Hackers tricked AI support tool into giving access to users' accounts @ Instagram, Inc.

In June 2026, Meta resolved a significant security vulnerability within Instagram’s AI-powered account recovery system, known as High Touch Support. The breach, which began in mid-April and was discovered in late May, resulted in the hijacking of appr...

Data breach involved internal use of unauthorised artificial intelligence-based software to handle sensitive customer information @ Community Bank

In May 2026, Community Bank, a subsidiary of CB Financial Services with operations in southwestern Pennsylvania, southeastern Ohio, and northwestern West Virginia, disclosed a data breach incident involving the unauthorized use of an artificial intell...

Threat actors claimed to have breached systems and stolen data offered for sale @ Vercel

In April 2026, Vercel, a cloud deployment firm and web3 hosting backbone, experienced a significant security breach stemming from a compromised third-party AI tool. The breach led to unauthorized access to Vercel's internal systems and customer data, ...

One of thousands of companies impacted by LiteLLM supply chain attack @ Mercor

In April 2026, Mercor, an AI recruiting startup valued at $10 billion, confirmed it was impacted by a supply chain cyberattack stemming from a compromise of the open-source LiteLLM project. This confirmation followed claims by the Lapsus$ extortion gr...

Unauthorised access to customer data via third-party applications @ Gainsight and Salesforce, Inc.

In November 2025, Salesforce confirmed it was investigating a security incident involving unusual activity within Gainsight-published applications connected to its platform. The investigation revealed that unauthorized access to certain customers' Sal...

Hackers stole customers’ data by breaching Salesforce database @ Google and Salesforce, Inc.

In August 2025, Google confirmed that one of its corporate Salesforce instances was breached in June by the cybercriminal group ShinyHunters, also tracked as UNC6040, resulting in the theft of customer data. This incident is part of a larger wave of a...

Researcher tricked Claude into uploading private data to attacker's account using indirect prompt injection @ Anthropic PBC

In October 2025, security researcher Johann Rehberger discovered a vulnerability in Anthropic's Claude AI model that allows for the exfiltration of private data through indirect prompt injection. The attack involves injecting malicious instructions in...

Customers' data exposed in the Salesloft Drift attacks which affected Salesforce databases @ Salesforce, Inc. and Zscaler, Inc.

In September 2025, Zscaler, along with numerous other organizations, disclosed a data breach stemming from a supply chain attack targeting Salesloft Drift, a marketing automation platform integrated with Salesforce. The threat actor, identified as UNC...

Attackers breached customer service platform and stole undisclosed number of customers' data @ Air France–KLM S.A.

In August 2025, KLM Royal Dutch Airlines and Air France disclosed a data breach stemming from unauthorized access to a third-party platform used for customer service. The incident exposed personal data of customers who had previously contacted custome...

AI hiring bot with password ‘123456’ leaked job seekers' data @ McDonald's Corporation

In July 2025, a series of significant cybersecurity incidents came to light, impacting various sectors globally. McDonald's faced a major data breach due to a glaring security lapse in its AI-powered hiring platform, McHire. Security researchers disco...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...