This timeline records significant cyber incidents since 2006, focusing on cyber attacks on government agencies, defense and high tech companies, or economic crimes with losses of more than a million dollars.
This timeline records significant cyber incidents since 2006. We focus on cyber attacks on government agencies, defense and high tech companies, or economic crimes with losses of more than a million dollars. If you think we’ve missed something, please send an email to [email protected] .
June 2026: Russia’s Federal security Service (FSB) claimed it uncovered a large-scale foreign espionage campaign in which malware infected the smartphones of senior Russian government officials, enabling attackers to steal data, intercept communications, and conduct covert audio and video surveillance. The FSB alleged that foreign intelligence agencies carried out the operation using the infrastructure of major international technology companies, opened a criminal investigation, and said it was working to identify those responsible. The agency did not provide technical evidence, identify the malware, or publicly attribute the operation to a specific country.
June 2026: India’s Tata Electronics suffered a cyberattack in which hackers allegedly stole and leaked thousands of confidential files, including sensitive information related to Apple and Tesla. Although Tata said its operations were not affected and that response protocols were activated immediately, the company reportedly received a ransom demand, and Apple launched an investigation into the incident.
June 2026: Iran’s state-owned Informatics Services Corporation announced that cyberattacks disrupted its card-based banking services at Bank Melli, Bank Saderat, and Bank Tejarat. The incident suspended card-related operations at the three banks, affecting ATMs, point-of-sale terminals, and mobile applications tied to card systems. Iranian officials said cybersecurity teams were working to restore services and that an earlier related incident did not compromise customer data. Iran has not publicly attributed the attacks.
June 2026: The National Association of Insurance Commissioners (NAIC) suspended assigning investment risk designations after a cyberattack compromised credit rating data from agencies including Moody’s, S&P, KBRA, Fitch, and Morningstar DBRS. The hacking group ShinyHunters claimed responsibility for accessing NAIC systems. The disruption prompted rating agencies to pause data sharing with NAIC, affecting designations that help determine how much capital insurers must hold to meet policyholder obligations.
May 2026: Instructure, the provider of the Canvas learning management system, suffered a massive data breach orchestrated by the ShinyHunters cybercriminal group. The attackers compromised the platform's cloud infrastructure, claiming to have exfiltrated 3.65 terabytes of data belonging to roughly 275 million users across nearly 9,000 global educational institutions. The historic breach exposed student names, IDs, and private communications, ultimately forcing Instructure to pay a ransom to prevent a catastrophic data leak.
May 2026: U.S. officials disclosed that suspected Iranian hackers successfully breached the systems monitoring fuel storage tanks at multiple gas stations across several states. The threat actors gained access by exploiting automatic tank gauge (ATG) systems that were left exposed to the public internet without proper password protection. While the intrusion did not physically alter actual fuel quantities, the hackers manipulated the digital display readings, creating severe safety concerns that such vulnerabilities could be used to conceal dangerous gas leaks.
May 2026: NVIDIA confirmed a significant data breach involving its GeForce NOW cloud gaming platform, specifically targeting GFN.am, a third-party Alliance partner operating the service in Armenia. An unidentified threat actor impersonating the notorious ShinyHunters syndicate compromised the regional operator's infrastructure to exfiltrate the personal records of local users. The attackers subsequently attempted to extort the company for $100,000 on a hacker forum by leaking the exposed names, phone numbers, and email addresses, though NVIDIA's core proprietary networks remained uncompromised.
April 2026: A hacker group suspected to be linked to the DPRK successfully exploited a major crypto-currency exchange platform with costs estimated at roughly $293 million dollars according to LayerZero Labs which provides the infrastructure for the KelpDAO’s RsETH configuration. LayerZero claims that this attack is isolated; however, the incident alone represents the largest decentralized finance (DeFi) attack of 2026.
April 2026: The National Agency for Secure Credentials (ANTS) of France announced that its database had been breached, identifying between 11 and 18 million accounts, exposing personally identifiable information such as names, user IDs, phone numbers, addresses. The Agency encouraged citizens to be broadly vigilant for increased targeted scams. French authorities identified the culprit of the attack as a 15-year-old citizen of France.
April 2026: ChipSoft, an online service provider for 70% of Dutch hospitals, was breached by a hacker group called Embargo in early April. No direct healthcare services were reportedly disrupted during the attack. However, ChipSoft temporarily disabled connections to compromised clients to avoid further damage which led to operational disruptions and portal shutdowns. Since the attack, ChipSoft has noted that it deleted compromised data but has not commented on whether they paid the ransom or if there is a chance that the criminal group possesses any remaining data.
April 2026 : Sistemi Informativi, an IT management firm owned by IBM Italy, was attacked in early April. Authorities are pointing at Salt Typhoon, the popular Chinese hacker group, although investigations have not concluded. Since the attack, the company has not released detailed information what was targeted; however, experts are calling this case a warning of the vulnerabilities associated with governments outsourcing IT management to third party
March 2026: Qilin, a Russian-speaking ransomware group, claimed responsibility for a cyberattack on the German democratic socialist political party Die Linke, threatening to publish stolen data if a ransom is not paid. Die Linke shut down parts of its IT systems to limit further damage. The party described the attack as a hybrid warfare operation, linking Qilin’s efforts to Moscow’s broader geopolitical goals.
March 2026: The European Commission claims it was targeted by a cyberattack on March 24, impacting its cloud infrastructure hosting the Europa web platform. Early findings suggest data exfiltration, though the Commission contained the incident swiftly. The Commission did not name any group or individual responsible for the incident.
March 2026: Foster City, California was forced to pause all public services outside of emergency responses following a ransomware attack on March 19. City officials warned that the hackers may have obtained personal information. The city was still recovering weeks later. No group has publicly claimed responsibility in the month following the attack.
March 2026: Medical device maker Stryker claimed a cyberattack hit its Microsoft computer systems on March 12, causing widespread disruption to business operations, including order processing, production, and shipping. Handala, an Iranian-linked hacking group, claimed responsibility for the attack, which triggered simultaneous factor resets on over 200,000 Stryker corporate devices across 79 countries. The group described the attack as retaliation for a U.S. strike on a girls’ school in Minab, southern Iran.
March 2026: Canadian telecommunications firm Telus reported a cybersecurity incident involving unauthorized access to its systems. The ShinyHunters hacking group took responsibility, claiming to have stolen at least 700 terabytes of data—including personally identifiable information, call data, background check details, and source code.
February 2026: Singapore's Cyber Security Agency revealed that China-linked group UNC3886 breached all four of the country's major telecommunications providers in a months-long espionage campaign. The attackers used zero-day exploits and rootkits to gain persistent access to telecom networks. Singapore mounted an 11-month counteroperation dubbed CYBER GUARDIAN, its largest ever, to evict the hackers and harden defenses.
February 2026: France's Ministry of Economy disclosed that a hacker used stolen credentials to access the national bank account registry, exposing data tied to approximately 1.2 million accounts. The compromised information included IBANs, account holder names, addresses, and in some cases tax identification numbers, though officials stated the attacker could not view balances or conduct transactions.
February 2026: The popular Iranian prayer app BadeSaba Calendar was hacked to broadcast anti-regime push notifications to users during U.S. and Israeli airstrikes on Iran. The messages, sent over a 30-minute period, urged Iranian military personnel to defect and lay down their weapons. While no group claimed responsibility, cybersecurity experts assessed the operation as likely Israeli in origin.
February 2026: The European Commission and the Dutch Data Protection Authority and Judicial Council confirmed they were hacked through critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile. Work-related data including names, email addresses, and phone numbers were accessed in the Dutch incident, while the Commission said it contained its breach within nine hours.
February 2026: A ransomware attack on the University of Mississippi Medical Center forced the closure of all 35 clinic locations statewide and the cancellation of scheduled appointments and elective surgeries. The attack took down UMMC's IT network, including its EPIC electronic medical records system, forcing clinicians to revert to pen-and-paper documentation.
January 2026: A coordinated cyberattack beginning in late December 2025 hit roughly 30 sites connected to Poland’s energy grid. The attack disrupted operational technology and damaged key equipment but did not cause any widespread power outages. Researchers attributed the operation to Electrum, a Russia-linked threat actor.
January 2026: A Pakistan-aligned group launched a hacking campaign targeting Indian government, academic, and strategic institutions, aiming to exfiltrate data and carry out persistent surveillance. The campaign has been attributed to APT36, also known as Transparent Tribe, a threat actor with a long history of spying on Indian government bodies, military-linked organizations, and universities.
January 2026: The notorious cybercrime group ShinyHunters targeted Crunchbase, a predictive private intelligence platform, in a hacking operation that extracted more than 2 million records containing personal data. The group later made the files available for download after Crunchbase refused to pay a ransom. Data samples include full names, information, addresses, and other internal business documents.
January 2026: In a campaign dubbed “Operation Neusploit,” threat actors targeted countries in the Central and Eastern European region with a multi-stage infection chain to deliver malicious backdoors. Researchers attribute the campaign to APT28, a threat group connected with Unit 26165 of Russia’s military intelligence service.
January 2026: A cyberattack targeting the Vladimir Bread Factory—one of the largest bakery producers in Russia’s Vladimir region—knocked out office computers, servers, and electronic management and accounting tools. The attack complicated order processing and disrupted food deliveries, with residents reporting temporary shortages. The identity of the attackers and the nature of the incident remain unclear.
December 2025: Approximately $7 million in cryptocurrency was stolen through the crypto wallet company Trust Wallet's Chrome extension from a supply chain attack on December 24th. The company has since released a patched version and pledged to reimburse affected users, with early findings suggesting the malicious update bypassed internal controls via a leaked Chrome Web Store API key.
December 2025: A distributed denial-of-service (DDoS) attack disrupted France's national postal service La Poste and its banking service La Banque Postale days before Christmas. The incident knocked websites and mobile applications offline, slowing parcel deliveries during the holiday rush. At this time, no group claimed responsibility for the attack.
December 2025: Venezuela's state oil company PDVSA reported a ransomware attack on December 15th that disrupted administrative systems and halted oil cargo deliveries. The company blamed the U.S. for the attack amidst high tensions and days after the U.S. seized a Venezuelan oil tanker carrying nearly two million barrels of oil.
December 2025: The French Interior Minister confirmed on December 12th that the ministry was breached in a cyberattack that compromised e-mail servers. During the ongoing investigation, the ministry has tightened security protocols and strengthened access controls to the information systems used by ministry personnel in response to the breach.
December 2025: South Korean e-commerce platform Coupang reported a data breach compromising 33.7 million customer account containing names, email addresses, phone numbers, shipping addresses, and certain order histories. Police have reportedly identified a former employee as a suspect and have launched an official investigation.
November 2025: On November 28, South Korean authorities reported that North Korea’s Lazarus Group stole $30.4 million in cryptocurrency from South Korea’s Upbit exchange. Investigators linked the attack to Pyongyang’s broader campaign to fund its regime via cyber theft and reported possible strategic timing given alignment with a major corporate acquisition.
November 2025: On November 21, Salesforce disclosed that hackers linked to the ShinyHunters group exploited Gainsight OAuth integrations to access over 200 companies’ data. The attackers stole sensitive records from major firms, showing the risks of interconnected SaaS systems.
November 2025: The INC ransomware gang compromised OnSolve’s CodeRED system in early November, halting emergency alerts across multiple U.S. states. The attackers stole resident data then attempted to extort the company, which refused to pay. Officials scrambled to deploy a new platform to end the critical infrastructure disruption.
November 2025: Russian-aligned group NoName057 claimed responsibility for DDoS attacks on Belgian telecom, health, and defense websites in early November. The politically motivated disruptions were brief but signaled continued cyber pressure on EU states supporting Ukraine.
November 2025: An unidentified adversary breached the U.S. Congressional Budget Office (CBO) in November, accessing internal communications and policy data. While the CBO took immediate action to contain the incident, it nonetheless raised concerns over foreign surveillance of U.S. legislative planning.
October 2025: The ransomware group Medusa claimed responsibility for a data breach involving SimonMed Imaging, during which hackers exfiltrated data belonging to approximately 1.2 million patients. The attackers reportedly demanded $1 million to delete the stolen files, and SimonMed has brought in cybersecurity experts to investigate.
October 2025: Hackers uploaded 23 million customer records belonging to several companies, including Vietnam Airlines, on data-trading forums. Vietnam Airlines confirmed this data-breach incident, which exposed customers’ personal information linked to its technology partner’s online customer service platform.
October 2025: Canadian Centre for Cyber Security warned that hacktivist groups have exploited industrial control systems at critical infrastructure sites. Attackers were observed leveraging weak security configurations, default credentials, and unpatched internet-facing PLCs and HMIs.
October 2025: North Korean Lazarus APT group targeted three European defense sector companies to steal sensitive information on drone components and manufacturing processes. The attackers used a social engineering campaign, sending fake job offers with a remote access trojan. The targeted companies supply military equipment to Ukraine and possess specialized knowledge on advanced single-rotor drones that North Korea is actively developing.
October 2025: Russian cybercrime group Lynx breached Dodd Group, a UK Ministry of Defence contractor, stealing approximately 4TB of data, including sensitive files on eight RAF and Royal Navy bases. The attackers deployed ransomware and exfiltrated visitor logs, staff details, security guidance, and construction records and began leaking roughly 1,000 documents. The UK MoD has launched an investigation into this breach.
September 2025: A ransomware gang calling itself Radiant breached Kido International, a childcare provider operating 18 London nurseries, and exfiltrated photographs and personal data of more than 8,000 children. The attackers used phishing emails to obtain remote-desktop access and deploy encryption tools. The group later claimed to delete the data after public backlash.
September 2025: A ransomware attack on Collins Aerospace’s vMUSE airport operations platform disrupted check-in and boarding systems at Heathrow, Brussels, and Berlin airports. The malware encrypted backend servers, forcing airlines to revert to manual check-in and causing hundreds of flight delays. European aviation authorities have not attributed the incident.
September 2025: Hackers infiltrated servers belonging to luxury conglomerate Kering, stealing personal data from clients of Gucci, Balenciaga, and Alexander McQueen. The attackers used credential-stuffing tools and web-exfiltration scripts. The criminal group ShinyHunters claimed responsibility, though Kering did not confirm their involvement.
September 2025: Threat actors exploited stolen OAuth 2.0 refresh tokens from Salesloft and Drift integrations to exfiltrate Salesforce data from hundreds of corporate environments worldwide. The financially motivated campaign affected firms across the finance, technology, and logistics sectors, with some estimates suggesting over a billion records accessed.
September 2025: Cybercriminals attacked Jaguar Land Rover’s IT network with ransomware that disrupted manufacturing and retail operations across multiple UK plants. The attack is estimated to cost £1.9B and be the most economically damaging cyber event in UK history. A group calling itself Scattered Lapsus$ Hunters claimed responsibility, though UK authorities have not confirmed attribution.
August 2025: The U.S., Five Eyes partners, and other allies accused three Chinese firms of aiding Beijing’s intelligence services in cyber espionage. The coalition linked them to sweeping breaches of telecommunications and government data worldwide.
August 2025: Interpol’s “Operation Serengeti 2.0” led to the arrest of more than 1,200 alleged cybercriminals across 18 African countries and the UK. Authorities disrupted tens of thousands of scams and recovered nearly $100 million.
August 2025: Nigeria deported more than 100 convicted foreign nationals, including 50 Chinese citizens, in a crackdown on one of the country’s largest foreign-led cybercrime syndicates.
August 2025: Russian hacktivists disrupted operations at a Polish hydropower plant in Tczew, marking a more destructive follow-up to a May attack on the same facility.
August 2025: Norway formally attributed an April cyberattack on a dam in Bremanger to Russia. Authorities said hackers briefly seized control of the facility to sow fear and chaos, though no damage occurred.
August 2025: An attack on Canada’s House of Commons exposed employee data and details of government-managed devices. Authorities said the breach exploited a Microsoft vulnerability and warned the information could be used in scams or impersonation attempts.
August 2025: Hackers exploited flaws in widely used application delivery and remote access systems to breach several critical infrastructure providers in the Netherlands. Dutch authorities warned that the vulnerabilities could affect thousands of systems worldwide.
August 2025: Several Caribbean governments part of the Kingdom of the Netherlands were hit by cyberattacks, including a ransomware attack on Curaçao’s Tax and Customs Administration. The Dutch Court of Justice was also affected.
July 2025: Chinese state-linked hackers exploited critical flaws in Microsoft’s SharePoint software, breaching U.S. government agencies, critical infrastructure, and global companies.
July 2025: Singapore reported ongoing cyberattacks on critical infrastructure by a China-linked espionage group. Units in Singapore’s military were called in to combat the attacks.
July 2025: Europol disrupted a pro-Russian hacktivist group behind DDoS attacks on Ukraine and NATO countries. The operation led to arrests in France and Spain, as well as warrants for six Russian nationals.
July 2025: A China-linked cyber espionage group targeted an African IT provider servicing government clients, marking a rare expansion into the region.
June 2025: OpenAI banned state-linked accounts from Russia, China, and other countries for abusing ChatGPT in cyber operations. The actors used the tool for malware development, espionage research, social engineering, and covert influence campaigns.
June 2025: Ukraine’s military intelligence agency claimed it breached Russian aerospace firm Tupolev, stealing classified data on strategic bomber programs.
June 2025: Researchers uncovered the largest known data leak in China, exposing over 4 billion user records from platforms including WeChat and Alipay. The data trove appeared designed for mass profiling and surveillance, though its origin remains unknown.
June 2025: An Iranian-linked espionage group maintained persistent access to Kurdish and Iraqi government networks for eight years. The hackers used custom implants and backdoors to spy on officials and sustain strategic footholds in both regions.
May 2025: The Czech Republic attributed a cyberattack targeting its Foreign Ministry to China. While the incident occurred earlier, the attribution was made public this May.
May 2025: Russian hackers conducted an espionage campaign against educational, government, and research-related entities in Tajikistan. The hackers reportedly used an HTML application to implant file-based malware.
May 2025: A Turkish espionage group exploited a vulnerability in a messaging app to spy on Kurdish military forces operating in Iraq over the last year. The hackers used a zero-day bug in the applications to gain access to Kurdish military messages.
May 2025: The U.K.’s National Cyber Security Center named China as the dominant threat to national cybersecurity after a series of hacks and breaches involving British government departments and critical infrastructure, including alleged attacks against the Electoral Commission and Members of Parliament.
May 2025: The United States, Britain, France, Germany, and other allies issued an advisory warning of a Russian cyber campaign targeting the delivery of defense support to Ukraine and other NATO defense and tech sectors.
April 2025: Algeria-linked hackers launched a cyberattack against Morocco's National Social Security Fund, leaking sensitive data online. The breach reportedly exposed personal and financial details for nearly two million people from roughly 500,000 companies.
April 2025: Hackers spied on the emails of roughly 103 U.S. bank regulators at the Office of the Comptroller of the Currency for over a year, ending in early 2025. The attackers gained access via a compromised administrator account, accessing roughly 150,000 emails containing highly sensitive financial institution data. The hacks have yet to be attributed.
April 2025: U.S. Cyber Command discovered Chinese malware implanted on partner networks in multiple Latin American nations during a series of 'hunt forward' operations, according to Lt. Gen. Dan Caine, Trump’s pick for chairman of the Joint Chiefs of Staff.
April 2025: North Korean cyber spies are expanding their infiltration operations to target European defense and government organizations. Hackers posed as remote workers to steal data, commit espionage, and generate revenue, increasingly using extortion against former employers after gaining access.
March 2025: Iranian hackers conducted ongoing cyber espionage campaigns against government entities in Iraq and telecommunications in Yemen. Attackers used custom backdoors and novel command-and-control methods like hijacked emails and backdoors to gain access.
March 2025: A network of front companies linked to a Chinese tech firm targeted recently laid-off U.S. federal workers using recruitment ads on job sites. The operation utilized fake consulting firms with non-functional details and addresses, mirroring methods identified by the FBI as potential foreign intelligence recruitment tactics.
February 2025: North Korean hackers conducted an espionage campaign against South Korean entities to exfiltrate system reconnaissance data from potentially thousands of machines. The attackers used PowerShell scripts and Dropbox for command and control and data exfiltration, demonstrating improved operational security by the attackers.
February 2025: Chinese cyber espionage operations surged by 150% overall in 2024, with attacks against financial, media, manufacturing, and industrial sectors rising up to 300%, according to new reporting.
February 2025: Chinese hackers conducted ongoing cyber espionage campaigns targeting government, manufacturing, telecom, and media sectors in Southeast Asia, Hong Kong, and Taiwan. The attackers deployed a backdoor and embedded themselves in cloud services like Dropbox for command and control to evade detection.
February 2025 : Chinese reporting claims that foreign APTs launched over 1,300 cyberattacks targeting 14 key sectors in China during 2024. Government agencies, education, research, defense, and transportation sectors were most affected, with attackers aiming to steal sensitive data and potentially conduct strategic sabotage.
February 2025: North Korean hackers stole $1.5 billion in Ethereum from the Dubai-based exchange ByBit. Attackers exploited a vulnerability in third-party wallet software during a fund transfer, laundering at least $160 million within the first 48 hours of the attack. It is the largest cryptocurrency heist to date.
February 2025: Chinese cyber actors conducted a coordinated disinformation campaign on WeChat against Canadian Liberal leadership candidate Chrystia Freeland, according to Canada's Security and Intelligence Threats to Elections Task Force. The operation involved numerous accounts spreading disparaging content linked to the PRC and reached 2 to 3 million global WeChat users.
January 2025: Suspected Russian hackers executed spearphishing attacks against Kazakh diplomatic entities. Attackers imbedded malicious code within diplomatic documents, including one allegedly outlining an agreement between Germany and several Central Asian countries, for cyber espionage purposes.
January 2025: A pro-Russian hacking group claimed responsibility for a cyberattack targeting Italian government websites, including ministries, public services, and transportation platforms in cities like Rome and Palermo. The attack was reportedly a response to Italian Prime Minister Giorgia Meloni's meeting with Ukrainian President Volodymyr Zelenskyy, where she reiterated support for Ukraine.
January 2025: Russian cyberattacks on Ukraine surged by nearly 70% in 2024, with 4,315 incidents targeting critical infrastructure, including government services, the energy sector, and defense-related entities. Ukraine’s cybersecurity agency reported that attackers aimed to steal sensitive data and disrupt operations, with tactics such as malware distribution, phishing, and account compromises.
January 2025: Cyberattacks on Taiwan by Chinese groups doubled to 2.4 million daily attempts in 2024, primarily targeting government systems and telecommunications firms, according to Taiwan's National Security Bureau. Attackers aimed to steal sensitive data and disrupt critical infrastructure, with successful attacks rising by 20% compared to 2023.
December 2024: Chinese hackers breached a third-party vendor for the U.S. Treasury Department to gain access to over 3,000 unclassified files. The documents related to principles such as Secretary Janet Yellen, Deputy Secretary Wally Adeyemo, and Acting Under Secretary Brad Smith, in addition to the Committee of Foreign Investment in the United States and the Office of Foreign Assets Control.
December 2024: Russian hackers infiltrated a Pakistani hacking group, exploiting their infrastructure to access sensitive information stolen from South Asian government and military targets.
December 2024: Cyberattacks on Indian government entities increased by 138% between 2019 and 2023, rising from 85,797 incidents in 2019 to 204,844 in 2023, according to the Indian Ministry of Electronics and IT.
December 2024: Russian hackers targeted Romania’s election systems with over 85,000 cyberattacks and leaked credentials on Russian hacker forums. The attacks came just before Romania's presidential vote, with attacks persisting through election day.
December 2024: Russian hackers launched a phishing campaign targeting Ukrainian armed forces and defense enterprises. The attackers deployed remote access tools to infiltrate military systems and steal credentials from platforms like Telegram and local networks.
December 2024: China's national cybersecurity agency accused a U.S. intelligence agency of conducting cyberattacks on two Chinese tech firms since May 2023, targeting an advanced materials research unit and a high-tech company specializing in intelligent energy and digital information. The attacks reportedly led to the theft of substantial trade secrets, coinciding with heightened U.S.-China tensions over export controls on semiconductors and AI technologies.
November 2024: The United Kingdom’s National Cyber Security Center found a three-fold increase in the most significant cyberattacks compared to a year ago. NCSC provided support for 430 cyberattacks, 89 of which were “nationally significant,” and listed China, Russia, Iran, and North Korea as “real and enduring threats.”
November 2024: Chinese hackers, dubbed Salt Typhoon, breached at least eight U.S. telecommunications providers, as well as telecom providers in more than twenty other countries, as part of a wide-ranging espionage and intelligence collection campaign. Researchers believe the attack began up to two years ago and still infects telecom networks. Attackers stole customer call data and law enforcement surveillance request data and compromised private communications of individuals involved in government or political activity.
November 2024: Chinese spies planted a chip in a former U.S. three-stars general’s conference name tag to track his every move during his time serving in the Indo-Pacific.
November 2024: Iranian hackers have been targeting aerospace, defense, and aviation industries in Israel, the UAE, Turkey, India, and Albania, according to Israeli reports. Hackers pose as recruiters on and distribute malware to victims through fake lucrative job offers to spy on targets and steal sensitive data starting in 2023. The malware and tactics are similar to those of a North Korean hacking group that targeted cryptocurrency exchange-traded funds.
November 2024: South Korean officials accused pro-Russian hackers of attacking civilian and government website, following South Korea’s decision to monitor North Korean troops in Ukraine. Several pro-Russian hacktivists have claimed the attacks, but no final attribution has been made.
October 2024: Russian agents sent emails bomb threats to nearly 60 Ukrainian embassies worldwide, as well as media outlets and state agencies.
October 2024: Iranian agents are increasing their espionage efforts against government agencies in the United Arab Emirates. Attackers deployed a backdoor to exfiltrate sensitive credentials
October 2024: Russian cybercriminals sent information-stealing malware to an unknown number of Ukrainian draft-age men to undermine Ukraine's military recruitment efforts.
October 2024: Australia introduced its first national cyber legislation, the Cyber Security Bill 2024. It is the country’s first attempt to codify security standards for ransomware reporting and smart devices and proposes a framework for managing the impact of significant cyber incidents.
October 2024: Chinese hackers have breached at least twenty Canadian government networks over the last four years, according to the Canadian Cantre for Cyber Security (CCCS). CCCS reported that the objectives of the breach include espionage, IP theft, malign influence, and translational repression. The statement comes after CCCS revealed a Chinese threat actor was conducting surveillance scans of Canadian parliamentary and political networks.
October 2024: Russian hackers sent compromised emails disguised to appear as if they were sent from Amazon or Microsoft to infiltrate Ukrainian state and military devices and steal credentials from victims. The scope of the campaign is unknown.
October 2024: Chinese hackers hacked cellphones used by senior members of the Trump-Vance presidential campaign, including phones used by former President Donald Trump and JD Vance as well as people affiliated with the Harris-Walz campaign. It is unclear what data may have been accessed. The FBI is investigating the incident.
October 2024: New reporting reveals Chinese-backed hackers have been conducting large data exfiltration operations against Thailand's government institutions. Hackers first gained access in 2023 through a brute force attack on a local area network before gaining privileged access and beginning data exfiltration.
October 2024: Ukrainian hackers attacked Russia’s state media company and electronic court document management system on Putin's birthday. The attack prevented Russian courts from filing lawsuits or viewing court hearing schedules for several days, and it interrupted all streaming services of prominent TV and radio stations in Russia.
September 2024: Chinese hackers have been conducting an ongoing cyber espionage campaign against Middle Eastern government entities that published human rights studies related to the Israel-Hamas War. The campaign was discovered in June 2024 after researchers discovered malware implants that were designed to ultimately deliver a malware implant.
September 2024: Russian cyber spies conducted an espionage campaign against Mongolia's Ministry of Foreign Affairs and Cabinet websites. The spies added malicious code to the websites to exfiltrate a victim’s browser cookies. Attackers used the same exploits as those sold by commercial surveillance vendors such as NSO Group and Intellexa, but it is unknown if these companies knowingly sold their exploits to the Russian government, according to reports.
August 2024: U.S. government officials blamed Iranian hackers for breaking into Donald Trump’s presidential campaign. Hackers also attempted to break into the then-Biden-Harris campaign, then offered to the stolen Trump campaign documents with the campaign, but were ignored. The attack comes as U.S. officials raise warnings potential foreign interference in the upcoming U.S. election from Russia, China, Iran, and North Korea.
August 2024: The United Nations unanimously approved its first treaty on cybercrime. The treaty will face a General Assembly vote in the fall.
August 2024: Russian cyber criminals are deploying malware against diplomats through a used-car email scheme. The attackers embed a file supposedly with images of a used car in their email, but the file contains backdoor malware that established persistent access for attackers to engage in for follow-on data theft, reconnaissance, and surveillance activities.
July 2024: South Korea’s military is investigating the leak of highly sensitive information on Seoul’s espionage activities and issued an arrest warrant for a suspect. The information included personal data on Seoul’s non-official agents conducting undercover espionage overseas. The information was transferred to the suspect’s personal laptop before being leaked. Lawmakers said the leak was first discovered in June and was not the result of a hack.
July 2024: A faulty software update for Microsoft Windows issues by cybersecurity firm CrowdStrike caused a global IT outage that disrupted airline and hospital operations. It affected approximately 8.5 million machines and cost Fortune 500 companies $5.4 billion, according to reports.
July 2024 : Germany accused China of directing a “serious” cyberattack against Germany’s Federal Office for Cartography and Geodesy (BKG), which conducts precision mapping of the entire country, in 2021. The findings come at the end of a three-year investigation into the incident and as Germany plans a rip-and-replace project for Chinese telecommunications infrastructure in Germany over security concerns.
July 2024: Australia, the United States, Canada, the United Kingdom, Germany, Japan, South Korea, and New Zealand issued a warning malicious Chinese state- cyber activity in their networks. It marked the first time South Korea and Japan joined with Australia to attribute malicious cyber actions to China, and the first time Australia led a cyber attribution effort against China.
June 2024: Japan’s space agency has suffered a series of cyberattacks since last year, according to the Japanese government. Japan’s Chief Cabinet Secretary claimed the targeted networks did not contain sensitive rocket or satellite information, and that the attackers were “from outside of Japan.”
June 2024: Hackers deployed ransomware in Indonesia’s national data center which briefly disrupted a variety of immigration services, including immigration document management services at airports, and deleted information that was not backed up. The attack prompted Indonesia’s Director General of Informatics Applications at the Communications and Informatics Ministry to resign and initiated and a nation-wide audit of Indonesia’s national data centers.
June 2024: Belarusian state- hackers launched an espionage campaign Ukraine’s Ministry of Defense and a Ukrainian military base. The attackers sent targets phishing emails with drone image files a malicious Microsoft Excel spreadsheet.
June 2024: Germany’s main opposition party, the Christian Democratic Union, suffered a cyberattack just ahead of European Parliamentary elections. Germany’s interior ministry did not disclose the extend of the attack or the suspected perpetrator, but acknowledged it was “serious.” The attack occurred shortly after Germany’s Social Democratic party was attacked by Russian hackers. The party briefly took down parts of its IT service as a precaution.
June 2024: The government of Palau accused Chinese hackers of stealing over 20,000 government documents shortly after the island nation signed a 20-year economic and security deal with the United States in March 2024. Palau’s president said this was the first major attack on government records that the island has seen.
May 2024: A new report from Canada’s Communications Security Establishment detected Chinese espionage activity against eight members of Parliament and one senator starting in 2021. The spies likely attempted to obtain information from the targets’ personal and work devices but were unsuccessful, according to the report. The Parliamentarians were members of Canada’s Inter-Parliamentary Alliance on China, which focuses on how democracies should approach PRC-related issues. The report also mentioned this activity was similar to activity against 19 European countries dating back to 2020.
May 2024: Recent media reports stated Pakistani cyber spies deployed malware against India’s government, aerospace, and defense sectors. The group sent phishing emails masquerading as Indian defense officials to infect their targets' devices and access sensitive information. The attack’s extent is unknown.
May 2024: Chinese hackers hit Britain’s Ministry of Defense with a cyberattack that exposed sensitive information on every troop apart from the UK’s special forces. The attackers targeted a third-party contractor to access names and bank details of current and former members of the armed forces. The UK Minister of Defence stopped short of publicly naming China as the culprit.
May 2024: Poland and the Czech Republic accused Russian cyber spies of targeting government and infrastructure networks. Both countries claim the attacks occurred around the same time Russian hackers attacked the German government. Hackers gained access by exploited a Microsoft Outlook vulnerability, and the extent of the compromised data is currently unknown.
May 2024: Germany accused Russian hackers of breaking into the emails of Germany’s Social Democrats, the leading party in its governing coalition, and recalled its ambassador from the country. The campaign started in March 2022 when hackers exploited vulnerabilities in Microsoft Outlook to target the party’s executive committee, as well as German defense and aerospace companies.
April 2024: Ukraine’s military intelligence agency launch a cyberattack against Russia’s ruling United Russia party the same day Russia hosted its Victory Dictation. Attackers launched a barrage of DDoS attacks against United Russia’s servers, websites, and domains to make them inaccessible. United Russia publicly admitted to suffering from a “massive” DDoS attack.
April 2024: Belarusian pro-democracy hackers, known as the Belarusian Cyber-Partisans, crippled the website of Belarus’ main security service agency for over two months. The hackers also published a list of website administrators, its database, and server logs on its Telegram channel. This is the latest in a series of attacks against the Belarusian government by the group.
April 2024: Police in the United Kingdom are investigating a series of “honey trap” attacks against British MPs. Attackers sent explicit messages allegedly of themselves over WhatsApp to their target for the apparent purpose of acquiring compromising images of the target. The perpetrators of these attacks are currently unknown.
April 2024: Germany plans to create a cyber military branch as part of its military restructuring. Germany's defense minister, Boris Pistorius, stated the new Cyber and Information Domain Service (CIR) would help deter increasing cyber aggression from Russia against Germany and its NATO allies.
April 2024: Hackers attacked El Salvador’s national cryptocurrency wallet Chivo and exposed over 144 GB of sensitive personal information of millions of Salvadorians. The hackers also released Chivo’s source code publicly. The Salvadorian government has not released an official public statement on the attack.
March 2024: A “massive” cyberattack disrupted the African Union’s systems for over a week and infected over 200 user devices, according to the deputy chair of the AU Commission. The cause of the cyberattack is unknown.
March 2024: Iranian hackers compromised an IT network connected to an Israeli nuclear facility. Hackers leaked sensitive facility documents but did not compromise its operational technology network.
March 2024: Russian hackers launched phishing attacks against German political parties. Hackers concealed ransomware in a fake dinner invitation from Germany’s Christian Democratic Union to install a backdoor in their victim’s computer.
March 2024: India’s government and energy sectors was breached in a cyber espionage campaign. Hackers sent a malicious file disguised as a letter from India’s Royal Air Force to offices responsible for India’s electronic communications, IT governance, and national defense. Researchers have not yet determined who conducted the attack.
March 2024: A U.S. Department of Justice indictment revealed Chinese hackers targeted several EU members of the Inter-Parliamentary Alliance on China and Italian MPs. The attack was designed to detect IP addresses and the targets’ locations.
March 2024: Canada pulled its financial intelligence system FINTRAC offline after a “cyber incident” by a currently unidentified attacker. FINTRAC claims the attack does not involve its intelligence or classified systems but declined to disclose further details of the incident.
March 2024: Russian hackers leaked an intercepted conversation between German military officials the country’s support for Ukraine. In the call, the head of Germany's Air Force discussed the possibility of supplying Taurus missiles to Ukraine and commented on German Chancellor Olaf Scholz's hesitance to send the missiles. Germany announced it would investigate the incident and believes the leak was intended to inflame divisions in Germany.
March 2024: Switzerland’s National Cyber Security Centre (NCSC) confirmed that leaded data from a May 2023 breach included 65,000 documents from the Federal Administration. The documents contained sensitive personal data, classified information, and passwords, and were from Switzerland’s federal police, judiciary, and migration offices. Swiss officials had originally assessed that breach only impacted non-government documents.
March 2024: Microsoft claims Russian hackers stole its source code and are continuing to gain unauthorized access to its internal systems as part of their November 2023 campaign to spy on senior Microsoft executives. Microsoft also said attackers increased the volume of their “password spray” attacks by nearly tenfold between January and February 2024. The company did not disclose further details on the source code access or breached internal systems.
February 2024: Russian hackers launched an espionage campaign against the embassies of Georgia, Poland, Ukraine, and Iran beginning in 2023. Hackers exploited a bug in a webmail server to inject malware into servers at the embassies and collect information on European and Iranian political and military activities.
February 2024: Roughly 190 megabytes of data from a Chinese cybersecurity company were exposed online, revealing the company’s espionage efforts on the governments of the United Kingdom, India, Indonesia, and Taiwan. The leak’s source is unknown.
February 2024: The Royal Canadian Mounted Police suffered a cyberattack against its networks. The RCMP stated it is investigating this “alarming” incident and does not believe it had an impact on its operations or the safety and security of Canadians. It is so far unclear who is behind the attack and if it was a data breach or security incident.
February 2024: U.S. officials hacked an Iranian military spy ship that was sharing intelligence with Houthi rebels who have been firing on ships in the Red Sea. According to U.S. officials, the attack was part of the Biden administration’s response to an Iranian drone stroke that killed three U.S. soldiers in Jordan.
February 2024: A data breach of French health insurance companies in January 2024 affected 33 million French citizens, or nearly half the country’s population. The attack compromised sensitive birth date, social security, and marital status information, but not medical history. The French data protection agency opened an investigation to determine if the companies complied with cybersecurity guidelines under the EU’s General Data Protection Regulations.
February 2024: Chinese spies places malware in a Dutch military network in 2023. The network was not connected to the defense ministry’s main network, which reduced damage. This is the first time the Netherlands has publicly accused China of cyber espionage.
January 2024: Hackers breached Global Affairs Canada’s secure VPN in December 2023, allowing hackers to access sensitive personal information of users and employees. It affected staff emails, calendars, and contacts. It’s unclear if classified information was compromised or lost. The hacker's identity is currently unknown.
January 2024: Russian hackers launched a ransomware attack against Sweden’s only digital service provider for government services. The attack affected operations for 120 government offices and came as Sweden prepared to join NATO. Sweden expects disruptions to continue for several weeks.
January 2024: Microsoft announced that Russian hackers broke into its corporate systems. Hackers used a “password spray attack” to steal emails and documents from accounts of Microsoft’s senior leadership, cybersecurity, and legal teams back in November 2023.
January 2024: Russian hackers attacked 65 Australian government departments and agencies and stole 2.5 million documents in Australia’s largest government cyberattack. Hackers infiltrated an Australian law firm that worked with the government to gain access to government files.
January 2024: The Australian government identified and sanctioned Aleksandr Ermakov as the Russian hacker who breached Medibank, the country’s largest private health insurance provider, in 2022. He stole information from 9.7 million current and former Medibank customers. This is the first time Australia has issued cyber sanctions against an individual since the framework was established in 2021. The U.S. and UK also sanctioned Ermakov.
January 2024: Russian agents hacked residential webcams in Kyi...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
