EUAC A.I CyberSecurity Scoring
EUAC
Company Information
Website:http://www.enisa.europa.eu
Employees number:313
Number of followers:138,926
NAICS:541514
Industry Type:Computer and Network Security
Homepage:europa.eu
EUAC Risk Score (AI oriented)
Between 0 and 549
EUACComputer and Network Security
Updated:
13/07/2026
13/07/2026
101/1000
Critical
C
EUAC Global Score (TPRM)
xxxx
EUACComputer and Network Security
Score locked

EUACCritical
Current Score
101C (CRITICAL)
01000
15 incidents
-55.4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
121
Cyber Attack
13 Jul 2026 • EUAC
European Union: URGENT: EU, UK Hit Russia With Joint Sanctions Over Cyber Attacks
EU and UK Impose Joint Sanctions on Russian Cyber Actors Linked to FSB
102
CRITICAL-19
EUR1783938476
EU and UK Impose Joint Sanctions on Russian Cyber Actors Linked to FSB
On July 13, 2026, the European Union and the United Kingdom announced coordinated sanctions targeting 33 Russian-linked individuals and entities accused of conducting cyberattacks across Europe. The measures specifically name actors allegedly tied to Russia’s FSB intelligence service, marking a unified response to Moscow’s ongoing malicious cyber activities.
The EU imposed sanctions on nine individuals and four entities, while the UK added 24 names to its blacklist. These restrictions aim to disrupt cyber operations attributed to Russian state-backed groups, which have increasingly targeted critical infrastructure, government institutions, and private sector networks in Europe.
The sanctions come amid heightened tensions between Russia and Western allies, with cyber warfare remaining a key battleground in the broader geopolitical conflict. The move underscores efforts by the EU and UK to hold Russian intelligence accountable for destabilizing cyber campaigns.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
JUNE 2026
112
MAY 2026
153
Breach
02 May 2026 • EUAC
Trellix: Trellix Confirms Source Code Breach With Unauthorized Repository Access
Trellix Source Code Repository Breach
100
LOW-53
TRE1777710220
Trellix Confirms Source Code Repository Breach, Investigates Unauthorized Access
Cybersecurity firm Trellix disclosed a security breach involving unauthorized access to a portion of its source code repositories. The company detected the compromise "recently" and has since engaged leading forensic experts to investigate the incident, while also notifying law enforcement.
Trellix stated that its investigation has found no evidence that the accessed source code was exploited or that its release and distribution processes were impacted. However, the company did not specify the exact data accessed, the duration of the breach, or the threat actors responsible. Additional details will be shared as the investigation progresses.
Formed in January 2022 through the merger of McAfee Enterprise and FireEye, Trellix is owned by Symphony Technology Group. The breach follows Google’s $5.4 billion acquisition of Mandiant, which was previously part of FireEye, around the same time. The incident remains under active investigation.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
169
Cyber Attack
21 Apr 2026 • EUAC
European Commission: Russia uses AI to hack Europe, Dutch intelligence warns
Dutch Intelligence Warns of Russia’s AI-Powered Cyberattacks on Europe
149
CRITICAL-20
EUR1776796029
Dutch Intelligence Warns of Russia’s AI-Powered Cyberattacks on Europe
Dutch military intelligence (MIVD) has issued a stark warning: Russia is leveraging artificial intelligence to accelerate and scale its cyberattacks against Europe, posing an escalating threat to critical infrastructure. The concern centers on advanced AI tools like Mythos, which experts fear could soon outpace human hackers in identifying and exploiting software vulnerabilities. Currently, access to such tools is restricted to select tech firms and undisclosed organizations while developers assess security risks but their potential proliferation remains a major concern.
AI-driven attacks compress traditional hacking timelines from hours to seconds, enabling threat actors to launch simultaneous strikes across multiple targets. Beyond speed, generative AI enhances social engineering tactics, producing highly convincing phishing emails, voice clones, and deepfake videos that bypass human intuition-based security measures. The MIVD’s report underscores Russia’s growing capabilities, noting that automation including AI has already allowed its cyber operatives to execute attacks at unprecedented velocity.
The warning arrives amid heightened cybersecurity tensions in Europe. Recent incidents include the theft and leak of personal data from the European Commission’s cloud, as well as ongoing efforts by Bulgaria to secure its April parliamentary elections against foreign interference. Meanwhile, cybersecurity teams are also adopting AI to counter threats, using it to monitor networks and detect anomalies faster than human analysts.
As Russia’s AI-driven cyber operations expand, the risk to EU systems and data continues to rise, with intelligence agencies bracing for further escalation.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
181
Vulnerability
15 Apr 2026 • EUAC
European Commission: It Takes 2 Minutes to Hack the EU’s New Age-Verification App
Cybersecurity Roundup: Surveillance, Breaches, and AI Risks Dominate the Week
167
CRITICAL-14
EUR1776515242
Cybersecurity Roundup: Surveillance, Breaches, and AI Risks Dominate the Week
This week’s cybersecurity landscape was marked by revelations of invasive surveillance, high-profile data breaches, and growing concerns over AI-driven threats.
Surveillance at Madison Square Garden
A WIRED investigation uncovered extensive surveillance practices at Madison Square Garden and other venues owned by Jim Dolan. Under the direction of head of security John Eversole, visitors have been subjected to facial recognition, social media monitoring, and in-person tracking. The findings, drawn from court records and sources, highlight the expansion of private surveillance infrastructure in public spaces.
Section 702 Reauthorization Stalls
Efforts to renew the U.S. government’s warrantless surveillance program, Section 702, faced a setback as 20 House Republicans opposed a long-term reauthorization. The resistance forced Speaker Mike Johnson to extend the program for just 10 days, delaying a broader legislative battle over privacy and national security.
AI Smartglasses Spark Privacy Backlash
Over 70 civil society groups, including the ACLU and the National Organization for Women, demanded Meta abandon plans to integrate facial recognition into its Ray-Ban and Oakley AI smartglasses. The coalition warned that the feature, combined with the glasses’ recording capabilities, could enable stalking, domestic abuse, and unwarranted government surveillance.
Deepfake Abuse in Schools
A WIRED and Indicator analysis revealed the global scale of nonconsensual deepfake nudes targeting minors. More than 600 victims across 28 countries primarily middle- and high-school-aged girls were identified in publicly reported incidents, underscoring the rapid spread of AI-powered exploitation.
Telegram’s Sanctioned Black Market Persists
Despite the UK government sanctioning Xinbi Guarantee a $20 billion black market for human trafficking and scams WIRED found the platform still operating on Telegram. Crypto-tracing firm Elliptic reported $505 million in transactions processed by Xinbi in the 19 days following the sanctions.
AI and Cybersecurity Advancements
Anthropic and OpenAI unveiled new AI models Mythos and GPT-5.4-Cyber, respectively positioning AI as a double-edged sword in cybersecurity. While these tools could bolster defenses, they also introduce new risks to the digital threat landscape.
EU’s Age-Verification App Fails Security Test
The European Commission launched a free, open-source app to verify ages on social media and adult sites, but security researchers quickly exposed critical flaws. Consultant Paul Moore and whitehat hacker Baptiste Robert demonstrated vulnerabilities, including an easily exploitable PIN storage system, raising concerns about potential large-scale breaches.
Major Data Breaches Hit Basic-Fit and Booking.com
Europe’s largest gym chain, Basic-Fit, confirmed a breach compromising the bank details of roughly one million customers across six countries. The stolen data included names, addresses, and dates of birth. Meanwhile, Booking.com acknowledged a breach exposing customer names, emails, phone numbers, and booking details, though financial information was reportedly unaffected.
Bluesky Targeted by DDoS Attack
Decentralized social platform Bluesky suffered intermittent outages after a sophisticated distributed denial-of-service (DDoS) attack began on April 15. While user data remained secure, the incident prompted migration requests to alternative AT Protocol-based communities like Blacksky.
ICE Hiring Practices Under Scrutiny
An Associated Press investigation found that U.S. Immigration and Customs Enforcement (ICE) hired agents with histories of misconduct and unpaid debts. Of 40 agents reviewed, three faced lawsuits over alleged misconduct, and several had unresolved legal or financial issues. DHS acknowledged issuing temporary offers before completing full background checks.
Russian Crypto Exchange Grinex Hacked
Grinex, a Russian cryptocurrency exchange linked to sanctions evasion, suspended operations after a breach drained over $13 million (1 billion rubles) in user funds. The company blamed "special services" of a foreign state, though no evidence was provided. Grinex, a successor to the sanctioned Garantex, had been flagged by U.S. authorities for facilitating illicit financial activity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
195
Cyber Attack
31 Mar 2026 • EUAC
OpenAI and European Commission: OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
OpenAI Supply Chain Attack Linked to North Korean Hackers
175
MEDIUM-20
OPEEUR1776099017
OpenAI Discloses Supply Chain Attack Linked to North Korean Hackers
OpenAI revealed that a GitHub Actions workflow used to sign its macOS applications inadvertently downloaded a malicious version of the Axios npm library on March 31, though the company confirmed no user data or internal systems were compromised. The incident stemmed from a supply chain attack attributed to UNC1069, a North Korean hacking group tracked by Google’s Threat Intelligence Group (GTIG).
The threat actors hijacked the Axios maintainer’s npm account to push two poisoned versions (1.14.1 and 0.30.4), embedding a malicious dependency called plain-crypto-js. This deployed WAVESHAPER.V2, a cross-platform backdoor targeting Windows, macOS, and Linux. OpenAI’s macOS app-signing workflow executed Axios 1.14.1, which had access to a signing certificate and notarization material for ChatGPT Desktop, Codex, Codex CLI, and Atlas.
While OpenAI found no evidence of certificate exfiltration, it is treating the certificate as compromised and revoking it by May 8, 2026. Older macOS app versions signed with the old certificate will no longer receive updates and will be blocked by macOS security protections. OpenAI is working with Apple to prevent further notarization of software signed with the compromised certificate.
### Broader Supply Chain Campaigns
The Axios breach was one of two major March supply chain attacks targeting open-source ecosystems. The second, attributed to TeamPCP (UNC6780), compromised Trivy, a vulnerability scanner by Aqua Security, leading to cascading impacts across five ecosystems. The group deployed SANDCLOCK, a credential stealer, and later used stolen secrets to push a self-propagating worm (CanisterWorm) via malicious npm packages.
TeamPCP later exploited Trivy’s compromise to inject malware into GitHub Actions workflows at Checkmarx, then published poisoned versions of LiteLLM and Telnyx on PyPI. The Telnyx Python SDK attack deployed DonutLoader, a shellcode loader hidden in a PNG image, which executed a trojan and AdaptixC2, an open-source command-and-control framework.
### Impact and Response
Google warned that hundreds of thousands of stolen secrets from these attacks could fuel further breaches, including ransomware, SaaS compromises, and cryptocurrency theft. Confirmed victims include Mercor, an AI training startup (breached via Trivy, with 4TB of data allegedly stolen by LAPSUS$), and the European Commission, where attackers exfiltrated AWS-hosted data from 71 Europa web hosting clients.
GitGuardian’s analysis found 474 public repositories executed malicious code from the compromised trivy-action workflow, while 1,750 Python packages were configured to auto-pull poisoned versions. The FBI noted that TeamPCP’s targeting of security tools which often run with elevated privileges grants attackers deep access to sensitive environments.
### Mitigation Efforts
OpenAI, Docker, PyPI, and CISA have outlined countermeasures, including:
- Pinning packages by digest (not mutable tags).
- Using hardened Docker images and enforcing minimum release age delays.
- Short-lived, scoped credentials and sandboxed CI runners.
- Trusted publishing for npm/PyPI packages and 2FA enforcement.
- CISA’s directive to federal agencies to mitigate CVE-2026-33634 by April 9, 2026.
The incidents underscore the risks of implicit trust in open-source dependencies, prompting calls for explicit verification at every layer of the software supply chain.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
256
Breach
24 Mar 2026 • EUAC
European Commission and European Parliament: How Does The EU Data Breach Impact The UK?
Cyberattack on Europa.eu Cloud Infrastructure
193
CRITICAL-63
EUR1774874405
EU Commission Confirms Cyberattack on Europa.eu Cloud Infrastructure
On 24 March, the European Commission detected a cyberattack targeting the cloud infrastructure hosting its Europa.eu web platform the primary online gateway for the Commission, European Parliament, Council of the EU, and other EU institutions. The attack was swiftly contained, with the Commission confirming that public access to EU websites remained uninterrupted while mitigation measures were implemented.
Early findings indicate that data was exfiltrated from the affected systems, though the type and volume of compromised data remain undisclosed. The Commission has begun notifying potentially impacted EU entities but has not identified the attackers. Notably, the breach did not penetrate the Commission’s internal networks, which handle sensitive communications and operations.
The incident underscores Europe’s escalating cyber threats, with ENISA (the EU’s cybersecurity agency) recently warning that the region is facing severe risks from both criminal gangs and state-backed hackers. While the investigation continues, the attack highlights vulnerabilities in shared digital infrastructure, even as the EU strengthens its defenses through regulations like the NIS2 Directive and the Cyber Solidarity Act.
Though the UK is no longer an EU member, the breach serves as a reminder that cyber threats transcend borders, affecting governments and organizations operating in the same high-risk environment. The Commission’s response limiting disruption and isolating the breach demonstrates the value of segmented infrastructure and rapid incident containment.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
396
Ransomware
23 Feb 2026 • EUAC
European Municipalities: LeakWatch 2026 – Security incidents, data leaks, and IT incidents in the current calendar week 9
Cybersecurity Incidents Surge in Early 2026: Ransomware, Cloud Misconfigurations, and Supply Chain Risks Dominate
246
CRITICAL-150
EUR1772346970
Cybersecurity Incidents Surge in Early 2026: Ransomware, Cloud Misconfigurations, and Supply Chain Risks Dominate
The ninth week of 2026 has seen a sharp rise in cyberattacks targeting public institutions, cloud infrastructures, and supply chains, with ransomware, credential abuse, and misconfigurations driving the majority of incidents.
Ransomware Disrupts European Municipalities
Multiple European local governments reported IT outages due to ransomware attacks, forcing the shutdown of citizen portals, appointment systems, and internal document management tools. Attackers gained initial access via compromised VPN credentials often weak or reused passwords and exploited poor network segmentation to move laterally. In one case, backups were accessible from the production network, complicating recovery efforts. Forensic investigations are ongoing, with data protection authorities notified.
Cloud Misconfiguration Exposes SaaS Provider’s Customer Data
A DACH-region SaaS company inadvertently exposed a cloud database due to an incorrect access configuration, leaking customer records, including email addresses and contract details. External researchers discovered the breach via an unsecured API. The incident underscores the risks of over-permissive cloud settings, particularly in multi-cloud environments where oversight is challenging.
Healthcare Sector Hit by Third-Party Data Leak
Patient data from multiple medical practices was exposed after an IT service provider managing appointment and billing systems suffered a breach. The attack stemmed from unauthorized access to an administrator account, with investigations examining whether credentials were previously leaked. The case highlights persistent vulnerabilities in outsourced IT infrastructure, where inconsistent security standards across vendors create systemic risks.
Credential Stuffing Targets E-Commerce Platforms
Major online retailers faced a wave of automated login attempts using stolen email-password combinations. Accounts with stored payment data or voucher balances were primary targets. Platforms lacking adaptive rate limits or multi-factor authentication (MFA) saw successful account takeovers, reinforcing the dangers of password reuse and weak application-level protections.
Zero-Day Vulnerability in Network Hardware
A leading network equipment manufacturer issued an emergency patch for a flaw allowing authentication bypass in its web management interface. The vulnerability, actively exploited in the wild, affects internet-exposed devices without additional access controls. Organizations were urged to apply updates immediately and restrict public access to management interfaces.
Supply Chain Attack via Compromised Open-Source Packages
An open-source DevOps project removed malicious packages from its repository after discovering hidden code designed to exfiltrate environment variables, including API keys. The attack, linked to a hijacked maintainer account, follows a growing trend of targeting software supply chains rather than direct infrastructure. Developers were advised to rotate credentials and audit build environments for unauthorized changes.
Key Trends and Impact
The week’s incidents reflect a persistent threat landscape where attackers exploit known weaknesses misconfigured clouds, unsegmented networks, and reused credentials rather than deploying novel techniques. Public institutions, particularly municipalities, remain high-value targets due to fragmented IT systems and resource constraints. Meanwhile, supply chain risks and third-party vulnerabilities continue to amplify the reach of breaches, demanding greater transparency and security rigor across vendor ecosystems.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
456
Breach
05 Feb 2026 • EUAC
Odido and European Commission: Odido hit with cyberattack, customer data compromised By Investing.com
Odido Suffers Cyberattack, Customer Data Compromised in Breach
392
CRITICAL-64
EURODI1770907059
Odido Suffers Cyberattack, Customer Data Compromised in Breach
Dutch telecommunications provider Odido disclosed a cyberattack on Thursday, confirming that customer data was compromised while maintaining that its services remained operational. The company, owned by private equity firms Apax Partners and Warburg Pincus, stated it swiftly contained the incident and reported the breach to the Authority for Personal Data.
Odido clarified that sensitive information such as passwords, call records, and invoice data was not accessed in the attack. However, due to the scale of the breach, the company plans to notify affected customers within 48 hours, though the exact number of impacted individuals was not specified.
The incident follows a separate cyberattack on the European Commission’s central mobile infrastructure reported on February 5, which potentially exposed staff names and mobile numbers. In response, the Commission emphasized its commitment to bolstering the EU’s cybersecurity resilience amid rising threats to critical services and institutions.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
520
Breach
03 Feb 2026 • EUAC
Substack: Substack data breach exposed users’ emails and phone numbers
Substack 2025 Data Breach Exposing User Email Addresses and Phone Numbers
456
CRITICAL-64
SUB1770295740
Substack Discloses 2025 Data Breach Exposing User Email Addresses and Phone Numbers
Substack has notified select users that their email addresses and phone numbers were exposed in a security incident last October. In an email sent to affected account holders, CEO Chris Best confirmed that an unauthorized third party accessed internal data on February 3, 2025, though passwords, credit card details, and financial information remained secure.
The breach involved email addresses, phone numbers, and internal metadata, but Substack stated there is no evidence the data has been misused. The company has since patched the vulnerability and is conducting a full investigation while strengthening its security measures to prevent future incidents. No details were provided on the root cause of the breach or the total number of impacted users.
Best apologized for the incident, acknowledging the company’s failure to adequately protect user data. Substack has not yet responded to requests for further clarification on the scope of the breach.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
519
DECEMBER 2025
514
NOVEMBER 2025
594
Breach
12 Nov 2025 • EUAC
Shinhan Card: Shinhan Card reports data breach involving 190,000 merchant records
Shinhan Card Personal Data Breach Involving Merchant Representatives
507
HIGH-87
SHI1766477260
Shinhan Card Reports Data Breach Affecting 190,000 Merchant Representatives
Shinhan Card disclosed a data breach involving approximately 192,088 records of merchant representatives, marking the latest in a series of recent leaks affecting major South Korean firms, including Coupang, KT, SK Telecom, and Lotte Card. The incident, reported to the Personal Information Protection Commission (PIPC) on Tuesday, was attributed to internal employee misconduct related to new card solicitation rather than external hacking.
The exposed data included:
- 181,585 records containing only mobile phone numbers
- 8,120 records with phone numbers and names
- 2,310 records with phone numbers, names, birth years, and gender
- 73 records with phone numbers, names, and full dates of birth
Shinhan Card confirmed that no highly sensitive information—such as resident registration numbers, card details, or bank accounts—was compromised. The breach was limited to merchant representatives, with no impact on individual cardholders. The company stated that the leak stemmed from isolated employee actions and posed no further dissemination risk.
The case came to light after a whistleblower submitted evidence to the PIPC, prompting an investigation. Shinhan Card began reviewing the allegations on November 13, verifying the breach through internal records. Following the findings, the company issued a public apology, notified affected merchants, and launched a webpage for individuals to check their exposure.
While Shinhan Card has taken measures equivalent to those for a data breach, further review is needed to classify the incident officially. The company pledged to strengthen protections to prevent future occurrences.
Security Investment Trends Lag Despite Rising Breaches
A recent survey by market tracker Leaders Index revealed that while major South Korean firms increased IT spending by 31.2% (from 16.5 trillion won in 2022 to 21.6 trillion won in 2024), information security investment grew only marginally in proportion—from 5.8% to 5.9% of total IT budgets. Security staffing saw a similar trend, with dedicated personnel rising 22.3% but remaining at just 6.7% of IT workforce share. Analysts noted that despite absolute increases, security priorities continue to trail broader technology spending.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
593
SEPTEMBER 2025
590
AUGUST 2025
586
MAY 2025
574
Vulnerability
23 May 2025 • EUAC
Ivanti
Exploitation of Ivanti EPMM Zero-Day Vulnerabilities by Chinese Cyber Espionage Group
570
CRITICAL-4
IVA357052325
The vulnerabilities CVE-2025-4427 and CVE-2025-4428 in Ivanti Endpoint Manager Mobile (EPMM) were exploited by a Chinese cyber espionage group. The attackers achieved remote code execution on internet-exposed Ivanti EPMM deployments, set up a reverse shell, deployed malware, and extracted data including IMEI, phone numbers, location, LDAP users, and Office 365 tokens. The attack affected various entities globally, including government authorities, healthcare organizations, research institutes, legal firms, telcos, manufacturers, aerospace companies, healthcare providers, and more.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2025
637
Breach
01 Feb 2025 • EUAC
Anthropic: Anthropic leaks its own AI coding tool’s source code in second major security breach
Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems
560
CRITICAL-77
ANT1774981746
Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems
Anthropic has inadvertently leaked the source code for Claude Code, its widely adopted AI-powered coding assistant, exposing roughly 500,000 lines of code across 1,900 files. The incident, confirmed by the company as a "release packaging issue" caused by human error, occurred when internal code was mistakenly uploaded to NPM a platform for software distribution instead of the final, compiled version.
The leak follows a separate accidental disclosure earlier this month, in which a draft blog post revealed details about Mythos (also referred to as Capybara), an upcoming AI model described as more powerful and potentially more dangerous than Anthropic’s current flagship, Opus. While the latest breach did not expose model weights or customer data, cybersecurity experts warn it could allow competitors to reverse-engineer Claude Code’s underlying "agentic harness" the software layer that governs the AI’s behavior, tool integration, and safety guardrails. This could enable the creation of open-source alternatives or help rivals refine their own AI systems.
Security researcher Roy Paz of LayerX Security noted that the leaked code also provided further evidence of Capybara, Anthropic’s next-generation model, which is expected to surpass Opus in capability and cost. The draft blog post previously described it as a new tier, with "fast" and "slow" variants likely replacing Opus as the company’s most advanced offering. Paz highlighted concerns that the exposed code may reveal vulnerabilities in how Claude Code interacts with Anthropic’s internal systems, potentially allowing malicious actors including nation-states to exploit the AI for cyberattacks or bypass existing safeguards.
Anthropic’s Opus model is already classified as a high-risk tool due to its ability to autonomously identify zero-day vulnerabilities, a capability that could be weaponized by threat actors. This is not the first time the company has faced such an exposure; in February 2025, an early version of Claude Code was similarly leaked, revealing internal workings and system connections before being removed.
The company has stated it is implementing measures to prevent future incidents but has not disclosed further details. The leak underscores the challenges of securing proprietary AI systems as adoption and scrutiny of advanced models continues to grow.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2025
752
Ransomware
01 Jan 2025 • EUAC
Ukrainian Critical Infrastructure, European Government and European Critical Infrastructure: Russian Hackers Exploit RDP and VPNs to Breach Target Networks
Russian Hackers Exploit Exposed RDP and VPN Gateways for Espionage and Ransomware
635
CRITICAL-117
EURNCS1779445606
Russian Hackers Exploit Exposed RDP and VPN Gateways for Espionage and Ransomware
Russian state-sponsored and criminal hacking groups are increasingly targeting exposed Remote Desktop Protocol (RDP) services and vulnerable VPN gateways as primary entry points into corporate and government networks. These compromised access points are then resold or weaponized for espionage, ransomware attacks, and other malicious activities.
Threat actors, including initial access brokers, systematically scan the internet for misconfigured RDP ports and poorly secured VPN gateways, exploiting weak passwords, outdated software, and unpatched vulnerabilities. Automated botnets, leveraging over 100,000 unique IP addresses, conduct brute-force and credential-stuffing attacks, making it difficult for defenders to block malicious traffic based on IP filtering alone.
Once access is gained, compromised RDP and VPN credentials are often harvested and auctioned on Russian-language underground forums. Brokers tag these credentials with details such as company size, location, and privilege levels, selling them to ransomware affiliates and advanced persistent threat (APT) groups. Recent intelligence reports indicate that RDP remains a dominant access vector, with VPN credentials rapidly gaining traction as organizations expand remote access infrastructure.
In recent operations targeting European and Ukrainian government and critical infrastructure networks, Russian-aligned groups have combined phishing attacks with VPN and RDP exploitation. Phishing lures trick users into opening malicious RDP files or interacting with fake portals, while attackers simultaneously scan for exposed remote access services. This approach allows ransomware groups to bypass initial reconnaissance, moving directly to high-value targets with pre-compromised credentials.
Ukrainian and European cyber agencies have documented multiple incidents in 2025 where Russian-speaking actors gained access via RDP or VPN, followed by lateral movement and the deployment of ransomware strains such as X2 and LockBit 3.0. Defenders face the challenge of countering both large-scale automated attacks and targeted intrusions by skilled APT groups, underscoring the need for robust security controls.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Vulnerability
01 Jan 2025 • EUAC
F5, Lloyds Banking Group, Citrix, Dutch Ministry of Finance and European Commission: Lloyds Banking Group - Security Affairs
Cybersecurity Roundup: Major Incidents and Emerging Threats
635
CRITICAL-117
EURF5LLOCITMIN1774989406
Cybersecurity Roundup: Major Incidents and Emerging Threats
Recent weeks have seen a surge in high-profile cybersecurity incidents, vulnerabilities, and state-linked attacks targeting governments, financial institutions, and critical infrastructure.
Financial Sector Breaches
Lloyds Banking Group confirmed a security incident affecting nearly 500,000 mobile customers, though details on the nature of the breach remain undisclosed. Meanwhile, the Dutch Ministry of Finance took treasury systems offline following a cyber incident under investigation.
Critical Vulnerabilities Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw (CVE-2026-3055) to its Known Exploited Vulnerabilities catalog after reports of active exploitation, with attackers probing the bug for potential data leaks. CISA also flagged a critical F5 BIG-IP AMP vulnerability under active attack. Additionally, security agencies warned of a severe flaw in PTC Windchill and FlexPLM, urging organizations to apply patches immediately.
State-Sponsored Threats
Russia-linked APT TA446 deployed the DarkSword exploit in a phishing campaign targeting iPhone users. China-associated groups launched advanced malware attacks against a Southeast Asian government in early 2025. Meanwhile, an Iran-linked group, Handala, compromised the personal email account of FBI Director Kash Patel, marking a significant escalation in espionage efforts.
Ransomware and Supply Chain Attacks
The Qilin ransomware group claimed responsibility for breaching Dow Inc., a major chemical manufacturer. Attackers also hijacked the Axios npm account, using it to distribute remote access trojan (RAT) malware to unsuspecting developers. In a separate incident, ShinyHunters asserted responsibility for hacking the European Commission, though the full impact remains unclear.
Emerging Threats
Apple issued urgent lock screen warnings for unpatched iPhones and iPads, highlighting ongoing risks to mobile security. A new macOS malware, Infinity Stealer, was discovered leveraging Nuitka Python payloads and ClickFix techniques to evade detection. Additionally, a new adversary-in-the-middle (AITM) phishing wave targeted TikTok Business accounts, demonstrating evolving social engineering tactics.
Government and Institutional Targets
The European Commission confirmed a cyberattack affecting part of its cloud infrastructure, though specifics on the attack vector and scope were not disclosed. These incidents underscore the persistent and evolving nature of cyber threats across sectors.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JANUARY 2022
756
Cyber Attack
01 Jan 2022 • EUAC
EU member states critical infrastructure: EU sanctions Chinese company behind 65,000-device hack
EU Imposes Sanctions on Chinese and Iranian Entities Over Cyberattacks
739
CRITICAL-17
EUR1773757760
EU Imposes Sanctions on Chinese and Iranian Entities Over Cyberattacks
The EU Council has sanctioned two Chinese companies, one Iranian firm, and two individuals for their involvement in cyberattacks targeting member states and international partners. The measures, announced under the EU’s cyber sanctions regime, include asset freezes, funding restrictions, and travel bans for the listed parties.
Among the sanctioned entities, a Chinese company provided hacking tools that compromised over 65,000 devices across six EU member states between 2022 and 2023. Another Chinese firm offered hacking services targeting critical infrastructure in the EU and other nations. Meanwhile, the Iranian company accessed a French subscriber database, sold the stolen data on the dark web, and hijacked advertising billboards to spread disinformation during the 2024 Paris Olympics. It also breached a Swedish SMS service.
With these additions, the EU’s cyber sanctions now apply to 19 individuals and seven entities. The Council reaffirmed its commitment to collaborating with global partners to uphold a secure and stable cyberspace.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for EUAC ??
What was EUAC's A.I Rankiteo Cyber Score in June 2026 ??
What was EUAC's A.I Rankiteo Cyber Score in May 2026 ??
What was EUAC's A.I Rankiteo Cyber Score in April 2026 ??
What was EUAC's A.I Rankiteo Cyber Score in March 2026 ??
What was EUAC's A.I Rankiteo Cyber Score in February 2026 ??
What was EUAC's A.I Rankiteo Cyber Score in January 2026 ??
What was EUAC's A.I Rankiteo Cyber Score in December 2025 ??
What was EUAC's A.I Rankiteo Cyber Score in November 2025 ??
What was EUAC's A.I Rankiteo Cyber Score in October 2025 ??
What was EUAC's A.I Rankiteo Cyber Score in September 2025 ??
What was EUAC's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on EUAC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with EUAC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view EUAC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?