🌐 hackmanac.com
🌐 hackrisk.io
🧠 𝗘𝘅𝗽𝗹𝗼𝗿𝗲:
hackrisk.io
Free access to dashboards, timely alerts, attack trends, threat actor insights, affected regions, and severity metrics powered by our proprietary ESIX© (Estimated Severity Index).
1/5
Zapier’s NPM Account Hacked, Multiple Packages Infected with Malware
A compromised Zapier NPM account triggered a large supply chain attack that planted the Shai Hulud malware into 425 packages with about 132 million monthly downloads.
Zapier’s NPM Account Hacked, Multiple Packages Infected with Malware
A compromised Zapier NPM account triggered a large supply chain attack that planted the Shai Hulud malware into 425 packages with about 132 million monthly downloads.
👉 Here are our insights of the week based on our proprietary ESIX© (Estimated Severity Index). We use this metric to measure the operational, financial (direct and indirect), technical, and reputational impact of cyber attacks.
1/6
👉 Here are our insights of the week based on our proprietary ESIX© (Estimated Severity Index). We use this metric to measure the operational, financial (direct and indirect), technical, and reputational impact of cyber attacks.
1/6
🇯🇵Japan - Japan Inspection Association (Shin Nihon Kentei Kyokai)
On November 26, 2025, the Japan Inspection Association (Shin Nihon Kentei Kyokai) experienced a system disruption caused by a cyberattack targeting its servers.
🇯🇵Japan - Japan Inspection Association (Shin Nihon Kentei Kyokai)
On November 26, 2025, the Japan Inspection Association (Shin Nihon Kentei Kyokai) experienced a system disruption caused by a cyberattack targeting its servers.
🇮🇩Indonesia - Bank Mandiri
BreachLaboratory threat actor claims to have breached Bank Mandiri.
Allegedly, the attackers leaked more than 18,000 financial records, including personal details, SWIFT code BMRIIDJA, account setup data, balances, fees, and debit card usage information.
🇮🇩Indonesia - Bank Mandiri
BreachLaboratory threat actor claims to have breached Bank Mandiri.
Allegedly, the attackers leaked more than 18,000 financial records, including personal details, SWIFT code BMRIIDJA, account setup data, balances, fees, and debit card usage information.
iOS 26 Zero-Click Exploit Claimed for Sale on Dark Web
A threat actor called ResearcherX claimed to be selling a full-chain zero-click exploit for iOS 26 on the dark web, allegedly allowing root access and bypassing new protections.
iOS 26 Zero-Click Exploit Claimed for Sale on Dark Web
A threat actor called ResearcherX claimed to be selling a full-chain zero-click exploit for iOS 26 on the dark web, allegedly allowing root access and bypassing new protections.
🇬🇧UK - Hitech Grand Prix Limited
Akira hacking group claims to have breached Hitech Grand Prix Limited.
Akira hacking group claimed responsibility for a cyberattack against Hitech, a UK-based single-seater racing team competing in FIA Formula 2, Formula 3, GB3, and Formula 4.
🇬🇧UK - Hitech Grand Prix Limited
Akira hacking group claims to have breached Hitech Grand Prix Limited.
Akira hacking group claimed responsibility for a cyberattack against Hitech, a UK-based single-seater racing team competing in FIA Formula 2, Formula 3, GB3, and Formula 4.
🇯🇵Japan - YAC GARTER CO., LTD. (subsidiary of Y.A.C. Holdings Co., Ltd.)
On November 25, 2025, YAC GARTER CO., LTD., a consolidated subsidiary of Y.A.C. Holdings Co., Ltd., detected a ransomware attack that caused internal system failures.
🇯🇵Japan - YAC GARTER CO., LTD. (subsidiary of Y.A.C. Holdings Co., Ltd.)
On November 25, 2025, YAC GARTER CO., LTD., a consolidated subsidiary of Y.A.C. Holdings Co., Ltd., detected a ransomware attack that caused internal system failures.
🇰🇷South Korea - Upbit
Upbit Halts Operations After Suspicious ₩44.5B (~$33M) Outflow
Upbit detected abnormal withdrawals from its Solana hot wallet, with about ₩44.5 billion KRW in assets sent to unknown wallets.
🇰🇷South Korea - Upbit
Upbit Halts Operations After Suspicious ₩44.5B (~$33M) Outflow
Upbit detected abnormal withdrawals from its Solana hot wallet, with about ₩44.5 billion KRW in assets sent to unknown wallets.
🇺🇸USA - OpenAI (via Mixpanel service)
OpenAI disclosed that Mixpanel, a third-party analytics provider used to track API frontend usage, suffered unauthorized access on November 9.
🇺🇸USA - OpenAI (via Mixpanel service)
OpenAI disclosed that Mixpanel, a third-party analytics provider used to track API frontend usage, suffered unauthorized access on November 9.
🇨🇴Colombia - Rama Judicial de Colombia
Kill Security claims to have breached the Rama Judicial de Colombia and leaked court documents containing sensitive personal, legal, and financial information.
🇨🇴Colombia - Rama Judicial de Colombia
Kill Security claims to have breached the Rama Judicial de Colombia and leaked court documents containing sensitive personal, legal, and financial information.
🇸🇦Saudi Arabia - Meena Health
Kill Security hacking group claims to have breached Meena Health.
🇸🇦Saudi Arabia - Meena Health
Kill Security hacking group claims to have breached Meena Health.
🇪🇸Spain - Iberia
Everest hacking group is now demanding $6,000,000 from Iberia to prevent the data from being leaked.
Sector: Transportation / Storage
Threat class: Cybercrime
Status: Pending verification
🇪🇸Spain - Iberia
Everest hacking group is now demanding $6,000,000 from Iberia to prevent the data from being leaked.
Sector: Transportation / Storage
Threat class: Cybercrime
Status: Pending verification
80,000+ Files Leaked via Code Tools Expose 5GB of Credentials from Critical Infrastructure, Government, Finance, and More
Sensitive credentials and personal data have been leaking for years through online code formatting tools JSONFormatter and CodeBeautify.
80,000+ Files Leaked via Code Tools Expose 5GB of Credentials from Critical Infrastructure, Government, Finance, and More
Sensitive credentials and personal data have been leaking for years through online code formatting tools JSONFormatter and CodeBeautify.
🇪🇸Spain - Iberia
Everest claims to have breached Iberia and stolen 596 GB of data, including 430 GB of .eml files with more than 5 million records.
🇪🇸Spain - Iberia
Everest claims to have breached Iberia and stolen 596 GB of data, including 430 GB of .eml files with more than 5 million records.
Hack Tuesday: Week 19 - 25 November 2025
⚠️317 cyber attacks across 43 countries ⚠️
More details:
hackmanac.com/news/hack-tu...
Hack Tuesday: Week 19 - 25 November 2025
⚠️317 cyber attacks across 43 countries ⚠️
More details:
hackmanac.com/news/hack-tu...
🇪🇸Spain - Marlex
Rhysida hacking group claims to have breached Marlex.
Ransom demand: 15 BTC (approx. $1,300,000)
Sector: Other Services
Threat class: Cybercrime
Observed: Nov 25, 2025
Status: Pending verification
🇪🇸Spain - Marlex
Rhysida hacking group claims to have breached Marlex.
Ransom demand: 15 BTC (approx. $1,300,000)
Sector: Other Services
Threat class: Cybercrime
Observed: Nov 25, 2025
Status: Pending verification
🇪🇸Spain - Fundación de la Universidad Autónoma de Madrid (FUAM)
The Fundación de la Universidad Autónoma de Madrid (FUAM) has disclosed a cyberattack that may have exposed user data.
🇪🇸Spain - Fundación de la Universidad Autónoma de Madrid (FUAM)
The Fundación de la Universidad Autónoma de Madrid (FUAM) has disclosed a cyberattack that may have exposed user data.
🇨🇦🇸🇪- NovAtel (Hexagon)
Qilin hacking group claims to have breached NovAtel.
Allegedly, the attackers exfiltrated 35 TB of data.
Sector: Manufacturing
Threat class: Cybercrime
Observed: Nov 24, 2025
Status: Pending verification
🇨🇦🇸🇪- NovAtel (Hexagon)
Qilin hacking group claims to have breached NovAtel.
Allegedly, the attackers exfiltrated 35 TB of data.
Sector: Manufacturing
Threat class: Cybercrime
Observed: Nov 24, 2025
Status: Pending verification
🇪🇸Spain - Travel Club (Air Miles España, S.A.)
Everest hacking group claims to have breached Travel Club (Air Miles España, S.A.).
🇪🇸Spain - Travel Club (Air Miles España, S.A.)
Everest hacking group claims to have breached Travel Club (Air Miles España, S.A.).
🇧🇷Brazil - Universidade Municipal de São Caetano do Sul (USCS)
Medusa hacking group claims to have breached Universidade Municipal de São Caetano do Sul (USCS).
The attackers demanded a $250,000 ransom.
🇧🇷Brazil - Universidade Municipal de São Caetano do Sul (USCS)
Medusa hacking group claims to have breached Universidade Municipal de São Caetano do Sul (USCS).
The attackers demanded a $250,000 ransom.
🇯🇵Japan - LINE hijacking scams in Japan now trick users and cause losses up to ¥100,000
Status: Confirmed
Source: www.fnn.jp/articles/-/9...
🇯🇵Japan - LINE hijacking scams in Japan now trick users and cause losses up to ¥100,000
Status: Confirmed
Source: www.fnn.jp/articles/-/9...
🇷🇴Romania - National Institute of Materials Physics (NIMP)
Nova hacking group claims to have breached National Institute of Materials Physics (NIMP).
Allegedly, the attackers exfiltrated 700 GB of data.
🇷🇴Romania - National Institute of Materials Physics (NIMP)
Nova hacking group claims to have breached National Institute of Materials Physics (NIMP).
Allegedly, the attackers exfiltrated 700 GB of data.
Source: thehackernews.com/2025/11/shad...
Source: thehackernews.com/2025/11/shad...
Source: thehackernews.com/2025/11/matr...
Source: thehackernews.com/2025/11/matr...
🇺🇸USA - JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack
SitusAMC suffered a cyberattack on November 12, 2025, exposing accounting documents and legal contracts tied to major clients, including JPMorgan Chase, Citi, and Morgan Stanley.
🇺🇸USA - JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack
SitusAMC suffered a cyberattack on November 12, 2025, exposing accounting documents and legal contracts tied to major clients, including JPMorgan Chase, Citi, and Morgan Stanley.