Cyber incident intelligence

Every incident, verified

Breaches, ransomware, infrastructure attacks, extortion — the cyber-incident landscape is noisy, and most claims are bluffs, exaggerations, or old data repackaged as new. We don’t race to amplify: we assess each case, declare our confidence level, and show the evidence. Every incident here carries an explicit seal.

The confidence seal

Claimed by the actor
Only the claim exists. Nothing has been corroborated yet.
Corroborated
An independent, legitimate source confirmed elements of the claim.
Confirmed
The affected organization or a regulator acknowledged the incident.

Verified incidents

RealConfirmedTLP:CLEAR

OT de saneamento do Minnesota atacada em 30 cidades — autoria ainda não confirmada

Sistemas municipais de água e esgoto do Minnesota (30+ comunidades)
🇺🇸Saneamento / Infraestrutura Crítica2026-07-28

Um ataque coordenado comprometeu tecnologia operacional em mais de 30 concessionárias de água e esgoto do Minnesota nos dias 26 e 27 de julho de 2026, derrubando temporariamente uma planta em Braham e forçando operação manual em ao menos outras três cidades. O incidente é confirmado por fonte regulatória estatal (MNIT), mas nenhuma agência federal atribuiu o ataque publicamente a qualquer ator — a suspeita recorrente de ligação iraniana via CyberAv3ngers é inferência analítica de pesquisadores, não atribuição oficial, e deve ser tratada como tal.

Full report

What we never do

  • We never host, link to, or distribute leaked content — we only index that the incident exists.
  • We never buy, sell, or broker data. We don’t take part in that market.
  • We only use open, legitimate sources: researchers, media, and regulators.
  • A rumor enters as “to verify” — never as fact.