or analyse a relationship
4673 incidents · 545 responses 0 threat actors
Years
Records
Analyse
5218 records 4673 incidents · 545 responses
GrayBravo #N/A ·Finance Threat Actor GrayBravo (aka TAG-150) Installed Malware DinDoor And NightshadeC2 On Systems Of Finance Organization In June 2026 1 Jun 2026
Incident 1 Jun 2026
GrayBravo #N/A ·Finance
Threat Actor GrayBravo (aka TAG-150) Installed Malware DinDoor And NightshadeC2 On Systems Of Finance Organization In June 2026
Unknown Spain ·Government & politics Unknown Threat Actor Compromised Low Emission Zone Application of Municipality Ciudad Real in Spain in June 2026 1 Jun 2026
Incident 1 Jun 2026
Unknown Spain ·Government & politics
Unknown Threat Actor Compromised Low Emission Zone Application of Municipality Ciudad Real in Spain in June 2026
CZJP2 statescoordinated Czech Republic and Japan Held Bilateral Talks on Cybersecurity Cooperation on 1 June 2026 Official policy 1 Jun 2026
Official policy 1 Jun 2026
CZJP2 states
Czech Republic and Japan Held Bilateral Talks on Cybersecurity Cooperation on 1 June 2026
Handala (MOIS) Israel ·Other Iranian State-Sponsored Hacking Group Handala Breached Holocaust Victim Support Centre in Israel on 31 May 2026 31 May 2026
Incident · Low severity 31 May 2026
Handala (MOIS) Israel ·Other
Iranian State-Sponsored Hacking Group Handala Breached Holocaust Victim Support Centre in Israel on 31 May 2026
World Leaks India ·Energy & utilities Ransomware Group World Leaks Breached Largest Nuclear Power Plant in India on 29 May 2026 29 May 2026
Incident 29 May 2026
World Leaks India ·Energy & utilities
Ransomware Group World Leaks Breached Largest Nuclear Power Plant in India on 29 May 2026
NLNetherlands’ National Cyber Security Centre Netherlands National Cyber Security Centre and Police Conducted a Joint Operation to Take Down Large Bot Network on 28 May 2026 Operational action 28 May 2026
Operational action 28 May 2026
NLNetherlands’ National Cyber Security Centre
Netherlands National Cyber Security Centre and Police Conducted a Joint Operation to Take Down Large Bot Network on 28 May 2026
Showing 115–120 of 5218 Prev Page 20 / 870 Next
How to read the ledger Every row is an incident or a response. Shape tells them apart; colour and the marks below each sigil carry the rest.
Row type
Incident — a square sigil. The connected dots below carry attribution.
Response — a round sigil. The two squares below show its anchors.
Incident types
Data theft
Disruption
Hijacking
Ransomware & extortion
Response types
Official policy
Unofficial policy
Criminal proceedings
Technical disclosure
Operational action
Reading the marks
Attribution dots (incidents) — how firmly an initiator is named; both filled and joined navy when fully attributed.
none one both
Weight squares (responses) — anchors present: left = a linked incident, right = a named actor.
0 1 2
Issuer stack — one chip is a single issuer; a stack of ISO codes marks a joint or coordinated response.
EUsingle DEFRNL+5several states

An independent, interdisciplinary research consortium providing evidence-based analysis of cyber incidents and the political and legal responses to them.

A consortium of

Heidelberg University · Stiftung Wissenschaft und Politik (SWP)

© 2026 European Repository of Cyber Incidents Evidence-based analysis of cyber incidents & responses
Search