38,000 patients ' information compromised in cybersecurity breach @ Nationwide Recovery Service, Inc. and UChicago Department of Medicine

In May 2025, UChicago Medicine Medical Group announced a data breach affecting approximately 38,000 patients. The breach stemmed from a cybersecurity incident impacting Nationwide Recovery Service (NRS), a third-party debt collection agency that UChic...

Cyber security breach affected 10 individuals, including three county employees @ Cobb County

In March 2025, Cobb County, Georgia, experienced a significant cyber security incident when an unauthorized user gained access to its servers. This prompted the county to shut down multiple online systems to contain the breach, which resulted in the d...

Unauthorised access by former employee sensitive customer data @ Toronto–Dominion Bank

In February 2025, TD Bank, the tenth-largest bank in the United States, disclosed a data breach stemming from unauthorized access and sharing of sensitive customer data by a former employee. The incident, which occurred between August and December 202...

Data breach involved 10,000 healthcare professionals' personal information @ D-Trust GmbH

In January 2025, a significant data breach compromised the personal information of over 10,000 healthcare professionals. The breach involved D-Trust, a company that issues electronic practice identification cards used to access healthcare data. The No...

Unauthorised access to personal data stored in donor management platform @ Blackbaud Inc. and University of Missouri

In September 2020, the university disclosed that a third-party vendor had informed four university campuses in May 2020 that the vendor had experienced a data security incident. This incident affected a substantial number of other higher education ins...

Data breach compromised full names and other personal identifying information @ Aus, Inc.

In January 2025, AUS Inc. reached a settlement in a class action lawsuit stemming from a data breach that occurred on November 28, 2022. The lawsuit alleged that AUS, a global security, investigations, and risk-consulting company, failed to implement ...

Suspicious email sent from an official SLRD email account to multiple recipients @ Squamish-Lillooet Regional District

In January 2025, the Squamish-Lillooet Regional District (SLRD) experienced a security incident involving a compromised email account. An unauthorized email, appearing to originate from SLRD Director Tony Rainbow, was sent to over 400 recipients on Ja...

Unauthorised access to consumers’ sensitive information @ Heritage Health Care

In January 2025, Heritage Health Care reported a data breach to the U.S. Department of Health and Human Services Office for Civil Rights, indicating that unauthorized access to consumer information had occurred. The company has begun notifying the est...

Malware attack stole payment customer card data @ Landry's, Inc.

In January 2020, the national restaurant chain alerted customers to a data breach that could have exposed their credit-card information. The company explained that they had implemented advanced security on their main point-of sale system, featuring en...

Ransomware attack disrupted donations and related activities @ New York Blood Center Enterprises

In late January 2025, the New York Blood Center Enterprises (NYBCe), a major blood collection and distribution organization serving hospitals in multiple states, fell victim to a ransomware attack. The organization detected suspicious activity on its ...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...