AUTO-UPDATED EVERY 30 MIN

Significant Cyber Incidents

Major breaches, ransomware attacks, and nation-state operations affecting businesses worldwide. Sourced from Cyber Scoop, The Record, SecurityWeek, DataBreaches.net and more.

📡 43 incidents tracked·🕐 Last refresh: Sep 13, 2026, 9:24 a.m. PT
Retail

Delaware Consumer Privacy and Data-Breach Law Updates

Joseph J. Lazzarotti of JacksonLewis writes: On September 2, 2026, Delaware’s Governor signed House Bill (HB) 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), which was enacted in 2023 and be…

DataBreaches.netSep 13, 2026
Government

AT&T store worker gets 16 months inside for SIM-swap side hustle

Connor Jones reports: A former AT&T retail worker who used his system access to hijack customers’ phone numbers for cybercriminals has been sentenced to 16 months in federal prison. Kenneth Carter, 44, carried …

DataBreaches.netSep 13, 2026
Healthcare

HHS Releases Updated Security Risk Assessment Tool

From HHS OCR: The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health IT (ONC) are pleased to announce the release of version 3.7 of the Securi…

DataBreaches.netSep 13, 2026
Enterprise

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measur…

SecurityWeekSep 13, 2026
Manufacturing

Not just Korea: Google leaked identifying info for sex crime victims across the world

Shin Da-eun and Park Kang-su report: Korea was not the only country where victims who sent Google removal requests about illegally obtained sexual images ended up having their private information posted online, the Hanky…

DataBreaches.netSep 12, 2026
Financial

NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities

New York State Department of Financial Services (DFS): September 10, 2026 New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the De…

DataBreaches.netSep 12, 2026
Manufacturing

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek .…

SecurityWeekSep 12, 2026
Manufacturing

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Sa…

SecurityWeekSep 12, 2026
Enterprise

Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems

OpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages. The post Researchers say OpenAI agents were behind May hacking…

Cyber ScoopSep 12, 2026
Government

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

A Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack. The post Cyberattack causes a flight d…

Cyber ScoopSep 11, 2026
Government

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.…

The RecordSep 11, 2026
Enterprise

TX: Two Lamesa ISD employees arrested over security breach

Urijah Jaushlin reports: Two Lamesa ISD employees were arrested in connection with a law enforcement investigation involving allegations of a breach of computer security, according to a press release by the Lamesa Indepe…

DataBreaches.netSep 11, 2026
Enterprise

GitLab’s critical flaw is already drawing internet-wide probes

One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately. The post GitLab’s critical flaw is already drawing internet-wi…

Cyber ScoopSep 11, 2026
Manufacturing

Microsoft sees some new wrinkles in invoice-scam emails

Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.…

The RecordSep 11, 2026
Manufacturing

Phishing Research Challenges Conventional Security Awareness Testing

Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared fi…

SecurityWeekSep 11, 2026
Enterprise

GitLab Vulnerability Exploited One Day After Disclosure

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek .…

SecurityWeekSep 11, 2026
Government

Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware

There’s an update to a previously reported case. From the Department of Justice, this press release: Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspi…

DataBreaches.netSep 11, 2026
Government

Personal Info Possibly Compromised at Japan’s Digital Agency

JiJi Press reports: Japan’s Digital Agency said Friday that about 246,000 sets of personal information, including the names and email addresses of government employees, may have been compromised through the unautho…

DataBreaches.netSep 11, 2026
Manufacturing

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Ot…

SecurityWeekSep 11, 2026
Enterprise

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails…

InfoSecuritySep 11, 2026
Enterprise

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack app…

SecurityWeekSep 11, 2026
Government

Anthropic caught Russia-linked spies using Claude in hacking operations

Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.…

The RecordSep 11, 2026
Manufacturing

Ukrainian hacker gets four years in US prison over Conti ransomware attacks

A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.…

The RecordSep 11, 2026
Enterprise

Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on Security…

SecurityWeekSep 11, 2026
Manufacturing

Check Point Patches Critical VPN Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek .…

SecurityWeekSep 11, 2026
Financial

Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance

Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek .…

SecurityWeekSep 11, 2026
Enterprise

Most Organizations Skip Permissions Reviews Before Deploying AI Tools

A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing so…

InfoSecuritySep 11, 2026
Financial

Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.…

The RecordSep 10, 2026
Manufacturing

Conti ransomware crew member sentenced to four years in prison

Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies. The post Conti ransomware crew member sentenced to four years in prison appeared first on CyberScoop .…

Cyber ScoopSep 10, 2026
Enterprise

Hawley probes OpenAI over Hugging Face breach

The Republican lawmaker called OpenAI’s leadership decisions “reckless,” and used recent warnings about the existential risk of AI to bolster his inquiry. The post Hawley probes OpenAI over Hugging Face breach appeared f…

Cyber ScoopSep 10, 2026
Government

AI lets small actors run state-level hacking campaigns, Anthropic report finds

The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations. The pos…

Cyber ScoopSep 10, 2026
Manufacturing

CISA Updates Insider Threat Guide With New Mitigation Advice

CISA has updated its insider threat guide with new advice on remote work, AI and risk detection…

InfoSecuritySep 10, 2026
Government

Governments ‘buying time’ in race between innovation, security, national cyber director says

Sean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones. The post Governments ‘buying time’ in race between innovation, security, national cyber director says appeared first on …

Cyber ScoopSep 10, 2026
Healthcare

FTC Withdraws Obsolete Policy Statement

From the Federal Trade Commission: The Federal Trade Commission rescinded the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. This controversial policy statement purported to apply the FTC’s…

DataBreaches.netSep 10, 2026
Manufacturing

Korea raises data breach fines to 10% of revenue

Korea JoongAng Daily reports: Korea’s privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing…

DataBreaches.netSep 10, 2026
Manufacturing

MantaxOtax Android Malware Combines Ransomware With Spyware

MantaxOtax Android malware combines ransomware with extensive spyware capabilities…

InfoSecuritySep 10, 2026
Government

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors…

InfoSecuritySep 10, 2026
Manufacturing

Anthropic Reveals Yet Another Cybersecurity Incident

Anthropic has found a fourth case of its model accessing third-party systems without authorization…

InfoSecuritySep 10, 2026
Manufacturing

OFAC Sanctions Chinese Scam Platform Xinbi Guarantee

The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee…

InfoSecuritySep 10, 2026
Enterprise

Chinese espionage groups swarm to exploit triple-link chain of zero-days

Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. The post Chinese espionage groups swarm to exploit trip…

Cyber ScoopSep 9, 2026
Healthcare

FTC rescinds policy statement requiring health apps to notify customers after a breach

The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. The post FTC rescinds policy statement requi…

Cyber ScoopSep 9, 2026
Enterprise

Lawmakers call on Commerce to sanction hackers-for-hire

The groups have allegedly targeted American citizens and companies, including the wife of GOP Senate candidate Mike Rogers, a former representative running in a Michigan swing race. The post Lawmakers call on Commerce to…

Cyber ScoopSep 9, 2026
Enterprise

Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls

The hacking tool, built using a combination of AI models, is effective against Android and iOS devices…

InfoSecuritySep 9, 2026