ECSG tracks confirmed cyberattacks, breaches, and law-enforcement actions from around the world and translates each one into a practical takeaway for growing businesses. Updated regularly.
A rundown of recent, verified cyberattacks and breaches — what happened, who it hit, and what it means if you run a small or mid-size business.
A breach at business-services provider Conduent, which handles back-office work for healthcare and government clients, has grown far beyond its original scope. Regulators now put the affected population above 62 million individuals, with Social Security numbers, medical records, and insurance details among the exposed data. Notifications and lawsuits are still unfolding.
European rail pass provider Eurail confirmed unauthorized access to its systems, with attackers claiming to have copied roughly 1.3TB of data from cloud storage and support systems. More than 300,000 travelers had names, travel companion details, and passport numbers exposed, raising the risk of follow-on phishing and identity fraud.
The European Commission confirmed that the cloud infrastructure hosting its public Europa website was struck by a cyberattack, with some data taken from affected pages before the incident was contained. Internal Commission systems were reportedly unaffected — an example of a public-facing environment being properly segmented away from core operations.
The FBI formally notified Congress after identifying that one of its surveillance systems had been compromised, in a breach reportedly linked to state-sponsored actors. The intrusion may have exposed phone numbers tied to individuals under federal surveillance — a reminder that even the most security-conscious organizations get breached.
A cyberattack attributed to an Iran-aligned hacktivist group hit a major medical technology manufacturer, with employees reportedly watching office computers get wiped in real time. Operations were shut down while the security team investigated — a stark illustration of how destructive, rather than purely data-stealing, attacks can bring a business to a halt.
Chemco, a Calgary-based manufacturer serving the energy, logistics, and oil & gas sectors, was targeted by the Qilin ransomware group — one of several active operations that specialize in hitting mid-size manufacturers with limited in-house security teams.
A heap-based buffer overflow in how 7-Zip processes certain archive data (CVE-2026-14266) is being exploited within days of public disclosure, according to telemetry showing exploitation attempts from multiple countries. A fix shipped in 7-Zip 26.02 on June 25 — before the flaw was even publicly detailed — underscoring the value of staying current on patches.
Spanish authorities disrupted a cyber fraud operation estimated to have moved roughly €140 million, a reminder that law enforcement cooperation across borders is increasingly effective against organized cybercrime — and that reporting incidents promptly helps investigators build these cases.
Summarized from public reporting by TechCrunch, Dark Reading, The Hacker News, BrightDefense, ACI Learning, SharkStriker, and official government disclosures. Details evolve as investigations continue; always confirm specifics with primary sources before making decisions.
Beyond any single incident, a few consistent patterns keep showing up across this year's breaches.
Most SMBs won't make national headlines when something goes wrong — but the same root causes apply to a 20-person business as they do to a Fortune 500 company.
Know which vendors touch your data, what they can access, and how quickly you'd hear about a breach on their end.
Automated patch management shrinks the gap between "vulnerability disclosed" and "your systems are covered."
Isolated backups and a tested incident response plan turn a destructive attack into a bad afternoon instead of a bad year.
ECSG can run a free security assessment against your current environment — the same lens we use to read these headlines, pointed at your business.