Customers’ personal information compromised in breach @ Evolve Bank & Trust

In June 2024, the company experienced a significant cyberattack and data breach. Initially, the LockBit ransomware group claimed responsibility and asserted that they had breached the Federal Reserve. However, it was later confirmed that the compr...

69,000 people affected by data breach @ Comstar, LLC

In June 2022, Comstar, LLC, an ambulance billing service, disclosed a data breach impacting approximately 69,000 individuals nationwide. The breach, discovered on March 26, 2022, stemmed from suspicious activity on Comstar's servers, later confirmed a...

Patients' data compromised @ Navvis & Company, LLC and SSM Health

In July 2023, the company (a business partner of SSM Health) experienced a data breach that compromised the personal information of some SSM Health patients. The breach occurred due to suspicious activity on the company's network two weeks in July...

Contactless payments and online orders impacted by incident @ Marks & Spencer

In April 2025, the company experienced a cyberattack that severely disrupted its operations. The attack led to the suspension of online orders, caused delays in click and collect services and impacted contactless payment systems across its UK stores. ...

Not yet released film withheld for ransom by hackers @ The Walt Disney Company

Over the past six months, there has been a significant increase in cyberattacks targeting Hollywood agencies and studios. These attacks involve hackers breaching company networks, stealing sensitive data like films, scripts, and employee information, ...

Patients' information exposed after third party vendor breached @ Community Health Systems Inc. and 2 more...

In June 2021, the company disclosed a data security incident encountered by an IT service provider (Netgain) for another third party (Health Centre Partners of Southern California) that provides a variety of support to the company, including grant-fun...

Cyber attack impacted operations after it caused an outage @ Lee Enterprises

In February 2025, Lee Enterprises, a major U.S. newspaper chain, experienced a significant cybersecurity event that disrupted its operations. The incident, initially detected on February 3, affected the company's business applications, leading to disr...

Unauthorised access to files on company’s computer network @ Birch Medical

In February 2025, Birch Medical, a healthcare services company, officially announced that they had experienced a data breach in September 2024. The company discovered that unauthorized individuals potentially accessed files on their computer network, ...

Unauthorised party access to portions of computer network @ Loyola University Maryland

In March 2025, Loyola University Maryland (Loyola) disclosed a data breach that occurred between July 19, 2024, and July 25, 2024. The breach came to light on January 30, 2025, when an investigation revealed unauthorized access to files containing sen...

Bank released woman’s bank details to third party who then stalked her abroad @ Bank of Ireland

In March 2025, the High Court of Ireland ordered the Bank of Ireland to pay a €350,000 settlement for an alleged data breach. A woman sued the bank, alleging they released her banking information to her estranged father. The woman claimed her father u...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...