Recent Cybersecurity Incidents
This page called "Events" displays many different attacks that happened over the last few decades. Each category has 3 attacks that have happened in the real world. With one attack being the biggest most prominent attack that has happened in that category, next being a major attack after 2021, and finally an attack that has happened in 2025 or 2026.
2013-2015
Google/Facebook BEC phishing scam
The Google phishing scam was a major business email compromise case in which attackers pretended to be a trusted company supplier to trick employees into approving fraudulent payments. From 2013 to 2015, false invoices and payment requests were sent to Google and Facebook, making the messages look legitimate enough that large money transfers were approved. The scam was later tied to Evaldas Rimasauskas, who used fake business records and bank accounts to carry out the fraud. What makes this case especially important is that it showed phishing is not always about stealing passwords; it can also be used to exploit trust inside normal business operations and cause extremely large financial losses.
September 2023
MGM Resorts social engineering/phishing attack
The MGM Resorts phishing attack was a major social engineering incident that began in September 2023 when attackers targeted the company’s IT help desk and used impersonation tactics to gain access to internal systems. Security agencies later said Scattered Spider commonly used this method by convincing help desk staff to reset passwords or multi-factor authentication, which made the MGM case one of the most well-known examples of phishing-style human manipulation leading to a large cyberattack. Once the attackers got in, MGM experienced widespread operational disruption across its hotel and casino systems, affecting reservations, digital room keys, payment systems, and other guest services. MGM later disclosed that the incident caused an estimated $100 million financial hit, showing how a phishing or social-engineering entry point can turn into a major business crisis.
April 2025 - October 2025
ClickFix / fake Booking.com hotel phishing attack
The Booking.com ClickFix phishing campaign was a major attack against hotels and travelers that ran from at least April 2025 to early October 2025. Attackers sent fake Booking.com-style messages to hotel staff, leading them to malicious pages that used the ClickFix technique to trick victims into running harmful commands on their own computers. This allowed malware such as PureRAT to be installed and gave attackers access to hotel accounts. The attackers then used that access to contact customers with fake payment messages and steal financial information. The campaign was especially serious because it targeted both businesses and their guests in the same operation.
August 2016
Dyn / Mirai botnet attack
The Mirai attack was a major DDoS botnet campaign that became active in August 2016 and quickly grew by infecting vulnerable Internet of Things devices such as routers and cameras. Instead of relying on advanced hacking methods, Mirai spread mainly by logging into devices that were still using common default usernames and passwords. Once those devices were infected, they were controlled together as a botnet and used to launch massive denial-of-service attacks against major online targets. At its peak, Cloudflare says Mirai infected over 600,000 IoT devices, showing how insecure smart devices could be turned into a powerful cyberweapon.
What made Mirai especially important was the scale of the attacks it produced. Cloudflare’s retrospective explains that Mirai was used against high-profile targets including Krebs on Security, OVH, and Dyn, and that some of those attacks exceeded 1 Tbps, making them record-breaking at the time. The attack is remembered as a turning point in cybersecurity because it showed that everyday internet-connected devices could be used to disrupt major online services around the world.
August 2023
Google Cloud HTTP/2 Rapid Reset attack
The Google Cloud Rapid Reset attack was a record-breaking HTTP/2 DDoS attack that Google said peaked at 398 million requests per second in August 2023. The attack used a technique called Rapid Reset, which took advantage of HTTP/2 stream multiplexing by sending huge numbers of requests and then canceling them almost immediately. This allowed attackers to create extremely high traffic levels very efficiently and made the attack much larger than previous web-layer DDoS incidents. Google described it as the largest DDoS attack recorded at the time and said the campaign targeted major infrastructure providers, including Google services, Google Cloud infrastructure, and customers.
What made the attack especially important was that it revealed a serious weakness affecting widely used HTTP/2 systems across the internet. Google said the issue was later tracked as CVE-2023-44487, and the company worked with other providers to coordinate mitigations and disclosures. The event became a major example of how attackers could abuse normal internet protocols to launch massive denial-of-service attacks at global scale.
May 2025
Cloudflare 7.3 Tbps hyper-volumetric attack
The 7.3 Tbps DDoS attack was a record-breaking denial-of-service attack that Cloudflare said it blocked in mid-May 2025. The attack targeted a hosting provider using Cloudflare’s Magic Transit service and delivered 37.4 terabytes of data in just 45 seconds, making it the largest DDoS attack Cloudflare had recorded at the time. According to the company’s debrief, the attack was mainly a UDP flood, though it also included smaller reflection and amplification components such as NTP, QOTD, Echo, Portmap, and RIPv1 traffic.
What made the attack especially significant was both its scale and its global reach. Cloudflare reported that it came from more than 122,000 source IP addresses, across 5,433 autonomous systems in 161 countries. The case highlighted how short, extremely intense DDoS attacks can still reach historic size and threaten critical internet infrastructure in a matter of seconds.
May 2017
WannaCry ransomware attack
The WannaCry ransomware attack was a massive global cyberattack that began on May 12, 2017 and quickly spread to more than 200,000 computers in over 150 countries. According to Cloudflare, WannaCry was especially dangerous because it combined ransomware with worm-like behavior, allowing it to move automatically across vulnerable networks instead of infecting only one machine at a time. It targeted older, unpatched versions of Microsoft Windows by exploiting EternalBlue, which made the attack spread at extraordinary speed. Major victims included organizations such as FedEx, Honda, Nissan, and the UK’s National Health Service, where the disruption was severe enough that some ambulances had to be diverted to other hospitals.
What made WannaCry so significant was that it showed how fast ransomware could become a worldwide crisis when paired with a powerful exploit. Cloudflare explains that the outbreak was temporarily stopped within hours after a security researcher discovered a “kill switch,” but many infected systems were still left encrypted and unusable. The attack remains one of the most important ransomware cases in cybersecurity because it demonstrated the danger of unpatched systems and the global impact a self-spreading ransomware worm can cause.
February 2024
Change Healthcare ransomware attack
The Change Healthcare ransomware attack was a major cyberattack detected on February 21, 2024, and it quickly became one of the most disruptive healthcare cybersecurity incidents in U.S. history. Hyperproof explains that Change Healthcare’s central role in processing claims, payments, eligibility checks, and prior authorizations meant the attack did not just affect one company—it created ripple effects across hospitals, pharmacies, insurers, and medical practices nationwide. After the attack, key systems were taken offline, causing widespread delays in claims processing, reimbursements, and patient services.
What made the incident especially significant was its scale and long-term fallout. Hyperproof says the ALPHV/BlackCat ransomware group claimed responsibility, that up to 6 TB of data was stolen, and that the stolen information included highly sensitive personal and healthcare data. The article also notes that the damage continued well beyond the initial outage, with lawsuits, federal scrutiny, major financial losses across the healthcare sector, and later notifications showing that millions of individuals were affected. The attack is remembered as a major ransomware case because it showed how one strike against a core healthcare technology provider could disrupt an entire national system.
April 2025
DaVita ransomware attack
The DaVita ransomware attack was a major healthcare cyberattack that was discovered on April 12, 2025, after attackers gained access to the company’s network, stole sensitive data, and encrypted files on parts of its systems. According to HIPAA Journal, the attack caused temporary operational disruption, but DaVita said patient care continued and its dialysis centers remained open while response measures were put in place. The incident later grew in seriousness as investigators confirmed that protected health information had been compromised, making it one of the largest healthcare breaches reported in 2025.
The report says the breach ultimately affected 2,689,826 individuals and involved information such as demographic details, insurance data, clinical information, and, in some cases, tax-related data. HIPAA Journal also notes that the Interlock ransomware group claimed responsibility and alleged it stole more than 20 terabytes of data. What makes this case especially important is that it shows how a ransomware attack on a major healthcare provider can create both immediate operational problems and a large-scale patient privacy breach at the same time.
2008
Heartland Payment Systems breach
The Heartland Payment Systems attack was a major SQL injection breach tied to Heartland’s network compromise in late 2008. According to the Philadelphia Fed paper, attackers exploited an old vulnerability in code connected to a web form, which gave them access to Heartland’s corporate network and eventually allowed them to move into the separate payment processing environment. After gaining access, the intruders spent months hiding their activity and installed sniffer malware that captured payment card data as it moved through Heartland’s systems. The stolen information included card numbers, expiration dates, and in some cases cardholder names, making the incident one of the most significant payment-data breaches of its time.
What made the Heartland case especially important was that it showed how SQL injection could be used as the starting point for a much larger compromise. The paper explains that the attackers focused on stealing data in transit rather than only targeting stored databases, which represented an important shift in how payment breaches were being carried out. It also notes that Heartland had been considered PCI compliant at the time, which made the incident a powerful example of how meeting compliance standards alone does not always prevent a serious cyberattack.
July 2025
Fortinet FortiWeb SQL injection exploitation
he FortiWeb SQL injection attack was a major 2025 cybersecurity incident involving CVE-2025-25257, a pre-authentication SQL injection flaw in Fortinet’s FortiWeb Fabric Connector. In its analysis, watchTowr explains that the vulnerability existed because attacker-controlled input from a bearer token was inserted directly into a SQL query without proper sanitization. By comparing vulnerable and patched FortiWeb versions, the researchers showed that the issue could be reached through Fabric-related API routes and that Fortinet fixed it by replacing the unsafe query with a prepared statement.
What made the case especially serious was that the bug was not limited to simple database abuse. watchTowr describes how the SQL injection could be chained into remote code execution, making it much more dangerous than a basic data-exposure flaw. The article also notes that the issue affected multiple FortiWeb versions and could be triggered through crafted HTTP or HTTPS requests before authentication, which made it a strong example of SQL injection still being used in real-world attacks against enterprise security products in 2025.
Man in the Middle (MITM)
July 2011 - August 2011
DigiNotar / Iranian Google MITM attack
The DigiNotar attack was a major man-in-the-middle attack uncovered in 2011 after attackers compromised the Dutch certificate authority DigiNotar and issued fraudulent SSL certificates for major websites, including Google. According to EFF, the fake certificates were then used in July and August 2011 to carry out large-scale interception of secure internet traffic, especially against users in Iran. Because browsers trusted DigiNotar’s certificates, victims could be sent to fake but convincing encrypted connections without realizing their communications were being watched. EFF notes that the attack affected more than 300,000 users, making it one of the largest known certificate-based MITM attacks ever.
What made the incident especially serious was that it exposed a deeper weakness in the internet’s certificate authority system. EFF explains that once a single trusted certificate authority is compromised, attackers can create fake certificates for major services and use them to steal passwords, spy on messages, or even alter downloaded files. The DigiNotar case became a landmark cybersecurity event because it showed that breaking trust in one certificate authority could put huge numbers of users at risk and undermine confidence in secure web connections worldwide.
August 2023
Tycoon 2FA AiTM platform
The Tycoon2FA attack was a large-scale adversary-in-the-middle (AiTM) phishing campaign that became active in August 2023 and grew into one of the most widespread phishing-as-a-service operations seen in recent years. Microsoft explains that Tycoon2FA gave criminals ready-made tools to create fake sign-in pages for services such as Microsoft 365, Outlook, SharePoint, OneDrive, and Gmail. Unlike basic phishing kits, Tycoon2FA was designed to intercept usernames, passwords, multifactor authentication codes, and session cookies in real time, allowing attackers to bypass MFA and keep access even after a password reset unless sessions were also revoked.
What made Tycoon2FA especially important was its scale and ease of use. Microsoft says the platform enabled campaigns responsible for tens of millions of phishing messages reaching over 500,000 organizations each month worldwide, affecting sectors such as education, healthcare, finance, government, and nonprofits. The service was sold through apps like Telegram and Signal and included features such as branded phishing templates, attachment generation, redirect chains, CAPTCHA options, and anti-detection measures. The case became a major MITM example because it showed how a commercial phishing platform could let even less-skilled attackers run highly effective MFA-bypassing account compromise campaigns at global scale.
2025
Storm-2657 “Payroll Pirates” AiTM campaign
The Storm-2657 “payroll pirate” attack was a targeted adversary-in-the-middle (AiTM) campaign that affected U.S. universities in the first half of 2025. According to Microsoft, the attackers used realistic phishing emails to steal credentials and MFA codes, then used that access to enter victims’ Exchange Online accounts and later their Workday profiles. After getting in, the attackers created inbox rules to hide warning emails and changed payroll settings so future salary payments would be sent to attacker-controlled bank accounts instead. Microsoft said the group had successfully compromised 11 accounts at three universities and used them to send phishing emails to nearly 6,000 accounts across 25 universities.
What made this campaign especially important was that it showed how a modern MITM-style attack could lead directly to financial theft instead of only account compromise. Microsoft noted that the attackers used tailored university-themed messages, including fake health alerts, misconduct notices, and HR-related communications, to make the phishing emails look believable. The case became a major 2025 MITM example because it demonstrated how AiTM phishing could bypass weak or non-phishing-resistant MFA and then be used to manipulate payroll systems for direct monetary gain.
Cross-Site Scripting (XSS)
October 2005
Samy MySpace worm
The Samy MySpace worm was a famous cross-site scripting (XSS) attack that began on October 4, 2005, when Samy Kamkar used MySpace profile customization features to inject a self-propagating script into his page. According to Vice, the worm automatically added Kamkar as a friend, inserted the phrase “but most of all, Samy is my hero” onto infected profiles, and then copied itself to every visitor’s page, allowing it to spread rapidly across the site. In less than a day, the worm reached more than one million users, forcing MySpace to temporarily shut down parts of the platform to stop it.
What made the attack so important was that it showed how dangerous XSS could be at internet scale. Vice describes it as a turning point for web security because it demonstrated that malicious script injected into a social platform could spread like a worm without needing users to download anything. Although the worm was mostly a prank, security experts quoted in the article said it proved an attacker could potentially take over accounts or do far more damage if the same type of flaw were used maliciously.
December 2021
Zimbra XSS espionage campaigns
The Operation EmailThief campaign was a major cross-site scripting (XSS) attack that Volexity discovered in December 2021 targeting organizations that used Zimbra webmail. According to the report, the attackers ran multiple spear-phishing waves and sent victims malicious links that exploited a zero-day XSS vulnerability in the Zimbra platform while the user was logged into the webmail client. Once triggered, the flaw allowed the attackers to run arbitrary JavaScript inside the victim’s active Zimbra session, which gave them the ability to steal emails, attachments, cookies, and other mailbox data directly from the browser.
What made the campaign especially important was that it showed how XSS could be used for serious espionage rather than just website defacement or nuisance attacks. Volexity said the attackers first used reconnaissance emails to see which users were active, then followed up with themed phishing lures such as interview requests, charity invitations, airline greetings, and Amazon messages. The malicious JavaScript was designed to search inbox and sent folders, collect email contents and attachments, and send that data back to attacker-controlled infrastructure. Volexity also noted that no patch was available at the time of discovery and that the activity likely came from a Chinese-linked threat actor targeting government and media organizations.
October 2025
Zimbra Collaboration zero-day XSS attack
The Zimbra zero-day attack was a major cross-site scripting (XSS) campaign reported on October 6, 2025, after attackers used a stored XSS flaw in Zimbra Collaboration to target the Brazilian military. According to The Hacker News, the vulnerability, tracked as CVE-2025-27915, affected the Classic Web Client and was triggered through malicious ICS calendar files containing unsafe HTML content. When a victim opened the email message with the malicious calendar entry, embedded JavaScript ran inside the user’s active Zimbra session, allowing the attackers to perform unauthorized actions in the account.
What made the attack especially serious was the amount of information the malicious script was designed to steal. The report says the payload could collect credentials, emails, contacts, and shared folders, and it also created malicious Zimbra email filters to forward messages to an attacker-controlled address. To stay hidden, the script removed certain interface elements and only activated if more than three days had passed since its last execution. This case stands out as a strong modern XSS example because it showed how a webmail flaw could be used in a targeted 2025 espionage-style operation rather than just a simple website defacement or nuisance attack.
May 2023 - June 2023
MOVEit Transfer mass exploitation campaign
The MOVEit Transfer attack was a major SQL injection exploitation campaign that began in late May 2023 and affected organizations around the world. According to Unit 42, attackers exploited a critical SQL injection vulnerability, CVE-2023-34362, in the MOVEit Transfer managed file transfer product, and additional SQL injection flaws were later identified as CVE-2023-35036, CVE-2023-35708, and CVE-2023-36934. These vulnerabilities allowed attackers to gain unauthorized access to the MOVEit database and, in the original exploit chain, upload a web shell to compromised servers. Once inside, the attackers could read configuration data, create or delete user accounts, and steal files from victim systems.
What made the incident especially significant was its scale and the way one vulnerable product led to widespread data theft across many organizations. Unit 42 reported evidence of exploitation as early as May 27, 2023, noted thousands of internet-exposed MOVEit servers, and said the activity was consistent with broader reporting that linked the campaign to the Cl0p ransomware group. The case became one of the most important recent SQL injection attacks because it showed how a single web application weakness could be used to compromise many victims in a large, coordinated campaign.
SQL Injection
Ransomware
DDoS
Phishing
Leave comments on how this attack events page helped you learn about certain topics. Leave criticisms on the information and ways to make it better.