Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
operational-disruptionransomware-group-operationcritical-infrastructure-threathacktivist-operation

High-Profile Cyber Incidents Expose Weak Security and Disrupt Critical Services

Updated 28d agoFirst seen May 25, 202614 sources

A series of high-profile cyber incidents disrupted major online platforms, exposed weak security practices, and highlighted the broad impact of both criminal and activist hacking. A global ransomware outbreak later identified as WannaCry spread rapidly across organizations before a security researcher slowed it by registering a domain used as a kill switch, while a separate attack briefly knocked major websites offline through distributed denial-of-service activity. In another major case, hackers compromised prominent US Twitter accounts and used them to promote a Bitcoin scam, demonstrating how access to trusted platforms can be weaponized at scale.

Other incidents underscored persistent failures in account security and access control. Equifax faced scrutiny after an Argentine employee portal was reportedly protected with the username and password admin, adding to concerns around the company’s security posture. Apple said some user accounts had been compromised while denying a broader breach of its systems, and the celebrity photo leak known as “the fappening” showed how attackers could exploit personal account weaknesses. Separately, US authorities linked Julian Assange to alleged conspiracy with Anonymous-affiliated hackers, activist campaigns targeted recording industry websites, and the Colonial Pipeline ransomware case showed how an intrusion into a critical fuel operator could trigger widespread operational disruption even when attackers later claimed they had not intended such consequences.

Share:
High-Profile Cyber Incidents Expose Weak Security and Disrupt Critical Services
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
May 10, 20215y ago

Colonial Pipeline hackers say disruption was unintended

The group behind the US fuel pipeline attack said it had not intended to create widespread societal problems, following the ransomware incident that disrupted fuel distribution.

Jul 15, 20206y ago

High-profile Twitter accounts hijacked in Bitcoin scam

Attackers compromised major US Twitter accounts and used them to promote a Bitcoin fraud scheme, affecting prominent politicians, executives, and companies.

Jun 25, 20206y ago

US indictment links Julian Assange to Anonymous-related hacking conspiracy

US prosecutors accused Julian Assange of conspiring with hackers associated with Anonymous and LulzSec, expanding the public allegations around WikiLeaks-related hacking activity.

May 27, 20197y ago

Baltimore hit by ransomware attack prompting NSA scrutiny

Baltimore suffered a ransomware attack that disrupted multiple city government systems and sparked renewed questions about the NSA's role in the spread of EternalBlue-linked cyber risks. The incident became a major example of ransomware affecting municipal services in the United States.

Baltimore ransomware attack: NSA faces questions
Sep 13, 20179y ago

Equifax Argentina exposed portal with weak admin credentials

An Equifax employee portal in Argentina was found accessible using 'admin' as both the username and password, deepening scrutiny of the company's security practices after its broader breach crisis.

May 23, 20179y ago

Evidence emerges linking WannaCry to North Korean hackers

Researchers reported stronger evidence connecting the WannaCry ransomware campaign to North Korean-linked hackers, advancing public attribution of the global outbreak beyond its initial spread and technical containment. The reporting highlighted code similarities and other indicators tying WannaCry to the Lazarus Group.

More evidence for WannaCry 'link' to North Korean hackers - BBC News
May 13, 20179y ago

Security researcher triggers WannaCry kill switch

A security blogger accidentally slowed the WannaCry outbreak after registering a domain name embedded in the malware, activating a kill switch in the ransomware's code.

May 12, 20179y ago

WannaCry ransomware outbreak spreads globally

A global ransomware attack hit organizations worldwide, disrupting hospitals, businesses, and government systems in one of the largest cyber incidents of 2017.

Oct 21, 201610y ago

Major websites disrupted by large-scale DDoS attacks

A wave of cyber attacks briefly knocked prominent websites offline, reflecting a significant distributed denial-of-service incident affecting major internet services.

Mar 16, 201610y ago

Man behind celebrity photo leak case is identified

Reporting on the celebrity nude photo leak identified the individual behind the intrusion campaign that became known as 'the fappening,' adding detail to the earlier account-compromise case.

Sep 2, 201412y ago

Apple confirms celebrity account compromises after photo leak

Apple said some iCloud and account holders had been compromised following the leak of celebrity nude photos, while denying that its core systems had suffered a broader security breach.

Dec 29, 201015y ago

Anonymous activists hit by retaliatory web attack

A counterattack took websites used by Anonymous activists offline, marking a reversal in the Operation Payback conflict as hacktivists themselves became targets. The disruption was reported as affecting the online infrastructure associated with the group.

Web attack takes Anonymous activists offline - BBC News
Sep 20, 201016y ago

Operation Payback targets recording industry websites

Online activists launched attacks against music industry websites as part of Operation Payback, marking an early wave of coordinated hacktivist disruption tied to anti-piracy disputes.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.