Data Breach
Nutex Health Filed Under 8.01. Seven Days Later It Filed Under 1.05. The Class Action Landed in Between.
Nutex Health filed a cyber incident under SEC Item 8.01, then converted to Item 1.05 seven days later. A class action arrived in between. What the sequence means for boards.
Take-Two Lost $2.8 Billion. The Hacker Cashed Out $250,000. Nobody Ever Sent a Ransom Note.
CyberLeek leaked GTA VI, pumped a memecoin, and cashed out $250K without ever demanding a ransom. What the first market-monetized extortion means for boards and deal teams.
Operation Epic Fury. Volt Typhoon. BRICS Settlement Rails. Your Portfolio's Cyber Risk Just Became a Geopolitical Position.
The convergence of Operation Epic Fury, Volt Typhoon's pre-positioned access inside US infrastructure, and BRICS de-dollarization is not a geopolitics story. It is a portfolio risk story. Ray Dalio calls this Stage 6 of the Big Cycle — the restructuring phase, where debt-laden empires compete through proxies and economic warfare rather than direct confrontation. Paul Kennedy called the underlying dynamic "imperial overstretch." Jared Diamond would note the resource pressure and institutional fragility. Thomas Friedman would observe that the world is no longer flat. For PE deal teams and portfolio operators, the relevant question is not who wins the geopolitical contest. It is which of your portcos are inside the blast radius of a conflict none of them signed up for.
Instructure Paid Off Its Hackers. The House Homeland Security Committee Wants to Know Why.
On May 12, 2026, Instructure announced a settlement with the ShinyHunters criminal organization that breached its Canvas platform, claiming that all stolen data has been "returned" and that the threat actor has provided "digital confirmation of data destruction." The same day, the House Homeland Security Committee sent a letter to Instructure CEO Steve Daly requesting a briefing on the breach response and on the adequacy of coordination with federal law enforcement and CISA. A settlement is not a resolution. A promise from criminals is not a defensive posture. The pattern of conduct that produced three breaches in eight months has not been addressed. The students at 8,809 schools whose data was taken were not parties to the agreement that supposedly now protects them.
30 Biggest Data Breaches of All Time
Ranked by records: Yahoo, NPD, LinkedIn, Marriott, Canvas, T-Mobile, Equifax, Target, Capital One, Change Healthcare — and the regulatory fallout each produced.
ADT 2026 Breach: Customer Trust Was the Breach
The ADT 2026 breach didn't compromise the alarm systems. It compromised the customer data underneath — and the vishing campaign that followed showed the real risk.
.png)