Curated · updated periodically · 13 incidents

Cyber Breach Tracker

A curated, fact-checked log of recent notable breaches, and, for each one, the specific security control that would have blunted it. Every incident is mapped to a real control from the cyber-insurance checklist and to a primary source. This is a hand-maintained list, not a real-time feed.

Score your own posture in 2 minutes, then close the gaps the breaches below exploit · no login, no email gate

How to read this tracker

Every breach has a control that would have changed the outcome

Most breaches are not exotic. They are a missing second factor, an exposed admin interface, an un-vetted vendor, or a staff member talked through an MFA prompt on the phone. For each incident below we name what happened, link the primary source, and map it to the exact control, by id, from the 47-control Cyber Insurance Prep Checklist that would have blunted it. The same controls your carrier asks about.

Recent breaches & the control that would have caught it

Newest first. Figures are reported as the cited sources report them, including where the numbers are still contested.

  1. N-able

    · MSP Software

    Third-party / supply chainCredential leakIdentitySaaS

    On July 31, 2026, N-able first observed anomalous licensing activity on on-premises N-central servers, which turned out to be the earliest signal of active exploitation. By August 2, 2026, N-able confirmed that CVE-2026-18577, an authentication bypass and account takeover vulnerability caused by an incomplete fix for the earlier CVE-2026-18556, had allowed remote unauthenticated attackers to gain administrative access to N-central servers running any build prior to 2026.3.1.7. Once inside, attackers leveraged N-central's own Take Control feature to reach downstream customer-managed endpoints, then registered Cloudflare tunnel services on those devices as a persistence mechanism that survives reboots and remains active even after access to the N-central server is revoked. N-able released build 2026.3.1.7 (2026.3 Hotfix 1) on August 2, 2026 as the minimum safe version; upgrading only to 2026.3, as initially instructed, is no longer sufficient. A limited number of affected customers were identified and contacted, though no public count of compromised servers or organizations has been disclosed.

    The control that would have caught it

    • CI-11HIGHPatching

      Apply critical operating-system patches within 30 days of release.

      CVE-2026-18577 was exploitable on any N-central build prior to 2026.3.1.7; a policy requiring critical patches within 30 days, applied to the earlier CVE-2026-18556 fix, would have prompted faster evaluation and upgrade before the incomplete patch was itself bypassed.

    • CI-22MEDIUMNetwork

      Segment the network, servers and workstations on separate VLANs.

      Network segmentation between the N-central management plane and downstream managed endpoints would have limited attackers' ability to pivot from a compromised N-central server through the Take Control feature to customer devices.

    • CI-40LOWLogging

      Put centralized logging in place for critical systems.

      Centralized logging of N-central administrative sessions and licensing activity would have surfaced the anomalous licensing signals observed on July 31 more quickly and correlated them with unauthorized admin access earlier in the timeline.

    • CI-42MEDIUMAsset Management

      Maintain an inventory of all internet-facing assets.

      Maintaining an inventory of all internet-facing N-central server versions would have allowed operators to identify unpatched instances immediately when CVE-2026-18556's incomplete fix was disclosed, reducing exposure before CVE-2026-18577 was actively exploited.

  2. Multiple North American Organizations (STAC4749 Campaign)

    · Cross-sector · Attributed to STAC4749 (assessed by Sophos as financially motivated; Chaos ransomware linked with moderate confidence by Cisco Talos to former BlackSuit/Royal members)

    RansomwareVishingData exfiltrationExtortion

    Between February and June 2026, a threat cluster Sophos tracks as STAC4749 conducted a Microsoft Teams voice-phishing campaign targeting dozens of organizations across Canada and the United States. Operators impersonated IT helpdesk staff via Teams chats and calls, socially engineering employees into granting remote access through Microsoft Quick Assist and, from approximately April 2026 onward, the RemSupp RMM tool. Once inside, attackers installed additional remote-access tools including DWAgent and AnyDesk, attempted to enable RDP for lateral movement, and deployed a modular custom loader and backdoor. At least three intrusions culminated in Chaos ransomware deployment, with at least one victim having data exfiltrated beforehand in an apparent double-extortion arrangement. In at least one case, encryption was achieved in under 17 hours of initial access. STAC4749 continually evolved its attack chain throughout the campaign, cycling payload names, persistence labels, and delivery methods. Sophos assessed with high confidence that the group is financially motivated and either deployed ransomware directly or coordinated with affiliates.

    The control that would have caught it

    • CI-34HIGHAwareness

      Provide security awareness training to all employees annually.

      Employees were socially engineered into granting remote access after brief Teams calls averaging roughly two to two-and-a-half minutes; annual security awareness training covering vishing and IT-impersonation tactics would have reduced the likelihood of compliance.

    • CI-35HIGHAwareness

      Conduct phishing simulation exercises at least annually.

      Regular phishing and vishing simulation exercises would have familiarized staff with the exact helpdesk-impersonation scenario STAC4749 used, making employees less likely to install remote-access tools on request.

    • CI-32CRITICALVendor Access

      Limit third-party vendor remote access to approved windows, with MFA.

      STAC4749 abused legitimate RMM tools (Quick Assist, RemSupp, DWAgent, AnyDesk) to establish persistent remote access; restricting third-party and unsanctioned remote-access tools to approved, MFA-gated windows would have denied the attackers their primary foothold.

    • CI-05CRITICALBackups

      Take offline or immutable backups at least weekly.

      Chaos ransomware encrypted systems in under 17 hours of initial access; offline or immutable backups taken at least weekly would have constrained recovery scope and reduced the leverage available to the extortion threat.

  3. Kratos PhaaS Platform

    · Cybercrime infrastructure · Attributed to Kratos PhaaS operator (developer arrested in Indonesia)

    PhishingMFA gapCredential leakIdentity

    On 20 July 2026, Germany's BKA and ZIT, working with the FBI Dallas Field Office and the US Attorney's Office for the Northern District of Texas, announced the dismantling of the Kratos Phishing-as-a-Service platform under Operation Olympus Blade. Indonesian authorities arrested the alleged developer and technical administrator. More than 200 servers were seized, and a seizure banner naming the operation was placed on the Kratos service website, with domain ownership transferred to the FBI. The BKA described Kratos as one of the most widespread and dangerous phishing kits in the world, with more than 1,800 criminal customers running approximately 15,000 phishing campaigns per month since at least 2024, generating more than €300,000 in criminal revenue. The platform primarily cloned Microsoft 365 sign-in pages and used an Adversary-in-the-Middle technique to steal session cookies alongside credentials, allowing attackers to bypass multi-factor authentication entirely. Approximately 850 victims were confirmed across 35 countries, with law enforcement estimating potential victims in the hundreds of thousands across more than 30 countries, concentrated in Europe and the United States. ANY.RUN research identified 148 suspected victim organizations concentrated in the US, Spain, and Southern Europe, while Forescout noted the campaign used rotating calendar-themed lures (tax themes in winter, seasonal invitations later) active since at least January 2026. Microsoft Threat Intelligence tracks the same kit as "SneakyLog," though KnowBe4 assessed Kratos evolved from an earlier infostealer family and the two research teams have not reconciled their accounts.

    The control that would have caught it

    • CI-01CRITICALMFA

      Require multi-factor authentication on every email account.

      Kratos used AiTM session-cookie theft precisely to defeat standard MFA on Microsoft 365 accounts; phishing-resistant MFA methods (such as hardware security keys or passkeys) bound to the legitimate origin would have prevented stolen cookies from granting access even after a victim submitted credentials to a fake portal.

    • CI-18HIGHEmail Security

      Configure anti-phishing policies (link scanning, spoofing protection).

      The platform relied on mass delivery of convincing Microsoft 365 lure emails using rotating seasonal themes; anti-phishing policies with link scanning and spoofing protection would have blocked or flagged the fraudulent sign-in links before employees clicked them.

    • CI-34HIGHAwareness

      Provide security awareness training to all employees annually.

      Kratos succeeded at scale partly because employees did not recognize fake Microsoft 365 login pages or seasonal-lure pretexts; annual security awareness training covering AiTM phishing and credential-harvesting pages would have reduced the number of victims who voluntarily submitted their credentials.

    • CI-35HIGHAwareness

      Conduct phishing simulation exercises at least annually.

      Regular phishing simulation exercises using realistic Microsoft 365 lure templates would have measured and improved employee resistance to the exact social-engineering patterns Kratos customers deployed across approximately 15,000 campaigns per month.

  4. Tata Electronics (Apple & Tesla contract manufacturer)

    · Electronics manufacturing / supply chain · Attributed to World Leaks (assessed rebrand of Hunters International)

    Third-party / supply chainData exfiltrationExtortionIP / trade-secret theft

    The headline-grabbing "confidential Apple files leaked on the dark web" was not a breach of Apple, it was a breach of Tata Electronics, an Indian contract manufacturer that builds iPhone components and assembled devices and is reported to account for roughly a third of Apple’s Indian iPhone output. The data-extortion group World Leaks (assessed by Group-IB as a rebrand of the former Hunters International operation, and now an extortion-only crew that steals and threatens to publish rather than encrypting) listed Tata on its leak site and claimed more than 630 GB across about 204,341 files. Researchers who reviewed a sample for Reuters said the trove appears to contain Apple supplier specifications and manufacturing documents, including a 52-page file carrying Apple’s proprietary markings detailing quality-inspection standards for iPhone circuit boards, plus Outlook email, SAP data, years of event logs, and employee passport scans; a separate set of files appears to include Tesla engineering documents. These contents are actor-claimed and only sample-verified, not fully confirmed by Apple or Tata. Tata confirmed it "identified a cybersecurity incident on some of [its] systems," said it activated its response protocols and saw "no impact on [its] operations," and declined to confirm whether Apple or Tesla data specifically was exposed; Apple is reportedly investigating and has not commented publicly. A ransom demand was reportedly made to Tata; no amount has been disclosed, and the initial access vector has not been disclosed. The durable lesson is supply-chain data exposure: Apple’s own perimeter was not the failure point, a vendor holding a copy of Apple’s confidential design data was.

    The control that would have caught it

    • CI-32CRITICALVendor Access

      Limit third-party vendor remote access to approved windows, with MFA.

      This is a third-party exposure: the breached systems belonged to a contract manufacturer holding Apple’s and Tesla’s confidential data, not to Apple or Tesla. Governing the vendors that hold or touch your sensitive data, access scoped to approved windows, MFA-gated, with contractual security and audit rights, is the control that keeps a supplier’s breach from becoming your IP leak.

    • CI-37CRITICALData

      Don’t store sensitive data in unauthorized locations.

      The leaked cache reportedly mixed proprietary design specs with general-purpose systems, Outlook mailboxes, SAP, and years of event logs. Sensitive IP sprawling into everyday business systems (and onto a vendor’s estate) is exactly what data-location controls exist to prevent; the less your crown-jewel data proliferates, the less there is to steal.

    • CI-36CRITICALData

      Encrypt sensitive customer data at rest (PII, PHI, payment card).

      Component specifications, trade-secret documents, and employee passport scans are precisely the categories that should be encrypted at rest, so that a copied file store is far less useful to an extortion crew than plaintext design documents.

    • CI-45LOWPolicy

      Document a data retention and disposal policy.

      The reported trove included multi-year event logs and older records. A real data-retention-and-disposal schedule shrinks the blast radius of any breach, you cannot leak what was already purged on a clock.

  5. Madison Square Garden Entertainment

    · Entertainment / venues · Attributed to ShinyHunters

    Data exfiltrationExtortionBiometric dataData retention

    The extortion group ShinyHunters published a trove of data it says it stole from Madison Square Garden Entertainment after MSG let a June 15 ransom deadline pass; the group says it took the data on June 5 and posted it on June 16. ShinyHunters claims roughly 42-45 GB (sources differ) and up to 26 million customer and corporate records, a figure that has not been independently verified, and MSG has not publicly confirmed the breach’s scope or commented. What stands out is the reported content: biometric facial-recognition surveillance logs, internal “threat assessment” dossiers ranking attendees by risk (reporting cited a “low risk” Ben Stiller and a “high risk” A Boogie wit da Hoodie), background checks, credit scores, and Social Security numbers. MSG has run facial recognition across its venues for years, including the contested practice of banning lawyers from firms that sue it. The entry point has not been disclosed, so the durable lesson is less about how attackers got in and more about how much sensitive data was retained to lose. A class action (Avalo v. MSG Entertainment) was filed June 17 in the Southern District of New York. It is MSG’s second disclosed incident in under a year: in February 2026 the Cl0p group exploited a zero-day (CVE-2025-61882) in a vendor-hosted Oracle E-Business Suite app used for MSG payroll and HR, exposing names, addresses, and SSNs of roughly 130,000 current and former employees.

    The control that would have caught it

    • CI-45LOWPolicy

      Document a data retention and disposal policy.

      The blast radius was set years before the breach, by retaining biometric surveillance logs, risk dossiers, background checks, credit scores, and SSNs. A real data-retention-and-disposal schedule that purges what is no longer needed is what shrinks a leak like this, you cannot lose what you have already deleted.

    • CI-36CRITICALData

      Encrypt sensitive customer data at rest (PII, PHI, payment card).

      Biometric identifiers, Social Security numbers, and credit data are exactly the categories that should be encrypted at rest, so a copied database is far less useful to an extortion crew than plaintext dossiers.

    • CI-32CRITICALVendor Access

      Limit third-party vendor remote access to approved windows, with MFA.

      MSG’s other 2026 breach ran through a vendor-hosted Oracle E-Business Suite application. Time-boxed, MFA-gated, logged third-party access is the control that keeps a partner’s system from becoming your breach.

    • CI-03CRITICALMFA

      Require MFA for every privileged and administrator account.

      MSG has not disclosed this breach’s entry point, but ShinyHunters’ established playbook is identity compromise, social-engineering a login into cloud/SaaS, as in its Charter intrusion. Phishing-resistant MFA on every privileged and SaaS account is the control that blunts that pattern.

  6. Fortinet FortiGate firewalls (FortiBleed campaign)

    · Network edge / multi-sector

    Credential leakNetwork edgeMFA gap

    A large-scale campaign nicknamed FortiBleed harvested working administrator and SSL-VPN credentials from internet-facing Fortinet FortiGate firewalls. Attackers pulled configuration files from exposed devices and cracked the stored credential hashes offline, older FortiOS versions stored admin passwords with a legacy, comparatively fast-to-crack SHA-256 scheme (Fortinet has since moved to a stronger PBKDF2 hash in FortiOS 7.2.11, 7.4.8, and 7.6.1). Researchers verified working credentials on roughly 30,000 devices, with broader estimates near 75,000, about half of all internet-facing Fortinet firewalls, across 194 countries. This was a credential-cracking campaign, not a zero-day: there is no single CVE behind FortiBleed.

    The control that would have caught it

    • CI-02CRITICALMFA

      Require MFA for all remote access, VPN, RDP, and SSH.

      A cracked password is worthless to an attacker who also needs a second factor on the VPN. MFA on all remote access is the control that turns a harvested credential into a non-event.

    • CI-03CRITICALMFA

      Require MFA for every privileged and administrator account.

      The leaked logins were administrator credentials; MFA on every privileged account is what stops a cracked admin hash from becoming live access.

    • CI-19HIGHNetwork

      Do not expose Remote Desktop Protocol (RDP) directly to the internet.

      The campaign only worked against firewalls whose management was reachable from the open internet; not exposing admin interfaces removes the attack surface entirely.

    • CI-11HIGHPatching

      Apply critical operating-system patches within 30 days of release.

      Upgrading to a FortiOS version with stronger password hashing was core remediation guidance, applying critical OS patches promptly is what closes the underlying weakness.

  7. Palo Alto Networks PAN-OS GlobalProtect (multiple victim organizations)

    · Multi-sector · Attributed to Qilin (aka Agenda) RaaS affiliates

    RansomwareData exfiltrationExtortionCredential leak

    Beginning as early as May 17, 2026, threat actors exploited CVE-2026-0257, an authentication bypass vulnerability (CVSSv4 7.8) in the Palo Alto Networks PAN-OS GlobalProtect portal and gateway, to establish unauthorized VPN sessions without credentials. Palo Alto Networks had disclosed the flaw and issued fixes (PAN-OS 10.2.10, 11.0.5, and 11.1.3) on May 13, 2026; CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on May 29, 2026, mandating federal agencies to remediate within three days, the same day the vendor updated the advisory to confirm active exploitation and raised the CVSSv4 score from 4.7 to 7.8. Arctic Wolf Labs investigated multiple intrusions in June 2026 sharing this initial access vector, all culminating in Qilin ransomware deployment. Post-exploitation activity included domain password hash theft, defense disabling, lateral movement via PsExec over administrative shares, ransomware staging in C:\PerfLogs\, and aggressive Windows event log clearing. In double-extortion cases, attackers exfiltrated data to cloud storage before encrypting victim systems domain-wide. Qilin, also known as Agenda, has operated as a Ransomware-as-a-Service since August 2022 and has been linked to over 2,000 victim organizations according to available reporting.

    The control that would have caught it

    • CI-11HIGHPatching

      Apply critical operating-system patches within 30 days of release.

      Palo Alto Networks issued fixed PAN-OS versions on May 13, 2026; organizations that applied critical OS-level patches within 30 days would have closed CVE-2026-0257 before Arctic Wolf observed the June 2026 Qilin intrusion cluster.

    • CI-02CRITICALMFA

      Require MFA for all remote access, VPN, RDP, and SSH.

      The vulnerability allowed unauthenticated VPN session establishment; requiring MFA on all remote-access entry points, including GlobalProtect, would have added a credential barrier that the authentication-override cookie bypass alone could not satisfy.

    • CI-36CRITICALData

      Encrypt sensitive customer data at rest (PII, PHI, payment card).

      Attackers exfiltrated data to cloud storage as part of double-extortion; encrypting sensitive customer data at rest would have limited the leverage gained from that exfiltration even after perimeter compromise.

    • CI-40LOWLogging

      Put centralized logging in place for critical systems.

      Attackers aggressively cleared Windows event logs to hinder forensic reconstruction; centralized logging for critical systems, shipping events off-host in near real time, would have preserved the audit trail and accelerated detection of lateral movement via PsExec.

  8. Charter Communications

    · Telecommunications · Attributed to ShinyHunters

    VishingIdentitySaaSMFA gap

    According to reporting, the extortion group ShinyHunters breached Charter Communications with no malware and no zero-day, a vishing (voice phishing) call compromised a Microsoft Entra identity account, which opened the door to Charter’s Salesforce environment, from which data was exfiltrated. The numbers are contested: ShinyHunters claimed more than 42 million records; Charter confirmed a breach but gave no figure, stating sensitive customer (CPNI) data was not exfiltrated. The breach-tracking service Have I Been Pwned later catalogued roughly 4.9 million unique email addresses from the leaked data. The entry method is the headline, a human, a convincing call, and a second factor that could be talked around.

    The control that would have caught it

    • CI-03CRITICALMFA

      Require MFA for every privileged and administrator account.

      The compromised account was an identity/admin login; carriers now expect phishing-resistant MFA (FIDO2 keys, passkeys) on privileged accounts, not just SMS or approve/deny push that a caller can talk a user through.

    • CI-04CRITICALMFA

      Require MFA for all cloud service consoles (AWS, Azure, M365 admin).

      The path ran through Microsoft Entra into Salesforce; MFA on every cloud console is the control that keeps one social-engineered login from cascading across SaaS platforms.

    • CI-34HIGHAwareness

      Provide security awareness training to all employees annually.

      The attack was a phone call. Security-awareness training that specifically covers vishing and help-desk impersonation is the human control that breaks the chain before MFA is ever tested.

    • CI-35HIGHAwareness

      Conduct phishing simulation exercises at least annually.

      Simulated social-engineering exercises are how an organization proves staff can recognize the exact pretext used here, rather than relying on a once-a-year video.

  9. Canvas (Instructure)

    · Education / SaaS vendor · Attributed to ShinyHunters

    Third-party riskSaaSVendor breach

    The learning platform Canvas, run by Instructure and used across a large share of higher education, was breached twice in the span of two weeks. Unauthorized access began April 25; Instructure detected the intrusion and revoked access April 29 and posted initial disclosure May 1; a second incident on May 7 defaced login pages with a ransom message during final-exam season and was claimed by ShinyHunters. Instructure reported exposed data included names, email addresses, student ID numbers, and private messages, while stating it found no evidence that passwords, dates of birth, government IDs, or financial data were involved. Reporting tied the entry point to an issue connected to free teacher accounts and put affected institutions in the thousands; exact figures are still being established. The lesson: the attackers broke into the vendor schools depend on, not the schools themselves.

    The control that would have caught it

    • CI-32CRITICALVendor Access

      Limit third-party vendor remote access to approved windows, with MFA.

      Your data lives in vendors you don’t control. Limiting and governing third-party access, knowing which vendors hold your sensitive data and on what terms, is the third-party-risk control insurers price because they pay for it.

    • CI-25HIGHIncident Response

      Maintain a written incident response plan.

      A written incident-response plan that covers a vendor breach (who you notify, on what timeline, how you contain access) is what separated organizations that fared well from those that scrambled.

    • CI-43MEDIUMAsset Management

      Monitor and address shadow IT (unapproved SaaS tools).

      Free/unmanaged accounts were tied to the entry point; tracking shadow IT and unapproved SaaS is how an organization avoids inheriting a breach through a tool nobody vetted.

  10. OnTrac (Lasership Inc.)

    · Logistics / Delivery

    Data exfiltrationCredential leakIdentityData retention

    Lasership Inc., doing business as OnTrac Final Mile, reported to the Maine Attorney General that unauthorized actors accessed a portion of its network between April 13 and April 15, 2025, with suspicious activity detected on April 15. The breach affected 40,017 individuals and exposed names, dates of birth, Social Security numbers, driver's license or state ID numbers, medical information, and health insurance information. OnTrac engaged third-party forensic specialists to investigate and stated that the data was re-secured and, as of the time of notification, had not been distributed or used to commit fraud. Notification letters were mailed to affected individuals on August 27, 2025, and 12 months of complimentary credit monitoring through TransUnion/CyberScout was offered. No ransomware or data extortion group had claimed responsibility at the time of reporting.

    The control that would have caught it

    • CI-36CRITICALData

      Encrypt sensitive customer data at rest (PII, PHI, payment card).

      Social Security numbers, medical information, and health insurance data were exposed in this breach; encrypting sensitive PII and PHI at rest would have reduced the value of any data accessed during the April 13–15 intrusion window.

    • CI-45LOWPolicy

      Document a data retention and disposal policy.

      A documented data retention and disposal policy would limit how long highly sensitive data such as SSNs and PHI are held on network-accessible systems, shrinking the pool of records available to an intruder.

    • CI-40LOWLogging

      Put centralized logging in place for critical systems.

      Centralized logging on critical systems would have supported faster detection of the unauthorized access and provided a clearer picture of which records were touched during the intrusion.

    • CI-22MEDIUMNetwork

      Segment the network, servers and workstations on separate VLANs.

      Network segmentation separating systems holding employee or customer PII and PHI from general operational infrastructure would have limited the attacker's lateral reach during the confirmed two-day access window.

  11. Snowflake customer accounts (UNC5537 campaign)

    · Cloud data platform (multi-sector) · Attributed to UNC5537

    Stolen credentialsCloudMFA gapInfostealer

    A financially motivated actor tracked by Mandiant as UNC5537 used login credentials stolen by infostealer malware to break into Snowflake cloud-database accounts that were not protected by multi-factor authentication. This was not a breach of Snowflake itself, it was customer accounts with no MFA, opened with passwords that had been harvested by earlier malware infections. Mandiant notified roughly 165 affected organizations; victims publicly tied to the campaign included Ticketmaster and AT&T, with AT&T disclosing that call and text records for about 110 million customers were taken. The takeaway: a cloud data warehouse is a console like any other, and a username and password alone is not enough to guard it.

    The control that would have caught it

    • CI-04CRITICALMFA

      Require MFA for all cloud service consoles (AWS, Azure, M365 admin).

      Every compromised account lacked MFA on the cloud console. Requiring MFA on all cloud service consoles is the single control that would have neutralized the stolen passwords.

    • CI-09HIGHEndpoint

      Deploy Endpoint Detection & Response (EDR) on all endpoints.

      The credentials were harvested by infostealer malware on endpoints; managed EDR is what catches and kills that malware before it ships passwords to an attacker.

    • CI-40LOWLogging

      Put centralized logging in place for critical systems.

      Centralized logging of cloud access is how a login from a brand-new location gets spotted and cut off before millions of records leave.

  12. Change Healthcare (UnitedHealth Group / Optum)

    · Healthcare / payments clearinghouse · Attributed to ALPHV/BlackCat

    RansomwareMFA gapRemote access

    A ransomware attack by the ALPHV/BlackCat group took down Change Healthcare, the clearinghouse that processes a large share of U.S. medical claims, disrupting pharmacies, providers, and payments for weeks. In Congressional testimony, UnitedHealth’s CEO said attackers got in through a Citrix remote-access portal that did not have multi-factor authentication enabled. UnitedHealth paid a ransom reported at $22 million. The company first put the toll at about 100 million people, then revised it upward in a later estimate reported as affecting roughly 190 million, figures that have shifted as the investigation continued, but that still rank it among the largest healthcare data breaches on record. A single remote-access door without a second factor undid one of the largest companies in U.S. healthcare.

    The control that would have caught it

    • CI-02CRITICALMFA

      Require MFA for all remote access, VPN, RDP, and SSH.

      The confirmed entry point was a remote-access portal with no MFA. Requiring MFA on all remote access (VPN, RDP, Citrix/SSH) is the exact control that would have stopped the initial intrusion.

    • CI-09HIGHEndpoint

      Deploy Endpoint Detection & Response (EDR) on all endpoints.

      EDR on the servers reached after entry is what detects and contains ransomware staging before it detonates across the environment.

    • CI-05CRITICALBackups

      Take offline or immutable backups at least weekly.

      Offline or immutable backups are the difference between restoring and paying; recovery here dragged on for weeks, exactly what tested, separated backups are meant to prevent.

  13. MOVEit Transfer (Progress Software), Cl0p mass exploitation

    · File transfer / supply chain (multi-sector) · Attributed to Cl0p

    Zero-daySupply chainMass exploitation

    The Cl0p extortion group mass-exploited a zero-day SQL-injection flaw (CVE-2023-34362) in Progress Software’s MOVEit Transfer, a widely used managed file-transfer product, stealing data from internet-facing servers before victims could patch. Because so many organizations moved sensitive files through MOVEit (often via a vendor or payroll/benefits provider rather than running it themselves), the blast radius was enormous and largely a supply-chain story: by independent tracking the campaign affected on the order of 2,700+ organizations and tens of millions of individuals. The lesson is that an internet-facing application you, or a vendor, run is part of your attack surface, and an emergency patch is only as good as how fast it is applied.

    The control that would have caught it

    • CI-12HIGHPatching

      Apply critical application patches within 30 days of release.

      This was an application vulnerability, not an OS one. Applying critical application patches fast, Progress shipped the emergency fix within days, is what shrank the window attackers had to pull data.

    • CI-42MEDIUMAsset Management

      Maintain an inventory of all internet-facing assets.

      You cannot defend an exposed MOVEit server you forgot you had. An inventory of internet-facing assets is the prerequisite to patching or pulling them offline in an emergency.

    • CI-39MEDIUMApplication

      Inventory software dependencies and check them for known vulnerabilities.

      Knowing which software, and which vendors’ software, touches your data is how you react in hours, not weeks, when a product like MOVEit is named in an advisory.

Sources, in full

  1. N-able Blog, "N-central Security Update August 2, 2026", https://www.n-able.com/blog/n-central-security-update-august-2-2026
  2. N-able Blog, "N-central Security Update August 1, 2026", https://www.n-able.com/blog/n-central-security-update-august-1-2026
  3. N-able Status Page, "N-central 2026.3 Hotfix 1 Mitigation for CVE-2026-18577", https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
  4. The Hacker News, "N-able Says Attackers Take Over N-central Servers", https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
  5. Huntress, "Rapid Response: Critical N-able N-central Vulnerability", https://www.huntress.com/blog/n-able-vulnerability-exploitation
  6. Sophos Threat Research Blog, "Chaos in Teams: Vishing", https://www.sophos.com/en-us/blog/chaos-in-teams-vishing
  7. BleepingComputer, "Microsoft Teams vishing attacks lead to Chaos ransomware attacks", https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/
  8. Cisco Talos Intelligence Blog, "New Chaos ransomware", https://blog.talosintelligence.com/new-chaos-ransomware/
  9. SC Media, "New Chaos ransomware group linked to BlackSuit amid site seizures", https://www.scworld.com/news/new-chaos-ransomware-group-linked-to-blacksuit-amid-site-seizures
  10. Windows Forum, "Microsoft Teams vishing leads to Chaos ransomware in under 17 hours", https://windowsforum.com/windows-news.4/microsoft-teams-vishing-leads-to-chaos-ransomware-in-under-17-hours.440732/
  11. Bundeskriminalamt (BKA), "Schlag gegen Phishing-Gruppierung Kratos", https://www.bka.de/SharedDocs/Kurzmeldungen/DE/Kurzmeldungen/260720_Schlag_gegen_Phishing_Gruppierung_Kratos.html
  12. BleepingComputer, "Police dismantle Kratos phishing platform, arrest developer", https://www.bleepingcomputer.com/news/security/police-dismantle-kratos-phishing-platform-arrest-developer/
  13. The Register, "German authorities lead takedown of Kratos phishing platform", https://www.theregister.com/security/2026/07/21/german-authorities-lead-takedown-of-kratos-phishing-platform/5275666
  14. ANY.RUN, "Kratos PhaaS targets US and EU: how to reduce Microsoft 365 account takeover risk", https://medium.com/@anyrun/kratos-phaas-targets-us-and-eu-how-to-reduce-microsoft-365-account-takeover-risk-5696ddc8ab09
  15. SC Media, "German authorities dismantle Kratos phishing-as-a-service infrastructure", https://www.scworld.com/brief/german-authorities-dismantle-kratos-phishing-as-a-service-infrastructure
  16. MacRumors, “Confidential Apple Files Leaked on Dark Web After Supplier Cyberattack”, https://www.macrumors.com/2026/06/23/apple-files-leaked-dark-web-cyberattack/
  17. TechCrunch, “Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach”, https://techcrunch.com/2026/06/22/tata-electronics-a-major-tech-supplier-to-apple-and-tesla-confirms-data-breach/
  18. CNBC, “India’s Tata Electronics hit by cyber breach claiming to expose Apple, Tesla trade secrets”, https://www.cnbc.com/2026/06/23/indias-tata-electronics-hit-by-cyber-breach-claiming-to-expose-apple-tesla-trade-secrets.html
  19. Cybernews, “Tata Electronics breach exposes thousands of Apple, Tesla secret files”, https://cybernews.com/security/tata-electronics-breach-apple-tesla-secret-files/
  20. BleepingComputer, “Hunters International rebrands as World Leaks in shift to data extortion”, https://www.bleepingcomputer.com/news/security/hunters-international-rebrands-as-world-leaks-in-shift-to-data-extortion/
  21. The Next Web, “ShinyHunters published 45GB of Madison Square Garden data, including facial recognition surveillance records”, https://thenextweb.com/news/shinyhunters-madison-square-garden-45gb-data-leak-facial-recognition
  22. Bloomberg Law, “Madison Square Garden Sued After ShinyHunters Data Leak”, https://news.bloomberglaw.com/privacy-and-data-security/madison-square-garden-sued-after-shinyhunters-data-leak-news
  23. Front Office Sports, “Madison Square Garden Hit With Class Action Lawsuit Over Apparent Data Breach”, https://frontofficesports.com/madison-square-garden-hit-with-class-action-after-apparent-data-breach/
  24. UpGuard, “Data breach reported for Madison Square Garden Entertainment due to Oracle EBS breach” (February 2026 Cl0p incident), https://www.upguard.com/news/msg-entertainment-data-breach-2026-03-01
  25. Arctic Wolf, "Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries", https://arcticwolf.com/resources/blog/active-fortibleed-campaign-impacting-fortinet-devices-across-194-countries/
  26. SOCRadar, "FortiBleed 2026: The Compromise of Fortinet FortiGate Firewalls and Credential Leak", https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/
  27. Kudelski Security, "Fortinet 'FortiBleed' Global Compromise & Active Exploitation", https://kudelskisecurity.com/research/fortinet-fortibleed-global-compromise-active-exploitation-of-fortinet-vulnerabilities
  28. Arctic Wolf Labs, "Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware", https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/
  29. Palo Alto Networks, "CVE-2026-0257 Security Advisory", https://security.paloaltonetworks.com/CVE-2026-0257
  30. Rapid7, "ETR: Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability CVE-2026-0257", https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/
  31. CISA, "CISA Adds One Known Exploited Vulnerability to Catalog", https://www.cisa.gov/news-events/alerts/2026/05/29/cisa-adds-one-known-exploited-vulnerability-catalog
  32. BleepingComputer, "Critical GlobalProtect VPN Bug Now Exploited in Ransomware Attacks", https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
  33. BleepingComputer, "Charter confirms data breach after ShinyHunters extortion threat", https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/
  34. BleepingComputer, "Charter Communications data breach affects 4.9 million accounts" (Have I Been Pwned email count), https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/
  35. eSecurity Planet, "ShinyHunters Alleges 42M Records Stolen from Charter Communications", https://www.esecurityplanet.com/threats/shinyhunters-alleges-42m-records-stolen-from-charter-communications/
  36. Wikipedia, "2026 Canvas data breach", https://en.wikipedia.org/wiki/2026_Canvas_data_breach
  37. NPR, "Canvas data breach rattles colleges during finals period", https://www.npr.org/2026/05/08/nx-s1-5815956/canvas-data-breach-school-finals
  38. EdWeek, "A Cyberattack on Canvas Could Cause Lasting Aftershocks for Schools", https://www.edweek.org/technology/a-cyberattack-on-canvas-could-cause-lasting-aftershocks-for-schools/2026/05
  39. Maine Attorney General, "Consumer Protection: Privacy, Identity Theft and Data Security Breaches", https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/a060a232-510d-49db-96b0-96f0c2d807e7.html
  40. BleepingComputer, "OnTrac notifies customers of data breach after network hack", https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/
  41. CyberNews, "Thousands exposed via data breach of major American delivery company", https://cybernews.com/privacy/ontrac-delivery-company-data-breach/
  42. Strauss Borrelli PLLC, "OnTrac Data Breach Investigation", https://straussborrelli.com/2025/08/28/ontrac-data-breach-investigation/
  43. ClassAction.org, "OnTrac Data Breach Affects 40K, Exposes SSNs, More", https://www.classaction.org/data-breach-lawsuits/ontrac-august-2025
  44. Mandiant (Google Cloud), "UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion", https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion
  45. Snowflake, statement on targeted threat activity against customer accounts, https://www.snowflake.com/en/blog/detecting-investigating-supply-chain-threats/
  46. BleepingComputer, "AT&T confirms data for 110 million customers stolen in Snowflake attack", https://www.bleepingcomputer.com/news/security/atandt-confirms-data-for-110-million-customers-stolen-in-snowflake-attacks/
  47. Reuters, "UnitedHealth hackers took advantage of Citrix vulnerability to break in", https://www.reuters.com/technology/cybersecurity/unitedhealth-hackers-took-advantage-citrix-vulnerability-break-2024-05-01/
  48. U.S. Senate Finance Committee, testimony of UnitedHealth CEO Andrew Witty (May 1, 2024), https://www.finance.senate.gov/hearings/hacking-americas-health-care-assessing-the-change-healthcare-cyber-attack-and-whats-next
  49. HIPAA Journal, Change Healthcare cyberattack coverage, https://www.hipaajournal.com/change-healthcare-responding-to-cyberattack/
  50. CISA, "#StopRansomware: CL0P Ransomware Gang Exploits MOVEit Vulnerability" (AA23-158A), https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a
  51. Progress Software, MOVEit Transfer critical vulnerability advisory (CVE-2023-34362), https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability
  52. Emsisoft, "Unpacking the MOVEit breach: Statistics and analysis", https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/

Stay ahead of the next one

Get the Breach Roundup

New breaches plus the one control that would’ve stopped each, straight to your inbox. No spam, unsubscribe anytime.

Don’t end up on a tracker like this

Every incident above maps back to controls underwriters verify. Find your gaps for free, then fix them with the checklist.

Start here · free

Cyber Insurance Readiness Score

$02 minutes
  • 14 plain-English questions
  • Instant 0-100 score & gap list
  • No login, no email gate
Take the free assessment ›

Most popular

Cyber Insurance Prep Checklist

$47one-time
  • All 47 controls underwriters verify
  • Verify & fix steps for each control
  • Required vs. premium-affecting vs. disqualifying
Get the checklist ›

Best value

Complete Compliance Bundle

$497one-time
  • Every checklist & hardening pack
  • Cyber insurance, M365, AWS, Azure, SOC 2, PCI
  • The full library at one price
Get the bundle ›

Reported figures vary by source and were accurate as of publication; this page is general security commentary, not specific security or underwriting advice. By purchasing you agree to our Terms. Digital products are non-refundable once accessed. A checklist supports your application; it does not guarantee an underwriting decision.