Breach Watch
Written for risk decisions, not headlines.
Breach, ransomware, vulnerability, advisory and threat intelligence, classified by LiveThreat and analysed in an ADTP brief for every item.
Showing 20 of 176
BREACH WATCH BRIEF
Ransomware Attack Disrupts Japan’s IDCF Cloud, Affecting 495 Companies and Government Clients
A ransomware group breached IDC Frontier’s IDCF Cloud service, encrypting 3.6 PB of data and shutting down management consoles for 495 corporate and government customers. The incident highlights the need for continuous third‑party monitoring and auditable incident‑response evidence.
BREACH WATCH BRIEF
MonsterCloud Owner Charged With Secretly Paying Ransomware Demands and Over‑Billing Clients
The owner of a ransomware‑recovery firm allegedly paid attackers on behalf of clients while inflating invoices by up to twenty‑fold, leading to a federal wire‑fraud charge. This highlights the need for robust third‑party oversight and auditable ransom‑payment processes for compliance readiness.
BREACH WATCH BRIEF
Ransomware Attack Stole PII from Advantest, Global Semiconductor Test‑Equipment Maker
Advantest disclosed that a February 2026 ransomware breach exfiltrated personal data—including SSNs, passports, and medical records—from its corporate network. The incident underscores the importance of incident‑response and privacy controls for audit readiness.
BREACH WATCH BRIEF
Osaka Metropolitan University Halts Classes After Suspected Ransomware Attack Exposing 130,000 Records
Osaka Metropolitan University shut down 500 servers after a suspected ransomware incident that disrupted email, academic, and administrative systems and may have exposed personal data of 130 000 individuals. The event underscores the need for continuous monitoring, incident‑response evidence, and security‑awareness training to meet audit‑readiness expectations.
BREACH WATCH BRIEF
Ransomware Gang Booba Steals 344 GB from University of Illinois Chicago College of Medicine
A ransomware group called Booba breached the University of Illinois Chicago’s College of Medicine, encrypting systems and exfiltrating 344 GB of data. The incident highlights the need for auditable incident‑response controls and continuous monitoring to satisfy multiple compliance frameworks.
BREACH WATCH BRIEF
Warlock Ransomware Targets Water and Telecom Operators, Disrupting Critical Services
Warlock ransomware leveraged legacy SharePoint flaws to encrypt data on water utility and telecom networks, leading to service outages. The incident underscores the need for continuous patch management and auditable incident‑response evidence.
BREACH WATCH BRIEF
Warlock Ransomware Exploits Unpatched SharePoint Flaws to Target Critical Infrastructure
Warlock ransomware (Longlegs) continues to breach water utilities, telecoms, governments and universities by exploiting legacy SharePoint vulnerabilities. The attacks highlight the need for robust vulnerability‑management controls and audit‑ready evidence for compliance programs.
BREACH WATCH BRIEF
Warlock Ransomware Exploits Zero‑Day SharePoint Flaws to Hit Water Utility, Telecom Operator and Others
Warlock ransomware leveraged four SharePoint zero‑day vulnerabilities to compromise a water utility, telecom provider, regional government and university, disabling AV/EDR on dozens of hosts before encrypting data. The incident highlights the need for continuous vulnerability management and auditable patch‑remediation evidence for compliance readiness.
BREACH WATCH BRIEF
Warlock Ransomware Exploits Unpatched SharePoint Vulnerabilities in Critical Infrastructure Across Portuguese‑ and Spanish‑Speaking Nations
A China‑based group used the Warlock ransomware to breach water utilities, telecoms, universities, and regional governments by exploiting unpatched Microsoft SharePoint flaws. The campaign underscores the importance of robust vulnerability‑management and audit‑ready evidence for control assurance.
BREACH WATCH BRIEF
Spain Arrests 16‑Year‑Old Suspected Leader of KillSec Ransomware, Tied to ~1,000 Attacks and 110 TB of Stolen Data
Spanish authorities detained a 16‑year‑old alleged administrator of the KillSec ransomware group, which has been linked to nearly 1,000 attacks since 2024. The operation’s dark‑web site and over 110 TB of stolen files were seized, highlighting the scale of the threat and the importance of robust incident‑response controls for audit readiness.
BREACH WATCH BRIEF
Teen Allegedly Leads KillSec Ransomware Campaign, 500 Victims Disrupted
International law‑enforcement agencies dismantled the KillSec ransomware operation, which is alleged to be run by a 16‑year‑old and has impacted roughly 500 victims over two years. The incident underscores the need for robust ransomware response controls and audit‑ready evidence.
BREACH WATCH BRIEF
Police Seize KillSec Ransomware Leak Site, Lock Down 110 TB of Stolen Data
Europol’s Operation KillSwitch took control of the KillSec ransomware group’s leak site, securing more than 110 TB of stolen files and halting further publication. The takedown affects roughly 1,000 victim organizations across multiple sectors, highlighting the importance of robust incident‑response and security‑awareness programs for audit readiness.
BREACH WATCH BRIEF
Spanish Police Arrest 16-Year-Old Suspected Leader of KillSec Ransomware Group, Seize Leak Site
Spanish authorities detained a 16‑year‑old believed to run the KillSec ransomware operation and took control of its public leak site and servers. The group had been exfiltrating data from multiple organizations and threatening publication unless ransom was paid, highlighting the ongoing ransomware threat landscape.
BREACH WATCH BRIEF
International Law Enforcement Dismantles KillSec Ransomware Gang, Seizes 110 TB of Stolen Data
Police across ten countries shut down the KillSec ransomware operation, arresting three suspects and seizing 110 TB of stolen data. The takedown highlights the need for robust ransomware‑response controls and audit‑ready evidence.
BREACH WATCH BRIEF
Warlock Ransomware Compromises Large Spanish and Portuguese Organizations
Warlock ransomware, attributed to a Chinese‑origin threat actor, has hit several large enterprises in Spain and Portugal, encrypting critical data and halting operations. The incident underscores the need for robust incident‑response controls, immutable backups, and auditable evidence to meet audit and regulatory expectations.
BREACH WATCH BRIEF
Warlock Ransomware Strikes Water Utility and Telecom Operator via SharePoint Zero‑Days
Longlegs used SharePoint zero‑day exploits to infiltrate a water utility and a telecom provider, disabling security tools and deploying ransomware on dozens of hosts. The incident underscores the need for auditable incident‑response controls and continuous monitoring.
BREACH WATCH BRIEF
Ransomware Toolkit Discovered on South Africa’s Air Traffic Control Network
A ransomware toolkit was found on at least one operational network supporting South Africa’s air traffic control, leading the aviation authority to seek external help. The incident highlights the need for auditable incident‑response controls that satisfy multiple compliance frameworks.
BREACH WATCH BRIEF
Ransomware Hits Core Payment Platform, Recovery Test Proves Value of Documented Restore
A major bank’s core payment system was taken offline by ransomware, forcing a rapid restore from an air‑gapped backup. The incident demonstrates why documented recovery testing is essential for audit‑ready control assurance.
BREACH WATCH BRIEF
Ransomware Attack Disrupts Keio Corporation’s Hospitality Systems, Threatens Payment Operations
Keio Corporation confirmed a ransomware intrusion that halted its hotel‑and‑hospitality IT services and impacted payment processing. The event underscores the importance of a tested incident‑response program and continuous evidence collection for audit readiness.
BREACH WATCH BRIEF
JadePuffer AI‑Driven Ransomware Destroys Azure Storage Accounts, Key Vaults and Other Cloud Resources
JadePuffer leveraged autonomous AI agents to harvest Azure service‑principal credentials and wipe more than 100 storage accounts, Key Vaults and other services in minutes. The attack underscores the need for continuous privileged‑identity monitoring and immutable resource‑lock controls to maintain audit‑ready evidence.
Breach Watch intelligence is provided by LiveThreat, a product of a founding sponsor of the association. Every ADTP brief carries LiveThreat's analysis and links the original source.
Practitioner briefings
Written by the association: what the week's intelligence means for the controls you run.
Reading a vendor's breach notice for what it does not say
A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.
Where AI inventory efforts stall, and the control that unblocks them
Findings from practitioner roundtables on AI governance programs in their first year.
Evidence reuse across customer diligence and audit
How practitioners are organizing one evidence base to serve buyers and auditors at the same time.
Global Privacy Control signals and state opt-out obligations
What a site must do when it sees a GPC signal, and how to evidence it.
Get the digest
No membership required. Confirm by email; unsubscribe in one click.