The Containment Era is here. →Explore

Industry Category

Research Industry

Breach intelligence, attack campaigns, and threat reports targeting the Research Industry sector.

23 threat reports
Page 2 of 2

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Research Industry Threat Reports

Showing 1323 / 23 reports
Spain's Ministry of Science 2026 Data Breach: A Wake-Up Call for Government Cybersecurity
Impact· HIGH

Spain's Ministry of Science 2026 Data Breach: A Wake-Up Call for Government Cybersecurity

In early February 2026, Spain's Ministry of Science, Innovation, and Universities experienced a significant cybersecurity incident. A threat actor known as 'GordonFreeman' claimed to have exploited an Insecure Direct Object Reference (IDOR) vulnerability, combined with leaked credentials, to gain full administrative access to the ministry's systems. The attacker allegedly exfiltrated sensitive data, including personal records, email addresses, enrollment applications, and official documents. In response, the ministry partially shut down its IT systems, affecting various services for researchers, universities, and students, and suspended all ongoing administrative procedures to assess and mitigate the breach. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spains-ministry-of-science-shuts-down-systems-after-breach-claims/?utm_source=openai)) This incident underscores the critical importance of robust access controls and vulnerability management within governmental institutions. The exploitation of an IDOR vulnerability highlights the need for comprehensive security assessments and prompt remediation of identified weaknesses. Additionally, the breach serves as a reminder of the persistent threats posed by cyber actors targeting sensitive governmental data, emphasizing the necessity for continuous monitoring and incident response preparedness.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
2025 University of Hawaii Cancer Center Ransomware Breach: Research Data Compromised
Impact· high

2025 University of Hawaii Cancer Center Ransomware Breach: Research Data Compromised

In August 2025, the University of Hawaii Cancer Center experienced a ransomware incident that resulted in threat actors encrypting systems associated with a specific research project. The intrusion led to the exfiltration and encryption of files, some of which dated back to the 1990s and included research participant data containing Social Security numbers, predating modern de-identification practices. While only research files and not clinical or patient treatment data were affected, the disruption necessitated a comprehensive remediation effort including system replacements, forensic investigations, ransomware payment for decryption, and negotiations for deletion of exfiltrated information. This incident underscores the targeting of higher-education and research organizations by ransomware attackers seeking both data and financial gain. With universities increasingly storing decades-old PII, and ransomware groups escalating both exfiltration and extortion, the breach exemplifies the urgency of robust detection, legacy data management, and compliance disciplines in the education and research sector.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GRU’s BlueDelta Targets Energy and Research: Advanced Credential Phishing in 2025
Impact· medium

GRU’s BlueDelta Targets Energy and Research: Advanced Credential Phishing in 2025

Between February and September 2025, the Russian state-sponsored threat group BlueDelta (APT28/GRU) conducted a series of targeted credential-harvesting attacks, focusing on organizations in Türkiye, Europe, North Macedonia, and Uzbekistan. The attackers deployed sophisticated phishing lures themed as Microsoft Outlook Web Access, Google, and Sophos VPN portals, abusing free hosting and tunneling services such as Webhook.site and ngrok to capture credentials and exfiltrate data. Victims were redirected through multi-stage phishing chains, and legitimate PDF documents were used to enhance believability and evade detection, ultimately supporting Russian intelligence collection. This incident underlines the evolution of state-sponsored phishing techniques, including automation for credential exfiltration and the increasing abuse of legitimate internet infrastructure. The campaign’s focus on energy and defense sectors reflects heightened geopolitical interest and reinforces the urgent need for robust email and identity security practices across sensitive organizations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ESA 2024 External Server Breach: Lessons on Third-Party and Perimeter Security
Impact· medium

ESA 2024 External Server Breach: Lessons on Third-Party and Perimeter Security

In June 2024, the European Space Agency (ESA) confirmed a cybersecurity incident involving unauthorized access to external servers outside its core corporate IT network. These servers contained 'unclassified' information tied to ESA's collaborative engineering activities. The breach was detected and announced on June 24, with the agency rapidly taking down the compromised servers to contain the incident and beginning an internal investigation. No critical or classified ESA infrastructure was reportedly affected, and mission operations remained unaffected. This breach underscores persistent risks facing organizations collaborating with external partners and utilizing externally accessible infrastructure. Similar methodologies targeting non-core systems and lateral movements are increasing, highlighting the importance of robust segmentation, external system monitoring, and continuous risk assessment for third-party assets.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ForumTroll APT Strikes Again: Russian Political Scientists Hit by Sophisticated Phishing Scheme
Impact· medium

ForumTroll APT Strikes Again: Russian Political Scientists Hit by Sophisticated Phishing Scheme

In October 2025, the ForumTroll advanced persistent threat (APT) group launched a spear-phishing campaign targeting Russian political science scholars and researchers. Victims received personalized emails disguised as plagiarism report notifications from a fake scientific library domain, prompting them to download a malicious archive. Opening the archive triggered a PowerShell-based attack chain, culminating in the deployment of the Tuoni red-teaming framework via a custom obfuscated loader, with persistence achieved through COM Hijacking. Attacker infrastructure included typosquatted domains and Fastly-based C2 servers. This incident underscores the increasing shift by APT actors to highly targeted, socially engineered phishing attacks, even when technical sophistication is dialed back. Organizations must contend with the reality of persistent, multi-phase campaigns adapting both commercial and bespoke toolkits, heightening the urgency for advanced detection and resilient user training.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ForumTroll Launches Sophisticated Phishing Attack on Russian Scholars Using Fake eLibrary Emails
Impact· low

ForumTroll Launches Sophisticated Phishing Attack on Russian Scholars Using Fake eLibrary Emails

In October 2025, Operation ForumTroll, a previously identified threat actor, launched a targeted phishing campaign against Russian academic and scholarly communities. Using convincingly crafted phishing emails that impersonated official eLibrary notifications, attackers distributed malicious attachments designed to harvest credentials and enable broader espionage operations. The campaign, identified by Kaspersky, marks a decisive tactical shift from prior attacks on organizations to focused targeting of individuals, raising concerns about the security posture of research and educational institutions in the region. This incident highlights the increasing trend of sophisticated phishing campaigns that employ social engineering and trusted brands to bypass traditional defenses. The focused targeting of scholars and intellectuals points towards a rise in espionage-motivated threats seeking sensitive research data, emphasizing the need for robust user education, multifactor authentication, and advanced anomaly detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Mirion Medical 2025: Critical Vulnerabilities in NMIS BioDose Software Threaten Healthcare Security
Impact· high

Mirion Medical 2025: Critical Vulnerabilities in NMIS BioDose Software Threaten Healthcare Security

In December 2025, Mirion Medical disclosed multiple high-severity vulnerabilities affecting its EC2 Software NMIS BioDose product, versions prior to 23.0. These flaws—incorrect permission assignments, use of hard-coded credentials, and client-side authentication weaknesses—could be exploited by attackers to gain unauthorized access, elevate privileges, manipulate executables, steal sensitive medical data, or execute arbitrary code. Impacting the healthcare and public health sectors globally, these vulnerabilities pose critical operational and patient-data risks, especially in environments with networked installations and exposed Microsoft SQL Server databases. No active exploitation has yet been reported, but CISA urges urgent mitigation measures due to the vulnerabilities’ remote exploitability and low attack complexity. This incident highlights intensifying regulatory scrutiny on medical device security as threat actors increasingly target healthcare systems for sensitive patient data and intellectual property. The vulnerabilities in Mirion’s product underscore persistent gaps in authentication and privilege controls—a growing concern amid adoption of connected medical technologies and regulatory frameworks such as HIPAA and NIST.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
University of Pennsylvania 2024 Data Breach: Alumni and Donor Information Compromised
Impact· high

University of Pennsylvania 2024 Data Breach: Alumni and Donor Information Compromised

In June 2024, the University of Pennsylvania confirmed a data breach involving unauthorized access to several internal systems linked to its development and alumni activities. Attackers infiltrated the university’s IT infrastructure, resulting in the theft of sensitive personal and institutional data. The breach impacted donors, alumni, and staff, exposing information such as names, contact details, and potentially financial data. University officials discovered the intrusion after observing suspicious activity and promptly initiated an investigation. Law enforcement and cybersecurity specialists were engaged to contain the incident, assess affected systems, and notify those impacted. This breach highlights the persistent risks that higher education institutions face from increasingly sophisticated cyberattacks, especially targeting sensitive donor and alumni databases. As ransomware and data exfiltration trends intensify, universities must enhance defenses and closely align with compliance frameworks to mitigate regulatory, reputational, and operational risks.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Oxford Nanopore 2025: MinKNOW Vulnerabilities Expose Medical Devices to Remote Exploitation
Impact· high

Oxford Nanopore 2025: MinKNOW Vulnerabilities Expose Medical Devices to Remote Exploitation

In October 2025, Oxford Nanopore Technologies disclosed three critical vulnerabilities in its MinKNOW DNA/RNA sequencing devices, impacting versions prior to 24.11. These flaws, which included missing authentication for critical functions, insufficiently protected credentials, and improper checks for exceptional conditions, allowed unauthorized users—both local and remote—to access, manipulate, or halt sequencing operations. Attackers could exploit default remote access settings and insecure credential storage to exfiltrate or alter sensitive data and cause denial of service in key sequencing workflows. The vulnerabilities were responsibly reported by academic researchers, prompting urgent advisories by CISA and the vendor. This incident underscores increasing risk to healthcare and life sciences infrastructure, with medical device supply chains emerging as a prime target for cyberattackers. As regulatory focus on medical device cybersecurity intensifies globally, organizations must swiftly address legacy systems and implement controls that secure both east-west and egress traffic, limit access, and ensure encrypted credential storage.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
BIETA & CIII Unmasked: China’s MSS Deploys Espionage Through Research Firms in 2025
Impact· low

BIETA & CIII Unmasked: China’s MSS Deploys Espionage Through Research Firms in 2025

In October 2025, a detailed investigation revealed that Chinese research firms BIETA (Beijing Institute of Electronics Technology and Application) and CIII were directly implicated in cyber operations orchestrated by China’s Ministry of State Security (MSS). The report, based on personnel link analysis and institutional relationships, highlights how BIETA coordinated with MSS operatives and academic partners to conduct covert cyber-espionage campaigns targeting international entities. These campaigns leveraged advanced tactics, including exploitation of internal network flows and the use of encrypted traffic, to exfiltrate sensitive data undetected. The exposure underscores the persistent and sophisticated nature of state-sponsored cyber threats, as well as risks posed by non-traditional actors collaborating with government intelligence agencies. This incident reflects a broader escalation in state-driven cyber espionage, demonstrating that commercial and academic organizations may serve as active operational arms for nation-state threat actors. As attribution capabilities improve, organizations must reassess third-party relationships and reinforce east-west and encrypted traffic controls to mitigate lateral movement and exfiltration risks.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
ComicForm and SectorJ149 Launch Formbook Infostealer Attacks in Eurasia (2025)
Impact· medium

ComicForm and SectorJ149 Launch Formbook Infostealer Attacks in Eurasia (2025)

In April 2025, a previously unknown threat group known as ComicForm, in tandem with the SectorJ149 collective, launched a sophisticated phishing campaign against organizations in Belarus, Kazakhstan, and Russia. Exploiting spear-phishing emails, the attackers delivered Formbook malware, an advanced infostealer, to infiltrate sectors including industrial, financial, biotechnology, research, tourism, and trade. The campaign's attack chain leveraged malicious email attachments and deceptive lures aimed at harvesting sensitive credentials, exfiltrating business information, and enabling internal lateral movement, causing operational disruptions and exposing confidential data. This incident exemplifies the rise of regionally targeted malware campaigns by emerging threat actors who combine phishing, credential theft, and infostealer malware. Current threat intelligence points to increased infostealer usage, especially in sectors with valuable intellectual property, necessitating enhanced vigilance and stronger defense-in-depth strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports