CiberLATAMbywhalemate
Intelligence report

USA Cybersecurity Status in September 2026

September in the USA was dominated by vulnerabilities and system exposure, with NetScaler, SonicWall, Microsoft, WSO2, and healthcare incidents in focus.

Oct 1, 202616 min read
USA Cybersecurity Status in September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-by-month readout, and the analysis that follows develops the cases without repeating this summary.

Indicator window: 53 dated facts in September 2026 · 3 from prior months (comparative frame, not month volume) · 4 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard September 2026 · USA Top threat: Vulnerabilities (23 of 53 items). Coverage: 53 dated items in September 2026 · 3 of me… VERIFIED FACTS 53 period base: total count measured from below against this total RANSOMWARE / EXTORTION 5 1 unencrypted exfiltration (simple extortion) · 4 undeterminable classification UNCLASSIFIED INCIDENTS 9 breaches or outages without declared threat type FRAUD / PHISHING 1 documented fraud campaigns REGULATION 7 standards, rulings, or penalties UNIQUE CVEs 27 CVE-2025-25249 / CVE-2025-39682
Verified Signal Monthly Dashboard — Base: 53 verified dated items for USA.
MONTHLY FIXED MODULE Threat-axis distribution September 2026 · USA Each incident is counted under only one axis, so the total is exactly 53. "Unclassified incidents" is the remainder. Vulnerabilities 23 Incidents 9 Unclassified 8 Regulation 7 Ransomware 5 Fraud 1
Threat-axis distribution — Each incident is assigned to a single axis based on its classification; the total reconciles to the 53 incidents in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Signal September 2026 · USA Base: 53 events in the period · total 83 because 21 events are classified in more than one sector. Public sector / OIV 32 Technology 26 Other / unidentified sector… 9 Healthcare 5 Finance 3 Telecom 3 Education 3 Retail / Consumer 2
Sectoral Distribution of Signal — Heuristic classification by victim sector. One event may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in the USA September 2026 · USA 5 of 53 findings in the period involve critical infrastructure. One finding may appear in more than one category. Public sector / government 32 Energy / utilities 4 Telecom / connectivity 2
Critical Infrastructure in the USA — Verified findings on public sector, utilities, and essential services

Executive monthly summary for the USA

September 2026 was a lighter month in the United States than the one before, but it was more concentrated around exploited vulnerabilities, unauthorized access, and warnings about third-party dependencies. The verified facts for the period total 53, including 9 unclassified incidents and 27 critical CVEs mentioned, while vulnerabilities were the leading threat, accounting for 23 of 53 facts. The month’s risk picture is high, driven by active exploitation, cross-sector reach, and repeated signals affecting critical infrastructure, healthcare, finance, and government.

The most visible campaign was the wave of exploited vulnerabilities in Citrix NetScaler, which ultimately covered two main CVEs and pushed CISA, Citrix, and several response teams to issue urgent advisories in the final week of the month. At the same time, the edge and remote access ecosystem remained under pressure with SonicWall SMA1000, Mikrotik RouterOS, WSO2, Adobe Commerce, SharePoint, and Linux kernel, confirming an operational agenda dominated by patching, KEV prioritization, and perimeter exposure. On the incident side, the public sector and healthcare accounted for the most sensitive cases, although water, energy, transportation, and digital services also appeared.

The most sensitive events in terms of impact were the FBI incident and the Department of Defense DMDC case, both involving possible exposure of large volumes of personal data, though with different levels of confirmation and public scope. That was joined by the investigation into FBI job portals, activity attributed to ShinyHunters, and the OpenAI episode involving unauthorized access to federal government sites, reinforcing a pattern of risk around identity, credentials, and exposed surfaces. In OT and critical infrastructure, the joint CISA and FBI guidance for ICS integrators was one of the month’s most important regulatory and operational milestones.

There were also notable moves on regulation and compliance. The SEC, the OCC, the Fed, CISA, the FTC, the FCC, and federal lawmakers advanced measures on incidents, third parties, telecom, healthcare, banking, and AI governance. The overall picture is of a defense posture reorganizing around vendors, supply chains, remote access, and reporting obligations, with less emphasis on pure ransomware campaigns than in previous months and greater attention to exploitable vulnerabilities as a disruption vector.

Monthly National Overview in the USA

The United States ended September with a more dispersed risk surface, but one with sharper fault lines, remote access, exposed appliances, identity platforms, industrial integrators, and digital services tied to public administration. The combination of 53 verified events, 27 critical CVEs, and 9 unclassified incidents supports a high risk reading, not because of a single major event, but because exposure persisted across multiple sectors and several flaws moved quickly into active exploitation.

The month’s dominant signal was clearly technical. CISA repeatedly added vulnerabilities to the KEV catalog, set aggressive mitigation deadlines, and ordered urgent response in several cases. That sat alongside more traditional incidents in health care, local government, and utilities, where exfiltration, unauthorized access, or partial disruption were reported, but with ransomware less central than in August. Compared with the previous month, the overall volume was lower, ransomware was down, and documented fraud or phishing was less frequent, but more critical CVEs were cited and guidance plus patching became the main defensive mechanism.

In sector terms, the month affected at least eight sectors. Health care, government, water, finance, energy, telecommunications, transportation, and digital services all appeared in documented incidents. Not every case carried the same weight, and several were alerts or advisories without confirmed impact, but the risk pattern was consistent, where exposed systems, connected third parties, or edge appliances existed, exposure followed. That was especially clear in water and OT, where CISA and FBI guidance for ICS integrators was issued in response to real compromises, and in finance, where the regulator focused on third parties, core vendors, and operational resilience.

Timeline de señales críticas en USA, septiembre 2026Hitos principales del mes en vulnerabilidades, incidentes y regulación.SonicWallActive KEVCisco, Citrixand FortinetLinux kernelexploitedColorado waterand OTNetScalerzero-daysFBIjobs.govlow underinvestigationSeptember 2026USA: incidents and vulnerabilities with the greatest operational impact
Critical Signals Timeline in the USA, September 2026 — Highest verified-impact milestones in the month, sorted by date.

U.S. period indicators

Indicator Value Note
Verified events in the period 53 Base for all indicators; dated events in September 2026
Time window for the indicators 53 events dated in September 2026 · 3 from previous months (comparative frame, not monthly volume) · 4 without confirmed date (excluded from the indicators) Report-declared window
Unclassified incidents (breaches or outages) 9 Period events
Cases with ransomware or extortion as the primary focus 5 Period events
Exfiltration without encryption (simple extortion) 1 Breakdown within ransomware/extortion
Cases with undeterminable classification based on the material 4 Breakdown within ransomware/extortion
Documented fraud or phishing cases 1 Period events
Documented regulatory moves 7 Period events
Critical CVEs mentioned 27 Period events
Sectors with at least one documented event 8 One event can affect more than one sector
Predominant threat of the month Vulnerabilities (23 of 53 events) Dominant category of the period
Events with direct source confirmation 75% Percentage declared for the period

Relevant Incidents in the USA

FBIjobs.gov and the ShinyHunters investigation

The FBI confirmed on September 22 that it was investigating unauthorized activity affecting its main job application portal and kept the site offline while the inquiry moved forward. Coverage later in the month added that the intrusion may have exposed personal data belonging to agents and applicants, but the exact scope has not been fully confirmed publicly.

The significance of the case is not only the possible volume of data, but also the surface that was compromised. The incident combines identity, human resources, and sensitive data exposure at one of the country’s most visible federal agencies. It also left open the question of whether the entry point was a third party or internal systems.

Defense Manpower Data Center, more than three million potentially affected

A DMDC system at the Department of Defense exposed personal information from more than three million people linked to the US military sphere, according to an official cited by Federal News Network. The unauthorized access allegedly took place between October 2025 and July 2026, which is why the matter became public this month, but it describes a long-running intrusion.

The key point for September is the structural nature of the compromise. This was not a one-off alert, but a sustained exposure of sensitive data tied to military personnel and others connected to defense. Available material does not allow a final attribution of the vector or the operational scale, but it does confirm the seriousness of the finding.

Astrana Health and the risk of phone impersonation

Astrana Health said a subsidiary detected unauthorized access after an attack in which the actors impersonated company staff using a spoofed corporate phone number. The case shows that social engineering remained effective for opening doors in sensitive environments, even when the intrusion did not rely on sophisticated malware.

The company filed an 8-K with the SEC and classified the incident as material because of the sensitivity of the data involved. In practice, the case ties a classic impersonation vector to a direct regulatory consequence and to an investigation that is still open.

Colorado and the compromise of two water utilities

Two small private drinking water providers in Colorado were compromised in late August, but the case continued to draw attention in September as authorities and the press detailed the technical scope. The attackers changed equipment configurations, disabled remote access and alarms, and altered pumping cycles, although there were no impacts on treatment, water quality, or public safety.

The value of the episode lies in the type of manipulation involved. This was not just access to an administrative network, but interference with OT systems and operating logic. The FBI also advised utilities to disconnect systems from the internet when possible and prepare for manual controls, linking the incident to guidance on third-party ICS issued days later.

Eudora, Douglas County, and the impact on interconnected networks

Eudora suffered an incident that, according to the fired former IT administrator, was foreign ransomware that began through the VPN connecting the police system with Douglas County sheriff servers. Coverage also said the ransomware encrypted police department files and that ransom was demanded to unlock them.

The impact did not remain contained within a single network. Dependence on shared infrastructure caused effects at the Lawrence Police Department, which had to disconnect from certain modules tied to the sheriff. It is a useful case for understanding the fragility of local ecosystems with mutually connected services.

Fort Smith and the exfiltration of municipal data

Fort Smith, Arkansas, said it was reviewing files after a dark web post claimed data copied from its network and the police department’s network. The city said the incident did not affect network security or recovery efforts, and public services continued operating.

The follow-up reporting indicated that the city had not yet publicly confirmed the scope, while the Interlock group claimed to have exfiltrated about 5.7 TB of data. The breach was better characterized as an extortion case with an allegation of information theft than as a verifiable encryption event in the available material.

Sutton, Massachusetts, and the municipality’s early response

The town of Sutton and its public schools reported a cybersecurity incident that affected part of their network environment. Systems were secured immediately, police were notified, and independent forensic specialists were hired, while services continued operating.

This case stands out less for confirmed damage than for the response pattern. The quick handling reduced operational impact and shows a more mature approach to initial containment in local events. Even so, it remains an incident that is not precisely classified in the available material.

CenterPoint Energy and customer data exposure

CenterPoint Energy told the SEC that an unauthorized party obtained personal information from some customers through one of its internet-exposed systems. The company said electricity and gas delivery were not affected and operations continued normally.

The news matters because it links public exposure, customer data, and operational continuity. The case does not describe a service outage, but it does confirm that exposed systems remain an effective entry point for information theft at large utilities.

Threats and active campaigns in the USA

Ransomware and extortion, with separate taxonomy

In September, five cases were recorded in the United States with ransomware or extortion as the primary focus, but the material does not allow them to be treated as one homogeneous set. There was one case of exfiltration without encryption, four publications whose exact classification cannot be determined from the material, and several victim mentions on leak sites that do not, by themselves, prove operational impact.

Exfiltration without encryption: Fort Smith

Fort Smith fits best as simple extortion with a claim of mass data theft. The city acknowledged intrusion and forensic work, and tracking sources speak of data theft and publication on a leak site, but not verified encryption in the consolidated material. The case falls into the realm of disclosure pressure, not confirmed unavailability.

Classification cannot be determined: Eudora, Sutton, and other local cases

Eudora had confirmed encryption, according to the former IT administrator, but in other incidents during the month the classification cannot be pinned down with the same certainty. Sutton, Fort Smith, and some notices from hospitals and providers appear as incidents with ongoing activity, group postings, or open investigations, without enough evidence to label them all as encryption, exfiltration, or a simple victim claim.

Monitoring from ransomware.live and other platforms added victims such as OnTrac and Electrolux, along with other organizations, but in several of those cases the source only documents the group's post. That does not amount to confirmed operational impact. The distinction matters because a leak-site appearance can be real, doubtful, or inflated, and the material does not always allow that gap to be closed.

Fraud and phishing, with one documented case

The only clearly documented fraud or phishing case in the United States during the period was the prosecution of two former Air Force members, tied to spam and phishing campaigns aimed at U.S. companies to steal credentials and use them in BEC fraud. The sentence was 111 months and 78 months in prison, plus restitution orders.

This confirms that phishing remains a useful entry point for financial fraud and account theft, even though the month was much more dominated by vulnerability exploitation than by mass email campaigns. The signal is smaller in volume, but not in legal sensitivity.

APT, espionage, and advanced intrusion activity

The month's advanced activity centered on the FBI cases, the DMDC, the movements around ShinyHunters, and the OpenAI episode involving federal sites. Not all of that is APT in the strict sense, but it does reflect an intrusion environment closer to reconnaissance, unauthorized access, credential theft, and selective exfiltration than to pure ransomware.

Coverage of NetScaler also showed the use of custom malware and early exploitation before Citrix's public announcement, suggesting campaigns with planning and preparation. In parallel, the OT and ICS front had a different signature, not so much exfiltration as pre-positioning, SCADA hunting, and preparation of compressed files with network schematics and configurations.

Critical vulnerabilities with impact in the USA

September’s technical agenda was defined by active exploitation, KEV additions, and aggressive remediation deadlines. CISA moved against edge appliances, Windows, Linux, collaboration products, commerce platforms, and administration tools that faced real pressure, not just theoretical risk.

CVE Software Exploitation Source
CVE-2026-88771 Citrix NetScaler ADC and Gateway Active exploitation, added to KEV Sygnia, CISA, Cybersecurity Dive
CVE-2026-88772 Citrix NetScaler ADC and Gateway Active exploitation, added to KEV Sygnia, Unit 42, CISA
CVE-2026-85102 Check Point Security Gateway and Security Management Active exploitation observed since September 12 Check Point
CVE-2026-93616 Check Point Management web service Zero-day, active exploitation Check Point
CVE-2026-81963 Microsoft Windows Active exploitation, added to KEV SANS, Automox, CISA
CVE-2026-85880 Microsoft Windows Active exploitation, added to KEV SANS, CISA
CVE-2026-19490 Citrix NetScaler Active exploitation, added to KEV F5 Labs, CISA
CVE-2026-83548 SonicWall SMA1000 Active exploitation, added to KEV SonicWall, CISA, Qualys
CVE-2026-83549 SonicWall SMA1000 Active exploitation, added to KEV SonicWall, CISA, Qualys
CVE-2026-5430 WSO2 API Control Plane, API Manager, Traffic Manager, Universal Gateway Active exploitation, added to KEV CISA, CiberPlaneta
CVE-2026-71362 Adobe Commerce and Magento Active exploitation, added to KEV CISA, SecurityAffairs
CVE-2026-65660 Microsoft SharePoint Active exploitation, added to KEV CISA, SecurityAffairs
CVE-2026-67279 Mikrotik RouterOS Active exploitation, added to KEV CISA, SecurityAffairs
CVE-2025-39682 Linux kernel Active exploitation, KEV Dataconomy, TechTimes
CVE-2026-53266 Linux kernel Active exploitation, KEV Dataconomy, TechTimes
CVE-2025-39964 Linux kernel Active exploitation, KEV Dataconomy, TechTimes
CVE-2026-87886 Acronis Backup for cPanel & WHM and Plesk Active exploitation in production, KEV F5 Labs, CISA
CVE-2026-21962 Not detailed in the source material Active exploitation confirmed Mishcon de Reya
CVE-2026-20079 Cisco Secure Firewall Management Center Active exploitation, KEV CISA, The Hacker News
CVE-2026-82329 JFrog Artifactory self-hosted Active exploitation, KEV CISA, JFrog, CiberPlaneta
CVE-2026-81578 PaperCut NG/MF Active exploitation, KEV CISA, Cyber Experts
CVE-2026-82078 PaperCut NG/MF Active exploitation, KEV CISA, Cyber Experts
CVE-2026-59310 VMware vCenter Exploited by ransomware groups, KEV BleepingComputer, CISA
CVE-2026-725... Not reported Not registered in the analyzed material n/a
Comparativo de señal principal en USABarras comparan indicadores clave de agosto y septiembre 2026 para Estados Unidos.Monthly ComparisonTotal volume, ransomware, and critical CVEsAug. incidents 92Sep. incidents 53Aug. ransomware 25Sep. ransomware 59253255Critical CVEsAug. 18Sep. 27
Main Signal Comparison in the USA — The dominant signal shifted from ransomware to vulnerabilities, with lower overall volume but more critical CVEs.

Regulation and compliance in the U.S.

September ended with a more active regulatory front than August, especially in banking, telecom, healthcare, privacy, and AI governance. Seven documented regulatory moves stood out, with notable intensity in building frameworks for third parties, incidents, and reporting obligations.

The SEC moved beyond the Reg S-P grace period and reminded regulated firms that they must have written incident response programs, notify customers within 30 days at most, and require vendors to report breaches within 72 hours. In parallel, the OCC updated its Cybersecurity Supervision Work Program to align it with NIST CSF 2.0, without creating new regulatory expectations, but making the exam focus for national banks and federal savings associations clear.

The Fed kept pushing the discussion on vendor risk and AI exposure. Michelle Bowman spoke about protecting banks, especially smaller ones, from risks tied to external services and AI. That was joined by the interagency debate over third-party risk management, with greater scrutiny of core providers and critical vendors.

In telecom, senators advanced a voluntary certification bill for providers and suppliers, in response to the debate that followed Salt Typhoon. In healthcare, Warner and Wyden reintroduced the Health Infrastructure Security and Accountability Act, with mandatory minimum standards, audits, continuity plans, and a $1.3 billion allocation to strengthen hospital cybersecurity.

CISA and the FBI also shaped the regulatory agenda with guidance on third-party ICS integrators. The guidance calls for reducing public exposure, logging remote access, maintaining hardware and software inventories, including security requirements in contracts, and preserving independent operating capability. It is a regulatory intervention grounded in a real attack pattern and aimed at lowering systemic risk across the industrial supply chain.

Most affected sectors in the USA

Healthcare was the most pressured sector, although the pressure did not come only through ransomware. There were incidents at hospitals, health providers, a major health tech player, and cases involving medical or sensitive data, alongside regulatory concerns tied to HIPAA, hospital security, and operational continuity. The signal is clear: healthcare remains a high-value target for information theft, extortion, and disruption.

Government and the public sector also had a difficult month. The FBI, the DMDC, local governments such as Fort Smith and Sutton, and the OpenAI episode involving federal portals showed a pattern of risk around identity, access, and administrative data. In this area, the problem was not a single type of attack, but the overlap between intrusion, data exposure, and dependence on vendors or third-party systems.

Water and OT carried disproportionate weight for the month’s total volume. Colorado and alerts about water utilities in other states showed that remote access and PLCs remain a weak point. The CISA and FBI guidance for ICS integrators was not an isolated piece, but a direct response to a problem that had already materialized.

Finance appeared through regulatory pressure and data incidents, but also through pressure on third parties, core vendors, and oversight. The OCC, the Fed, the FTC, and September legislative proposals put banks at the center of a broader debate on operational resilience, consumer protection, and the use of technology vendors.

Energy and transportation saw less volume, but high risk because of their critical nature. The tankers under investigation in the Gulf of Mexico and the CenterPoint Energy case show that vectors affecting OT, IT, and customer data can coexist. In telecommunications, the discussion shifted more toward public policy, although interest in certification and vendor resilience points to sustained concern.

Compared with August, volume fell sharply from 92 to 53 verified incidents, but risk did not ease. Unclassified incidents, ransomware or extortion cases, and documented fraud or phishing declined, while critical CVEs mentioned rose from 18 to 27. Last month was dominated by ransomware, this month by vulnerabilities. That reversal is the main tactical signal.

The second signal is the consolidation of the edge and remote access as the most urgent attack surface. SonicWall, Citrix, Mikrotik, WSO2, VMware, Check Point, and Microsoft products appeared with active exploitation or added to the KEV. The market for appliances and internet-exposed software continued to serve as the first line of impact for attackers, with objectives ranging from initial access to positioning for later intrusion.

The third trend is the growing density of incidents in third-party and vendor environments. The FBI case, the debate over ICS integrators, the interagency banking guidance, and regulatory moves on core providers and external service providers point in the same direction. This is not only about vendor audits, but about operational continuity in the face of critical dependency.

In health care and local government, September showed that the combination of exfiltration, ransomware, and administrative exposure remains active, but with fewer mass cases than in August. At the same time, the narrative of AI-assisted attack appeared less as a direct operational fact in the USA and more as a broader risk context, especially in the campaigns described by Anthropic and Unit 42 in other arenas.

The most relevant signal for October is straightforward: the pace of KEV publication and mitigation deadlines will continue to shape the defense agenda. If last month was the warning of a ransomware surge, September was the reminder that vulnerability exploitation remains the fastest path to compromise services, data, and industrial networks.

Security recommendations for teams in the USA

Prioritize patching edge and remote access appliances, with a focus on NetScaler, SonicWall, WSO2, Mikrotik, VMware, Check Point, and Microsoft products that were added to KEV or showed active exploitation. In organizations with public exposure, the remediation window should be measured in hours, not weeks.

Review third-party dependencies immediately, especially ICS integrators, core banking providers, and external services with persistent remote access. Contracts should include session logging, hardware and software inventory, accelerated incident notification, and the ability to operate without the integrator if that third party is compromised.

In government, health care, and utilities, strengthen monitoring for identity, authentication, and exfiltration. The FBI, Astrana, CenterPoint, and Fort Smith cases show that initial access still comes through credentials, impersonation, or exposed systems. Protecting the perimeter is not enough if sensitive data is already reachable internally or through connected portals.

In OT and water environments, limit direct internet exposure, log and segment remote access, and keep manual procedures ready. The CISA and FBI guidance on ICS integrators, along with the Colorado case, shows that operational continuity depends on both architecture and operational discipline.

For response teams, distinguish precisely between encryption, simple extortion, and mere publication on a leak site. That distinction is essential to avoid overestimating or underestimating the event, measure the real impact, and communicate with legal, executives, and regulators without mixing unverified claims with confirmed intrusions.

Frequently Asked Questions

What changed between August and September 2026 in the USA?

September saw fewer verified incidents than August, 53 compared with 92, and far less ransomware. At the same time, pressure on critical vulnerabilities increased, with 27 CVEs mentioned versus 18 the month before. The main signal shifted from ransomware to technical exploitation, especially on exposed edge devices and remote access.

Which sectors were most exposed this month in the USA?

Healthcare, government, water, finance, energy, telecommunications, transportation, and digital services all had documented incidents. The most sensitive combination crossed government and defense, with the FBI and the DMDC, while water and OT stood out because of the Colorado cases and the CISA-FBI guidance for ICS integrators.

Which vulnerabilities drove the operational urgency in the USA?

Citrix NetScaler, SonicWall SMA1000, Microsoft Windows, WSO2, Adobe Commerce, SharePoint, Mikrotik RouterOS, and the Linux kernel dominated the agenda. The common thread was active exploitation or inclusion in CISA’s KEV catalog, which forced immediate patching priority in exposed environments.

How should the month’s five ransomware or extortion cases be read?

They should not be grouped as a single block. One is better characterized as exfiltration without encryption, four do not allow the impact type to be determined with certainty, and in several cases the source only records publication on a leak site. That distinction changes the damage assessment completely.

What does the US regulatory front mean for banks and vendors?

It means tighter oversight of third parties, greater documentation demands, and less room for informal responses. Reg S-P already requires rapid notification, the OCC aligned its work with NIST, the Fed strengthened its focus on vendors, and the TPRM debate points to core providers with stricter responsibilities.

Material limitations

This report was prepared exclusively from the material provided for the US and September 2026. The 53 verified facts from the period are the basis for all indicators. The three facts in the comparative frame block were used only for month-over-month trend analysis and do not count toward the month’s volume. The four facts without confirmed dates were excluded from the indicators.

A zero value, especially for CVEs or categories such as fraud, does not mean the phenomenon is absent in the United States or across the region. It means it did not appear in the material analyzed for this period with the level of confirmation required by these rules.

The report’s stated time window includes 53 facts dated in September 2026, plus three facts from earlier months used only for comparison, and four without confirmed dates excluded from the counts. The material does not include aggregated telemetry such as incidents, and any figure for attempts or blocks should be read, if it appears, as operational noise and not as a confirmed intrusion.

Consumer social media posts and sponsored content were also excluded as evidence. When third-party mentions were used, priority was given to official bodies, vendor notices, CISA, FBI, SEC, OCC, Fed, and other primary or directly observed sources. When a claim depended only on attacker attribution or secondary coverage, it was treated as such and not as a closed fact.

Sources