April 2026: ShinyHunters Hits Medtronic and ADT as North Korean Hackers Drain DeFi Protocols
ID: b13c70a4-547f-5e8d-87a6-0b8e9fb81127
STIX ID: report--b13c70a4-547f-5e8d-87a6-0b8e9fb81127
Feed Name: SOCRadar Blog
April 2026 featured a concentrated wave of high-impact incidents: ShinyHunters conducted mass extortion and data leaks impacting Medtronic, ADT, and McGraw Hill; North Korean-linked groups (Lazarus, UNC1069) executed sophisticated DeFi exploits and an npm compromise that delivered RAT malware; supply-chain attacks tied to TeamPCP/Trivy and LAPSUS$ produced large GitHub data leaks; and numerous credential- and misconfiguration-driven breaches across sectors resulted in millions of exposed records and hundreds of millions in stolen funds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
