Skip to content
COOEY

◄ GEO INTEL

THREAT FEEDS

LIVE

External threat-intelligence feeds — global attack origins, active command-and-control infrastructure, and fresh breach disclosures. Read live from the estate intel pipeline.

ATTACK ORIGINS · L7 cf radar · app-layer
01United States 22.3%
02Singapore 6.9%
03China 6.3%
04Germany 4.4%
05Indonesia 4.3%
06Malaysia 3.8%
07Canada 3.8%
08France 3.2%
09Netherlands 3.1%
10Brazil 3.0%
layer-7 (application) attack-traffic share
ATTACK ORIGINS · L3 cf radar · network-layer
01Brazil 14.2%
02United States 10.5%
03Chile 6.5%
04Argentina 5.8%
05Russian Federation 5.4%
06Ukraine 5.2%
07Bangladesh 3.7%
08Poland 3.6%
09Colombia 3.4%
10India 3.3%
layer-3/4 (network) attack-traffic share
C2 · BY COUNTRY
US1
active Feodo/botnet command-and-control servers, by hosting country
FEODO C2 TRACKER
1 online · 1 tracked
ACTIVE COMMAND-AND-CONTROL SERVERS
IPPORTSTATUSASCCLAST ONLINE
50.16.16.211 443 ONLINE AMAZON-AES US 2026-03-12
RECENT BREACH DISCLOSURES
early-warning side channel
Alcon
alcon.com
218K
breached 2026-08-01 · 218,395 accounts
In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly sourced from Alcon...
Brinks Home
brinkshome.com
732K
breached 2026-07-13 · 732,162 accounts
In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from the company,...
Exact Sciences
exactsciences.com
10M
breached 2026-07-15 · 10,869,543 accounts
In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign. The group claimed to have obtained data from...
Fanlore
fanlore.org
144K
breached 2026-08-06 · 144,520 accounts
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k...
Golf Canada
golfcanada.ca
568K
breached 2026-05-14 · 568,972 accounts
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with...
Houston City College
hccs.edu
831K
breached 2026-06-16 · 831,642 accounts
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and...
Inter-Con Security
icsecurity.com
276K
breached 2026-06-18 · 276,114 accounts
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company,...
NIUS
nius.de
6K
breached 2025-07-13 · 6,090 accounts
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical...
Oz Hair and Beauty
ozhairandbeauty.com
1M
breached 2026-08-15 · 1,988,331 accounts
In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the...
RingCentral
ringcentral.com
1M
breached 2026-07-27 · 1,596,490 accounts
In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published...
SplitVPN
splitvpn.io
865K
breached 2026-07-21 · 865,336 accounts
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique...