An attacker used a compromised government VPN account to query Argentina's RENAPER national ID database for all 45 million Argentines. Photos and ID details for the president, soccer star Lionel Messi, and other public figures were posted to Twitter as proof. The data went on sale on a dark-web forum.
- Victim
- Registro Nacional de las Personas (RENAPER), Argentina
- Records
- 45.0M
DeepBlueMagic ransomware โ attributed by Israeli officials to a Chinese criminal group โ hit Hillel Yaffe Medical Center in Hadera, becoming the first known successful ransomware attack on an Israeli healthcare entity. Recovery extended for months. Israeli authorities subsequently reported a wave of follow-on attempts against nine more hospitals.
- Victim
- Hillel Yaffe Medical Center
A 21-year-old American living in Turkey, John Binns, claimed to have hacked T-Mobile via an exposed GGSN router and exfiltrated personal data on 76.6 million current, former, and prospective customers.
- Victim
- T-Mobile US
- Loss
- $500.0M
- Records
- 76.6M
A ransomware attack on South Africa's state-owned logistics firm Transnet shut down operations at Durban, Ngqura, Port Elizabeth and Cape Town container terminals, forcing the operator to declare force majeure. Durban โ 60% of Southern Africa's containerised trade โ reverted to paper-based clearance for cargo for a week.
- Victim
- Transnet SOC (state-owned freight & port operator)
REvil affiliates exploited a SQL injection zero-day in Kaseya's VSA remote-management platform to push ransomware to ~60 MSPs and through them to ~1,500 downstream organisations. The largest supply-chain ransomware attack on record.
- Victim
- Kaseya VSA customers (~60 MSPs, ~1,500 downstream organisations)
- Loss
- $200.0M
REvil affiliates encrypted the world's largest meat processor, shutting down beef and pork plants across the U.S., Canada, and Australia. JBS paid an $11 million ransom โ one of the largest publicly-confirmed ransomware payments at the time.
- Victim
- JBS S.A. / JBS USA
- Loss
- $100.0M
Conti ransomware paralysed Ireland's Health Service Executive, forcing cancellation of outpatient appointments nationwide for weeks. Conti released the decryptor for free; recovery still cost an estimated โฌ100M+.
- Victim
- Health Service Executive (HSE) of Ireland
- Loss
- $130.0M
- Records
- 700.0K
Conti operators tricked an HSE user into downloading a booby-trapped Excel attachment; the resulting ransomware forced the Health Service Executive to shut down all of Ireland's healthcare IT systems and exfiltrated 700 GB including COVID-19 vaccination PHI. Recovery cost exceeded โฌ100 million.
- Victim
- Health Service Executive (HSE) of Ireland
- Loss
- $110.0M
A reused VPN password let DarkSide encrypt Colonial Pipeline's billing systems. The operator shut down 5,500 miles of fuel pipeline for six days, paid $4.4M, and triggered a federal emergency.
- Victim
- Colonial Pipeline Company
- Loss
- $4.4M
HelloKitty ransomware encrypted CD Projekt Red devices and exfiltrated source code for Cyberpunk 2077, The Witcher 3, Gwent, and an unreleased version of The Witcher 3. CDPR refused to pay; the data was auctioned and reportedly sold to a private buyer.
- Victim
- CD Projekt Red