Home Blog TX Tech Sector Threat Brief

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →
CoreRecon Threat Intelligence  •  Tech Sector  •  June 2026

Texas Tech Sector
Under Siege.
2026 Briefing

49 million Dell customer records exposed. AT&T call logs on the dark web. Okta cascading into TX SaaS. Four threat actors with active TX tech campaigns. Here's what you need to know — and what to do about it.

  • Scattered Spider: help desk impersonation bypasses MFA, targets cloud storage and GitHub repos
  • IntelBroker: actively selling TX tech company data on dark web forums — confirmed ongoing sales
  • Volt Typhoon / APT41: pre-positioned inside TX tech supply chains since mid-2022 — sabotage posture, not theft
  • LAPSUS$: social engineering + insider recruitment — confirmed targeting of major tech company source code
Free Security Assessment
📅 June 2026 📊 14 documented TX tech incidents (2023–2026)
49M
Dell customer records
exposed (May 2024)
14
Documented TX tech
incidents (2023–2026)
4
Active threat actor
profiles (Scattered, LAPSUS$, IntelBroker, Volt)
30–60
Avg days from breach
to detection (TX tech)

Austin–Plano–Houston corridor:
high-value, high-volume target

The Austin/Plano/Dallas tech corridor is one of the most concentrated tech ecosystems in the US. Dell (Round Rock), Samsung (Austin), AT&T (Dallas), and hundreds of SaaS companies serving Fortune 500 clients call this region home. That concentration makes it a primary target for threat actors who understand that breaching a single vendor or platform gives them access to thousands of downstream customers.

Why Tech Is Uniquely Exposed
  • Supply chain leverage: One breach cascades to hundreds of customers — Okta 2022/2023, MOVEit, Snowflake prove the cascade model
  • Customer data concentration: Tech companies hold millions of consumer records and B2B contact data in SaaS platforms
  • Federated identity blast radius: OAuth/token compromise at one SaaS grants access across interconnected apps
  • SaaS-to-SaaS attack chains: npm/PyPI supply chain attacks inject malicious code that flows to enterprise customers
Austin/Plano/Houston Corridor Profile
  • Dell Round Rock: 49M customer records (May 2024), 10,863 employee records (Sep 2024) — both via partner API exposure
  • AT&T Dallas: Dark web SSN/passcode sale (Mar 2024), Snowflake call records (Jul 2024) — two distinct incidents, one org
  • Samsung Austin Semiconductor: Employee data + US customer data exfiltrated byINC Ransom (Aug 2024)
  • TX SaaS portcos: Snowflake-attributed compromises hit multiple TX companies in 2024 campaign

TX Tech Incident Database —
2023–2026

14 documented incidents. Scroll or use the filter to find relevant events by attack type or region.

Date Entity Location Records Attack Vector Threat Actor TX Impact
Dec 2020 SolarWinds Austin HQ ~18,000 TX customers affected, CUI, credentials Supply chain injection (SUNBURST backdoor in Orion update) APT / SVR (Russia) ✓ Austin HQ
Jan 2022 Okta (LAPSUS$ breach) San Francisco (TX SaaS cascade) Customer support tool access, 366 customers affected Subcontractor laptop compromise via personal Google account LAPSUS$ ✓ TX SaaS cascade
Oct 2022 Okta (duplicate) Re-used same support tool access from Jan 2022 Same subcontractor access vector persisted LAPSUS$ ✓ TX SaaS cascade
May 2023 MOVEit Transfer (TX cascade) Progress Software (MA, TX SaaS victims) TX HRIS, payroll, benefits admin systems compromised SQL injection (CVE-2023-34362) — zero-day exploit Cl0p / LockBit affiliates ✓ TX SaaS + HRIS cascade
May 2024 Dell Technologies Round Rock, TX ~49 million customer records exposed Partner portal API exposing customer PII without auth Unknown (discovered by researcher) ✓ TX HQ — Round Rock
Aug 2024 Samsung Austin Semiconductor + US customers Austin, TX Employee data + US customer data exfiltrated Unknown initial access, exfil via internal systems INC Ransom ✓ Austin HQ — direct victim
Sep 2024 Dell (second incident) Round Rock, TX 10,863 employee records via internal system exposure Internal system misconfiguration, credentials accessible Unknown ✓ TX HQ — direct victim
Mar 2024 AT&T (dark web SSN/passcode breach) Dallas, TX 73M current + former customer records on dark web Credential stuffing + data broker aggregation — AT&T attributed to 2021 breach ShinyHunters (dark web actor) ✓ Dallas HQ — direct victim
Jul 2024 AT&T (Snowflake call records) Dallas, TX Nearly all AT&T cellular customers — call + text records Snowflake platform breach (MFA not enforced on admin account) UNC5536 (Snowflake campaign) ✓ Dallas HQ — second incident
2023 23andMe (TX user data) South San Francisco (TX users affected) TX user genetic data exposed via credential stuffing wave Credential stuffing (password reuse across platforms) Unknown ✓ TX users — credential stuffing wave
2024 GitHub Actions (TX startups — UNC4902) GitHub (TX startup CI/CD exposure) Source code secrets, OAuth tokens, CI/CD pipeline access GitHub OAuth app token theft via malicious GitHub Actions UNC4902 (UNC Threat Group) ✓ TX startup CI/CD exposure
2023–2024 PyPI / npm (TX Python/JS SaaS supply chain) PyPI + npm registries (TX Python/JS SaaS exposure) Malicious packages exfiltrating env vars, secrets, API keys from CI/CD Typosquatting, dependency confusion, compromised maintainer accounts Multiple threat actors ✓ TX Python/JS SaaS supply chain
2024–ongoing IntelBroker (TX tech company data) Online dark web forum (ongoing) Ongoing sales of TX tech company data, internal credentials, source code Initial access via vulnerability exploitation, insider access purchase IntelBroker ✓ IntelBroker selling TX tech data
2024 Snowflake-attributed TX portcos (multiple) Snowflake platform (TX SaaS companies affected) Customer data, authentication tokens, downstream access Snowflake admin account compromise (no MFA), token reuse across platforms UNC5536 / UNC4899 (attribution to Scattered Spider) ✓ TX SaaS portcos — Snowflake cascade

Four groups with active
TX tech campaigns

Scattered Spider
CRITICAL
English-speaking, Western-origin group. Specializes in help desk impersonation — calls the company's IT help desk pretending to be an employee locked out, uses personal information from prior breaches to pass authentication. Also runs SIM swap attacks. Known for rapid reconnaissance and targeting of cloud storage, GitHub, and collaboration tools. Attribution links to UNC5536 in Snowflake campaign. Targets employees across all seniority levels.
Help desk impersonationSIM swapMFA fatigueCloud storage targetingGitHub/token theft
TX exposure: Snowflake campaign (2024) attributed to Scattered Spider — multiple TX SaaS portcos compromised via stolen Snowflake credentials. AT&T call records (Jul 2024) linked to same campaign.
CoreRecon callout: Scattered Spider's primary leverage is your help desk. Fortress tier includes help desk security controls, call-center fraud detection, and phishing-resistant MFA deployment. CoreRecon's 24/7 SOC monitors for anomalous help desk access patterns.
LAPSUS$
CRITICAL
Known for social engineering + insider recruitment. Group pays employees of target companies for access credentials or VPN tokens. Okta (Jan 2022) — compromised subcontractor's personal Google account, gained access to customer support tool, then used that access to target Okta customers directly. Also targets telecom companies, gaming studios, and retailers. Rapid operational tempo — multiple simultaneous campaigns.
Insider recruitmentSocial engineeringSubcontractor targetingOkta support toolSource code exfil
TX exposure: Okta 2022/2023 incidents directly cascaded to TX SaaS and tech companies via customer support tool access. LAPSUS$ confirms that SaaS platforms are force multipliers — breach one provider, access hundreds of downstream customers.
CoreRecon callout: LAPSUS$ proved that your subcontractor access is your attack surface. Command tier includes vendor/subcontractor security assessments, third-party access reviews, and CIEM (cloud infrastructure entitlement management) to audit who has access to what.
IntelBroker
HIGH
Active breach-as-a-service actor selling company data on dark web forums. Known for claiming credit for breaches at AT&T, Dell, and other major tech companies — selling SSNs, credentials, and internal data to other threat actors. Operates on dark web markets and breach forums. Confirmed selling TX tech company internal data, credentials, and source code. Uses vulnerability exploitation and credential stuffing for initial access.
Breach data salesCredential aggregationVulnerability exploitationDark web distributionOngoing sales
TX exposure: Confirmed selling data from multiple TX tech company breaches via dark web forums. AT&T (73M records) and Dell data attributed to IntelBroker sales listings. Ongoing — not historical.
CoreRecon callout: IntelBroker is your darknet monitoring priority. Sentinel tier includes darknet monitoring for company domains, employee credentials, and exposed API keys. CoreRecon's threat intel team tracks IntelBroker's TX data sales in real time.
Volt Typhoon / APT41
CRITICAL
China MSS operation. Pre-positioning inside US critical infrastructure since mid-2022 — confirmed by CISA, FBI, NSA, and Five Eyes intelligence partners (advisory AA24-038B, Jan 2024). Uses living-off-the-land binaries (LOLBins) that blend into normal network traffic, evading every signature-based detection tool. Goal is sabotage capability, not data theft. Targets tech company supply chains because a compromised SaaS vendor gives access to the vendor's entire customer base.
LOLBin evasionSupply chain targetingPre-positioningSabotage postureChina MSS nexus
TX exposure: Tech companies in the Austin/Plano corridor are in Volt Typhoon's targeting scope via co-location providers, managed service providers, and cloud connectivity. Tech sector supply chain access is a strategic target for disruption scenarios. CISA specifically calls out tech sector as an initial access vector for OT/premises attacks.
CoreRecon callout: Volt Typhoon cannot be detected by traditional signatures. Command tier includes network anomaly detection, LOLBin behavioral analysis, and OT/IT boundary monitoring. CoreRecon's threat hunters run hypothesis-based threat hunts quarterly.

The cascading obligation story:
8 frameworks, all active

Your customers are requiring these frameworks. Your procurement team needs to be ready. One breach may trigger multiple frameworks simultaneously.

Framework Applies To Key Requirement What To Do
SOC 2 Type II All SaaS companies with enterprise customers Annual audit: security, availability, confidentiality, privacy. Continuous monitoring of controls. Engage a CPA firm for Type II audit. CoreRecon covers the security controls that auditors check: access management, change management, monitoring, incident response.
ISO 27001 / 27017 / 27018 Cloud providers, SaaS, enterprise customers requiring international coverage 27001: ISMS. 27017: cloud-specific controls. 27018: PII in cloud. Third-party certified. ISO certification is a procurement requirement for many EU and enterprise customers. CoreRecon maps controls to ISO 27001 and 27017.
FedRAMP Moderate SaaS companies selling to federal agencies, including TX state/local agencies via TX-RAMP Third-party assessment organization (3PAO) assessment, CSP package, agency authorization. FedRAMP Moderate is a prerequisite for federal agency contracts. If you sell to any government entity, TX-RAMP is the Texas state equivalent (launched 2024). CoreRecon's Command tier covers FedRAMP/TX-RAMP readiness.
TX-RAMP Companies selling SaaS to Texas state agencies and local governments TX Risk and Authorization Management Program — similar to FedRAMP at state level. Required for TX public sector contracts. Assess applicability against your customer base. CoreRecon maps TX-RAMP requirements and helps build the SSP and POA&M.
CMMC L2 Companies handling CUI for DoD contractors (includes SaaS serving defense contractors) 110 controls from NIST 800-171. Third-party assessment required by Nov 10, 2026 for many contractors. If any customer is a defense contractor, your handling of their data may require CMMC L2. CoreRecon covers CMMC L2 controls in our DoD contractor packages.
HIPAA SaaS companies with healthcare customers (BAA required if PHI processed) Business Associate Agreement required. Breach notification within 60 days. Security, technical, and administrative safeguards. If you have healthcare clients, you need a BAA. Breach of your platform becomes a HIPAA reportable event for your healthcare customers. CoreRecon covers HIPAA controls in our Healthcare tier.
PCI DSS v4.0.1 SaaS companies processing payment card data (enterprise B2B platforms with payment flows) 12 requirements, 64 base requirements, growing to 70+ in v4.0.1 mandatory updates. Requires formal risk assessment annually. For SaaS companies that process payments on behalf of clients, PCI DSS may apply at a merchant level. CoreRecon can scope and assess PCI applicability.
GDPR / CPRA / TDPSA SaaS companies with EU users (GDPR), California residents (CPRA), TX residents (TDPSA) GDPR: EU residents — 72-hr breach notification, DPO required. CPRA: CA residents — right to delete, opt-out. TDPSA: TX residents — data broker obligations, breach notification. TX TDPSA (effective July 2024) is the newest Texas data privacy law. Data broker registration, consumer rights requests, breach notification timelines. GDPR and CPRA are standard for any SaaS with broad consumer or enterprise use. CoreRecon's privacy compliance support covers all three.
SEC Item 1.05 Publicly traded tech companies (pre-IPO companies with SEC filings) Material cybersecurity incidents must be disclosed in 4 business days (Form 8-K). Annual disclosure of cyber risk management. If you're public or near-IPO, SEC Item 1.05 means your breach notification clock is 4 business days — not the GDPR 72 hours. The IR plan has to be ready before a breach, not after. CoreRecon's Command tier includes SEC Item 1.05 IRP documentation.

6 vectors unique to the
tech sector attack surface

🔑
A. Secrets in Repos & CI/CD Pipelines
GitHub, GitLab, Bitbucket, and CI/CD pipelines are primary exfiltration targets. Hardcoded AWS keys, API tokens, database credentials, and service account tokens in code or pipeline configs give attackers lateral movement without needing to breach the application itself.
  • Run GitGuardian, TruffleHog, or Gitleaks across all repos — audit what secrets are exposed in current code
  • Move all secrets to AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault
  • Rotate every credential found in any repo — assume it's compromised
  • Enforce branch protection + require secret scanning in pre-commit hooks and CI pipelines
  • Audit CI/CD service accounts (GitHub Actions, CircleCI, Jenkins) — principle of least privilege
🔗
B. OAuth Token Theft & IDP Federation Abuse
OAuth/OIDC federation means one compromised identity provider or OAuth app grants attackers access across your entire SaaS stack. Okta 2022/2023 incidents, Snowflake campaign, and GitHub Actions UNC4902 all used OAuth token theft as the initial access vector.
  • Enforce MFA on all IdP admin accounts (Okta, Azure AD, Google Workspace)
  • Audit all OAuth apps with "highly privileged" permissions — remove unused integrations
  • Implement OAuth token lifetime limits — 1-hour access tokens for high-sensitivity apps
  • Enable token binding — correlate OAuth tokens with device/hardware security keys
  • Monitor for anomalous OAuth app installs — especially in GitHub org and cloud console
📦
C. npm / PyPI Supply Chain Attacks
Typosquatting (e.g., `reqests` vs `requests`), dependency confusion, and compromised maintainer accounts inject malicious packages into your build pipeline. These packages exfiltrate environment variables, secrets, and API keys at CI/CD build time — before your code even runs in production.
  • Use lock files (package-lock.json, pip.lock) — never install from unpinned versions
  • Run Sonatype Nexus, JFrog Xray, or Snyk to scan every dependency for known malware
  • Enable GitHub Dependabot or Renovate Bot for automated dependency updates
  • Monitor for new maintainers on your critical packages — ownership changes are a known compromise signal
  • Pin to known-good SHA hashes for dependencies in package.json
🔄
D. SaaS-to-SaaS OAuth Scope Abuse
A single OAuth integration between two SaaS platforms creates an implicit trust chain. If your CRM grants read/write access to your email platform, and your email platform gets compromised, attackers inherit CRM access. The Okta 2022 and Snowflake incidents both demonstrate how third-party integrations amplify initial access.
  • Map every SaaS-to-SaaS integration and document OAuth scopes granted
  • Apply principle of least OAuth scope — if a Salesforce integration only needs read access, don't grant write
  • Review OAuth token lifetimes per connected app — revoke tokens for deprecated integrations
  • Monitor connected app activity for unusual data access patterns in SIEM
  • Disable integrations for departed employees — access persistence is a known attack vector
🏢
E. Customer-Tenant Blast Radius
Multi-tenant SaaS platforms mean one customer's breach can expose another customer's data if tenant isolation is insufficient. Snowflake's platform-wide breach happened because one customer's admin credentials were used to access data across the platform. Your architecture decisions determine your blast radius.
  • Audit tenant isolation — confirm row-level security, data partitioning, and access controls per tenant
  • Ensure database credentials are unique per customer or customer cohort
  • Monitor cross-tenant data access patterns in your data warehouse or analytics platform
  • Build customer notification workflow — TDPSA requires notification within 60 days; GDPR requires 72 hours
  • Conduct architecture review with your security team or CoreRecon for tenant isolation gaps
🤖
F. AI / LLM Prompt Injection & Model Exfil
AI-native startups building on LLMs face novel attack surfaces: prompt injection (malicious user input alters AI behavior to exfiltrate data), model exfiltration attempts, training data poisoning, and RAG (Retrieval-Augmented Generation) vector database attacks. These are early-stage but growing threats as AI-native apps scale.
  • Implement input sanitization and output validation on all LLM integrations — treat user input as untrusted
  • Restrict LLM access to system commands and data stores — use least privilege at the tool/function level
  • Monitor for prompt injection attempts in application logs — anomalous user inputs with system-level instructions
  • Audit RAG vector database access controls — ensure customer data is not inadvertently retrievable by other tenants
  • Conduct LLM red team testing before production deployment — OWASP LLM Top 10 is the baseline

30/60/90-day roadmap —
50–500 employee TX tech companies

24 concrete checklist items. Prioritized by impact and urgency for tech companies in the Austin/Plano/Dallas/Houston corridor.

  • 1
    Enforce phishing-resistant MFA on all cloud and code platform accounts
    Okta 2022, Snowflake, AT&T — MFA would have stopped all three. Deploy FIDO2 passkeys or hardware security keys for all engineers and admin accounts.
  • 2
    Rotate all service account credentials and API keys
    GitHub Actions tokens, AWS IAM access keys, CI/CD service accounts. Assume any credential that touched a public repo is compromised. Rotate immediately and audit rotation policy.
  • 3
    Enable darknet monitoring for company domains and executive email addresses
    IntelBroker sells company data. Darknet monitoring gives you advance warning when your data appears in breach forums before it becomes a customer notification crisis.
  • 4
    Audit secrets in CI/CD pipelines — find and remediate exposed credentials
    Run TruffleHog or GitGuardian across all repos. Every hardcoded credential found is a compromised credential. Move to Vault or cloud-native secrets management.
  • 5
    Enable vendor and device certificate pinning for internal tools
    Reduces risk of man-in-the-middle attacks on internal APIs. For SaaS platforms with internal tooling, ensure TLS everywhere and certificate validation is enforced.
  • 6
    Audit all OAuth apps and integrations — remove unused or over-privileged grants
    OAuth is the attack chain multiplier. Review every connected app in Okta/Azure/Google Workspace. Remove anything that doesn't have a current business justification.
  • 7
    Enforce branch protection and require security scanning in CI/CD
    GitHub/GitLab: require PR reviews, enable Dependabot, add secrets scanning in pre-merge pipelines. Every commit should be scanned before it lands in main.
  • 8
    Create and test an incident response plan — document the first 4 hours
    SEC Item 1.05 requires 4 business day disclosure. If you don't have a documented IR plan, the clock starts badly. Document containment, forensics, legal, and customer notification steps now.
  • 9
    Implement least-privilege OAuth token scopes per application
    Map every SaaS integration and audit the scopes granted. If a Salesforce integration only needs read access to contacts, don't grant admin or write access. Scopes are the blast radius.
  • 10
    Lock down third-party app integrations — enumerate and review every OAuth grant
    Use OAuth scope audit tools or your IdP's connected apps dashboard. Create a quarterly review cadence for all OAuth grants.
  • 11
    Enable SaaS endpoint detection and response (EDR) on all developer workstations and production servers
    Tech companies have large attack surfaces on developer machines (access to prod, CI/CD, secrets). EDR on every endpoint is non-negotiable — Sentinel tier covers this.
  • 12
    Deploy Secrets Manager (AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault) for all credentials
    Move every API key, database password, and service account token out of code and config files. This is the most critical CI/CD security improvement for tech companies.
  • 13
    Implement SSH key rotation policy — no static SSH keys for production access
    Replace static SSH keys with ephemeral certificates via HashiCorp Vault or cloud-native certificate authority. Static SSH keys persist for years — they're a common lateral movement vector.
  • 14
    Enable cloud provider security health alerts (AWS Security Hub, GCP Security Command Center, Azure Defender)
    Configure alerts for: root account usage, public S3 buckets, security group changes, IAM policy modifications, and unusual API calls. 24/7 SOC should receive these alerts immediately.
  • 15
    Conduct SaaS-to-SaaS integration audit — map the OAuth trust chain
    Document every integration: which SaaS connects to which, what scopes are granted, what data is accessible. This becomes your tenant isolation and supply chain risk map.
  • 16
    Implement package lock files + dependency scanning in all CI/CD pipelines
    Pin every npm and PyPI dependency to a known-good version via lock files. Integrate Sonatype Nexus, Snyk, or GitHub Dependabot to flag known-vulnerable packages at build time.
  • 17
    Conduct a full penetration test — specifically test OAuth abuse and supply chain attack paths
    Standard pen tests often miss OAuth token abuse and supply chain attack scenarios. Request a specific OAuth abuse scenario and a simulated npm/PyPI compromise in scope.
  • 18
    Implement SBOM (Software Bill of Materials) generation for all build pipelines
    SBOMs are becoming a procurement requirement (SEC, FedRAMP, enterprise contracts). Generate SBOMs for every release and store them with the artifact. SPDX or CycloneDX format.
  • 19
    Establish formal incident response plan with tabletop exercise — test the first 4-hour playbook
    Run a tabletop exercise with the engineering team, legal, and executive stakeholders. Test containment procedures, legal notification timelines (SEC 1.05 = 4 days; GDPR = 72 hours), and customer notification workflow.
  • 20
    Enroll in threat intelligence feeds — FS-ISAC, CISA AIS, or comparable sector feeds
    Sector-specific threat intel (FS-ISAC for fintech-adjacent tech, CISA AIS for all) gives your SOC early warning on campaigns targeting your vertical. IntelBroker, Scattered Spider, and Volt Typhoon TTPs are in these feeds.
  • 21
    Assess FedRAMP Moderate / TX-RAMP applicability — determine if either is required for your customer base
    If you sell to federal agencies or Texas state/local government customers, FedRAMP/TX-RAMP is a contract requirement, not an optional enhancement. CoreRecon's Command tier includes FedRAMP readiness assessments.
  • 22
    Implement customer-tenant isolation audit — confirm multi-tenant data separation is enforced
    Snowflake demonstrated that insufficient tenant isolation turns one breach into many. Audit your architecture: database credentials per customer, row-level security enforcement, cross-tenant query monitoring.
  • 23
    Conduct LLM red team testing and AI security review if you have AI-native product features
    OWASP LLM Top 10 is the baseline. Test: prompt injection, data exfiltration via model outputs, RAG vector database access controls, and model exfiltration scenarios.
  • 24
    Document and test SEC Item 1.05 disclosure workflow with legal counsel
    If you're public or near-IPO: material cyber incident disclosure in 4 business days. This requires pre-built disclosure templates, legal review workflow, and board communication procedures — not something you build during a breach.

Start with your
next move

🔒
Free Security Assessment
15-minute call with a CoreRecon security architect. Map your exposure against the TX tech threat landscape and get a prioritized remediation roadmap.
Get My Assessment →
📊
Cyber Insurance Estimator
Find out what controls reduce your cyber insurance premium. Get a premium range estimate based on your current security posture — takes 3 minutes.
Estimate My Premium →
Tech Vertical Landing Page
Full coverage model for Austin/Plano/Dallas/Houston tech companies. Dev-laptop model, SaaS pricing, vCISO options, customer proof points.
View Tech Sector Page →
SDVOSB Certified
24/7 Texas-based SOC
Austin / Dallas / Houston coverage
15-minute response SLA
No long-term contracts
CoreRecon Texas Tech Sector Cyber Threat Brief 2026
Sources: CISA KEV Catalog, FBI IC3, MS-ISAC, FS-ISAC, MITRE ATT&CK, IBM X-Force Threat Intelligence Index 2026, CrowdStrike 2026 Global Threat Report, Mandiant M-Trends 2026, Dell breach disclosure (May 2024), AT&T breach notifications (Mar 2024, Jul 2024), Samsung Austin Semiconductor INC Ransom disclosure (Aug 2024), Okta security notices (Jan 2022, Oct 2022), CISA AA24-038B (Volt Typhoon advisory, Jan 2024), SEC Item 1.05 Final Rule (Dec 2023). Research Report ID: 1301074.
Last updated: June 16, 2026. Threat intelligence current as of publication date.