Hacker in a Hoodie Index

Beyond the Filings · complete ledger

Company results statements (Attested), and outside estimates and news reports (Inferred), approved to this index. No Verified grade appears here; that grade is reserved for the primary filings and enforcement records on the government record. This is the complete record for this feed, uncapped, and like everything on this index it is never summed.

67 approved media-reported incidents, most recent first. The complete record, nothing hidden, never summed.
The full record as open data (CC BY 4.0): CSV · JSON · about the data
Subscribe to new incidents: RSS · JSON Feed
How each figure is graded VVerifiedthe linked primary document states it AAttesteda published report credits a named source IInferredno direct confirmation; a lead, not a figure The full standard →
The revision trail
A cost figure arrives after an incident is disclosed, and it moves as stronger sources report it. Early estimates run below the figure a company eventually discloses. The amount shown for each incident is its most recent claim; the trail beneath it is every claim in order, each with its date, its source, and its grade, from an Inferred estimate to an Attested company figure.
Corrections
Every figure on this ledger is drawn from its cited source and links to it. If we have read one wrong, tell us: info@hackerinahoodie.com.
Thomson Reuters detected unauthorized activity in a C-Track cloud environment on June 30, 2026, three months after the intrusion it now traces to March. The stolen files touched court records and personal data across eleven states, the Virgin Islands, and Ontario; the company still cannot say what was taken or how many people were affected. One cloud platform running case management for a dozen jurisdictions turns a single failure into a multi-state event. We'll see if Thomson Reuters gets a "get out of jail free" card for this incident.
Thomson Reuters hit by cyberattack that saw court documents across 11 states accessed by a hacker
Not yet quantified
AAttestedProfessional and Business Services
Norcross, Georgia, was hit by ransomware on August 1, with no vector named, no actor named, and no accounting of what data, if any, left the network. City officials notified police and cybersecurity professionals and kept most services running while restoration continued. Calling in digital fixers after the fact is incident response, not architecture. The filing never says what allowed the encryption in. An organization that cannot name the crack in its defenses has not yet found the boundary that failed.
Metro Atlanta city hit by ransomware, working on full system restoration
Not yet quantified
AAttestedPublic Sector and Education
ATF confirmed a 'major incident' only after Qilin's ransomware gang posted the agency's name to its dark web leak site, not from its own monitoring. The bureau says the breach was confined to a standalone system, separate from its enterprise network and eForms. Qilin has not said whether it stole data or demanded a ransom, and ATF has not said what that system held. An agency that tracks explosives learned about its own breach from the people who lit the fuse. Or, it knew about it and didn't bother to disclose it.
ATF confirms “major incident” after recent Qilin breach claims
Not yet quantified
AAttestedPublic Sector and Education
MAG's breach note names neither the entry point nor the attacker, only the wreckage: 8.7 million customers' emails, phone numbers, vehicle registration numbers, and postcodes, pulled from the car park, lounge, and wifi sign-up systems shared across Manchester, Stansted, and East Midlands. Three airports ran their ancillary bookings through one common system, so a single hole became a three-airport hole. MAG points out that no bank details were held there, as if a name, a plate number, and a postcode were not already enough to track someone.
UK airports operator hit by cyber-attack and customer data accessed
Not yet quantified
AAttestedTransportation and Logistics
CarharttAug 2026
ShinyHunters says it pulled more than 50GB from Carhartt's Databricks analytics platform, claiming the intrusion on August 13 and later publishing the archive after Carhartt declined a $3.3 million ransom demand. How the platform was actually entered, credentials, misconfiguration, or something else, is not stated; Carhartt has not confirmed the breach at all. Troy Hunt's independent analysis puts the toll at 12.9 million accounts, names, emails, phones, addresses, and over 15,000 internal @carhartt.com employee addresses sitting in the same analytics warehouse as the customer file. An analytics platform became the record of the whole company, employees, and customers alike, and nobody built a wall between them.
Carhartt data breach exposes information of 12.9 million accounts
Not yet quantified
AAttestedRetail and Consumer
Troutman Pepper Locke's breach began when one employee, targeted by a social engineering attack, trusted communications that looked legitimate but were not, exposing information now claimed to affect roughly 37,000 people in an accompanying lawsuit. The account gives no vendor, no malware, no stolen credential chain: just a single inbox that functioned as the firm's whole perimeter. A law firm built on judgment left one employee's judgment as its only control point.
Large Atlanta law firm hit with data breach and associated lawsuit
Not yet quantified
AAttestedProfessional and Business Services
Sotheby's International, a luxury real estate firm, reported it is investigating a cyber security incident involving unauthorized access to data held in a third-party software platform used to store marketing contact information. The company said the person who accessed the data claimed to have obtained 1.6 million contacts but it refuted that claim because it did not have that many on its database. Regardless of the number, given Sotheby's clientele, even marketing data seems to be a valuable haul from a valuable brand.
Luxury real estate firm hit by cyber security attack
Not yet quantified
AAttestedRetail and Consumer
breach at Beacon CRM
A North Wales mental health charity confirms sensitive data was accessed, informing their clients that their trusted provider Beacon CRM had experienced a breach on 7/29/2026 that affected many of Beacon's non-profit clients.
Cyber attack on North Wales mental health charity sees sensitive data accessed
Not yet quantified
AAttestedPublic Sector and Education
The notice attached to this incident reads "to review," which means the source confirms nothing beyond a name and a date: not the vector, not the actor, not what was reached, not how many were affected. Apollo Global sits in the Index with a placeholder where an accounting should be. An institution's disclosure obligation is itself a control point, and a statement that has not yet been given is not transperancy, especially for customers. .
Apollo Global reveals data breach after hackers target financial firms
Not yet quantified
AAttestedFinancial Services
AlationAug 2026
AI data giant Alation confirmed a cyberattack, and the headline confirms nothing else: no entry point, no actor, no data type, no count of records or systems touched. That leaves a data-governance vendor built to sit inside other companies' data stacks, cataloging and connecting sensitive information as its core function, now acknowledging compromise without saying what that position exposed.
Alation Confirms Cyberattack: What Security Teams Need to Know
Not yet quantified
AAttestedTechnology and Software
A state Medicaid portal exposed data on 41,000 members. Per usual, the state and their auditor declared that "no social security numbers were taken" but the laundry list of other data elements stolen suggest a ready-made-cookbook for use in other forms of targeted consumer attacks such as social engineering and financial scams.
State says data from 41,000 Medicaid members exposed in portal breach
Not yet quantified
AAttestedPublic Sector and Education
SFRAug 2026
2.1 million SFR fiber customer records surfaced as exposed and SFR has confirmed that attackers compromised a legitimate user account to access an internal fiber connection management tool named NOVA. The data loss is a treasure trove of information for targeted scams and phishing against SFR customers.
SFR data breach in France: 2.1 million fibre customer records exposed
Not yet quantified
AAttestedTelecommunications
CanvasAug 2026
Vulnerabilities in Canvas, the third-party learning platform four Hong Kong institutions leaned on, exposed more than 153,000 student and staff accounts; names, IDs, emails, login credentials, course messages. The institutions' internal systems were in place but ended up being irrelevant, since Canvas was the actual perimeter, and one vendor's flaw became four campuses' breach.
More than 153,000 students, staff affected in Canvas data breach: privacy watchdog
Not yet quantified
AAttestedPublic Sector and Education
Up to 1.36 million Sakura Internet accounts were exposed in a recently disclosed breach, which was only discovered when Sakura was investigating an entirely separate breach in one of its other business units.
Sakura Internet hack exposes data of up to 1.36 million accounts
Not yet quantified
AAttestedTelecommunications
CognizantAug 2026
Cognizant notified individuals of a data breach and is offering one million dollars in identity theft coverage. The headline confirms notification and a remediation gesture but does not name the entry point, the actor, the number affected, or the data types involved. A company built on managing other organizations' systems and data has disclosed a breach of unspecified scope, and the insurance offer addresses downstream harm, but not the architecture that allowed the exposure.
Cognizant notifies individuals of data breach; offers $1 mn identity theft cover
Not yet quantified
AAttestedProfessional and Business Services
An unpatched, internet-facing hole in a CSDD system, one that was legally classed as critical, requiring multi-factor authentication and penetration testing it never got, gave attackers a path to eighteen years of payment records: 1.2 million people, 200,000 companies, IDs and addresses intact. The immediate result? The resignation of the entire safety advisory board.
Data of 1.2 million people leaked in CSDD cyberattack in Latvia - including personal ID numbers and addresses
Not yet quantified
AAttestedPublic Sector and Education
breach at CEVA Logistics
Another CEVA Logistics supply chain victim. Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information. CEVA's reply? Gotta get 'em all.
Pokémon Center data breach exposes customer info, cancels some orders
Not yet quantified
AAttestedTechnology and Software
Access Bank lost N1.3bn to hackers in an expanding attack against Nigerian banks nationwide. entry point, method, and timeline all unnamed. The breach notification is precise on the loss but skips, entirely, how the breach occurred.
Banks continue to battle hackers over deposits, as Access Bank loses N1.3bn
Not yet quantified
AAttestedFinancial Services
Bits of Gold, Israel's largest crypto broker, confirms a breach touching 200,000 customers. The Tel Aviv, Israel-based company reported the security breach on Sunday, saying a hacker gained unauthorized access to a third-party data analytics network and,gained access to customers’ names, national ID numbers, emails, phone numbers, IP addresses, bank account details, and public wallet addresses.
Israel's largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers
Not yet quantified
AAttestedFinancial Services
SafePalAug 2026
SafePal disclosed a data breach affecting roughly 40,000 customers, exposing customer information associated with purchases while the company says wallet credentials, private keys, and recovery seeds were not compromised. This is high quality signal, cryptocurrrency relatedcustomer data that gives attackers a better map for phishing and social engineering. Exactly what adversaries want for conducting further identity based attacks.
SafePal Data Breach Hits Tens of Thousands of Customers - Infosecurity Magazine
Not yet quantified
AAttestedFinancial Services
About 180,000 students, alumni, and employees at Sogang University had their data exposed through the school's integrated login system. IDs, names, affiliations, emails, phone numbers, encrypted passwords. The entry point stays unnamed, the attacker unidentified; what's clear is one login system built to serve every population became one failure domain for all of them. Network separation arrived after detection, not before.
Sogang University hit by personal information breach of 180,000
Not yet quantified
AAttestedPublic Sector and Education
Cl0p listed nearly fifty companies at once and walked off with 89GB of Shell's facility drawings and test reports. The hole was in PTC's Windchill, patched 17 June. Shell's security spend didn't include understanding the path from Windchill to their doorstep.
Shell and Philips hit by Russian ransomware attack
Not yet quantified
AAttestedEnergy and Utilities
H&MAug 2026
H&M confirmed that an attack on a business system exposed Korean customers' email addresses, phone numbers, and order or return reference numbers. More sensitive payment and password data were reportedly not affected, but the company did not disclose the number of customers or the access path. The useful boundary held around payment data; disclosure and accountability around the breached business tool remain thin.
H&M discloses customer data breach in South Korea
Not yet quantified
AAttestedRetail and Consumer
623GB out the door, no ransom paid, 280GB published in response. RingCentral assured customers that silence meant safety, and Have I Been Pwned then counted 1.6 million email addresses sitting in the archive.
RingCentral data breach exposed info of 1.6 million accounts
Not yet quantified
AAttestedTechnology and Software
A stolen identity got someone onto the French tax authority's VPN and into an internal lookup tool built for querying taxpayers. DGFiP cut the access in June, filed it under routine, and let the hacker break the news in August.
French tax data stolen in cyberattack, ministry says
Not yet quantified
AAttestedPublic Sector and Education
TrezorAug 2026
13,689 hardware wallet buyers had their home addresses taken from a fulfilment partner. What capped the damage was a 90-day deletion rule, not a security control. Data you have already deleted cannot be stolen, and nobody puts that on a compliance dashboard.
Trezor discloses data breach affecting nearly 14,000 customers
Not yet quantified
AAttestedFinancial Services
Ransomware hit Colombia's Justice Ministry five days before a presidential handover and one day after the national CERT warned this was coming. The warning was the control. It was issued, logged, and changed nothing.
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Not yet quantified
AAttestedPublic Sector and Education
LawCareAug 2026
Lawyers in crisis contacted LawCare in confidence, all of it lived in Beacon CRM, and all of it is now assumed gone. No vendor questionnaire in existence asks whether the supplier left an AWS key in a public JavaScript file. [LawCare]
UK legal mental health charity LawCare confirms database was compromised in hacking incident
Not yet quantified
AAttestedProfessional and Business Services
No system was breached at Sunshine Health. A caller posing as someone trusted asked an employee to hand over health-plan files, and the employee did. About 41,569 people had their names, birth dates, and medical histories walk out through a phone call. The security boundary was a person's willingness to help, and it held only as long as the caller sounded familiar.
Data Breaches Reported by Sunshine Health; Health Payment Systems
Not yet quantified
AAttestedHealthcare and Life Sciences
Ransomware took the HVAC and the door locks at Manitoba's largest hospital. The provincial auditor general flagged Shared Health's cybersecurity in 2024. Somebody measured this, wrote it down, and filed it. [Health Sciences Centre, Winnipeg]
Ransomware attack on Health Sciences Centre affects doors, ventilation and air-conditioning
Not yet quantified
AAttestedHealthcare and Life Sciences
FrameworkAug 2026
Framework confirms customer data were exposed, and the headline is pretty much all you get: no named vector, no timeline, no data type, no actor. A breach notice with no information is not a disclosure. It's a stall tactic.
Framework Admits Customer Data Were Exposed in Latest Security Breach
Not yet quantified
AAttestedTechnology and Software
The notice names Sawyer Savings Bank and a disclosure date; it does not name an entry point, an actor, a record count, or the type of data reached.
Sawyer Savings Bank Branches Closed After Security Incident
Not yet quantified
AAttestedFinancial Services
North Carolina Ports confirms operations disrupted by a cyberattack. Operations were disrupted and impacted by gate mechanisms being activated. No threat groups have been identified for this event but ports are critical infrastructure and a desirable target for many types of adversaries.
North Carolina Ports confirms cyberattack disrupting operations
Not yet quantified
AAttestedTransportation and Logistics
The notice for Zenith Bank's August 2026 incident contains no facts: no confirmed entry point, no named actor, no data types, no count of people affected. What remains is a disclosure obligation met with a placeholder, from an institution whose core function is holding other people's money and identity records. The duty to explain a breach is being treated as different from the duty to prevent one.
Zenith Bank customers told to immediately check their deposits after data breach
Not yet quantified
AAttestedFinancial Services
BeaconAug 2026
Beacon CRM flared up as a news headline in the UK, and the headline is nearly all there is - no entry point, no actor, no data type, no count. What's confirmed is the scale: a single CRM widely used by charities, meaning one vendor's compromise fans out into every donor and beneficiary file it was trusted to hold. The platform was the perimeter for organizations that focused on the mission of helping other while depending on Beacon CRM to help them.
Beacon CRM, Widely Used by Charities, Suffers Data Breach
Not yet quantified
AAttestedPublic Sector and Education
breach at Beacon CRM
English National Ballet's headline confirms a cyber attack and a possible breach; entry point, actor, and what data may have been reached go unnamed in the source. The National Ballet finds itself unable to answer these questions because they don't have them. They are one of the many clients of Beacon CRM.
English National Ballet suffers possible data breach following cyber attack
Not yet quantified
AAttestedPublic Sector and Education
EU anti-money-laundering rules require a single register naming the humans behind Liechtenstein's companies, foundations, and trusts. Overnight on 30 July, copies covering 31,000 entities left. The transparency measure worked exactly as designed, for the adversaries.
Cyberattack hits Liechtenstein's anti-money laundering data register, Vaduz says
Not yet quantified
AAttestedPublic Sector and Education
Brinks Home's disclosure names a leak, not a cause: no entry point, no actor, no data type, no count. Just files surfacing after the fact. Announcing a leak isn't transparency. Brinks should know better than most that sounding an alarm isn't the same as responding to one.
Brinks Home Discloses Data Breach as Hackers Leak Files
Not yet quantified
AAttestedRetail and Consumer
3.8 million patients, from five days in October 2025, took until July 2026 to size. UTS says an unauthorized actor copied patient data from its commercial data center during five days in October 2025. The scale came from concentration: a billing vendor that most patients never chose held identity, insurance, and medical data for many providers in one place.
Unlimited Technology Systems breach impacts 3.8 million people
Not yet quantified
AAttestedHealthcare and Life Sciences
Minnesota officials disclosed a coordinated cyberattack targeting more than 30 community water systems between July 26 and July 27, 2026. Several communities, including Braham, Plymouth, South St. Paul and Maple Plain, reported disruptions to operational technology supporting water treatment, although officials stated there was no impact to drinking water quality or public safety. In Braham, the attack temporarily shut down the city's water treatment plant until operators restored service using manual processes. The incident is one of the largest coordinated cyberattacks against U.S. municipal water systems publicly disclosed to date and underscores the continued targeting of critical infrastructure.
Authorities investigating a coordinated cyberattack against Minnesota water systems
Not yet quantified
AAttestedPublic Sector and Education
UnitelJul 2026
Angola's largest telecommunications provider suffered a cyberattack that disrupted nationwide voice, mobile data, and internet services just one day before its planned stock market listing. The incident affected more than 21 million subscribers, forcing the company to activate incident response and recovery efforts while services remained degraded. Unitel has not disclosed the attack vector, threat actor, or whether customer data was compromised, but did proceed with their public offering.
Angola's Unitel hit by cyberattack ahead of stock market debut
Not yet quantified
AAttestedTelecommunications
State-owned Bank of Baroda (BoB) on Monday, July 27, confirmed a security incident that led to unauthorised access to “certain data” by threat actors. The incident involved comprise of an employee’s email account, Bank of Baroda said. Reports suggest that the exfiltrator dumped 1TB on the internet, for free.
Bank of Baroda confirms data breach, says employee email account compromised in hack
Not yet quantified
AAttestedFinancial Services
Triple-AJul 2026
Triple- A, a Singapore-based company said it unauthorized access on July 25th, 2026 and temporarily placed certain services into maintenance mode for about three hours while it secured the affected infrastructure. Triple-A did not disclose the amount lost or explain how the wallets were compromised. Onchain investigator Specter previously estimated the losses at about $11.8 million.
Triple-A Confirms Treasury Wallet Breach After Reported $11.8M Loss
Not yet quantified
AAttestedFinancial Services
According to the notification letter sent to affected customers, hackers launched an automated attack against Chick-fil-A's website and mobile application between June 17 and June 19 using credentials obtained from a third-party source. Chik-Fil-A has not disclosed the number of customers impacted and has filed incident notifications with several State AG offices around the US.
Newsweek
Not yet quantified
AAttestedRetail and Consumer
NichireiJul 2026
The ransomware attack caused widespread chaos, directly impacting approximately 5,000 corporate clients. The breach paralyzed cold storage warehouse logistics and frozen food shipments nationwide, forcing major retailers to scramble.
Company announcement
Not yet quantified
AAttestedWholesale and Distribution
Origin Energy confirmed that full bank account details belonging to 60 customers were accessed in a July breach. While 60 may seem small compared to the 900,000 Australian customers impacted by this massive breach, it isn't small for each one of those 60 people who took the hit for Origin Energy's lack of stewardship.
Origin Energy says bank account details of 60 customers accessed in July data breach
Not yet quantified
AAttestedEnergy and Utilities
SunoJul 2026
404 Media disclosed that Suno was breached in Nov 2025, as confirmed by HaveIBeenPwnd. Suno has not yet publicly disclosed the cyberattack or notified individuals that their information was taken, and has refused to answer reporter questions on this matter.
Security analyst report
Not yet quantified
IInferredTechnology and Software
PaidworkJul 2026
Gig-work platform Paidwork disclosed that a breach exposed the personal and financial information of approximately 23 million users after a stolen database surfaced publicly. The leaked data reportedly includes names, email addresses, phone numbers, physical addresses, dates of birth, banking and payout information, device details, IP addresses, and bcrypt-hashed passwords.
Paidwork data breach reportedly exposes 23M accounts and bank data
Not yet quantified
AAttestedTechnology and Software
EcopetrolJul 2026
The Colombian state-controlled ‌energy company Ecopetrol announced on Friday that a cyberattack resulted in the theft of data tied to about 3,300 user accounts ​and that it could not "guarantee" the breach would ​not have a "material adverse" financial impact.
News: Reuters
Not yet quantified
IInferredEnergy and Utilities
AbbottJul 2026
Abbott did not disclose what kind of information was accessed. The company declined to respond further to MedTech Dive’s request for comment regarding when the attack was discovered and what kind of information was accessed.
News: MedTech Dive
Not yet quantified
IInferredHealthcare and Life Sciences
StadlerJul 2026
Stadler refuses to pay ransom to the Everest hacking group, claims core IT systems were not hacked. ENISA warned that the railway sector’s growing strategic importance was outpacing its ability to manage cyber risks. Findings point to weaknesses highlighted by the Stadler breach. Only 35% of railway companies surveyed regularly assessed the effectiveness of their cybersecurity controls, while 50% did so on an ad hoc basis. Just 25% regularly tested business-continuity and disaster-recovery arrangements.
Media report
Not yet quantified
IInferredTransportation and Logistics
EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents. The ShinyHunters extortion gang added Ernst & Young to its data leak site, claiming it conducted the attack and threatened to release the allegedly stolen data if the company does not contact the group by July 31, 2026. E&Y took more than 3 months to disclose the cyber incident.
Ernst & Young data breach claimed by ShinyHunters extortion gang
Not yet quantified
AAttestedProfessional and Business Services
Healthcare diagnostics company Centers Laboratory (Centers Lab NJ LLC) has informed the US government that a data breach discovered nearly one year ago affects more than 540,000 individuals.
News: SecurityWeek
Not yet quantified
IInferredHealthcare and Life Sciences
FiestaJul 2026
The Las Vegas-based insurance and tax-services franchisor said it became aware on June 9, 2025, that systems within its network environment had been affected by a cyber incident. Following a forensic investigation and an "extensive data review," it was determined on June 26, 2026, that potentially accessed or acquired files contained personal information. While it took a year for Fiesta to determine that customer data had been exposed, Fiesta violated no disclosure laws as written due to their efforts to notify customers within 17 days of the confirmation that customer data had been impacted.
Fiesta Insurance took a year to identify breached customer data - report
Not yet quantified
AAttestedFinancial Services
Mount Royal University Confirms Data Stolen in Ransomware Attack.
News: SecurityWeek
Not yet quantified
IInferredPublic Sector and Education
AccentureJul 2026
Accenture faces massive data breach that could put clients at risk.
News: Cybersecurity Dive
Not yet quantified
IInferredProfessional and Business Services
MedtronicJul 2026
Medtronic Notifies 3.8M Individuals About April 2026 Cyberattack.
News: The HIPAA Journal
Not yet quantified
IInferredHealthcare and Life Sciences
MCBSJul 2026
MCBS confirmed that there had been unauthorized network access between September 22 and September 25, 2025, and files containing protected health information may have been viewed or exfiltrated from its network. The review of the affected data was completed on May 28, 2026, some 8 months after the network intrusion.
MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals
Not yet quantified
AAttestedHealthcare and Life Sciences
An investigation was launched on December 1, 2025, when anomalous activity was identified within its computer network. During the course of the investigation, unauthorized network access was confirmed. It is unclear from the breach notice when the unauthorized access occurred or for how long the network was compromised. The review of the exposed data was completed on April 27, 2026, when it was confirmed that personal and protected health information had been exposed. Notification letters were mailed to the affected individuals on June 23, 2026, and complimentary credit monitoring and identity theft protection services have been offered to certain individuals. Over 169,000 customer and patient records were exposed.
Tennessee Pathology Group Announces 170K-record Data Breach
Not yet quantified
AAttestedHealthcare and Life Sciences
QantasJul 2025
An unnamed threat actor impersonating "Qantas IT help" contacted the airline's call centre. The agent was tricked into connecting a customised version of Salesforce's Data Loader tool to the customer relationship management platform used by Qantas, which enabled mass data extraction. 5.67 mm customer records were exposed. The cost of cyber losses and recovery has never been disclosed, with Qantas executives agreeing to forfeit $800k AUD in bonuses due to the incident.
Company statement
Not yet quantified
AAttestedTransportation and Logistics
Scattered Spider exfilitrated 15 million lines of user data and then exposed the user data of 10 mm customers. The stolen database included names, contact details, home addresses, and Oyster refund data containing banking details and sort codes for about 5,000 customers
Company announcement
Losses on the record
£10M
Business interruption
AAttested
£29M
Direct expense
AAttested
Separate losses, separate sources. We do not add them, because no source adds them.
Attested: a published report credits an identifiable source for this figure.
Transportation and Logistics
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The losses on the record come from other sources.
undated$49mmAAttestedCompany announcement ↗
Kawasaki originally stated that they experienced a cyber attack, but avoided an incident by shutting down and isolating their servers. The action had a direct impact on operations. Ransomhub later dumped 487 GB of data after Kawasaki refused to pay for a ransom, contradicting Kawasaki's initial representations of the breach and its consequences.
Company statements to media
Not yet quantified
AAttestedRetail and Consumer
CDKJun 2024
CDK's ransomware event drove an immediate payment of $25mm in Bitcoin payments to the BlackSuit ransomware gang. A year before the incident CDK was acquired by a private equity organization, effectively turning it into a private company. Several public companies were impacted, resulting in 8k filings that show in excess of $1bn losses across the automotive industry.
Company announcement
Losses on the record
$25M
Direct expense
AAttested
Attested: a published report credits an identifiable source for this figure.
Technology and Software
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
undated$25mmAAttestedCompany announcement ↗
Medisecure experienced a massive ransomware and data exfiltration attack, exposing 6.5 TB of data included names, addresses, Medicare numbers, and sensitive prescription medication and healthcare card details. The costs of this attack in losses and recovery expenses were never disclosed, as Medisecure declared insolvency within weeks of the disclosure of the incident.
Company announcements
Not yet quantified
AAttestedHealthcare and Life Sciences
AscensionDec 2024
Ascension stated that an employee at one of its facilities accidentally downloaded a malicious file they believed was legitimate, which the company characterised as an honest mistake. Security reporting also linked the intrusion to the suspected exploitation of CVE-2024-1709, a vulnerability in ConnectWise's ScreenConnect remote-access software. The combination highlights how a single user action and unpatched third-party software can open the door to a major ransomware incident.
Company PR statements
The company's own complete incident total.
Losses on the record
$1.3B
Total incident cost
AAttested
Attested: a published report credits an identifiable source for this figure.
Healthcare and Life Sciences
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
undated$1.3BAAttestedCompany PR statements ↗
CranewareJul 2020
Craneware sits inside the billing systems of more than 2,000 US hospitals and roughly 10,000 clinics and pharmacies, so an intrusion into a Scottish software vendor is really an intrusion into American healthcare's revenue plumbing. The company stressed that much of what left was non-sensitive or already public regulatory data, a reassurance that quietly conceded a significant volume had gone, employee records and a subset of customer and partner data among it. Contained is not the same as empty-handed when the files are already gone.
Cybersecurity incident report
Not yet quantified
AAttestedHealthcare and Life Sciences
HarrodsSep 2025
Attackers gained access to approximately 430,000 customer records through one of Harrods' third-party provider systems. The stolen data included names and contact details such as email addresses and telephone numbers. Additional information relating to marketing preferences, loyalty tier levels and connections to Harrods co-branded cards was also caught up in the breach.
Media reports
Not yet quantified
AAttestedRetail and Consumer
← Back to the index