SecureFact – May 18, 2026
Major cyberattacks impacted pharmaceutical manufacturers, critical infrastructure, AI companies, technology providers, and automotive platforms, exposing sensitive data and disrupting operations globally.
West Pharmaceutical says hackers stole data, encrypted systems
West Pharmaceutical Services, a publicly traded S&P 500 pharmaceutical manufacturing company with over 10,800 employees and annual revenues exceeding $3 billion, disclosed a material cybersecurity attack detected on May 4, 2026. The attackers exfiltrated data from the company’s network and encrypted systems globally, forcing the company to proactively take systems offline for containment purposes. The exact nature and scope of the incident, including the specific types of data stolen, was still under investigation at the time of disclosure. The company immediately activated incident response protocols, notified law enforcement, and engaged external cyber-forensic experts including Palo Alto Networks’ Unit 42 for incident response and recovery efforts. Core enterprise systems supporting shipping and manufacturing operations were restored, with manufacturing partially restarted, though complete restoration of all systems had not yet been achieved. The company took steps to mitigate the risk of dissemination of exfiltrated data but did not specify the exact mitigation measures.
(Source: Read full report)
Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible
U.S. officials suspect Iranian hackers were behind cyber breaches targeting automatic tank gauge (ATG) systems used at gas stations across multiple states. The attackers reportedly exploited internet-connected fuel monitoring systems that lacked password protection, allowing them to manipulate displayed fuel readings, though not the actual fuel supply. While no physical damage or fuel leaks have been reported, cybersecurity experts warned that compromising these systems could potentially hide dangerous gas leaks or disrupt fuel operations. Officials believe the activity is part of an escalating wave of Iran-linked cyber operations targeting critical infrastructure amid rising geopolitical tensions. The incidents have renewed concerns about weak cybersecurity practices in industrial control systems and the risks posed by unsecured internet-exposed devices.
(Source: Read full report)
Foxconn confirms cyberattack claimed by Nitrogen ransomware gang
Foxconn, the world’s largest electronics manufacturer with over 900,000 employees across 240 campuses in 24 countries and revenues exceeding $260 billion, confirmed a cyberattack on its North American factories. The Nitrogen ransomware gang claimed responsibility and alleged theft of 8TB of data and more than 11 million documents containing confidential instructions, projects, and drawings from major Foxconn customers including Apple, Intel, Google, Nvidia, and AMD. The company’s cybersecurity team immediately activated response mechanisms and implemented operational measures to ensure production continuity. Affected factories were working to resume normal operations at the time of disclosure. Nitrogen ransomware, which emerged in 2023 and developed its own strain using leaked Conti 2 builder code, has been slowly adding victims to its leak site since 2024. This was not Foxconn’s first ransomware incident, with previous attacks from LockBit and DoppelPaymer ransomware groups in prior years.
(Source: Read full report)
UK fines water supplier $1.3M for exposing data of 664k customers
The UK Information Commissioner’s Office (ICO) fined South Staffordshire Water Plc and parent company South Staffordshire Plc £963,900 ($1.3 million) for a cyberattack that exposed personal data of 663,887 customers and employees. The breach, which can be traced back to September 2020 but largely occurred between May and July 2022, exposed full names, physical addresses, email addresses, phone numbers, dates of birth, customer account credentials, bank account details, and employee HR data including National Insurance numbers. The attack occurred through a phishing email that enabled installation of malware, which remained undetected for 20 months. The ICO identified multiple security failures including insufficient privilege escalation controls, monitoring covering only 5% of the IT environment, use of obsolete software like Windows Server 2003, poor vulnerability management, and lack of regular security scans. The company admitted liability early, cooperated with the investigation, and agreed to settle without appeal, resulting in a 40% reduction of the initial fine.
(Source: Read full report)
TeamPCP hackers advertise Mistral AI code repos for sale
The TeamPCP hacker group claimed to have stolen nearly 5 gigabytes of internal repositories and source code from Mistral AI, a French artificial intelligence company founded by former researchers from Google’s DeepMind and Meta. The attackers offered 450 repositories for sale at $25,000, stating they would leak all data for free if no buyer was found within a week. The breach occurred after a developer device was compromised during the TanStack supply-chain attack, which also impacted hundreds of npm and PyPI packages. Mistral AI confirmed that hackers compromised a codebase management system after stealing CI/CD credentials through the supply chain attack. The company stated that the contaminated SDK packages were only affected for a brief period and that forensic investigation determined the impacted data was not part of core code repositories. Mistral emphasized that neither hosted services, managed user data, nor research and testing environments were compromised, and no evidence was found of the stolen credentials being used in additional attacks.
(Source: Read full report)
OpenAI confirms security breach in TanStack supply chain attack
OpenAI confirmed that two employees’ devices were breached in the TanStack supply chain attack that impacted hundreds of npm and PyPI packages. The breach was linked to the “Mini Shai-Hulud” supply-chain campaign by the TeamPCP extortion gang, which targeted developers by injecting malicious updates into trusted software packages. OpenAI observed unauthorized access and credential-focused exfiltration activity in a limited subset of internal source code repositories to which the two impacted employees had access. Only limited credentials were stolen from the repositories, and forensic investigation found no evidence they were used in additional attacks. The company isolated affected systems and accounts, revoked sessions, rotated credentials across affected repositories, and temporarily restricted deployment workflows. Code-signing certificates used for OpenAI products on macOS, Windows, iOS, and Android were exposed but showed no evidence of abuse. OpenAI rotated these certificates as a precaution, requiring macOS users to update their OpenAI desktop applications before June 12, 2026. The incident did not impact customer data, production systems, intellectual property, or deployed software.
(Source: Read full report)
Škoda warns of customer data breach after online shop hack
Škoda Auto suffered a customer data breach after hackers exploited a vulnerability in its online shop software, gaining temporary unauthorized access to customer information. The exposed data may include names, addresses, email IDs, phone numbers, order details, and hashed passwords, although the company stated that payment card information was not compromised because payments are handled through third-party providers. Škoda has since taken the affected system offline, fixed the vulnerability, initiated a forensic investigation with external cybersecurity experts, and notified relevant authorities. However, the company noted that it cannot confirm whether any customer data was actually exfiltrated, prompting it to advise customers to stay alert for phishing attempts, suspicious emails, and unauthorized account activity.
(Source: Read full report)