Cyber incident intelligence

Every incident, verified

Breaches, ransomware, infrastructure attacks, extortion — the cyber-incident landscape is noisy, and most claims are bluffs, exaggerations, or old data repackaged as new. We don’t race to amplify: we assess each case, declare our confidence level, and show the evidence. Every incident here carries an explicit seal.

The confidence seal

Claimed by the actor
Only the claim exists. Nothing has been corroborated yet.
Corroborated
An independent, legitimate source confirmed elements of the claim.
Confirmed
The affected organization or a regulator acknowledged the incident.

Verified incidents

RealCorroboratedTLP:CLEAR

AnMed: sequestro do Facebook amplifica extorsão sem prova de vazamento

AnMed
🇺🇸SaúdeThe Gentlemen2026-08-11

O sistema hospitalar AnMed, da Carolina do Sul, sofreu ataque de ransomware confirmado em 26 de julho de 2026, que fechou 83 de suas 106 unidades por semanas. O grupo The Gentlemen reivindicou a autoria, invadiu a página do Facebook da organização para publicar exigências de resgate e alega ter exfiltrado 6 TB de dados altamente sensíveis — mas não apresentou nenhuma evidência, e a AnMed ainda não confirmou comprometimento de dados de pacientes.

Full report

What we never do

  • We never host, link to, or distribute leaked content — we only index that the incident exists.
  • We never buy, sell, or broker data. We don’t take part in that market.
  • We only use open, legitimate sources: researchers, media, and regulators.
  • A rumor enters as “to verify” — never as fact.