These Breaches Cost Billions - Don't Be Next
Real-world examples of breaches and major cybersecurity report findings (2017-2026)
Romania's ANCPI / e-Terra land registry
Impact: Complete freeze on property sales, mortgages, and land registrations nationwide.
Imagine trying to buy a home, secure a mortgage, or register a property, only to find the entire country's land registry is completely shut down. That is exactly what happened when Romania's national e-Terra database went offline, freezing real estate transactions across the country. The root cause was entirely preventable: instead of a highly sophisticated exploit, attackers gained entry by combining known software vulnerabilities that had gone unpatched with administrative passwords that had already been leaked and published on the public internet. While the agency had to rebuild its systems from backups in stages, the incident highlights how easily basic, exposed oversights can turn into a nationwide standstill.
Read our analysis: What public evidence tells us about the ANCPI / e-Terra attackVerizon 2026 DBIR
Impact: Comprehensive threat assessment of 31,000+ incidents and 22,000+ confirmed breaches.
The Verizon 2026 DBIR highlighted that exploitation of vulnerabilities is now the most common initial access vector for breaches, at 31%. Credential abuse remains important, representing 13% as an initial access vector and appearing in 39% of breach progression when counted across the full path. Organizations struggled to remediate vulnerabilities, with only 26% of CISA Known Exploited Vulnerabilities fully remediated in 2025 and the median time to fully remediate rising to 43 days. For SMBs, about 96% of ransomware victims (where organization size was known) were SMBs.
Cisco Secure Firewall Management Center
Impact: Zero-day exploitation by Interlock ransomware (CVE-2026-20131)
A critical vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20131) was exploited by the Interlock ransomware group as a zero-day before public disclosure, allowing unauthenticated remote root code execution. Amazon Threat Intelligence reported that exploitation began in January 2026, more than a month before public disclosure. Firewall management consoles control core security infrastructure; when reachable from the internet, a single edge vulnerability can become a direct route into the business network.
Global RDP Botnet & RansomHub Campaign
Impact: 100,000+ IP addresses, multiple organizations compromised
Massive RDP botnet targeting 100+ countries with timing attacks and login enumeration. Coordinated campaign with identical TCP fingerprints led to RansomHub ransomware deployment through password spray attacks. Attackers spent hours attempting logins before successfully compromising credentials.
Jaguar Land Rover (JLR)
Impact: Five-week global production shutdown, 5,000 vehicles/week production loss
CVE-2025-31324 vulnerability in exposed SAP NetWeaver servers allowed attackers to upload webshells and gain remote code execution. Lack of IT/OT segmentation enabled lateral movement from business systems to manufacturing controls, forcing complete shutdown of facilities in UK, Slovakia, Brazil, China, and India.
Indonesian National Data Center
Impact: 210 state institutions disrupted
Brain Cipher ransomware exploited exposed administrative systems, affecting public services and immigration processes nationwide.
Change Healthcare
Impact: 192.7M individuals affected
ALPHV/BlackCat exploited Citrix remote access without MFA. Most consequential healthcare breach in U.S. history.
Boeing Parts & Distribution
Impact: 43GB data leaked
LockBit exploited Citrix Bleed (CVE-2023-4966) vulnerability, bypassing MFA to hijack legitimate sessions.
ICBC (Industrial & Commercial Bank of China)
Impact: U.S. Treasury market disruption
Citrix Bleed exploitation forced ICBC to inject $9 billion and send settlement details via USB messenger.
MOVEit Transfer Mass Breach
Impact: 2,700+ organizations, 95M+ individuals
Cl0p exploited SQL injection vulnerability in MOVEit Transfer, affecting Shell, BBC, British Airways, and 2,700+ organizations.
Log4Shell (Apache Log4j2)
Impact: 93% of cloud environments affected
Critical remote code execution vulnerability in Apache Log4j2, discovered November 2021, affected millions of applications worldwide.
Colonial Pipeline
Impact: 5-day U.S. East Coast shutdown
Compromised VPN password found on dark web allowed DarkSide ransomware access. Legacy account lacked MFA despite not being used.
Microsoft Exchange ProxyLogon
Impact: Thousands of organizations
HAFNIUM APT exploited SSRF vulnerability in Exchange OWA, achieving remote code execution before patches were available.
MongoDB Ransomware Campaign
Impact: 22,900 databases wiped
Automated campaign targeting unsecured MongoDB instances, deleting contents and leaving ransom notes threatening GDPR violations.
NotPetya (Global)
Impact: 200+ countries, critical infrastructure
NotPetya used EternalBlue to spread via SMBv1, destroying data at Maersk ($250-300M), Merck ($870-915M), FedEx ($400M), and Mondelez.
Key Findings - 9+ Years of Evolving Entry Vectors
This comprehensive timeline spans from 2017-2026, showing how entry vectors have evolved. The Verizon 2026 DBIR notes that exploitation of vulnerabilities is now the most common initial access vector for breaches, at 31%. Credential abuse remains critical, representing 13% of initial access vectors and appearing in 39% of breach progression across the full path.
Furthermore, remediation speed is declining: only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, and the median time to fully remediate rose to 43 days. Breaches with third-party involvement reached 48% of total breaches, and ransomware remains a major threat, appearing in 48% of breaches. For SMBs, about 96% of ransomware victims (where organization size was known) were SMBs.
Highest Impact by Cost: NotPetya ($10B+), MOVEit ($65B estimated), WannaCry ($4-8B), Change Healthcare ($2.87B), JLR (£1.9B).
AISMOND Visibility: AISMOND helps teams see and prioritize exposed services, risky assets, abuse signals, geo changes, and listed CVE information where available, helping teams identify vulnerabilities before they are exploited.
Ready to See and Prioritize Your External Exposures?
AISMOND helps teams see and prioritize exposed services, risky assets, abuse signals, geo changes, and listed CVE information where available. Start monitoring your attack surface today.