Cl0p exploited zero-day vulnerability in E-Business Suite @ Oracle Corporation

In November 2025, the cybercriminal organization Cl0p exploited a zero-day vulnerability in Oracle's E-Business Suite, leading to significant data breaches for over 100 companies worldwide. The group, known for its sophisticated extortion techniques a...

Data breach affected over 4,500 customers, later revised to 33.7 million customers @ Coupang, Inc.

In November 2025, Coupang, a major e-commerce company, experienced a significant data breach that compromised the personal information of over 4,500 customers. Unauthorized access to user accounts occurred on November 6th, but the breach went undetect...

146,000 impacted by data breach @ Delta Dental of Virginia

In April 2025, Delta Dental of Virginia (DDVA) detected suspicious activity within an employee email account, leading to the discovery of a data breach that compromised the personal information of approximately 145,918 individuals. An unauthorized thi...

Exposure of limited user data associated with API platform @ MixPanel and OpenAI Incorporated

In November 2025, OpenAI experienced a significant data breach stemming from a security incident at Mixpanel, its third-party analytics provider. The breach exposed the personal data of some OpenAI API users, including names, email addresses, and user...

Data breach hit alumni and donors @ Harvard University

Harvard University experienced a data breach in November 2025, impacting its Alumni Affairs and Development Office. An unauthorized party gained access to the university's systems through a phone-based phishing attack. The compromised data includes pe...

Personal data tied to almost 2 million people compromised @ Asahi Breweries, Ltd

In late September 2025, Asahi Group Holdings, Japan's largest brewing company, experienced a significant ransomware cyberattack that crippled its operations. The attack, claimed by the Qilin ransomware group, led to the theft of approximately 27 gigab...

Persistent phishing operation targeted company to infect with malware, including RATs and infostealers @ Booking.com

Booking.com has become the latest target of the ClickFix cyberattack, a persistent phishing operation aimed at infecting hospitality workers with malware such as Remote Access Trojans (RATs) and infostealers. Threat actors are attempting to compromise...

Unknown actor viewed and copied certain files @ Furniture Mart

In November 2024, Furniture Mart USA experienced a security incident that led to a data breach, compromising the sensitive personal information of 9,718 individuals. The company detected suspicious activity on its IT network on November 3, 2024, and i...

Breach compromised players' personal data @ MERKUR GmbH

In March 2025, Merkur, a prominent German gambling company, experienced a significant security breach that potentially compromised the personal data of up to 800,000 players across several of its platforms, including Slotmagie, Crazybuzzer, and Merkur...

Business extorted over hundreds of gigabytes of confidential documents @ Brydens Lawyers

In late February 2025, Brydens Lawyers, a prominent New South Wales law firm with offices across Sydney and regional NSW, fell victim to a significant cyberattack. The firm, known for its close ties to various sporting organizations, including the NRL...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...