The first cyber attacks timeline of October 2021 is here and let me say that, at least in terms of numbers, I have recorded a new low for this year: 77 events in comparison with 108 of the previous timeline. Nonetheless, ransomware continues to dominate the threat landscape, characterizing, directly or indirectly, 28.6% of events (it was 26.8% in the previous timeline) with more high-profile victims, especially in the healthcare sector, joining the list of the targets.

Vulnerabilities continue to be one of the preferred inital access vectors for attackers for opportunistic and state-sponsored attackers: a Chinese threat actor dubbed IronHusky, was discovered targeting IT companies, military/defense contractors, and diplomatic entities since 2012 using a new 0-day tracked as CVE-2021-40449, the Atom Silo ransomware gang started to target Confluence servers vulnerable to CVE-2021-26084, and even the Apache Software Foundation had to patch its Web Server to address three vulnerabilites, one of which, CVE-2021-41773, was actively exploited by attackers.

But even the mobile operating systems are under attack: Apple released iOS 15.0.2 and iPadOS 15.0.2 to fix CVE-2021-30883, a zero-day vulnerability actively exploited in the wild.

As always the cyber espionage front is rich of events. APT28 is always very active, and Google had to send out email notifications to more than 14,000 Gmail users, victims of a spear-phishing attack orchestrated by the same actor… But they are not the only ones. Besides the above quoted IronHusky, the timeline includes fresh new campaigns by APT35, APT41, the Donot Team, and also a new actor dubbed DEV-0343 targeting the Office 365 tenants of US and Israeli defense technology companies in extensive password spraying attacks.

Expand for details

Enjoy the interactive timeline, and thanks for sharing it, and supporting my work in spreading the risk awareness across the community. Also, don’t forget to follow @paulsparrows on Twitter, or even connect on Linkedin, for the latest updates.



The “Breachometer” compares the current number of events/day with the max and min values recorded in the previous 12 months.

  • Photo by Towfiqu barbhuiya on UnsplashThe Biggest Data Breaches of 2023

    Similarly to what I have done in 2022 and 2021, I am collecting the main mega breaches...

  • Leaky Buckets in 2023

    Similarly to what I have done in 2022 and 2021, I am collecting the incidents due to cloud misconfigurations and leading to...

  • November 2023 MotivationsNovember 2023 Cyber Attacks Statistics

    November 2023 saw a rise to 39 events, with Cyber Crime remaining dominant at 78.7%. Cyber Espionage increased to 9.7%, while Hacktivism fell to 5.4%. Malware was the leading attack technique at 42.1%, and Multiple Organizations were the most targeted at 17.7%.

  • Image by Pete Linforth from Pixabay1-15 May 2023 Cyber Attacks Timeline

    In the first half of May 2023 I collected 173 events (corresponding to 11.53 events/day), a value that confirms the sustained trend characterizing this year from an information security perspective.

  • Image by wastedgeneration from Pixabay1-15 December 2023 Cyber Attacks Timeline

    In early December 2023, event recordings decreased significantly to 135, with ransomware dominating 35.5% of incidents. The period saw a notable data breach at ESO Solutions, affecting 2.7 million patients, and a $2.7 million crypto theft at OKX. Geopolitical tensions spurred active cyber espionage, with ...


The Perfect Storm

I have decided to create a new timeline tracking the high-impact vulnerabilities targeting both remote access and on-premise technologies exploited…

Continue Reading

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.