Data Breach
Elsevier Was the Name on the Page. RELX Was the Pattern.
The page was staged Sept 2. The FBI named the credentials in July. LexisNexis, Elsevier's sister company, was breached by the same network in February. RELX has disclosed none of it.
Is Sherpath Hacked? What Happened to Evolve and Elsevier on September 21
Evolve, the sign-in door for Sherpath and HESI, redirected to an extortion page for about two hours on Sept 21. What happened, and what to do if you signed in.
Nutex Health Filed Under 8.01. Seven Days Later It Filed Under 1.05. The Class Action Landed in Between.
Nutex Health filed a cyber incident under SEC Item 8.01, then converted to Item 1.05 seven days later. A class action arrived in between. What the sequence means for boards.
Take-Two Lost $2.8 Billion. The Hacker Cashed Out $250,000. Nobody Ever Sent a Ransom Note.
CyberLeek leaked GTA VI, pumped a memecoin, and cashed out $250K without ever demanding a ransom. What the first market-monetized extortion means for boards and deal teams.
Operation Epic Fury. Volt Typhoon. BRICS Settlement Rails. Your Portfolio's Cyber Risk Just Became a Geopolitical Position.
The convergence of Operation Epic Fury, Volt Typhoon's pre-positioned access inside US infrastructure, and BRICS de-dollarization is not a geopolitics story. It is a portfolio risk story. Ray Dalio calls this Stage 6 of the Big Cycle — the restructuring phase, where debt-laden empires compete through proxies and economic warfare rather than direct confrontation. Paul Kennedy called the underlying dynamic "imperial overstretch." Jared Diamond would note the resource pressure and institutional fragility. Thomas Friedman would observe that the world is no longer flat. For PE deal teams and portfolio operators, the relevant question is not who wins the geopolitical contest. It is which of your portcos are inside the blast radius of a conflict none of them signed up for.
Instructure Paid Off Its Hackers. The House Homeland Security Committee Wants to Know Why.
On May 12, 2026, Instructure announced a settlement with the ShinyHunters criminal organization that breached its Canvas platform, claiming that all stolen data has been "returned" and that the threat actor has provided "digital confirmation of data destruction." The same day, the House Homeland Security Committee sent a letter to Instructure CEO Steve Daly requesting a briefing on the breach response and on the adequacy of coordination with federal law enforcement and CISA. A settlement is not a resolution. A promise from criminals is not a defensive posture. The pattern of conduct that produced three breaches in eight months has not been addressed. The students at 8,809 schools whose data was taken were not parties to the agreement that supposedly now protects them.
.png)