Cyber incident intelligence

Every incident, verified

Breaches, ransomware, infrastructure attacks, extortion — the cyber-incident landscape is noisy, and most claims are bluffs, exaggerations, or old data repackaged as new. We don’t race to amplify: we assess each case, declare our confidence level, and show the evidence. Every incident here carries an explicit seal.

The confidence seal

Claimed by the actor
Only the claim exists. Nothing has been corroborated yet.
Corroborated
An independent, legitimate source confirmed elements of the claim.
Confirmed
The affected organization or a regulator acknowledged the incident.

Verified incidents

RealCorroboratedTLP:CLEAR

Clop explora zero-day em PLM industrial e reivindica 43 vítimas

Múltiplas organizações (campanha Windchill/FlexPLM — Clop)
Múltiplos (Manufatura, Energia, Saúde, Financeiro)Clop (Cl0p)2026-08-18

O grupo Clop explorou a CVE-2026-12569 — uma RCE sem autenticação no PTC Windchill e FlexPLM, provavelmente como zero-day desde início de junho de 2026 — e reivindica roubo de dados de 43 organizações, entre elas Shell, Philips, GE e Fiserv. A Philips confirmou comprometimento de um servidor interno; Shell, GE e Fiserv investigam sem confirmar os volumes alegados; nenhum regulador confirmou impacto a dados pessoais de clientes até o momento.

Full report
RealCorroboratedTLP:CLEAR

Clop explora zero-day em PLM e atinge gigantes globais

Shell, General Electric (GE) e Philips
🇬🇧Energia / Tecnologia / ManufaturaClop (Cl0p)2026-08-18

O grupo Clop explorou CVE-2026-12569 — falha crítica de RCE (CVSS 9.8) no PTC Windchill/FlexPLM — como zero-day desde o início de junho de 2026, comprometendo ao menos 43 organizações, incluindo Shell, GE e Philips. Shell e Philips confirmaram incidentes; GE está em avaliação; nenhuma das três confirmou os volumes alegados pelo grupo, e a extensão real do comprometimento permanece aberta.

Full report

What we never do

  • We never host, link to, or distribute leaked content — we only index that the incident exists.
  • We never buy, sell, or broker data. We don’t take part in that market.
  • We only use open, legitimate sources: researchers, media, and regulators.
  • A rumor enters as “to verify” — never as fact.