or analyse a relationship
4673 incidents · 545 responses 0 threat actors
Years
Records
Analyse
5218 records 4673 incidents · 545 responses
"Kurdish sr" United States ·Defence & military Hacker "Kurdish sr" Defaced US Army Subdomains on 6 July 2026 6 Jul 2026
Incident 6 Jul 2026
"Kurdish sr" United States ·Defence & military
Hacker "Kurdish sr" Defaced US Army Subdomains on 6 July 2026
The Gentlemen Ransomware Group Portugal ·Transport Ransomware Group "The Gentlemen" Breached Metro Mondego in Portugal on 6 July 2026 6 Jul 2026
Incident 6 Jul 2026
The Gentlemen Ransomware Group Portugal ·Transport
Ransomware Group "The Gentlemen" Breached Metro Mondego in Portugal on 6 July 2026
Unknown France ·Government & politics Unknown Threat Actors Launched A Ransomware Attack On City Of Drancy In France On 3 July 2026 3 Jul 2026
Incident 3 Jul 2026
Unknown France ·Government & politics
Unknown Threat Actors Launched A Ransomware Attack On City Of Drancy In France On 3 July 2026
Unknown Spain ·Government & politics Unattributed Hackers Deployed Ransomware Against University of Alicante In Spain On 02 July 2026 2 Jul 2026
Incident 2 Jul 2026
Unknown Spain ·Government & politics
Unattributed Hackers Deployed Ransomware Against University of Alicante In Spain On 02 July 2026
cenfecracked Mexico ·Government & politics Threat Actor Cenfecracked Breached Municipality of León in Mexico in July 2026 1 Jul 2026
Incident 1 Jul 2026
cenfecracked Mexico ·Government & politics
Threat Actor Cenfecracked Breached Municipality of León in Mexico in July 2026
Unknown Germany ·Energy & utilities Unidentified Perpetrators Carried Out DDoS Attacks On Internet Pages Of Leipzig Group In Germany In July 2026 1 Jul 2026
Incident 1 Jul 2026
Unknown Germany ·Energy & utilities
Unidentified Perpetrators Carried Out DDoS Attacks On Internet Pages Of Leipzig Group In Germany In July 2026
Showing 25–30 of 5218 Prev Page 5 / 870 Next
How to read the ledger Every row is an incident or a response. Shape tells them apart; colour and the marks below each sigil carry the rest.
Row type
Incident — a square sigil. The connected dots below carry attribution.
Response — a round sigil. The two squares below show its anchors.
Incident types
Data theft
Disruption
Hijacking
Ransomware & extortion
Response types
Official policy
Unofficial policy
Criminal proceedings
Technical disclosure
Operational action
Reading the marks
Attribution dots (incidents) — how firmly an initiator is named; both filled and joined navy when fully attributed.
none one both
Weight squares (responses) — anchors present: left = a linked incident, right = a named actor.
0 1 2
Issuer stack — one chip is a single issuer; a stack of ISO codes marks a joint or coordinated response.
EUsingle DEFRNL+5several states

An independent, interdisciplinary research consortium providing evidence-based analysis of cyber incidents and the political and legal responses to them.

A consortium of

Heidelberg University · Stiftung Wissenschaft und Politik (SWP)

© 2026 European Repository of Cyber Incidents Evidence-based analysis of cyber incidents & responses
Search