Employee hacked servers after being fired, altering prices, adding profanities, and mislabeling allergy info @ The Walt Disney Company

A former Walt Disney World employee was arrested by the FBI for allegedly hacking into the company's servers and tampering with menu information. The suspect, a former menu production manager, was fired in June 2024 under contentious circumstances. Hi...

Customers' data exposed in the Salesloft Drift attacks which affected Salesforce databases @ Salesforce, Inc. and Zscaler, Inc.

In September 2025, Zscaler, along with numerous other organizations, disclosed a data breach stemming from a supply chain attack targeting Salesloft Drift, a marketing automation platform integrated with Salesforce. The threat actor, identified as UNC...

Hackers stole customers’ data by breaching Salesforce database @ Google and Salesforce, Inc.

In August 2025, Google confirmed that one of its corporate Salesforce instances was breached in June by the cybercriminal group ShinyHunters, also tracked as UNC6040, resulting in the theft of customer data. This incident is part of a larger wave of a...

Private information compromised @ Alpha Baking Co.

In January 2025, Alpha Baking Co. experienced a data breach that compromised the private information of its consumers, leading to a class action lawsuit. The lawsuit alleged that Alpha Baking failed to adequately protect sensitive information, includi...

Hackers stole some data after latest code security issue @ OpenAI Incorporated

In May 2026, OpenAI confirmed a security breach stemming from a supply chain attack targeting open-source software. The incident involved the Shai-Hulud malware campaign and affected two employee devices through a compromised TanStack npm package, a t...

Hacker accessed potentially 389,000 clients' information @ Gîtes de France

In May 2026, a series of cyberattacks targeted France's tourism industry, impacting multiple booking websites. Gîtes de France, a popular booking platform, reported a security incident resulting in unauthorized access to customer booking records. The ...

Personal and health information compromised @ Verber Dental Group

Verber Dental Group, a dental practice operating 14 locations in South Central Pennsylvania, experienced a data security breach that potentially compromised patient information. The company detected unusual network activity on January 27, 2026, and im...

Town lost more than $545,000 in cyber scam @ Town of Surfside Beach

The town of Surfside Beach, South Carolina, fell victim to a cyber scam in March 2026, resulting in a loss of over $545,000. The incident involved a fraudulent payment intended for Wildcat Contractors, Inc., a North Carolina construction firm. Town of...

2 million private member records exposed @ African National Congress

In May 2026, the African National Congress (ANC), South Africa's largest political party, was reportedly hit by a data breach in which nearly 2GB of private information belonging to its members was exposed. The cybercriminal group Black X claimed resp...

Cyber criminals removed data from network @ Goodstone Group

The Goodstone Group, a hospitality organization operating in northern Tasmania, Australia, has confirmed it was the victim of a ransomware attack by the CMD Organization. The attack, which began on April 18, 2026, resulted in the theft of data from th...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...