80,000 patients’ sensitive personal information exposed @ Conceptions Reproductive Associates Inc.

A Colorado-based fertility clinic, Conceptions Reproductive Associates Inc., is at the center of a proposed class action lawsuit for an alleged breach of sensitive personal information belonging to approximately 80,000 patients. The lawsuit stems from...

Encryption of electronic data on some servers @ Nikki-Universal Co. Ltd.

Nikki-Universal Co. Ltd., a major chemical manufacturer, experienced a ransomware attack on December 22, 2024. The ransomware group, Hunters International, encrypted data on some of the company's servers and claim to have stolen 761.8 GB of data acros...

Unauthorised access to multiple employee email accounts through phishing campaign @ Illinois Department of Human Services

In April 2025, the Illinois Department of Human Services (IDHS) fell victim to a phishing campaign that exposed the personal data of over one million individuals. The attackers, using compromised employee accounts, gained access to files containing So...

Unauthorised access to consumers’ sensitive information @ Crown Mortgage Company

Crown Mortgage Company, a lending company based in Oak Lawn, Illinois, experienced a data breach that resulted in the exposure of sensitive customer information. On December 20, 2024, the company discovered unauthorized access to its systems, potentia...

Data breach exposed 8 million people @ Scholastic Corporation

In January 2025, the educational publisher Scholastic suffered a data breach impacting an estimated 8 million customers. A hacker, using the alias "Parasocial," infiltrated Scholastic's network, likely gaining access through an employee's compromised...

Unauthorised access to customer and business partner database at solar panel company @ Hanwha Q CELLS Co.

In July 2024, Hanwa Qcells, a German solar energy provider, experienced a cyberattack on their IT systems. The attackers, a cybercriminal group known as "Abyss", were able to access and steal customer and business partner data, potentially including n...

'Cyber event' caused city-wide outage @ Winston-Salem

On December 26, 2024, the City of Winston-Salem, North Carolina experienced a cyber security event that caused a significant outage of city systems. City officials took numerous systems offline upon discovery of the event and are working with the FBI,...

£25 million misappropriated after video call with deepfake ‘chief financial officer’ @ Arup Group

## Summary of Cyber Security Event: Deepfake Business Email Compromise (BEC) Scam A sophisticated cybercrime incident has surfaced involving the use of deepfake technology in a Business Email Compromise (BEC) scam targeting a multinational firm. The ...

Data breach exposed IDs and passports of people who bought products @ Stiiizy

In a recent security breach, the California-based cannabis company Stiiizy had customer data compromised through a third-party vendor responsible for point-of-sale processing services. The breach occurred between October 10 and November 10, 2024, and ...

Customers on website using debit or credit card impacted by data breach @ Green Bay Packers

The Green Bay Packers organization experienced a data breach between September 23-24 and October 3-23, 2024, impacting approximately 8,514 customers. A malicious actor injected code into the Packers Pro Shop website, exposing customer data entered at...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...