A series of high-profile cyber incidents disrupted major online platforms, exposed weak security practices, and highlighted the broad impact of both criminal and activist hacking. A global ransomware outbreak later identified as WannaCry spread rapidly across organizations before a security researcher slowed it by registering a domain used as a kill switch, while a separate attack briefly knocked major websites offline through distributed denial-of-service activity. In another major case, hackers compromised prominent US Twitter accounts and used them to promote a Bitcoin scam, demonstrating how access to trusted platforms can be weaponized at scale.
Other incidents underscored persistent failures in account security and access control. Equifax faced scrutiny after an Argentine employee portal was reportedly protected with the username and password admin, adding to concerns around the company’s security posture. Apple said some user accounts had been compromised while denying a broader breach of its systems, and the celebrity photo leak known as “the fappening” showed how attackers could exploit personal account weaknesses. Separately, US authorities linked Julian Assange to alleged conspiracy with Anonymous-affiliated hackers, activist campaigns targeted recording industry websites, and the Colonial Pipeline ransomware case showed how an intrusion into a critical fuel operator could trigger widespread operational disruption even when attackers later claimed they had not intended such consequences.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
The group behind the US fuel pipeline attack said it had not intended to create widespread societal problems, following the ransomware incident that disrupted fuel distribution.
Attackers compromised major US Twitter accounts and used them to promote a Bitcoin fraud scheme, affecting prominent politicians, executives, and companies.
US prosecutors accused Julian Assange of conspiring with hackers associated with Anonymous and LulzSec, expanding the public allegations around WikiLeaks-related hacking activity.
Baltimore suffered a ransomware attack that disrupted multiple city government systems and sparked renewed questions about the NSA's role in the spread of EternalBlue-linked cyber risks. The incident became a major example of ransomware affecting municipal services in the United States.
An Equifax employee portal in Argentina was found accessible using 'admin' as both the username and password, deepening scrutiny of the company's security practices after its broader breach crisis.
Researchers reported stronger evidence connecting the WannaCry ransomware campaign to North Korean-linked hackers, advancing public attribution of the global outbreak beyond its initial spread and technical containment. The reporting highlighted code similarities and other indicators tying WannaCry to the Lazarus Group.
A security blogger accidentally slowed the WannaCry outbreak after registering a domain name embedded in the malware, activating a kill switch in the ransomware's code.
A global ransomware attack hit organizations worldwide, disrupting hospitals, businesses, and government systems in one of the largest cyber incidents of 2017.
A wave of cyber attacks briefly knocked prominent websites offline, reflecting a significant distributed denial-of-service incident affecting major internet services.
Reporting on the celebrity nude photo leak identified the individual behind the intrusion campaign that became known as 'the fappening,' adding detail to the earlier account-compromise case.
Apple said some iCloud and account holders had been compromised following the leak of celebrity nude photos, while denying that its core systems had suffered a broader security breach.
A counterattack took websites used by Anonymous activists offline, marking a reversal in the Operation Payback conflict as hacktivists themselves became targets. The disruption was reported as affecting the online infrastructure associated with the group.
Online activists launched attacks against music industry websites as part of Operation Payback, marking an early wave of coordinated hacktivist disruption tied to anti-piracy disputes.
14 references tracked. Mallory keeps watching after this page renders.
bbc.com
Open sourcebbc.com
Open sourcetime.com
Open sourcebbc.com
Open sourcebbc.com
Open sourcebbc.com
Open sourcebbc.co.uk
Open sourcebbc.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.