Supply-Chain Attack
Supply-chain attacks compromise a trusted vendor, library, or service to reach that vendor’s many downstream customers at once.
57tracked breaches
Groups using this method
Qilin 4The Gentlemen 3LockBit 2worldleaks 2ShinyHunters 2lapsus$ 2Icarus 1Akira 1coinbasecartel 1nitrogen 1ransomhouse 1J 1payoutsking 1cuba 1revil 1conti 1
Breaches using Supply-Chain Attack
August 22, 2026HIGH
August 17, 2026HIGH
August 15, 2026LOW
August 11, 2026HIGH
August 4, 2026CRIT
July 30, 2026HIGH
July 30, 2026HIGH
July 17, 2026HIGH
July 11, 2026HIGH
July 7, 2026HIGH
July 7, 2026HIGH
July 3, 2026HIGH
July 3, 2026MED
July 2, 2026HIGH
July 2, 2026CRIT
July 1, 2026HIGH
June 25, 2026HIGH
June 22, 2026MED
June 18, 2026MED
June 18, 2026HIGH
June 16, 2026HIGH
June 13, 2026CRIT
June 12, 2026HIGH
June 12, 2026HIGH
June 12, 2026CRIT
June 11, 2026HIGH
June 10, 2026HIGH
June 10, 2026HIGH
June 10, 2026HIGH
June 9, 2026HIGH
June 8, 2026MED
June 3, 2026HIGH
June 2, 2026HIGH
June 2, 2026HIGH
June 1, 2026MED
June 1, 2026HIGH
May 25, 2026MED
May 22, 2026HIGH
May 20, 2026HIGH
May 17, 2026HIGH
May 14, 2026HIGH
May 14, 2026HIGH
May 12, 2026HIGH
May 11, 2026HIGH
May 8, 2026MED
May 8, 2026MED
May 7, 2026CRIT
May 5, 2026LOW
May 4, 2026MED
April 28, 2026HIGH
Nebraska Orthopaedic Center breach: names, birth dates and SSNs were copied
Supply-Chain Attack
Indico Data Solutions breach: was my Social Security number exposed?
Supply-Chain Attack
Those viral bank voice-clone fraud numbers are not a confirmed incident
Supply-Chain Attack
CISA Adds Three Vulnerabilities to Known Exploited Vulnerabilities Catalog
Supply-Chain Attack
CISA Adds Langflow, N-central, Tomcat to KEV Catalog
Supply-Chain Attack
Analog Devices Discloses Cybersecurity Incident in SEC 8-K
Supply-Chain Attack
CISA Alerts on PLC Targeting in Water Sector
Supply-Chain Attack
Ernst & Young Discloses Third-Party Support System Breach
Supply-Chain Attack
Bancroft Engineering Listed by LockBit
LockBit Ransomware
TheGentlemen breaches Michigan IT services provider
The Gentlemen Ransomware
Accenture confirms breach after 35GB source code offered for sale
Ransomware
SISINT Engineering Firm Breached by Qilin
Qilin Ransomware
Brazilian IT Firm Service IT Breached by WorldLeaks
worldleaks Ransomware
Chaos Ransomware Claims Breach of Universal Plant Services
Ransomware
First Agentic AI Ransomware Attack via Langflow
Ransomware
JadePuffer Executes First Fully Autonomous LLM Ransomware Attack
Ransomware
Nissan Discloses Employee Data Breach via Oracle PeopleSoft Zero-Day
Supply-Chain Attack
Bancroft Engineering Claimed by LockBit Ransomware
LockBit Ransomware
Icarus Group Steals Salesforce Data via Klue OAuth Breach
Icarus Ransomware
Additional Klue Supply-Chain Breach Victims Identified
Supply-Chain Attack
Italian Customs Broker CAD 93 Hit by DeadLock Ransomware
Ransomware
30K+ Fortinet Devices Compromised in Credential Heist
Supply-Chain Attack
Texas Parks & Wildlife Vendor Breach Exposes 3M License Holders
Supply-Chain Attack
Dynatrace Source Code Allegedly Stolen from GitHub
Supply-Chain Attack
Ivanti Sentry Critical Flaw Exploited in Under 24 Hours
Supply-Chain Attack
Port Air Express Breached by Akira Ransomware
Akira Ransomware
ShinyHunters Targets Oracle PeopleSoft Servers
ShinyHunters Supply-Chain Attack
Mackay Sugar Hit by The Gentlemen Ransomware, Mills Shut
The Gentlemen Ransomware
Tata Electronics Confirms Cyberattack, Apple Manufacturing Data Leaked
worldleaks Ransomware
ServiceNow Discloses Customer Data Query Incident
Supply-Chain Attack
SoFi Hong Kong Discloses Third-Party Vendor Data Breach
Supply-Chain Attack
Emmy.tv AWS Credentials Exposed in Public HTML
Supply-Chain Attack
Red Hat NPM Packages Backdoored in Supply Chain Attack
Supply-Chain Attack
Ingka Group (IKEA) Targeted in Alleged Lapsus$ Data Theft
lapsus$ Ransomware
Oxford University Career Platform Hit by Third-Party Breach
Supply-Chain Attack
Oxford University Discloses CareerConnect Platform Breach
Supply-Chain Attack
ACAM Systemautomation Breached by TheGentlemen
The Gentlemen Ransomware
Oncology Institute Confirms Patient Data Impacted by Vendor Breach
Supply-Chain Attack
GitHub Confirms Breach of ~3,800 Internal Repos via Malicious VS Code Extension
Supply-Chain Attack
Grafana Suffers GitHub Token Breach and Extortion Attempt
coinbasecartel Ransomware
OpenAI Confirms Breach via TanStack Supply Chain Attack
Supply-Chain Attack
Malicious node-ipc npm Versions Steal Credentials
Supply-Chain Attack
Nitrogen Ransomware Claims Foxconn Breach
nitrogen Ransomware
Lapsus$ Leaks Vodafone Source Code and Database Credentials
lapsus$ Ransomware
SailPoint Discloses GitHub Repository Hack
Supply-Chain Attack
NVIDIA Confirms GeForce NOW Data Breach for Armenian Users
Supply-Chain Attack
West Pharmaceutical Services Hit by Ransomware
Ransomware
Cushman & Wakefield Data Breach (2026)
QilinShinyHunters Ransomware
RansomHouse claims breach of Trellix source code
Ransomware
Cybersecurity Vendor Listed by ransomhouse Ransomware Group
ransomhouse Ransomware
Check your exposure
Check if you’re exposed →Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.