Filter
Exclude
Time range
-
Near
๐Ÿ‘๐ŸŽ ๐๐š๐ฒ๐ฌ. ๐๐ž๐ฐ ๐ญ๐จ๐ฉ ๐š๐œ๐ญ๐จ๐ซ. ๐๐ž๐ฐ ๐ญ๐จ๐ฉ ๐œ๐จ๐ฎ๐ง๐ญ๐ซ๐ฒ. ๐’๐š๐ฆ๐ž ๐›๐ฅ๐ข๐ง๐ ๐ฌ๐ฉ๐จ๐ญ๐ฌ. In April, Handala was the most impactful threat actor in our dataset. In May, it dropped out of the top four. ๐“๐ž๐š๐ฆ๐๐‚๐, previously a single-incident outlier, is now the most severe actor in the landscape, with the highest ๐–. ๐€๐ฏ๐ . ๐„๐’๐ˆ๐—ยฉ (๐Ÿ“.๐Ÿ—๐Ÿ”) and the strongest positive ๐ˆ๐ฆ๐ฉ๐š๐œ๐ญ ๐Œ๐จ๐ฆ๐ž๐ง๐ญ๐ฎ๐ฆ ( ๐Ÿ๐Ÿ’.๐Ÿ“๐Ÿ”%). ๐†๐จ๐ซ๐๐จ๐ง๐…๐ซ๐ž๐ž๐ฆ๐š๐ง, flagged in our April report as an emerging escalation signal, is now confirmed among the top four. This is what we call ๐ข๐ฆ๐ฉ๐š๐œ๐ญ ๐ฅ๐ž๐š๐๐ž๐ซ๐ฌ๐ก๐ข๐ฉ ๐ซ๐จ๐ญ๐š๐ญ๐ข๐จ๐ง: the most critical threats are not static. They emerge, accelerate, and shift faster than traditional monitoring can follow. May 2026 in numbers: โ†’ ๐Ÿ,๐ŸŽ๐Ÿ‘๐Ÿ‘ analyzed attacks ( ๐Ÿ’.๐Ÿ”%) โ†’ Global Avg. ๐„๐’๐ˆ๐—ยฉ ๐Ÿ’.๐Ÿ•๐Ÿ ( ๐Ÿ.๐Ÿ’%) โ†’ ๐‡๐ž๐š๐ฅ๐ญ๐ก๐œ๐š๐ซ๐ž still the most severe sector (๐Ÿ“.๐Ÿ’๐Ÿ‘), but decelerating โ†’ ๐†๐จ๐ฏ / ๐Œ๐ข๐ฅ / ๐‹๐„: first signs of rising impact ( ๐Ÿ•.๐Ÿ–%) in a sector historically defined by volume, not severity โ†’ ๐’๐จ๐ฎ๐ญ๐ก ๐€๐Ÿ๐ซ๐ข๐œ๐š rises to most impacted country (๐Ÿ“.๐Ÿ”๐Ÿ) โ†’ ๐Œ๐ข๐ง๐ข๐ง๐  / ๐๐ฎ๐š๐ซ๐ซ๐ฒ๐ข๐ง๐ : most structurally overexposed sector โ†’ ๐๐จ๐ฅ๐š๐ง๐ ( ๐Ÿ‘๐Ÿ“.๐Ÿ‘%), ๐ƒ๐ž๐ง๐ฆ๐š๐ซ๐ค ( ๐Ÿ‘๐Ÿ’.๐Ÿ‘%), ๐’๐จ๐ฎ๐ญ๐ก ๐Š๐จ๐ซ๐ž๐š ( ๐Ÿ๐Ÿ—.๐Ÿ“%): sharpest geographic acceleration Cyber risk is no longer just about where attacks concentrate. It's about how fast impact shifts between actors, sectors, and geographies. The full analysis is in the ๐™ƒ๐™–๐™˜๐™ ๐™ข๐™–๐™ฃ๐™–๐™˜ ๐™ˆ๐™ค๐™ฃ๐™ฉ๐™๐™ก๐™ฎ ๐™๐™š๐™ฅ๐™ค๐™ง๐™ฉ โ€” ๐™ˆ๐™–๐™ฎ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ. ๐Ÿ“„ Read online: online.fliphtml5.com/hackmanโ€ฆ ๐Ÿ“ฅ Download: hackmanac.com/monthly-reportโ€ฆ
3
6
3,916
โ€ผ๏ธWe just hit 50,000 cyberattacks analyzed From 2018 to today, every case manually reviewed, verified, and structured. Thatโ€™s the foundation of HackRisk.io. Thanks to the Hackmanac team and everyone supporting us!
1
3
17
8,486
Hackmanacใฎใƒใ‚นใƒˆใฏโ€ใƒชใƒผใ‚ฏใ‚ตใ‚คใƒˆใ‚„ใƒ•ใ‚ฉใƒผใƒฉใƒ ใงใ“ใ‚“ใชใ‚‚ใฎใŒๆŽฒ่ผ‰ใ•ใ‚ŒใฆใŸใ‚ˆ๏ผๆŽฒ่ผ‰ใ•ใ‚ŒใŸๆƒ…ๅ ฑใฎ็ฒพๆŸปใฏใ—ใฆใชใ„ใ‚ˆ๏ผโ€ใชๆฐ—ใŒใ—ใฆใ‚‹ใ‹ใ‚‰ๆคœ็Ÿฅใงใใ‚‹ๆ‰‹ๆฎตใจใ—ใฆ่ฆ‹ใ‚‹ใฎใฏ่‰ฏใ„ใจๆ€ใ†ใ‘ใฉใ€ใ€ŽHackmanacใŒใƒใ‚นใƒˆใ—ใŸใ‹ใ‚‰ใƒคใƒใ„๏ผใ€ใจๅๅฟœใ™ใ‚‹ใฎใฏ้•ใ†ใจๆ€ใฃใฆใƒžใƒณใƒขใ‚นใ€‚
4
1,033
Mar 27
๐Ÿ“ก JAXAใ€ๆ–ฐ่ˆˆใƒฉใƒณใ‚ตใƒ ใ‚ฆใ‚งใ‚ขใ‚ฐใƒซใƒผใƒ—ใ€ŒALP-001ใ€ใซไพตๅฎณใ‚’ไธปๅผตใ•ใ‚Œใ‚‹ โ€” 6.9TBใฎใƒ‡ใƒผใ‚ฟๆตๅ‡บใ‹ ใ‚ตใ‚คใƒใƒผ่„…ๅจใ‚คใƒณใƒ†ใƒชใ‚ธใ‚งใƒณใ‚นใฎHackmanac๏ผˆ@H4ckmanac๏ผ‰ใŒ3ๆœˆ27ๆ—ฅใ€JAXA๏ผˆๅฎ‡ๅฎ™่ˆช็ฉบ็ ”็ฉถ้–‹็™บๆฉŸๆง‹๏ผ‰ใŒใƒฉใƒณใ‚ตใƒ ใ‚ฆใ‚งใ‚ขใ‚ฐใƒซใƒผใƒ—ใ€ŒALP-001ใ€ใซใ‚ˆใ‚‹ไพตๅฎณใ‚’ๅ—ใ‘ใŸใจๅ ฑๅ‘Šใ—ใŸใ€‚ๆ”ปๆ’ƒ่€…ใฏ6.9TBใฎใƒ‡ใƒผใ‚ฟใ‚’็ชƒๅ–ใ—ใŸใจไธปๅผตใ—ใฆใ„ใ‚‹ใ€‚ โ–  ไฝ•ใŒ่ตทใใŸใฎใ‹ - ่„…ๅจใ‚ขใ‚ฏใ‚ฟใƒผ: ALP-001 - ๅฏพ่ฑก: JAXA๏ผˆjaxa.jp๏ผ‰ - ไธปๅผตใ•ใ‚Œใ‚‹ใƒ‡ใƒผใ‚ฟ้‡: 6.9TB - ่ฆณๆธฌๆ—ฅ: 2026ๅนด3ๆœˆ26ๆ—ฅ - ใ‚นใƒ†ใƒผใ‚ฟใ‚น: ๆœชๆคœ่จผ๏ผˆPending verification๏ผ‰ - ่บซไปฃ้‡‘ๆœŸ้™: ็ด„10ๆ—ฅ๏ผˆ4ๆœˆ5ๆ—ฅ้ ƒ๏ผ‰ - ESIXยฉใ‚นใ‚ณใ‚ข: 7.84 โ–  ALP-001ใจใฏไฝ•่€…ใ‹ 2026ๅนด3ๆœˆใซๅ‡บ็พใ—ใŸๆ–ฐ่ˆˆใ‚ฐใƒซใƒผใƒ—ใ€‚ใใฎๆญฃไฝ“ใฏใ€ๅฐ‘ใชใใจใ‚‚2024ๅนดๅŠใฐใ‹ใ‚‰ใƒ€ใƒผใ‚ฏใ‚ฆใ‚งใƒ–ใƒ•ใ‚ฉใƒผใƒฉใƒ ๏ผˆExploitใ€DarkForums็ญ‰๏ผ‰ใงๆดปๅ‹•ใ—ใฆใใŸInitial Access Broker๏ผˆIAB๏ผ‰ใ ใ€‚ ๅพ“ๆฅใฏVPNใƒปCitrixใ‚ฒใƒผใƒˆใ‚ฆใ‚งใ‚คใƒปSSH็ญ‰ใฎไผๆฅญใƒใƒƒใƒˆใƒฏใƒผใ‚ฏใธใฎไพตๅ…ฅๅฃใ‚’ๅฃฒ่ฒทใ—ใฆใ„ใŸใŒใ€่‡ชๅ‰ใฎใƒ‡ใƒผใ‚ฟใƒชใƒผใ‚ฏใ‚ตใ‚คใƒˆใ‚’็ซ‹ใกไธŠใ’ใ€ๆๅ–ๅž‹ใ‚ชใƒšใƒฌใƒผใ‚ทใƒงใƒณใธใจ้€ฒๅŒ–ใ—ใŸใ€‚ใ€ŒAlpha Groupใ€ใ€ŒDGJT Groupใ€ใชใฉใฎๅˆฅๅใงใ‚‚็Ÿฅใ‚‰ใ‚Œใ‚‹ใ€‚ 3ๆœˆ21ๆ—ฅใซHikvision๏ผˆ19.9TB็ชƒๅ–ใ‚’ไธปๅผต๏ผ‰ใ€ไป่พฒๆฉŸใƒกใƒผใ‚ซใƒผPellenc๏ผˆ228GB๏ผ‰ใ€็ฑณIngersoll Randใชใฉใ‚’ๆจ™็š„ใซใ—ใฆใŠใ‚Šใ€JAXAใฏใใฎๆœ€ๆ–ฐใฎๆจ™็š„ใจใชใ‚‹ใ€‚ โ–  JAXAใฎ้ŽๅŽปใฎใ‚คใƒณใ‚ทใƒ‡ใƒณใƒˆ JAXAใฏ2023ใ€œ2024ๅนดใซใ‚‚่ค‡ๆ•ฐใฎใ‚ตใ‚คใƒใƒผๆ”ปๆ’ƒใ‚’ๅ—ใ‘ใฆใ„ใ‚‹ใ€‚VPN่„†ๅผฑๆ€งใ‚’่ตท็‚นใซMicrosoft 365ใ‹ใ‚‰1ไธ‡ไปถไปฅไธŠใฎใƒ•ใ‚กใ‚คใƒซใŒๆตๅ‡บใ—ใŸๅฏ่ƒฝๆ€งใŒใ‚ใ‚Šใ€NDA็ท ็ตๅ…ˆใฎๆƒ…ๅ ฑใ‚‚ๅซใพใ‚Œใฆใ„ใŸใ€‚ไปŠๅ›žใฎALP-001ใฎไธปๅผตใŒไบ‹ๅฎŸใงใ‚ใ‚Œใฐใ€ๆ—ฅๆœฌใฎๅฎ‡ๅฎ™ๆฉŸ้–ขใฎใ‚ปใ‚ญใƒฅใƒชใƒ†ใ‚ฃไฝ“ๅˆถใŒๅ†ใณๅ•ใ‚ใ‚Œใ‚‹ใ“ใจใซใชใ‚‹ใ€‚ โ–  ็พๆ™‚็‚นใงใฎๆณจๆ„ ALP-001ใฎไธปๅผตใฏๆœชๆคœ่จผใ€‚ใ“ใฎใ‚ฐใƒซใƒผใƒ—ใฏIABใ‹ใ‚‰ใฎ่ปข่บซ็ต„ใงใ‚ใ‚Šใ€ใƒใƒƒใƒˆใƒฏใƒผใ‚ฏใ‚ขใ‚ฏใ‚ปใ‚น่‡ชไฝ“ใฏๆœฌ็‰ฉใงใ‚‚ใ€ๅคง่ฆๆจกใƒ‡ใƒผใ‚ฟ็ชƒๅ–ใฎ่จผๆ‹ ใฏ็พๆ™‚็‚นใง็ขบ่ชใ•ใ‚Œใฆใ„ใชใ„ใ€‚JAXAใ‹ใ‚‰ใฎๅ…ฌๅผ็™บ่กจใ‚’ๅพ…ใคๅฟ…่ฆใŒใ‚ใ‚‹ใ€‚

๐ŸšจCyber Alert โ€ผ๏ธ ๐Ÿ‡ฏ๐Ÿ‡ตJapan - ๐—๐—ฎ๐—ฝ๐—ฎ๐—ป ๐—”๐—ฒ๐—ฟ๐—ผ๐˜€๐—ฝ๐—ฎ๐—ฐ๐—ฒ ๐—˜๐˜…๐—ฝ๐—น๐—ผ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—”๐—ด๐—ฒ๐—ป๐—ฐ๐˜† (๐—๐—”๐—ซ๐—”) ALP-001 hacking group claims to have breached Japan Aerospace Exploration Agency (JAXA). Allegedly, the attackers exfiltrated 6.9 TB of data. Threat actor: ALP-001 Sector: Manufacturing Data exposure (claimed): 6.9 TB of data Data type: Not specified Observed: Mar 26, 2026 Status: Pending verification ESIXยฉ: 7.84 Full details and impact assessment on HackRisk.io
2
7
2,959
JD - ๐Ÿค” Hey Hackmanac, how does the cyber threat landscape look over the last 3 months? HM - 6,040 cyber attacks recorded ( 40.5% vs the previous 3 months) JD - ๐Ÿง But how many of these are severe? HM - 874 critical attacks (14.5% of total, 21.4%) JD - ๐Ÿ˜ฐ And which sector is the most impacted? HM - Healthcare (5.57 avg. ESIX) JD - ๐Ÿ˜ฑ Full details and impact assessment on HackRisk.io
4
11
4,389
Eid Al Fitr Mubarak from Hackmanac Team ๐ŸŒ™ โœจ
1
5
46
4,906
Our ๐…๐ž๐›๐ซ๐ฎ๐š๐ซ๐ฒ ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ” ๐‡๐š๐œ๐ค๐ฆ๐š๐ง๐š๐œ ๐Œ๐จ๐ง๐ญ๐ก๐ฅ๐ฒ ๐‚๐ฒ๐›๐ž๐ซ ๐‘๐ข๐ฌ๐ค ๐‘๐ž๐ฉ๐จ๐ซ๐ญ is ready! This edition introduces several new analytical elements, including the ๐ˆ๐ง๐๐ฎ๐ฌ๐ญ๐ซ๐ฒ ๐Œ๐š๐ ๐ข๐œ ๐๐ฎ๐š๐๐ซ๐š๐ง๐ญ, designed to visualise how cyber risk distributes across sectors by combining attack exposure and impact severity by ESIXยฉ. The report applies the ๐‡๐š๐œ๐ค๐ฆ๐š๐ง๐š๐œ ๐‚๐ฒ๐›๐ž๐ซ ๐‘๐ข๐ฌ๐ค ๐…๐ซ๐š๐ฆ๐ž๐ฐ๐จ๐ซ๐ค, a four-dimension model analysing confirmed cyber attacks across: โ€ข ๐ˆ๐ง๐๐ฎ๐ฌ๐ญ๐ซ๐ข๐ž๐ฌ โ€ข ๐†๐ž๐จ๐ ๐ซ๐š๐ฉ๐ก๐ฒ โ€ข ๐“๐ก๐ซ๐ž๐š๐ญ ๐€๐œ๐ญ๐จ๐ซ๐ฌ โ€ข ๐„๐ฆ๐ž๐ซ๐ ๐ข๐ง๐  ๐‘๐ข๐ฌ๐ค ๐’๐ข๐ ๐ง๐š๐ฅ๐ฌ using three core indicators: โ€ข ๐„๐’๐ˆ๐—ยฉ โ€” severity per incident โ€ข ๐ˆ๐ฆ๐ฉ๐š๐œ๐ญ ๐Œ๐จ๐ฆ๐ž๐ง๐ญ๐ฎ๐ฆ โ€” month-over-month acceleration of cyber impact โ€ข ๐๐’๐ˆ (๐๐ฎ๐ข๐ž๐ญ ๐’๐ก๐ข๐Ÿ๐ญ ๐ˆ๐ง๐๐ž๐ฑ) โ€” divergence between attack activity and damage concentration Some insights from February: โ€ข ๐Œ๐š๐ง๐ฎ๐Ÿ๐š๐œ๐ญ๐ฎ๐ซ๐ข๐ง๐  emerges in the Critical Risk Zone, combining high exposure with sustained incident severity. โ€ข Most industries cluster in Tail Risk Hotspots, where cyber incidents generate ๐๐ข๐ฌ๐ฉ๐ซ๐จ๐ฉ๐จ๐ซ๐ญ๐ข๐จ๐ง๐š๐ญ๐ž ๐ข๐ฆ๐ฉ๐š๐œ๐ญ ๐๐ž๐ฌ๐ฉ๐ข๐ญ๐ž ๐ฆ๐จ๐๐ž๐ซ๐š๐ญ๐ž ๐š๐œ๐ญ๐ข๐ฏ๐ข๐ญ๐ฒ ๐ฅ๐ž๐ฏ๐ž๐ฅ๐ฌ. โ€ข ๐…๐ซ๐š๐ง๐œ๐ž shows the strongest acceleration of cyber impact, with Impact Momentum exceeding 30% month-over-month. โ€ข Several threat actors generate ๐๐ข๐ฌ๐ฉ๐ซ๐จ๐ฉ๐จ๐ซ๐ญ๐ข๐จ๐ง๐š๐ญ๐ž ๐ข๐ฆ๐ฉ๐š๐œ๐ญ ๐ซ๐ž๐ฅ๐š๐ญ๐ข๐ฏ๐ž ๐ญ๐จ ๐ญ๐ก๐ž๐ข๐ซ ๐š๐œ๐ญ๐ข๐ฏ๐ข๐ญ๐ฒ ๐ฅ๐ž๐ฏ๐ž๐ฅ๐ฌ, highlighting increasing operational efficiency. ๐Ÿ“Š Download the full report: hackmanac.com/monthly-reportโ€ฆ For continuous access to the underlying dataset, trends and severity indicators: ๐Ÿ‘‰ hackrisk.io
2
5
4,820
Over the past week we have been closely monitoring the cyber dimension of the ongoing tensions in the Middle East. Cyber activity is already accompanying the conflict, involving multiple countries, threat actors and sectors across the region. Today we published the first issue of the ๐‡๐š๐œ๐ค๐ฆ๐š๐ง๐š๐œ ๐Œ๐ข๐๐๐ฅ๐ž ๐„๐š๐ฌ๐ญ ๐‚๐ฒ๐›๐ž๐ซ ๐‚๐จ๐ง๐Ÿ๐ฅ๐ข๐œ๐ญ ๐Œ๐จ๐ง๐ข๐ญ๐จ๐ซ, a weekly snapshot designed to track how the cyber landscape evolves as the situation develops. The analysis is based on ๐Ÿ‘๐Ÿ–๐Ÿ ๐ฉ๐ฎ๐›๐ฅ๐ข๐œ๐ฅ๐ฒ ๐๐ข๐ฌ๐œ๐ฅ๐จ๐ฌ๐ž๐ ๐œ๐ฒ๐›๐ž๐ซ ๐ข๐ง๐œ๐ข๐๐ž๐ง๐ญ๐ฌ recorded in the ๐Ÿ๐ข๐ซ๐ฌ๐ญ ๐Ÿ• ๐๐š๐ฒ๐ฌ ๐จ๐Ÿ ๐ญ๐ก๐ž ๐œ๐จ๐ง๐Ÿ๐ฅ๐ข๐œ๐ญ. Of course, what we observe represents only the visible layer of a much broader cyber battlefield โ€” especially when espionage, sabotage and information warfare are involved. We will continue monitoring the situation and publishing updates every 7 days. ๐Ÿ‘‡ Full analysis in the original post.
For the past seven days we have been closely monitoring the cyber dimension of the ongoing tensions in the Middle East. Today we are introducing a new weekly intelligence snapshot: the ๐‡๐š๐œ๐ค๐ฆ๐š๐ง๐š๐œ ๐Œ๐ข๐๐๐ฅ๐ž ๐„๐š๐ฌ๐ญ ๐‚๐ฒ๐›๐ž๐ซ ๐‚๐จ๐ง๐Ÿ๐ฅ๐ข๐œ๐ญ ๐Œ๐จ๐ง๐ข๐ญ๐จ๐ซ. The goal is to provide a structured view of the cyber activity surrounding the conflict โ€” highlighting ๐š๐Ÿ๐Ÿ๐ž๐œ๐ญ๐ž๐ ๐œ๐จ๐ฎ๐ง๐ญ๐ซ๐ข๐ž๐ฌ, ๐ญ๐š๐ซ๐ ๐ž๐ญ๐ž๐ ๐ฌ๐ž๐œ๐ญ๐จ๐ซ๐ฌ, ๐ญ๐ก๐ซ๐ž๐š๐ญ ๐š๐œ๐ญ๐จ๐ซ๐ฌ and ๐ญ๐ž๐œ๐ก๐ง๐ข๐ช๐ฎ๐ž๐ฌ ๐จ๐›๐ฌ๐ž๐ซ๐ฏ๐ž๐. The data presented in this monitor is based exclusively on successful cyber attacks that have become publicly disclosed. Especially in a sensitive geopolitical context like the current one, many operations โ€” particularly those involving espionage, sabotage or information warfare โ€” are unlikely to surface immediately, if at all. As a result, the activity we observe should be considered only the visible layer of a much broader cyber conflict landscape. First 7 days overview: โ€ข ๐Ÿ‘๐Ÿ–๐Ÿ ๐œ๐ฒ๐›๐ž๐ซ ๐ข๐ง๐œ๐ข๐๐ž๐ง๐ญ๐ฌ ๐จ๐›๐ฌ๐ž๐ซ๐ฏ๐ž๐ ๐š๐œ๐ซ๐จ๐ฌ๐ฌ ๐ญ๐ก๐ž ๐ซ๐ž๐ ๐ข๐จ๐ง โ€ข ๐Ÿ๐Ÿ ๐œ๐จ๐ฎ๐ง๐ญ๐ซ๐ข๐ž๐ฌ ๐ข๐ฆ๐ฉ๐š๐œ๐ญ๐ž๐ โ€ข ๐Ÿ’๐Ÿ“ ๐ญ๐ก๐ซ๐ž๐š๐ญ ๐š๐œ๐ญ๐จ๐ซ๐ฌ ๐ข๐ง๐ฏ๐จ๐ฅ๐ฏ๐ž๐ ๐ข๐ง ๐ญ๐ก๐ž ๐š๐œ๐ญ๐ข๐ฏ๐ข๐ญ๐ฒ โ€ข ๐€๐ฏ๐ž๐ซ๐š๐ ๐ž ๐„๐’๐ˆ๐—ยฉ ๐ข๐ฆ๐ฉ๐š๐œ๐ญ ๐ฌ๐œ๐จ๐ซ๐ž: ๐Ÿ‘.๐Ÿ•๐Ÿ‘ The data shows a strong concentration of activity around ๐ ๐จ๐ฏ๐ž๐ซ๐ง๐ฆ๐ž๐ง๐ญ, ๐ฆ๐ข๐ฅ๐ข๐ญ๐š๐ซ๐ฒ and ๐ฅ๐š๐ฐ ๐ž๐ง๐Ÿ๐จ๐ซ๐œ๐ž๐ฆ๐ž๐ง๐ญ targets, which alone account for nearly half of the observed incidents. In terms of geography, the highest volumes of activity have been observed in ๐ˆ๐ฌ๐ซ๐š๐ž๐ฅ, ๐Š๐ฎ๐ฐ๐š๐ข๐ญ and ๐‰๐จ๐ซ๐๐š๐ง, while ๐ˆ๐ซ๐š๐ง, ๐ˆ๐ซ๐š๐ช and ๐ญ๐ก๐ž ๐”๐€๐„ appear as the most impacted countries. From a technical perspective, ๐ƒ๐ƒ๐จ๐’ campaigns dominate the activity, representing the vast majority of incidents recorded during the first week of the conflict โ€” although typically associated with lower impact levels. By contrast, ๐ฆ๐ฎ๐ฅ๐ญ๐ข๐ฉ๐ฅ๐ž ๐ญ๐ž๐œ๐ก๐ง๐ข๐ช๐ฎ๐ž๐ฌ and ๐ฆ๐š๐ฅ๐ฐ๐š๐ซ๐ž appear to be the most dangerous threats in terms of severity. This monitor will be updated every 7 days to track how the cyber dimension of the conflict evolves over time.
1
3
389
For the past seven days we have been closely monitoring the cyber dimension of the ongoing tensions in the Middle East. Today we are introducing a new weekly intelligence snapshot: the ๐‡๐š๐œ๐ค๐ฆ๐š๐ง๐š๐œ ๐Œ๐ข๐๐๐ฅ๐ž ๐„๐š๐ฌ๐ญ ๐‚๐ฒ๐›๐ž๐ซ ๐‚๐จ๐ง๐Ÿ๐ฅ๐ข๐œ๐ญ ๐Œ๐จ๐ง๐ข๐ญ๐จ๐ซ. The goal is to provide a structured view of the cyber activity surrounding the conflict โ€” highlighting ๐š๐Ÿ๐Ÿ๐ž๐œ๐ญ๐ž๐ ๐œ๐จ๐ฎ๐ง๐ญ๐ซ๐ข๐ž๐ฌ, ๐ญ๐š๐ซ๐ ๐ž๐ญ๐ž๐ ๐ฌ๐ž๐œ๐ญ๐จ๐ซ๐ฌ, ๐ญ๐ก๐ซ๐ž๐š๐ญ ๐š๐œ๐ญ๐จ๐ซ๐ฌ and ๐ญ๐ž๐œ๐ก๐ง๐ข๐ช๐ฎ๐ž๐ฌ ๐จ๐›๐ฌ๐ž๐ซ๐ฏ๐ž๐. The data presented in this monitor is based exclusively on successful cyber attacks that have become publicly disclosed. Especially in a sensitive geopolitical context like the current one, many operations โ€” particularly those involving espionage, sabotage or information warfare โ€” are unlikely to surface immediately, if at all. As a result, the activity we observe should be considered only the visible layer of a much broader cyber conflict landscape. First 7 days overview: โ€ข ๐Ÿ‘๐Ÿ–๐Ÿ ๐œ๐ฒ๐›๐ž๐ซ ๐ข๐ง๐œ๐ข๐๐ž๐ง๐ญ๐ฌ ๐จ๐›๐ฌ๐ž๐ซ๐ฏ๐ž๐ ๐š๐œ๐ซ๐จ๐ฌ๐ฌ ๐ญ๐ก๐ž ๐ซ๐ž๐ ๐ข๐จ๐ง โ€ข ๐Ÿ๐Ÿ ๐œ๐จ๐ฎ๐ง๐ญ๐ซ๐ข๐ž๐ฌ ๐ข๐ฆ๐ฉ๐š๐œ๐ญ๐ž๐ โ€ข ๐Ÿ’๐Ÿ“ ๐ญ๐ก๐ซ๐ž๐š๐ญ ๐š๐œ๐ญ๐จ๐ซ๐ฌ ๐ข๐ง๐ฏ๐จ๐ฅ๐ฏ๐ž๐ ๐ข๐ง ๐ญ๐ก๐ž ๐š๐œ๐ญ๐ข๐ฏ๐ข๐ญ๐ฒ โ€ข ๐€๐ฏ๐ž๐ซ๐š๐ ๐ž ๐„๐’๐ˆ๐—ยฉ ๐ข๐ฆ๐ฉ๐š๐œ๐ญ ๐ฌ๐œ๐จ๐ซ๐ž: ๐Ÿ‘.๐Ÿ•๐Ÿ‘ The data shows a strong concentration of activity around ๐ ๐จ๐ฏ๐ž๐ซ๐ง๐ฆ๐ž๐ง๐ญ, ๐ฆ๐ข๐ฅ๐ข๐ญ๐š๐ซ๐ฒ and ๐ฅ๐š๐ฐ ๐ž๐ง๐Ÿ๐จ๐ซ๐œ๐ž๐ฆ๐ž๐ง๐ญ targets, which alone account for nearly half of the observed incidents. In terms of geography, the highest volumes of activity have been observed in ๐ˆ๐ฌ๐ซ๐š๐ž๐ฅ, ๐Š๐ฎ๐ฐ๐š๐ข๐ญ and ๐‰๐จ๐ซ๐๐š๐ง, while ๐ˆ๐ซ๐š๐ง, ๐ˆ๐ซ๐š๐ช and ๐ญ๐ก๐ž ๐”๐€๐„ appear as the most impacted countries. From a technical perspective, ๐ƒ๐ƒ๐จ๐’ campaigns dominate the activity, representing the vast majority of incidents recorded during the first week of the conflict โ€” although typically associated with lower impact levels. By contrast, ๐ฆ๐ฎ๐ฅ๐ญ๐ข๐ฉ๐ฅ๐ž ๐ญ๐ž๐œ๐ก๐ง๐ข๐ช๐ฎ๐ž๐ฌ and ๐ฆ๐š๐ฅ๐ฐ๐š๐ซ๐ž appear to be the most dangerous threats in terms of severity. This monitor will be updated every 7 days to track how the cyber dimension of the conflict evolves over time.
11
54
10,464
Grazie a Elena Betti per avermi permesso di raccontare a @wireditalia cosa sta accadendo davvero in UAE, dove vivo con la mia famiglia da 9 anni. La situazione nella zona รจ certamente molto delicata, il paese tuttavia non รจ oggetto di offensive dirette, ma solo indirette, in quanto i target di missili e droni sono solo strategici e militari. Nonostante il comprensibile clima di tensione e di prudenza, non c'รจ panico, ma molta fiducia nelle istituzioni locali, che vantano uno dei sistemi difensivi migliori al mondo e stanno gestendo l'emergenza con precisione ed efficacia (94% delle offensive intercettate e distrutte nel momento in cui scrivo il post). L'aspetto forse piรน importante, oltre alla protezione dei residenti, รจ che l'economia continua a funzionare, con negozi e centri commerciali aperti e servizi di delivery operativi come sempre, un fortissimo segno di resilienza. Parallelamente, da CEO & Founder di Hackmanac, ho osservato e raccontato unโ€™altra dimensione del conflitto, quella digitale. Ogni escalation geopolitica moderna porta con sรฉ anche una dimensione cyber, e i primi segnali hanno iniziato ad emergere giร  dai primi giorni nella regione. Qui l'articolo completo con entrambe le prospettive: ๐Ÿ”— wired.it/article/dubai-attacโ€ฆ
2
3
7
2,323
๐ŸšจCyber Alertโ€ผ๏ธ ๐Ÿ‡ฆ๐Ÿ‡ชUAE - Scammers are taking advantage of the situation in the UAE. The caller claims to be from the Ministry of Interior (MOI) and asks you to confirm that you received the national alert. They request your Emirates ID (EID) number for verification. Please do not provide any personal information or data. The government would never call you to ask for such details. Stay safe, Hackmanac Team
30
65
21,370
๐–๐žโ€™๐ฏ๐ž ๐ฃ๐ฎ๐ฌ๐ญ ๐ซ๐ž๐ฅ๐ž๐š๐ฌ๐ž๐ ๐จ๐ฎ๐ซ ๐Ÿ๐ข๐ซ๐ฌ๐ญ ๐Œ๐จ๐ง๐ญ๐ก๐ฅ๐ฒ ๐‘๐ž๐ฉ๐จ๐ซ๐ญ ๐จ๐Ÿ ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ”! Starting this year, Hackmanac introduces a dedicated monthly severity-driven analysis of confirmed cyber attacks, designed to go beyond volume and reveal where real damage is intensifying. This edition introduces two new analytical lenses: โ€ข๐ˆ๐ฆ๐ฉ๐š๐œ๐ญ ๐Œ๐จ๐ฆ๐ž๐ง๐ญ๐ฎ๐ฆ โ€” measuring the month-over-month acceleration of our ESIXยฉ severity index โ€ข๐๐’๐ˆ (๐๐ฎ๐ข๐ž๐ญ ๐’๐ก๐ข๐Ÿ๐ญ ๐ˆ๐ง๐๐ž๐ฑ) โ€” identifying where impact concentration exceeds activity levels Combined with attack volume and ESIXยฉ impact analysis, these metrics provide clearer answers to strategic risk questions: โ€ขWhere is severity accelerating? โ€ขWhich industries are structurally over-exposed? โ€ขWhich threat actors generate disproportionate damage? โ€ขWhere are early systemic signals emerging? This report is built for: โ€ขCISOs and security leaders prioritising exposure โ€ขCyber insurance and underwriting teams assessing loss concentration โ€ขRisk managers and boards seeking severity-based indicators โ€ขThreat intelligence professionals tracking structural shifts For continuous, real-time access to the complete dataset, trends and severity breakdowns, explore ๐‡๐š๐œ๐ค๐‘๐ข๐ฌ๐ค.๐ข๐จ, our Strategic Threat Intelligence platform. ๐Ÿ”Ž ๐ƒ๐จ๐ฐ๐ง๐ฅ๐จ๐š๐ ๐ญ๐ก๐ž ๐ซ๐ž๐ฉ๐จ๐ซ๐ญ ๐Ÿ๐จ๐ซ ๐Ÿ๐ซ๐ž๐ž ๐ก๐ž๐ซ๐ž: hackmanac.com/monthly-reportโ€ฆ
2
3
5
4,702
Ramadan Kareem from Hackmanac Team ๐ŸŒ™
2
5
102
5,790
Hackmanacใ‚’ไธ€ๆฌกใ‚ฝใƒผใ‚นใจใ—ใฆๆ‰ฑใ†ใฎใƒคใƒ•ใƒผใƒ‹ใƒฅใƒผใ‚นใ‚’1ๆฌกใ‚ฝใƒผใ‚นใจใ—ใฆๆ‰ฑใ†ใฎใจๅŒใ˜ๆ„Ÿ่ฆšใชๆฐ—ใŒใ™ใ‚‹ใฎๅƒ•ใ ใ‘๏ผŸ
2
2
15
4,075
๐ŸšจCyberattack Alert โ€ผ๏ธ ๐Ÿ‡ฆ๐Ÿ‡ชUAE - Emirates National Group The Gentlemen hacking group claims to have breached Emirates National Group. Sector: Transportation Threat class: Cybercrime Observed: Feb 12, 2026 Status: Pending verification โ€” About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
1
5
25
7,461
๐ŸšจCyberattack Alert โ€ผ๏ธ ๐Ÿ‡ช๐Ÿ‡ธSpain - Renovagy LockBit 5.0 hacking group claims to have breached Renovagy. Sector: Professional / Scientific / Technical Threat class: Cybercrime Observed: Feb 12, 2026 Status: Pending verification โ€” About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
12
48
7,708
๐ŸšจCyber Alert โ€ผ๏ธ ๐Ÿ‡ฎ๐Ÿ‡นItaly - Siem Srl Space Bears hacking group claims to have breached Siem Srl. Allegedly, the attackers exfiltrated data, including customer contracts, financial reports, customer drawings (factories, airports, etc.), employee personal data, and projects. Sector: Professional Threat class: Cybercrime Observed: Feb 13, 2026 Status: Pending verification โ€” About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
5
7
4,663
๐ŸšจCyber Alert โ€ผ๏ธ ๐Ÿ‡ฏ๐Ÿ‡ตJapan - Nippon Medical School Musashi Kosugi Hospital NetRunnerPR threat actor claims to have breached Nippon Medical School Musashi Kosugi Hospital and exfiltrated 131,135 patient PII records, including names, IDs, contacts, and personal details, with samples released as proof. The actor also threatened to leak 20,000 additional records on February 16, 2026. Sector: Healthcare Threat class: Cybercrime Observed: Feb 11, 2026 Status: Pending verification โ€” About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
2
63
148
56,715
๐ŸšจCyberattack Alert โ€ผ๏ธ ๐Ÿ‡บ๐Ÿ‡ธUS - Tsunami Tsolutions Everest hacking group claims to have breached Tsunami Tsolutions. Allegedly, the attackers exfiltrated 562 GB of data, including a database containing proprietary aviation data, aircraft component documentation, maintenance records, software source code, and export-controlled technical files. Sector: Professional / Scientific / Technical Threat class: Cybercrime Observed: Feb 11, 2026 Status: Pending verification โ€” About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
1
11
21
6,582
๐ŸšจCyberattack Alert โ€ผ๏ธ ๐Ÿ‡ฌ๐Ÿ‡ญGhana - Ghana Bauxite Company Limited The Gentlemen hacking group claims to have breached Ghana Bauxite Company Limited. Sector: Mining / Quarrying Threat class: Cybercrime Observed: Feb 12, 2026 Status: Pending verification โ€” About this post: Hackmanac provides early warning and cyber situational awareness through its social channels. This alert is based on publicly available information that our analysts retrieved from clear and dark web sources. No confidential or proprietary data was downloaded, copied, or redistributed, and sensitive details were redacted from the attached screenshot(s). For more details about this incident, our ESIX impact score, and additional context, visit HackRisk.io.
4
7
4,512