Cyber incident intelligence

Every incident, verified

Breaches, ransomware, infrastructure attacks, extortion — the cyber-incident landscape is noisy, and most claims are bluffs, exaggerations, or old data repackaged as new. We don’t race to amplify: we assess each case, declare our confidence level, and show the evidence. Every incident here carries an explicit seal.

The confidence seal

Claimed by the actor
Only the claim exists. Nothing has been corroborated yet.
Corroborated
An independent, legitimate source confirmed elements of the claim.
Confirmed
The affected organization or a regulator acknowledged the incident.

Verified incidents

To verifyCorroboratedTLP:CLEAR

Clop reivindica Shell pela terceira vez — empresa investiga

Shell plc
🇬🇧EnergiaCl0p (Clop)2026-08-14

O grupo Cl0p reivindica ter roubado 89 GB de dados de engenharia da Shell explorando CVE-2026-12569, vulnerabilidade crítica de RCE no PTC Windchill/FlexPLM — parte de uma campanha de extorsão contra ao menos 43 organizações. A Shell confirmou apenas que investiga 'um possível incidente'; nenhuma exfiltração foi verificada de forma independente até agora. Este é o terceiro episódio em que Cl0p afirma ter atingido a Shell: a mesma tática de pressão, o mesmo padrão de recusa em confirmar.

Full report

What we never do

  • We never host, link to, or distribute leaked content — we only index that the incident exists.
  • We never buy, sell, or broker data. We don’t take part in that market.
  • We only use open, legitimate sources: researchers, media, and regulators.
  • A rumor enters as “to verify” — never as fact.