated:</strong> 2026-09-01</p>
<p>Oncology medical device company NovoCure disclosed unauthorized access to subsidiary information systems detected in mid-August 2026.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-01 16:45 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 8.01 Filing: NovoCure reports containment of unauthorized access to subsidiary IT systems with no impact on patient therapy. (<a href="https://www.sec.gov/Archives/edgar/data/1645113/000164511326000065/0001645113-26-000065-index.htm">SEC EDGAR 8-K Item 8.01 (Adsh 0001645113-26-000065)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-novocure.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>medical-device</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Park Dental Partners — Dental support organization Park Dental Partners filed Form 8-K Item 1.05 disclosing network disruption and forensic containment efforts.</title>
      <link>https://securityincident.net/incidents/2026-09-park-dental-partners.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-09-park-dental-partners.html</guid>
      <pubDate>Tue, 01 Sep 2026 18:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> parkdental.com<br/>
<strong>Threat Actor:</strong> Akira<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-09-01<br/>
<strong>Last Updated:</strong> 2026-09-01</p>
<p>Dental support organization Park Dental Partners filed Form 8-K Item 1.05 disclosing network disruption and forensic containment efforts.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-09-01 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Park Dental Partners confirms unauthorized network activity and initiates third-party forensic containment. (<a href="https://www.sec.gov/Archives/edgar/data/2069604/000110465926104300/0001104659-26-104300-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001104659-26-104300)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-09-park-dental-partners.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>healthcare</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Berkeley Research Group — State of California Department of Justice data breach disclosure notice filed by Berkeley Research Group.</title>
      <link>https://securityincident.net/incidents/2026-08-berkeley-research-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-berkeley-research-group.html</guid>
      <pubDate>Mon, 31 Aug 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> berkeleyresearchgroup.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-31<br/>
<strong>Last Updated:</strong> 2026-08-31</p>
<p>State of California Department of Justice data breach disclosure notice filed by Berkeley Research Group.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-31 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-629096">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-berkeley-research-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Bennett College — State of California Department of Justice data breach disclosure notice filed by Bennett College.</title>
      <link>https://securityincident.net/incidents/2026-08-bennett-college.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-bennett-college.html</guid>
      <pubDate>Fri, 28 Aug 2026 17:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> bennettcollege.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-28<br/>
<strong>Last Updated:</strong> 2026-08-28</p>
<p>State of California Department of Justice data breach disclosure notice filed by Bennett College.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-28 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: California Attorney General Data Breach Disclosure Notice (<a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-628990">California Attorney General Data Breach Notice (SB-24)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-bennett-college.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>california</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] RB American Group — Washington State Attorney General formal data breach disclosure notice filed by RB American Group affecting 974 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-rb-american-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-rb-american-group.html</guid>
      <pubDate>Fri, 28 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> rbamericangroup.com<br/>
<strong>Threat Actor:</strong> RansomHub<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-28<br/>
<strong>Last Updated:</strong> 2026-08-28</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by RB American Group affecting 974 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-28 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42591.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-rb-american-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Greystar Real Estate Partners — Washington State Attorney General formal data breach disclosure notice filed by Greystar Real Estate Partners affecting 333 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-greystar-real-estate-partners.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-greystar-real-estate-partners.html</guid>
      <pubDate>Thu, 27 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> greystarrealestatepartners.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-27<br/>
<strong>Last Updated:</strong> 2026-08-27</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Greystar Real Estate Partners affecting 333 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-27 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42570.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-greystar-real-estate-partners.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Cascade Coffee — Washington State Attorney General formal data breach disclosure notice filed by Cascade Coffee affecting 610 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-cascade-coffee.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-cascade-coffee.html</guid>
      <pubDate>Wed, 26 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> cascadecoffee.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-26<br/>
<strong>Last Updated:</strong> 2026-08-26</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Cascade Coffee affecting 610 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-26 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42548.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-cascade-coffee.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Murfreesboro Medical Clinic — Washington State Attorney General formal data breach disclosure notice filed by Murfreesboro Medical Clinic affecting 845 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-murfreesboro-medical-clinic.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-murfreesboro-medical-clinic.html</guid>
      <pubDate>Wed, 26 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> murfreesboromedicalclinic.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-26<br/>
<strong>Last Updated:</strong> 2026-08-26</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Murfreesboro Medical Clinic affecting 845 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-26 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42565.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-murfreesboro-medical-clinic.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] News  UK &amp; Ireland Limited — Washington State Attorney General formal data breach disclosure notice filed by News  UK &amp; Ireland Limited affecting 3304 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-news-uk-ireland-limited.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-news-uk-ireland-limited.html</guid>
      <pubDate>Wed, 26 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> newsukirelandlimited.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-26<br/>
<strong>Last Updated:</strong> 2026-08-26</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by News  UK & Ireland Limited affecting 3304 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-26 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42560.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-news-uk-ireland-limited.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Pan American Group — Washington State Attorney General formal data breach disclosure notice filed by Pan American Group affecting 12309 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-pan-american-group.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-pan-american-group.html</guid>
      <pubDate>Mon, 24 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> panamericangroup.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-24<br/>
<strong>Last Updated:</strong> 2026-08-24</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Pan American Group affecting 12309 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-24 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42509.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-pan-american-group.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] ASOS US Sales — Washington State Attorney General formal data breach disclosure notice filed by ASOS US Sales affecting 1929 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-asos-us-sales.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-asos-us-sales.html</guid>
      <pubDate>Fri, 21 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> asosussales.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-21<br/>
<strong>Last Updated:</strong> 2026-08-21</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by ASOS US Sales affecting 1929 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-21 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42451.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-asos-us-sales.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Rockwood Retirement Communities — Washington State Attorney General formal data breach disclosure notice filed by Rockwood Retirement Communities affecting 7136 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-rockwood-retirement-communities.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-rockwood-retirement-communities.html</guid>
      <pubDate>Thu, 20 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> rockwoodretirement.org<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-20<br/>
<strong>Last Updated:</strong> 2026-08-20</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Rockwood Retirement Communities affecting 7136 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-20 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42441.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-rockwood-retirement-communities.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Southern Illinois University — Washington State Attorney General formal data breach disclosure notice filed by Southern Illinois University affecting 552 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-southern-illinois-university.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-southern-illinois-university.html</guid>
      <pubDate>Thu, 20 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> southernillinoisuniversity.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-20<br/>
<strong>Last Updated:</strong> 2026-08-20</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Southern Illinois University affecting 552 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-20 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42450.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-southern-illinois-university.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Nebraska Orthopaedic Center — Washington State Attorney General formal data breach disclosure notice filed by Nebraska Orthopaedic Center affecting 992 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-nebraska-orthopaedic-center.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-nebraska-orthopaedic-center.html</guid>
      <pubDate>Wed, 19 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> nebraskaorthopaediccenter.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-19<br/>
<strong>Last Updated:</strong> 2026-08-19</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Nebraska Orthopaedic Center affecting 992 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-19 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42412.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-nebraska-orthopaedic-center.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Apple American Group  and Apple American Group II — Washington State Attorney General formal data breach disclosure notice filed by Apple American Group  and Apple American Group II affecting 20653 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-apple-american-group-and-apple.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-apple-american-group-and-apple.html</guid>
      <pubDate>Tue, 18 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> appleamericangroupandapple.com<br/>
<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-18<br/>
<strong>Last Updated:</strong> 2026-08-18</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Apple American Group  and Apple American Group II affecting 20653 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-18 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42400.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-apple-american-group-and-apple.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Turner Construction Company — Washington State Attorney General formal data breach disclosure notice filed by Turner Construction Company affecting 3401 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-turner-construction-company.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-turner-construction-company.html</guid>
      <pubDate>Tue, 18 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> turnerconstructioncompany.com<br/>
<strong>Threat Actor:</strong> Unattributed<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-18<br/>
<strong>Last Updated:</strong> 2026-08-18</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Turner Construction Company affecting 3401 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-18 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42399.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-turner-construction-company.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[DEVELOPING] TaxAct — Tax preparation provider TaxAct investigated unauthorized acquisition of over 2 million user records following sample leaks on illicit forums.</title>
      <link>https://securityincident.net/incidents/2026-08-taxact.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-taxact.html</guid>
      <pubDate>Mon, 17 Aug 2026 13:15:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> taxact.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-17<br/>
<strong>Last Updated:</strong> 2026-08-17</p>
<p>Tax preparation provider TaxAct investigated unauthorized acquisition of over 2 million user records following sample leaks on illicit forums.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-17 13:15 UTC</strong> [INDEPENDENT VERIFICATION]: Threat actor leaks 450k tax preparation sample records, claiming access to 2 million customer files. (<a href="https://databreaches.net/2026/08/17/more-than-2-million-user-records-from-taxact-allegedly-acquired-450k-already-leaked/">DataBreaches.net Telemetry Audit</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-taxact.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>tax-data</category>
      <category>leak-site</category>
      <category>developing</category>
    </item>
    <item>
      <title>[EMERGING] Fairlife — Dairy brand Fairlife suffered an Anubis ransomware cyberattack compromising 500 network hosts and resulting in 1 TB of exfiltrated operational data.</title>
      <link>https://securityincident.net/incidents/2026-08-fairlife.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-fairlife.html</guid>
      <pubDate>Sun, 16 Aug 2026 19:20:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> EMERGING<br/>
<strong>Target Domain:</strong> fairlife.com<br/>
<strong>Threat Actor:</strong> Anubis<br/>
<strong>Open Weights Confidence:</strong> 8% (UNVERIFIED CLAIM)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-16<br/>
<strong>Last Updated:</strong> 2026-08-16</p>
<p>Dairy brand Fairlife suffered an Anubis ransomware cyberattack compromising 500 network hosts and resulting in 1 TB of exfiltrated operational data.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-16 19:20 UTC</strong> [UNVERIFIED CLAIM]: Anubis ransomware gang publishes technical telemetry detailing compromise of 500 internal hosts at Fairlife. (<a href="https://databreaches.net/2026/08/16/500-hosts-1-tb-and-no-negotiation-anubis-provides-details-on-the-fairlife-attack/">DataBreaches.net Extortion Watch</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-fairlife.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>EMERGING</category>
      <category>investigative</category>
      <category>ransomware</category>
      <category>industrial</category>
      <category>emerging</category>
    </item>
    <item>
      <title>[CONFIRMED] AdaptHealth — Healthcare solutions provider AdaptHealth Corp disclosed an external threat actor gained unauthorized access to internal systems and exfiltrated company data.</title>
      <link>https://securityincident.net/incidents/2026-07-adapthealth.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-adapthealth.html</guid>
      <pubDate>Thu, 02 Jul 2026 18:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> adapthealth.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2026-07-02<br/>
<strong>Last Updated:</strong> 2026-08-14</p>
<p>Healthcare solutions provider AdaptHealth Corp disclosed an external threat actor gained unauthorized access to internal systems and exfiltrated company data.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-02 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: AdaptHealth confirms threat actor breached company systems and exfiltrated files. (<a href="https://www.sec.gov/Archives/edgar/data/1725255/000110465926080297/0001104659-26-080297-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001104659-26-080297)</a>)</li>
  <li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42340.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-adapthealth.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>healthcare</category>
      <category>confirmed</category>
      <category>state-ag</category>
      <category>washington</category>
    </item>
    <item>
      <title>[CONFIRMED] Baylor Genetics — Washington State Attorney General formal data breach disclosure notice filed by Baylor Genetics affecting 27243 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-baylor-genetics.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-baylor-genetics.html</guid>
      <pubDate>Fri, 14 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> baylorgenetics.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-14<br/>
<strong>Last Updated:</strong> 2026-08-14</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Baylor Genetics affecting 27243 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42352.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-baylor-genetics.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Lennar Mortgage — Washington State Attorney General formal data breach disclosure notice filed by Lennar Mortgage affecting 11417 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-lennar-mortgage.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-lennar-mortgage.html</guid>
      <pubDate>Fri, 14 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> lennarmortgage.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-14<br/>
<strong>Last Updated:</strong> 2026-08-14</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Lennar Mortgage affecting 11417 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42347.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-lennar-mortgage.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Paylogix — Washington State Attorney General formal data breach disclosure notice filed by Paylogix affecting 28449 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-paylogix.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-paylogix.html</guid>
      <pubDate>Fri, 14 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> paylogix.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-14<br/>
<strong>Last Updated:</strong> 2026-08-14</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Paylogix affecting 28449 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42351.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-paylogix.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Quantum Health — Washington State Attorney General formal data breach disclosure notice filed by Quantum Health affecting 5909 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-quantum-health.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-quantum-health.html</guid>
      <pubDate>Fri, 14 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> quantumhealth.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-14<br/>
<strong>Last Updated:</strong> 2026-08-14</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Quantum Health affecting 5909 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-14 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42356.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-quantum-health.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Chelan County, WA — Washington State Attorney General formal data breach disclosure notice filed by Chelan County, WA.</title>
      <link>https://securityincident.net/incidents/2026-08-chelan-county-wa.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-chelan-county-wa.html</guid>
      <pubDate>Tue, 11 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> chelancountywa.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-11<br/>
<strong>Last Updated:</strong> 2026-08-11</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Chelan County, WA.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-11 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42288.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-chelan-county-wa.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Kovack Financial — Washington State Attorney General formal data breach disclosure notice filed by Kovack Financial affecting 657 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-kovack-financial.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-kovack-financial.html</guid>
      <pubDate>Mon, 10 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> kovackfinancial.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-10<br/>
<strong>Last Updated:</strong> 2026-08-10</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Kovack Financial affecting 657 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-10 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42272.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-kovack-financial.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] American Addiction Centers — Washington State Attorney General formal data breach disclosure notice filed by American Addiction Centers affecting 1155 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-american-addiction-centers.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-american-addiction-centers.html</guid>
      <pubDate>Fri, 07 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> americanaddictioncenters.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-07<br/>
<strong>Last Updated:</strong> 2026-08-07</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by American Addiction Centers affecting 1155 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-07 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42250.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-american-addiction-centers.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Golden Opportunities And Local Support — Washington State Attorney General formal data breach disclosure notice filed by Golden Opportunities And Local Support.</title>
      <link>https://securityincident.net/incidents/2026-08-golden-opportunities-and-local.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-golden-opportunities-and-local.html</guid>
      <pubDate>Fri, 07 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> goldenopportunitiesandlocal.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-07<br/>
<strong>Last Updated:</strong> 2026-08-07</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Golden Opportunities And Local Support.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-07 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42237.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-golden-opportunities-and-local.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Aesto — Washington State Attorney General formal data breach disclosure notice filed by Aesto affecting 37253 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-aesto.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-aesto.html</guid>
      <pubDate>Tue, 04 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> aesto.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-04<br/>
<strong>Last Updated:</strong> 2026-08-04</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Aesto affecting 37253 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-04 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42154.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-aesto.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] CTS Journey — Washington State Attorney General formal data breach disclosure notice filed by CTS Journey affecting 2226 residents.</title>
      <link>https://securityincident.net/incidents/2026-08-cts-journey.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-08-cts-journey.html</guid>
      <pubDate>Mon, 03 Aug 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> ctsjourney.com<br/>
<strong>Open Weights Confidence:</strong> 68% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-08-03<br/>
<strong>Last Updated:</strong> 2026-08-03</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by CTS Journey affecting 2226 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-08-03 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42137.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-08-cts-journey.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Amgen — Biotechnology company Amgen filed Form 8-K Item 1.05 disclosing unauthorized cyber activity detected in July 2026.</title>
      <link>https://securityincident.net/incidents/2026-07-amgen.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-amgen.html</guid>
      <pubDate>Fri, 31 Jul 2026 16:15:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> amgen.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-31<br/>
<strong>Last Updated:</strong> 2026-07-31</p>
<p>Biotechnology company Amgen filed Form 8-K Item 1.05 disclosing unauthorized cyber activity detected in July 2026.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-31 16:15 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Amgen discloses detection of unauthorized access to corporate IT systems and initiates incident response. (<a href="https://www.sec.gov/Archives/edgar/data/318154/000031815426000119/0000318154-26-000119-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0000318154-26-000119)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-amgen.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>biotech</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Everside Health — Washington State Attorney General formal data breach disclosure notice filed by Everside Health affecting 21308 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-everside-health.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-everside-health.html</guid>
      <pubDate>Fri, 31 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> eversidehealth.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-31<br/>
<strong>Last Updated:</strong> 2026-07-31</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Everside Health affecting 21308 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-31 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42089.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-everside-health.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Microcode — Washington State Attorney General formal data breach disclosure notice filed by Microcode affecting 4096 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-microcode.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-microcode.html</guid>
      <pubDate>Thu, 30 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> microcode.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-30<br/>
<strong>Last Updated:</strong> 2026-07-30</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Microcode affecting 4096 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-30 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42069.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-microcode.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] River Financial — River Financial Corporation (parent of River Bank &amp; Trust) disclosed an unauthorized intrusion into its banking network involving corporate data exfiltration.</title>
      <link>https://securityincident.net/incidents/2026-07-river-financial.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-river-financial.html</guid>
      <pubDate>Mon, 06 Jul 2026 17:15:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> riverbankandtrust.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 87% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-06<br/>
<strong>Last Updated:</strong> 2026-07-30</p>
<p>River Financial Corporation (parent of River Bank & Trust) disclosed an unauthorized intrusion into its banking network involving corporate data exfiltration.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-06 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Initial Disclosure: River Financial detects unauthorized network intrusion and begins forensic investigation. (<a href="https://www.sec.gov/Archives/edgar/data/1641601/000119312526295704/0001193125-26-295704-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001193125-26-295704)</a>)</li>
  <li><strong>2026-07-10 18:30 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Amendment: Confirms unauthorized threat actor accessed internal systems and exfiltrated sensitive data files. (<a href="https://www.sec.gov/Archives/edgar/data/1641601/000119312526300763/0001193125-26-300763-index.htm">SEC EDGAR 8-K/A Item 1.05 (Adsh 0001193125-26-300763)</a>)</li>
  <li><strong>2026-07-17 16:45 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Update: Details containment milestones, ongoing litigation tracking, and customer notification procedures. (<a href="https://www.sec.gov/Archives/edgar/data/1641601/000119312526307288/0001193125-26-307288-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001193125-26-307288)</a>)</li>
  <li><strong>2026-07-30 19:00 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Status Conclusion: Confirms core network restoration, enhanced multi-factor controls, and complete containment. (<a href="https://www.sec.gov/Archives/edgar/data/1641601/000119312526325324/0001193125-26-325324-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001193125-26-325324)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-river-financial.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>banking</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] ADT — Washington State Attorney General formal data breach disclosure notice filed by ADT affecting 5129 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-adt.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-adt.html</guid>
      <pubDate>Tue, 28 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> adt.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-28<br/>
<strong>Last Updated:</strong> 2026-07-28</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by ADT affecting 5129 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-28 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42014.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-adt.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] JRK Property — Washington State Attorney General formal data breach disclosure notice filed by JRK Property affecting 5667 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-jrk-property.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-jrk-property.html</guid>
      <pubDate>Mon, 27 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> jrkproperty.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-27<br/>
<strong>Last Updated:</strong> 2026-07-27</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by JRK Property affecting 5667 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-27 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42008.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-jrk-property.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] SPay  dba Stack Sports — Washington State Attorney General formal data breach disclosure notice filed by SPay  dba Stack Sports affecting 1190 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-spay-dba-stack-sports.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-spay-dba-stack-sports.html</guid>
      <pubDate>Mon, 27 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> spaydbastacksports.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-27<br/>
<strong>Last Updated:</strong> 2026-07-27</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by SPay  dba Stack Sports affecting 1190 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-27 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA42002.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-spay-dba-stack-sports.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] AnMed Health — South Carolina healthcare system AnMed Health experienced extensive IT and telecommunications outages across all hospital campuses.</title>
      <link>https://securityincident.net/incidents/2026-07-anmed-health.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-anmed-health.html</guid>
      <pubDate>Sun, 26 Jul 2026 14:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> anmed.org<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 57% (CONFIRMED BY TARGET)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-26<br/>
<strong>Last Updated:</strong> 2026-07-26</p>
<p>South Carolina healthcare system AnMed Health experienced extensive IT and telecommunications outages across all hospital campuses.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-26 14:00 UTC</strong> [CONFIRMED BY TARGET]: AnMed Health confirms widespread network and phone outages affecting all facilities, maintaining emergency room triage. (<a href="https://databreaches.net/2026/07/26/developing-anmed-reports-phone-and-internet-outage-impacting-all-hospital-locations-ers-remain-open/">DataBreaches.net Telemetry Alert</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-anmed-health.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>investigative</category>
      <category>healthcare</category>
      <category>outage</category>
      <category>acknowledged</category>
    </item>
    <item>
      <title>[DEVELOPING] Tribeca Film Festival — Confidential attendee records, contact information, and travel itineraries for celebrity directors and actors leaked from Tribeca Festival systems.</title>
      <link>https://securityincident.net/incidents/2026-07-tribeca-film-festival.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-tribeca-film-festival.html</guid>
      <pubDate>Sun, 26 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> tribecafilm.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 39% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-26<br/>
<strong>Last Updated:</strong> 2026-07-26</p>
<p>Confidential attendee records, contact information, and travel itineraries for celebrity directors and actors leaked from Tribeca Festival systems.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-26 16:30 UTC</strong> [INDEPENDENT VERIFICATION]: Independent audit confirms exposure of internal filmmaker directories and high-profile attendee rosters. (<a href="https://databreaches.net/2026/07/26/a-list-directors-actors-and-celebrities-exposed-in-tribeca-film-festival-data-leak/">DataBreaches.net Security Report</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-tribeca-film-festival.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>entertainment</category>
      <category>data-leak</category>
      <category>developing</category>
    </item>
    <item>
      <title>[CONFIRMED] Bridgeway Benefit Technologies — Washington State Attorney General formal data breach disclosure notice filed by Bridgeway Benefit Technologies affecting 640 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-bridgeway-benefit-technologies.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-bridgeway-benefit-technologies.html</guid>
      <pubDate>Fri, 24 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> bridgewaybenefittechnologies.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-24<br/>
<strong>Last Updated:</strong> 2026-07-24</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Bridgeway Benefit Technologies affecting 640 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-24 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41982.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-bridgeway-benefit-technologies.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] CareCloud — Washington State Attorney General formal data breach disclosure notice filed by CareCloud affecting 20706 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-carecloud.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-carecloud.html</guid>
      <pubDate>Fri, 24 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> carecloud.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-24<br/>
<strong>Last Updated:</strong> 2026-07-24</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by CareCloud affecting 20706 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-24 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachM25126.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-carecloud.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[DEVELOPING] Crime Stoppers USA — Over 1 million confidential crime tip records intended to remain strictly anonymous were exposed through an unsecured online system.</title>
      <link>https://securityincident.net/incidents/2026-07-crime-stoppers-usa.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-crime-stoppers-usa.html</guid>
      <pubDate>Fri, 24 Jul 2026 18:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> DEVELOPING<br/>
<strong>Target Domain:</strong> crimestoppersusa.org<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 43% (INDEPENDENT VERIFICATION)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-24<br/>
<strong>Last Updated:</strong> 2026-07-24</p>
<p>Over 1 million confidential crime tip records intended to remain strictly anonymous were exposed through an unsecured online system.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-24 18:00 UTC</strong> [INDEPENDENT VERIFICATION]: Investigative audit reveals misconfigured repository leaking over 1 million anonymous tipster reports. (<a href="https://databreaches.net/2026/07/24/crime-stoppers-assured-people-their-tips-would-be-anonymous-then-more-than-1-million-tips-leaked/">DataBreaches.net Investigation</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-crime-stoppers-usa.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>DEVELOPING</category>
      <category>investigative</category>
      <category>law-enforcement</category>
      <category>exposure</category>
      <category>developing</category>
    </item>
    <item>
      <title>[CONFIRMED] Eyemart Express — Washington State Attorney General formal data breach disclosure notice filed by Eyemart Express affecting 1704 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-eyemart-express.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-eyemart-express.html</guid>
      <pubDate>Fri, 24 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> eyemartexpress.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-24<br/>
<strong>Last Updated:</strong> 2026-07-24</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Eyemart Express affecting 1704 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-24 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41958.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-eyemart-express.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Safetyfirst Systems — Washington State Attorney General formal data breach disclosure notice filed by Safetyfirst Systems affecting 1157 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-safetyfirst-systems.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-safetyfirst-systems.html</guid>
      <pubDate>Thu, 23 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> safetyfirstsystems.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-23<br/>
<strong>Last Updated:</strong> 2026-07-23</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Safetyfirst Systems affecting 1157 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-23 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41934.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-safetyfirst-systems.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] The Moody Bible Institute of Chicago — Washington State Attorney General formal data breach disclosure notice filed by The Moody Bible Institute of Chicago affecting 8955 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-the-moody-bible-institute.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-the-moody-bible-institute.html</guid>
      <pubDate>Thu, 23 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> moodybible.org<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-23<br/>
<strong>Last Updated:</strong> 2026-07-23</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by The Moody Bible Institute of Chicago affecting 8955 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-23 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41947.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-the-moody-bible-institute.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Kootenai County, Idaho — Washington State Attorney General formal data breach disclosure notice filed by Kootenai County, Idaho affecting 746 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-kootenai-county-idaho.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-kootenai-county-idaho.html</guid>
      <pubDate>Wed, 22 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> kootenaicountyidaho.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-22<br/>
<strong>Last Updated:</strong> 2026-07-22</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Kootenai County, Idaho affecting 746 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-22 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41917.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-kootenai-county-idaho.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Unlimited Technology Systems — Washington State Attorney General formal data breach disclosure notice filed by Unlimited Technology Systems affecting 724 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-unlimited-technology-systems.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-unlimited-technology-systems.html</guid>
      <pubDate>Tue, 21 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> unlimitedtechnologysystems.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-21<br/>
<strong>Last Updated:</strong> 2026-07-21</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Unlimited Technology Systems affecting 724 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-21 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41907.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-unlimited-technology-systems.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] The Estée Lauder Companies — Washington State Attorney General formal data breach disclosure notice filed by The Estée Lauder Companies affecting 2110 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-the-estee-lauder-companies.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-the-estee-lauder-companies.html</guid>
      <pubDate>Fri, 17 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> theesteelaudercompanies.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-17<br/>
<strong>Last Updated:</strong> 2026-07-17</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by The Estée Lauder Companies affecting 2110 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-17 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41847.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-the-estee-lauder-companies.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] ZenPatient — Washington State Attorney General formal data breach disclosure notice filed by ZenPatient affecting 651 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-zenpatient.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-zenpatient.html</guid>
      <pubDate>Fri, 17 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> zenpatient.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-17<br/>
<strong>Last Updated:</strong> 2026-07-17</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by ZenPatient affecting 651 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-17 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41853.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-zenpatient.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] DentaQuest — Washington State Attorney General formal data breach disclosure notice filed by DentaQuest affecting 148300 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-dentaquest.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-dentaquest.html</guid>
      <pubDate>Thu, 16 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> dentaquest.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-16<br/>
<strong>Last Updated:</strong> 2026-07-16</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by DentaQuest affecting 148300 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-16 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41829.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-dentaquest.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Fox Rothschild — Washington State Attorney General formal data breach disclosure notice filed by Fox Rothschild affecting 1891 residents.</title>
      <link>https://securityincident.net/incidents/2026-07-fox-rothschild.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-fox-rothschild.html</guid>
      <pubDate>Thu, 16 Jul 2026 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> foxrothschild.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-16<br/>
<strong>Last Updated:</strong> 2026-07-16</p>
<p>Washington State Attorney General formal data breach disclosure notice filed by Fox Rothschild affecting 1891 residents.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-16 16:30 UTC</strong> [CONFIRMED BY REGULATOR]: Washington State Attorney General Breach Notice (RCW 19.255) (<a href="https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA41834.pdf">Washington State Attorney General Breach Notice (RCW 19.255)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-fox-rothschild.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>state-ag</category>
      <category>washington</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[REFUTED] Synopsys — Threat actor extortion claims asserting an intrusion into Synopsys systems were formally audited and disproven with no evidence of compromise.</title>
      <link>https://securityincident.net/incidents/2026-07-synopsys.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-synopsys.html</guid>
      <pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> REFUTED<br/>
<strong>Target Domain:</strong> synopsys.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 0% (REFUTED)<br/>
<strong>Corroborated Source Domains:</strong> 0<br/>
<strong>First Seen:</strong> 2026-07-14<br/>
<strong>Last Updated:</strong> 2026-07-14</p>
<p>Threat actor extortion claims asserting an intrusion into Synopsys systems were formally audited and disproven with no evidence of compromise.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-14 12:00 UTC</strong> [REFUTED]: Synopsys completes comprehensive forensic review and confirms threat actor claims are false with no breach of corporate data. (<a href="https://databreaches.net/2026/07/14/synopsys-finds-no-evidence-of-data-breach-amid-bosch-hack-claims/">DataBreaches.net Forensic Verification Notice</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-synopsys.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>REFUTED</category>
      <category>investigative</category>
      <category>semiconductors</category>
      <category>refuted</category>
    </item>
    <item>
      <title>[CONFIRMED] Navient — Student loan servicer Navient disclosed a third-party ransomware attack affecting legal service provider systems containing Navient corporate data.</title>
      <link>https://securityincident.net/incidents/2026-07-navient.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2026-07-navient.html</guid>
      <pubDate>Thu, 02 Jul 2026 17:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> navient.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 84% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 1<br/>
<strong>First Seen:</strong> 2026-07-02<br/>
<strong>Last Updated:</strong> 2026-07-02</p>
<p>Student loan servicer Navient disclosed a third-party ransomware attack affecting legal service provider systems containing Navient corporate data.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2026-07-02 17:30 UTC</strong> [CONFIRMED BY REGULATOR]: SEC Form 8-K Item 1.05 Filing: Navient discloses ransomware breach at third-party law firm impacting company data. (<a href="https://www.sec.gov/Archives/edgar/data/1593538/000114036126027441/0001140361-26-027441-index.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001140361-26-027441)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2026-07-navient.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>third-party</category>
      <category>financial</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Change Healthcare — Change Healthcare (UnitedHealth Group) suffered a devastating ALPHV / BlackCat ransomware extortion attack halting healthcare clearinghouse networks nationwide and impacting 100M individuals.</title>
      <link>https://securityincident.net/incidents/2024-02-change-healthcare.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2024-02-change-healthcare.html</guid>
      <pubDate>Wed, 21 Feb 2024 14:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> changehealthcare.com<br/>
<strong>Threat Actor:</strong> ALPHV / BlackCat<br/>
<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 4<br/>
<strong>First Seen:</strong> 2024-02-21<br/>
<strong>Last Updated:</strong> 2024-10-24</p>
<p>Change Healthcare (UnitedHealth Group) suffered a devastating ALPHV / BlackCat ransomware extortion attack halting healthcare clearinghouse networks nationwide and impacting 100M individuals.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2024-02-21 14:00 UTC</strong> [CONFIRMED BY TARGET]: Change Healthcare confirms widespread network disruption to prescription routing, claims processing, and clinical operations. (<a href="https://www.unitedhealthgroup.com/changehealthcarecyberresponse">UnitedHealth Group Official Disruption Bulletin</a>)</li>
  <li><strong>2024-02-22 17:30 UTC</strong> [CONFIRMED BY REGULATOR]: UnitedHealth Group files SEC Form 8-K Item 1.05 disclosing suspected cybercrime intrusion into Change Healthcare IT environments. (<a href="https://www.sec.gov/Archives/edgar/data/731766/000073176624000010/uhg-20240221.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0000731766-24-000010)</a>)</li>
  <li><strong>2024-02-28 19:00 UTC</strong> [INDEPENDENT VERIFICATION]: ALPHV / BlackCat ransomware extortion gang claims responsibility, stating 6 TB of sensitive patient and financial records were exfiltrated. (<a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a">CISA &amp; FBI Joint Cybersecurity Advisory (AA24-060A)</a>)</li>
  <li><strong>2024-10-24 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: HHS OCR breach portal registers confirmed affected population of approximately 100,000,000 individuals. (<a href="https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf">HHS OCR Data Breach Portal Entry (Change Healthcare)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2024-02-change-healthcare.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>hhs-ocr</category>
      <category>healthcare</category>
      <category>ransomware</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Halliburton — Oilfield services corporation Halliburton filed Form 8-K Item 1.05 disclosing an unauthorized intrusion by RansomHub that forced the company to take global systems offline.</title>
      <link>https://securityincident.net/incidents/2024-08-halliburton.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2024-08-halliburton.html</guid>
      <pubDate>Wed, 21 Aug 2024 16:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> halliburton.com<br/>
<strong>Threat Actor:</strong> RansomHub<br/>
<strong>Open Weights Confidence:</strong> 94% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2024-08-21<br/>
<strong>Last Updated:</strong> 2024-09-03</p>
<p>Oilfield services corporation Halliburton filed Form 8-K Item 1.05 disclosing an unauthorized intrusion by RansomHub that forced the company to take global systems offline.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2024-08-21 16:00 UTC</strong> [CONFIRMED BY TARGET]: Energy giant Halliburton detects unauthorized third-party access to corporate systems and activates incident response protocols. (<a href="https://www.halliburton.com/en/about-us/corporate-governance">Halliburton Incident Advisory</a>)</li>
  <li><strong>2024-08-23 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: Halliburton files Form 8-K Item 1.05 disclosing material disruption to business operations and systems shutdown. (<a href="https://www.sec.gov/Archives/edgar/data/45012/000004501224000067/hal-20240823.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0000045012-24-000067)</a>)</li>
  <li><strong>2024-09-03 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 8.01 supplemental filing confirms company is restoring operational capabilities and remediating core IT environments. (<a href="https://www.sec.gov/Archives/edgar/data/45012/000004501224000072/hal-20240903.htm">SEC EDGAR 8-K Item 8.01 (Adsh 0000045012-24-000072)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2024-08-halliburton.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>energy</category>
      <category>oil-gas</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] CDK Global — Dealership software giant CDK Global suffered an operational paralysis cyberattack by the BlackSuit ransomware group, shutting down 15,000 auto dealerships nationwide.</title>
      <link>https://securityincident.net/incidents/2024-06-cdk-global.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2024-06-cdk-global.html</guid>
      <pubDate>Wed, 19 Jun 2024 14:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> cdkglobal.com<br/>
<strong>Threat Actor:</strong> BlackSuit<br/>
<strong>Open Weights Confidence:</strong> 88% (CONFIRMED BY TARGET)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2024-06-19<br/>
<strong>Last Updated:</strong> 2024-07-02</p>
<p>Dealership software giant CDK Global suffered an operational paralysis cyberattack by the BlackSuit ransomware group, shutting down 15,000 auto dealerships nationwide.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2024-06-19 14:00 UTC</strong> [CONFIRMED BY TARGET]: CDK Global shuts down all core dealership management systems following massive cyberattack disrupting 15,000 car dealerships nationwide. (<a href="https://www.cdkglobal.com/outage-update">CDK Global Customer Advisory Bulletin</a>)</li>
  <li><strong>2024-06-21 16:30 UTC</strong> [INDEPENDENT VERIFICATION]: BlackSuit ransomware collective demands $25M ransom; second intrusion detected during restoration attempt. (<a href="https://www.bleepingcomputer.com/news/security/cdk-global-cyberattack-dealership-outage-details/">BleepingComputer Cybersecurity Investigation</a>)</li>
  <li><strong>2024-07-02 18:00 UTC</strong> [CONFIRMED BY TARGET]: CDK confirms phased restoration of dealer management system (DMS) for core dealership clients nationwide. (<a href="https://www.cdkglobal.com/news-insights">CDK Global Restoration Announcement</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2024-06-cdk-global.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>investigative</category>
      <category>automotive</category>
      <category>software</category>
      <category>ransomware</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Advance Auto Parts — Automotive retailer Advance Auto Parts filed Form 8-K Item 1.05 after cybercriminals compromised its cloud database tenant, stealing 380 million customer profiles.</title>
      <link>https://securityincident.net/incidents/2024-06-advance-auto-parts.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2024-06-advance-auto-parts.html</guid>
      <pubDate>Thu, 23 May 2024 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> advanceautoparts.com<br/>
<strong>Threat Actor:</strong> UNC5537<br/>
<strong>Open Weights Confidence:</strong> 100% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 3<br/>
<strong>First Seen:</strong> 2024-05-23<br/>
<strong>Last Updated:</strong> 2024-06-05</p>
<p>Automotive retailer Advance Auto Parts filed Form 8-K Item 1.05 after cybercriminals compromised its cloud database tenant, stealing 380 million customer profiles.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2024-05-23 16:30 UTC</strong> [CONFIRMED BY TARGET]: Unauthorized actor accesses company's cloud data environment via stolen contractor credentials. (<a href="https://corp.advanceautoparts.com/investors">Advance Auto Parts Security Notice</a>)</li>
  <li><strong>2024-06-04 18:00 UTC</strong> [INDEPENDENT VERIFICATION]: Threat actor offers 380 million customer records for sale on dark web breach forums for $1.5 million. (<a href="https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft">Mandiant Threat Intelligence Audit (UNC5537)</a>)</li>
  <li><strong>2024-06-05 17:30 UTC</strong> [CONFIRMED BY REGULATOR]: Advance Auto Parts files Form 8-K Item 1.05 confirming exfiltration of customer and employee data files. (<a href="https://www.sec.gov/Archives/edgar/data/1158449/000115844924000163/aap-20240605.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001158449-24-000163)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2024-06-advance-auto-parts.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>retail</category>
      <category>snowflake-cloud</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Prudential Financial — Prudential Financial filed Form 8-K Item 1.05 following an administrative system intrusion by the ALPHV / BlackCat ransomware group compromising employee and user data.</title>
      <link>https://securityincident.net/incidents/2024-02-prudential-financial.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2024-02-prudential-financial.html</guid>
      <pubDate>Mon, 05 Feb 2024 16:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> prudential.com<br/>
<strong>Threat Actor:</strong> ALPHV / BlackCat<br/>
<strong>Open Weights Confidence:</strong> 98% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2024-02-05<br/>
<strong>Last Updated:</strong> 2024-03-29</p>
<p>Prudential Financial filed Form 8-K Item 1.05 following an administrative system intrusion by the ALPHV / BlackCat ransomware group compromising employee and user data.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2024-02-05 16:00 UTC</strong> [CONFIRMED BY TARGET]: Threat actor breaches internal administrative network environments and exfiltrates corporate data files. (<a href="https://www.prudential.com/links/security">Prudential Information Security Bulletin</a>)</li>
  <li><strong>2024-02-13 18:30 UTC</strong> [CONFIRMED BY REGULATOR]: Prudential files Form 8-K Item 1.05 disclosing unauthorized access to administrative and internal user directories. (<a href="https://www.sec.gov/Archives/edgar/data/1137774/000113777424000012/pru-20240212.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001137774-24-000012)</a>)</li>
  <li><strong>2024-03-29 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 1.05 amendment updates scope to confirm 32,183 individuals impacted by exfiltration. (<a href="https://www.sec.gov/Archives/edgar/data/1137774/000113777424000028/pru-20240329.htm">SEC EDGAR 8-K/A Item 1.05 (Adsh 0001137774-24-000028)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2024-02-prudential-financial.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>financial</category>
      <category>insurance</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] Hewlett Packard Enterprise — Hewlett Packard Enterprise filed Form 8-K Item 1.05 disclosing that nation-state actor Midnight Blizzard compromised its cloud-based Office 365 email environment.</title>
      <link>https://securityincident.net/incidents/2024-01-hewlett-packard-enterprise.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2024-01-hewlett-packard-enterprise.html</guid>
      <pubDate>Fri, 19 Jan 2024 16:30:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> hpe.com<br/>
<strong>Threat Actor:</strong> Midnight Blizzard (APT29)<br/>
<strong>Open Weights Confidence:</strong> 91% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2024-01-19<br/>
<strong>Last Updated:</strong> 2024-01-24</p>
<p>Hewlett Packard Enterprise filed Form 8-K Item 1.05 disclosing that nation-state actor Midnight Blizzard compromised its cloud-based Office 365 email environment.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2024-01-19 16:30 UTC</strong> [CONFIRMED BY TARGET]: HPE notified that nation-state actor Midnight Blizzard gained unauthorized access to Office 365 cloud email environment. (<a href="https://www.hpe.com/us/en/newsroom/press-releases/2024/01/hpe-security-update.html">HPE Press &amp; Security Disclosure Notice</a>)</li>
  <li><strong>2024-01-24 17:00 UTC</strong> [CONFIRMED BY REGULATOR]: HPE files Form 8-K Item 1.05 disclosing data exfiltration from cybersecurity, legal, and operational team mailboxes dating back to May 2023. (<a href="https://www.sec.gov/Archives/edgar/data/1645590/000164559024000003/hpe-20240119.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001645590-24-000003)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2024-01-hewlett-packard-enterprise.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>technology</category>
      <category>nation-state</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] LoanDepot — LoanDepot filed Form 8-K Item 1.05 disclosing a major ransomware extortion attack encrypting mortgage servicing systems and compromising 16.6 million customers.</title>
      <link>https://securityincident.net/incidents/2024-01-loandepot.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2024-01-loandepot.html</guid>
      <pubDate>Mon, 08 Jan 2024 15:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> loandepot.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 98% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2024-01-08<br/>
<strong>Last Updated:</strong> 2024-01-22</p>
<p>LoanDepot filed Form 8-K Item 1.05 disclosing a major ransomware extortion attack encrypting mortgage servicing systems and compromising 16.6 million customers.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2024-01-08 15:00 UTC</strong> [CONFIRMED BY TARGET]: LoanDepot detects unauthorized cyber incident that encrypted company systems and took loan servicing portals offline. (<a href="https://www.loandepot.com/cybersecurity-notice">LoanDepot Cybersecurity Response Bulletin</a>)</li>
  <li><strong>2024-01-11 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: LoanDepot files Form 8-K Item 1.05 confirming unauthorized third-party access and ransomware encryption. (<a href="https://www.sec.gov/Archives/edgar/data/1831631/000183163124000002/lndi-20240108.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001831631-24-000002)</a>)</li>
  <li><strong>2024-01-22 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 1.05 amendment confirms sensitive personal data of approximately 16.6 million individuals was exfiltrated. (<a href="https://www.sec.gov/Archives/edgar/data/1831631/000183163124000004/lndi-20240122.htm">SEC EDGAR 8-K/A Item 1.05 (Adsh 0001831631-24-000004)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2024-01-loandepot.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>financial</category>
      <category>mortgage</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] VF Corporation — VF Corporation (parent of Vans, The North Face, and Timberland) filed Form 8-K Item 1.05 following an ALPHV ransomware attack compromising 35.5 million customer records.</title>
      <link>https://securityincident.net/incidents/2023-12-vf-corporation.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2023-12-vf-corporation.html</guid>
      <pubDate>Wed, 13 Dec 2023 19:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> vfc.com<br/>
<strong>Threat Actor:</strong> ALPHV / BlackCat<br/>
<strong>Open Weights Confidence:</strong> 98% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2023-12-13<br/>
<strong>Last Updated:</strong> 2024-01-18</p>
<p>VF Corporation (parent of Vans, The North Face, and Timberland) filed Form 8-K Item 1.05 following an ALPHV ransomware attack compromising 35.5 million customer records.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2023-12-13 19:00 UTC</strong> [CONFIRMED BY TARGET]: Threat actor encrypts operational IT systems and exfiltrates corporate data from apparel conglomerate VF Corp. (<a href="https://www.vfc.com/news">VF Corporation Incident Briefing</a>)</li>
  <li><strong>2023-12-18 17:30 UTC</strong> [CONFIRMED BY REGULATOR]: VF Corp files Form 8-K Item 1.05 disclosing material disruption to retail logistics and e-commerce order processing. (<a href="https://www.sec.gov/Archives/edgar/data/103379/000010337923000039/vfc-20231215.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0000103379-23-000039)</a>)</li>
  <li><strong>2024-01-18 18:00 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 1.05 update confirms 35.5 million individual customer records compromised during the intrusion. (<a href="https://www.sec.gov/Archives/edgar/data/103379/000010337924000003/vfc-20240118.htm">SEC EDGAR 8-K Item 1.05 Update (Adsh 0000103379-24-000003)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2023-12-vf-corporation.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>retail</category>
      <category>ransomware</category>
      <category>confirmed</category>
    </item>
    <item>
      <title>[CONFIRMED] First American Financial — First American Financial filed the very first SEC Form 8-K Item 1.05 disclosure under the SEC mandate following an unauthorized network intrusion that disabled title portals.</title>
      <link>https://securityincident.net/incidents/2023-12-first-american-financial.html</link>
      <guid isPermaLink="true">https://securityincident.net/incidents/2023-12-first-american-financial.html</guid>
      <pubDate>Wed, 20 Dec 2023 18:00:00 GMT</pubDate>
      <description><![CDATA[<p><strong>Status:</strong> CONFIRMED<br/>
<strong>Target Domain:</strong> firstam.com<br/>
<strong>Threat Actor:</strong> Unknown / Unattributed<br/>
<strong>Open Weights Confidence:</strong> 98% (CONFIRMED BY REGULATOR)<br/>
<strong>Corroborated Source Domains:</strong> 2<br/>
<strong>First Seen:</strong> 2023-12-20<br/>
<strong>Last Updated:</strong> 2024-01-16</p>
<p>First American Financial filed the very first SEC Form 8-K Item 1.05 disclosure under the SEC mandate following an unauthorized network intrusion that disabled title portals.</p>
<h3>Milestone Timeline</h3>
<ul>
  <li><strong>2023-12-20 18:00 UTC</strong> [CONFIRMED BY TARGET]: First American detects unauthorized cybersecurity activity and isolates systems, taking email, title production, and web portals offline. (<a href="https://www.firstam.com/update">First American Cybersecurity Advisory</a>)</li>
  <li><strong>2023-12-22 17:15 UTC</strong> [CONFIRMED BY REGULATOR]: First American files SEC Form 8-K Item 1.05—marking the landmark first-ever disclosure under the SEC's material cybersecurity disclosure mandate. (<a href="https://www.sec.gov/Archives/edgar/data/1472787/000147278723000072/faf-20231220.htm">SEC EDGAR 8-K Item 1.05 (Adsh 0001472787-23-000072)</a>)</li>
  <li><strong>2024-01-16 16:45 UTC</strong> [CONFIRMED BY REGULATOR]: Form 8-K Item 1.05 amendment confirms core title and escrow transaction systems are restored and operational. (<a href="https://www.sec.gov/Archives/edgar/data/1472787/000147278724000003/faf-20240116.htm">SEC EDGAR 8-K/A Item 1.05 (Adsh 0001472787-24-000003)</a>)</li>
</ul>
<p><a href="https://securityincident.net/incidents/2023-12-first-american-financial.html">View Full Verified Timeline &amp; Evidence on securityincident.net</a></p>]]></description>
      <category>CONFIRMED</category>
      <category>regulatory</category>
      <category>sec-8k</category>
      <category>financial</category>
      <category>title-insurance</category>
      <category>confirmed</category>
    </item>
  </channel>
</rss>
