indications & warnings
9 actors moved in the last 365 days- KP · DPRKLazarus Group1 eventlast Apr 17
Lazarus / TraderTraitor steals $577M from Drift + KelpDAO inside three weeks
watch yourfinancialcryptocurrencydefensemedia+1 - ?? · UnknownShinyHunters2 eventslast Apr 15
ShinyHunters extorts McGraw Hill via Salesforce misconfiguration
watch yourtechnologyfinancialeducationretail+1 - ?? · UnknownQilin1 eventlast Mar 31
Qilin emerges as the most-active healthcare ransomware brand of Q1 2026
watch yourhealthcaremanufacturingeducationprofessional services - IR · IranHandala1 eventlast Mar 10
Handala wipes 200,000+ Stryker devices via Microsoft Intune abuse
watch yourdefensetechnologyhealthcaregovernment+2 - RU · RussiaOperation Zero1 eventlast Feb 23
OFAC sanctions Operation Zero and Sergey Zelenyuk for exploit-broker activity
watch yourtechnologyresearch - ?? · UnknownALPHV/BlackCat1 eventlast Nov 18
Two U.S. cybersecurity workers plead guilty to ALPHV BlackCat affiliate scheme
watch yourhealthcarefinancialprofessional servicesmanufacturing+1 - ?? · UnknownAkira1 eventlast Nov 12
Updated joint advisory: Akira tied to ~$244M in proceeds, now hitting Nutanix AHV
watch yourmanufacturingprofessional serviceseducationhealthcare - CN · ChinaGTG-10021 eventlast Nov 12
Anthropic discloses GTG-1002 — first AI-orchestrated cyber espionage
watch yourtechnologyfinancialchemicalgovernment - ?? · UnknownCl0p1 eventlast Sep 28
Cl0p mass-exfiltrates Oracle E-Business Suite via CVE-2025-61882 zero-day
watch yourfinancialhealthcareeducationgovernment+1
Pure aggregation over the cited timeline — sectors are the actor's publicly attributed targeting profile, not a prediction. Hover an actor to open their page for the full cited record.
Defending an LLM application against real attacks
For AI startups and teams training their own models. Each category maps an attack class (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF) to example prompts, documented incidents, and concrete defenses grouped by lifecycle phase.
chronological activity
showing 25 of 153 events- CompromiseLazarus / TraderTraitor steals $577M from Drift + KelpDAO inside three weeksLazarus Group · TRM Labs
- CompromiseShinyHunters extorts McGraw Hill via Salesforce misconfigurationShinyHunters · The Register
- ReportQilin emerges as the most-active healthcare ransomware brand of Q1 2026Qilin · Comparitech / Paubox aggregated tracking
- CompromiseHandala wipes 200,000+ Stryker devices via Microsoft Intune abuseHandala · Krebs on Security
- SanctionOFAC sanctions Operation Zero and Sergey Zelenyuk for exploit-broker activityOperation Zero · U.S. Department of the Treasury
- IndictmentTwo U.S. cybersecurity workers plead guilty to ALPHV BlackCat affiliate schemeALPHV/BlackCat · U.S. Department of Justice
- ReportAnthropic discloses GTG-1002 — first AI-orchestrated cyber espionageGTG-1002 · Anthropic
- AdvisoryUpdated joint advisory: Akira tied to ~$244M in proceeds, now hitting Nutanix AHVAkira · CISA
- AnnouncementShinyHunters launches 'Trinity of Chaos' Salesforce leak site, 39 victims listedShinyHunters · BleepingComputer
- CompromiseCl0p mass-exfiltrates Oracle E-Business Suite via CVE-2025-61882 zero-dayCl0p · Google Cloud / Mandiant
- Advisory13-nation joint advisory AA25-239A on PRC global telecom espionageSalt Typhoon · CISA
- CompromiseRomCom exploits WinRAR zero-day in spear-phishing against EU + CanadaRomCom · ESET Research
- IndictmentEurojust and Europol announce Operation Eastwood takedown of NoName057(16)NoName057(16) · Eurojust
- CompromiseScattered Spider summer-2025 airline-sector wave: WestJet, Hawaiian, QantasScattered Spider · FBI Internet Crime Complaint Center (IC3)
- CompromisePredatory Sparrow attacks Bank Sepah and Nobitex crypto exchangePredatory Sparrow · TechCrunch
- ReportCISA documents Play ESXi variant and per-victim recompilationPlay · CISA
- ReportGoogle GTIG disrupts APT41 TOUGHPROGRESS Google-Calendar-C2 campaignAPT41 · Google Cloud / Mandiant
- AnnouncementCzech Republic publicly attributes multi-year MFA intrusion to APT31APT31 · NUKIB (National Cyber and Information Security Agency, Czech Republic)
- CompromiseScattered Spider compromises Marks & Spencer, Co-op, HarrodsScattered Spider · UK National Crime Agency / National Cyber Security Centre
- CompromiseShuckworm targets foreign military mission in Ukraine with updated GammaSteelGamaredon · Symantec (Broadcom)
- CompromiseLazarus / TraderTraitor executes $1.5B Bybit heist — largest crypto theft in historyLazarus Group · U.S. Federal Bureau of Investigation
- ReportMicrosoft details Seashell Blizzard 'BadPilot' subgroup multi-year access opsSandworm · Microsoft Threat Intelligence
- ReportBlack Basta internal chat logs leaked (BlackBastaGPT dataset)Black Basta · Hudson Rock / open-source
- SanctionOperation Phobos Aetor takes down 8Base; Russian operators arrested in Phuket8Base · Europol
- AnnouncementFBI attributes $308M DMM Bitcoin theft to DPRK TraderTraitorLazarus Group · U.S. Federal Bureau of Investigation