CrowdStrike
A faulty Falcon content update caused Windows crashes across millions of hosts and disrupted critical services worldwide.
Incident catalog
Search by company or ticker. Filter by incident type, year, recovery or available data. Your choices stay in the URL, so you can share the same view.
A faulty Falcon content update caused Windows crashes across millions of hosts and disrupted critical services worldwide.
AT&T disclosed that threat actors illegally downloaded call and text interaction records covering nearly all wireless customers for specified periods.
The Change Healthcare ransomware attack disrupted US claims, pharmacy and payment infrastructure on a national scale.
Microsoft disclosed that Midnight Blizzard accessed and exfiltrated email from a small percentage of corporate accounts, including senior leadership.
Caesars disclosed a social-engineering attack through an outsourced IT support vendor that led to theft of loyalty-program customer data.
MGM disclosed a cybersecurity issue that forced system shutdowns and disrupted hotel and casino operations across multiple US properties.
Clorox disclosed unauthorized activity that forced systems offline and later caused widescale operational, order-processing and product-availability disruption.
Progress disclosed a zero-day vulnerability in MOVEit Transfer that was exploited across many customer environments in a mass data-theft campaign.
Uber disclosed a compromise of internal systems after an attacker used a contractor's credentials and gained access to several employee tools.
Twilio disclosed that a social-engineering campaign stole employee credentials and enabled access to data associated with customer accounts.
Okta confirmed that an attacker had accessed a third-party support engineer's laptop and could interact with limited customer-support data.
T-Mobile confirmed unauthorized access to its data and later identified tens of millions of current, former and prospective customers in stolen files.
A latent Fastly software bug triggered by a valid customer configuration caused a broad global outage across its edge network.
A ransomware attack encrypted Garmin systems and interrupted online services, customer support, applications and company communications.
Cognizant disclosed a Maze ransomware attack on internal systems that caused service disruption for some clients.
Capital One disclosed unauthorized access affecting about 100 million people in the United States and 6 million in Canada.
Marriott disclosed long-running unauthorized access to the legacy Starwood reservation database, affecting hundreds of millions of guest records.
Reporting and Facebook's response exposed large-scale misuse of platform-derived user data by Cambridge Analytica and related parties.
Equifax disclosed unauthorized access involving sensitive identity information for roughly 143 million US consumers at the initial announcement.
NotPetya significantly disrupted FedEx subsidiary TNT Express worldwide, affecting communications, operations, revenue and restoration work.
NotPetya disrupted Merck's worldwide manufacturing, research and sales operations and produced hundreds of millions of dollars in recorded effects.
The NotPetya malware incident affected a significant portion of Mondelez's global sales, distribution and financial networks.
Anthem disclosed a sophisticated external attack that obtained personal information associated with tens of millions of people.
A destructive attack on Sony Pictures disabled systems, exposed sensitive business and employee data, and disrupted studio operations.
JPMorgan Chase disclosed that a cyberattack compromised contact information associated with 76 million households and 7 million businesses.
Home Depot confirmed a breach of payment systems at US and Canadian stores, later reporting exposure involving up to 56 million cards.
eBay disclosed that compromised employee credentials enabled access to a customer database and asked all users to reset passwords.
Target confirmed unauthorized access to payment-card data from US stores during the peak holiday shopping period.
Adobe disclosed unauthorized access to customer information and source code for multiple products, followed by a broad password reset.
TJX disclosed an intrusion into systems processing customer transactions after investigators found that payment-card data had been stolen.
Change or reset the filters. The catalog is curated, so a missing company does not mean it never had an incident.