Incidents are not CVEsOriginal sources on every recordUnknown details stay unknown
Beyond the vulnerability catalogue Public beta

When cyber incidents become public.

Track what organisations actually disclosed, when they disclosed it, and what remains unconfirmed. Each record leads back to its original source.

2 source-verified records in this pilot1 first disclosure1 follow-up update
Source-led timeline

What organisations have disclosed

Listed by the date of the source, not the date an attack began. An October update about a June incident is labelled as an update.

2 of 2 verified records
Incident update
iRhythmHealthcare technologyUnited States

iRhythm begins notifying people affected by a June data incident

iRhythm says an investigation found that data in third-party-hosted business applications was accessed and downloaded in June. Its October notice describes the affected personal information and says notification has begun.

Incident period3 to 8 June 2026

What remains unknownThe notice does not identify an attacker, motive, entry method, or a CVE used in the incident.

Original sourceiRhythm: Notice of Data Event ↗
First disclosure
Shinhan BankFinancial servicesSouth Korea

Shinhan Bank discloses unauthorised access to customer information

Its parent company reports that an external party accessed certain services and obtained customer information. The cause, scope and potential impact remain under investigation.

Incident periodNot disclosed

What remains unknownThe filing does not give an incident date, attacker, motive, entry method, or a CVE used in the incident.

Original sourceShinhan Financial Group, via the US SEC: Form 6-K: Cybersecurity Incident at Shinhan Bank ↗
How to read this page

Evidence before attribution.

We include a record only when the affected organisation or an official filing confirms the incident. Dates shown in the timeline are publication dates for those sources. Where the actual incident period is known, it is shown separately.

We do not infer a CVE, attack technique, actor or motive from a company name or a news report. A vulnerability in a product is not proof that it caused a particular incident. Later source corrections should replace earlier wording while keeping the source trail visible.