CyberSweep Request a Free Consultation
Live · refreshed by the 5th of each month

The cyber risks we track, in real time

Every month our intelligence agent turns global ransomware and breach activity into deal-stage action items for PE and M&A teams. This is the same threat picture that informs every CyberSweep engagement, published openly.

$6M+Avg hidden liability surfaced per assessment
5–7×True breach cost vs. the ransom demand
48%Of all breaches now include ransomware
2026 Verizon DBIR
$400M+Avg deal value at risk per engagement
72hrsQuickSweep™ turnaround for pre-LOI screening
Intelligence reports

M&A Cyber Risk Intelligence, month by month

Published by the 5th of each month. Every brief translates the month’s ransomware activity into deal-stage action items for private equity and M&A teams.

Key incidents
Tata Electronics / World Leaks

630.4 GB exfiltrated including Apple and Tesla technical drawings, manufacturing specs, and employee passports. 204,341 files published publicly.

Critical
NYC Health + Hospitals

1.8 million individuals affected. SSNs, biometric fingerprints, palm prints, medical records, precise geolocation, and financial credentials exfiltrated via a third-party vendor. Senate HELP Committee inquiry.

Critical
Bajaj Auto + BATL

Ransomware attack on Bajaj Auto and subsidiary Bajaj Auto Technology Ltd. Regulatory filing to NSE and CERT-In. Detected June 23 at 8:00 AM IST. No confirmed data exfiltration.

High
ServiceNow API Breach

Unauthenticated API endpoint flaw exploited June 2–5 across all hosted customer instances. Internal tickets, employee records, and operational documentation exposed. Patch deployed June 5.

High
KDDI Email Platform

Up to 14.22 million email addresses and passwords exposed across 6 Japanese ISPs via a third-party software vulnerability. Detected June 17, disclosed June 23.

High
Nintendo / ShadowByt3$

859 MB stolen: employee PII, internal surveys, sentiment analytics, progress plans, and reports spanning 2016–2026. Corporate intelligence value.

Elevated
Eastman Kodak / ShinyHunters

ShinyHunters claimed a ransomware attack; scope under investigation. Follows the group’s prolific April and May 2026 campaign against high-visibility brands.

Elevated
KTR Real Estate Advisors / Anubis

Anubis ransomware claimed the real estate appraisal and consulting firm June 22. Property valuations, client financials, and HNW individual PII at risk.

Elevated
Key incidents
West Pharmaceutical Services

SEC 8-K filed May 7 as a material event. Data exfiltrated and global systems encrypted; manufacturing and shipping disrupted worldwide. Unit 42 engaged. Only the third S&P 500 company to file a cyber 8-K in 2026.

Critical
Instructure / Canvas LMS

275 million records stolen across 8,800+ institutions (Duke, Harvard, Penn, Wisconsin). 3.65 TB exfiltrated via an XSS flaw in the free-tier support flow. Ransom paid. FBI PSA issued.

Critical
Fiserv + TSYS / Everest

Both listed within 24 hours. Fiserv serves 10,000+ financial institutions with core banking and Clover POS. A coordinated strike against US payment infrastructure with systemic downstream risk.

Critical
Jones Day / Silent Ransom Group

$13M ransom demand. 10 clients notified. M&A deal files, litigation memos, and client financials exposed via targeted phishing at a law firm actively handling live transactions.

High
Medtronic / ShinyHunters

9M+ PII records and terabytes of corporate data claimed. Medtronic confirmed unauthorized access; the listing was removed, suggesting a quiet settlement. HIPAA exposure at scale.

High
Moorman Harting / Akira

21 GB exfiltrated: HNW client files, NDAs, passports, payroll, government IDs, and contracts. A classic high-value, low-security-posture wealthcare target.

High
JRK Property Holdings / The Gentlemen

111,000 individuals notified. SSNs and names exposed via Fortinet edge-gear exploitation. Class action filed. Real estate investment firm.

Elevated
Checkmarx / Lapsus$

Source code, employee database, API keys, MongoDB and MySQL credentials stolen. Every Checkmarx customer’s DevOps pipeline placed at downstream risk. Software supply-chain multiplier.

Elevated
Key incidents
Stryker Corp / Handala (Iran-linked)

200,000+ devices wiped across 79 countries with 50 TB of data theft claimed and simultaneous factory resets. Nation-state retaliation; BYOVD technique used to neutralize EDR.

Critical
Bladex Bank / LockBit 5

Multinational bank from a central-bank consortium listed April 22. Cross-border banking data, inter-bank records, and regulatory exposure. LockBit 5 resurgent after takedown.

Critical
Checkmarx / Lapsus$ (initial claim)

Source code, employee database, API keys, and database credentials stolen. DevSecOps platform compromise creates a supply-chain multiplier for all downstream customers.

Critical
Dow Chemical / Qilin

Qilin claimed unauthorized access with internal data allegedly exfiltrated. Chemical manufacturing with an OT/IT boundary vulnerability. Unconfirmed ransom demand.

High
Die Linke Party / Qilin

German political entity. Ransomware plus data theft; IT systems partially shut down. Russian-aligned framing via spear-phishing and remote desktop exploitation.

High
Foster City, CA / Municipal Gov

All non-emergency public services suspended; personal data potentially compromised. Opportunistic targeting of under-resourced municipal IT with a weeks-long recovery.

High
Heinrichs Logistic / LockBit 5

German logistics provider and supply-chain bottleneck target with high disruption leverage. Listed April 24. Client data and logistics records exposed.

Elevated
Getulio Vargas Foundation / DragonForce

1.52 TB exfiltrated including names, IDs, and banking data. Leading Brazilian government-linked institution. LGPD regulatory exposure.

Elevated
JUL
2026
July 2026 Threat Intelligence Brief May 29 – June 28, 2026 · auto-generates August 5, 2026 Scheduled
AUG
2026
August 2026 Threat Intelligence Brief June 29 – July 28, 2026 · auto-generates September 5, 2026 Scheduled

Reports auto-generate by the 5th of each month via the CyberSweep Intelligence Agent · Aug 5 → July window · Sep 5 → August window · Oct 5 → September window

Sector risk index

Every sector in your portfolio is under active attack

Updated monthly from ransomware.live and corroborating intelligence feeds. Threat levels reflect trailing 30-day activity.

ManufacturingCritical
HealthcareCritical
Financial TechnologyCritical
Legal / AccountingHigh
ConstructionHigh
Pharma / Life SciencesHigh
Education / SaaSHigh
Real EstateElevated
Energy / UtilitiesElevated
Retail / DistributionElevated
Technology / IT ServicesHigh
Government AdjacentHigh
Threat actor 2026 activity Primary sectors Vector Relative volume
Qilin 1,448 attacks Healthcare, Legal, Mfg Phishing, credential theft
ShinyHunters 275M records SaaS, Healthcare, Tech XSS, session hijacking
Everest Fiserv, TSYS Financial infrastructure Third-party vendor access
World Leaks Tata 630GB Manufacturing, Tech Exfiltration focus, no encryption
The Gentlemen 182 Q1 victims Construction, Real Estate Fortinet VPN exploitation

Threat-actor names and figures are drawn from public intelligence feeds for situational awareness. CyberSweep is not affiliated with, and does not endorse, any organization named.

Turn this intelligence into deal leverage

The most expensive breach is the one you discover after closing.

This dashboard is the free tier. On a live deal, CyberSweep translates the same threat picture into a defensible, dollar-denominated risk figure your investment committee can act on.

© 2026 CyberSweep. All rights reserved. QuickSweep™, DeepSweep™, TotalSweep™, Portfolio Shield™ and Recommended Deal Adjustment™ are trademarks of CyberSweep.