May 2025 has seen a surge in cyberattacks targeting a wide range of industries. From critical infrastructure and healthcare to fashion and finance, this month’s data breaches reveal troubling trends: increasingly long dwell times, deeper third-party risks, and threat actors leveraging social engineering and ransomware with alarming precision. Below, we break down the most significant incidents you need to know about.
Victoria’s Secret Shuts Down Website Amid Security Incident
Victoria’s Secret temporarily took down its website and some in-store services following a security incident currently under investigation. While store locations remain open, the company has enlisted third-party experts and enacted response protocols to assess the impact and restore operations. CEO Hillary Super told staff that recovery “is going to take awhile.” Although the nature of the breach remains undisclosed, this event comes amid a wave of retail sector cyberattacks, including recent incidents at Dior, Adidas, and several UK retailers. Threat groups like DragonForce and Scattered Spider are suspected in some of these cases.
ConnectWise Confirms Breach Tied to Nation-State Threat Actor
IT software firm ConnectWise disclosed a cyberattack linked to a suspected nation-state actor that compromised its systems and affected a small number of cloud-hosted ScreenConnect customers. The company is investigating the breach with Mandiant and has informed impacted clients while working with law enforcement. The attack appears tied to a critical vulnerability (CVE-2025-3935) patched in April 2025, which could allow remote code execution by exploiting unsafe ASP.NET ViewState deserialization. While ConnectWise hasn’t confirmed the exact exploit path, the flaw may have enabled attackers to steal machine keys and access customer environments. Enhanced monitoring has since been implemented, but limited details and a lack of IOCs have left customers frustrated. Notably, a similar ScreenConnect flaw was exploited by ransomware groups and APTs just last year.
Adidas Confirms Data Breach via Third-Party Vendor
Adidas disclosed that a third-party customer service provider was breached, exposing contact details of consumers who previously reached out to their help desk. The compromised data does not include passwords or payment information. The company has contained the incident, launched a full investigation with cybersecurity experts, and is notifying affected individuals and authorities. Adidas emphasized its ongoing commitment to data privacy and security.
Kettering Health Faces System-Wide Outage After Ransomware Attack
Ohio-based healthcare network Kettering Health suffered a system-wide outage caused by a ransomware attack, forcing the cancellation of elective procedures and disrupting patient services. Emergency rooms and clinics remain operational. The Interlock ransomware group, linked to the Nefarious Mantis threat actor, is believed to be behind the attack and has threatened to leak stolen data unless a ransom is paid. Kettering Health is also warning patients of scam calls requesting payments, though it’s unclear if they’re related to the breach. The organization is investigating and has not confirmed if patient data was compromised.
Coinbase Breach Exposes Data of Nearly 70,000 Customers
Coinbase has confirmed a data breach affecting 69,461 customers, traced to overseas support staff who improperly accessed sensitive user data. While no passwords or crypto keys were compromised, exposed details include names, contact info, partial SSNs, and in some cases, government ID images and transaction history. The attackers demanded a $20 million ransom—which Coinbase refused—and instead launched a $20 million reward fund to identify those responsible. The incident may cost the company up to $400 million in reimbursements and remediation, with social engineering attacks already reported in the aftermath.
SK Telecom Breach Exposes SIM Data of 27 Million Users Over 3-Year Period
SK Telecom, South Korea’s largest mobile provider, revealed that malware remained undetected on its systems from mid-2022 until April 2025, exposing sensitive SIM data of 26.95 million customers. The breach compromised IMSI numbers, USIM keys, and SMS/contact data, increasing SIM-swapping risks. Investigators found 25 malware strains across 23 servers, some containing personal data, though SK Telecom disputes certain findings. The company is issuing SIM replacements, enhancing network security, and pledging full accountability for any resulting harm.
Cyberattack on Arla Foods Disrupts German Production Site
Arla Foods confirmed a cyberattack disrupted operations at its Upahl, Germany facility, leading to product delays and potential cancellations. A company spokesperson addressed the attack saying, “We can confirm that we have identified suspicious activity at our dairy site in Upahl that impacted the local IT network.” The international dairy giant, whose brands include Arla, Lurpak, and Puck, says other sites remain unaffected. While production is being restored, the company has not disclosed whether ransomware or data theft was involved. No group has claimed responsibility. Arla is actively notifying affected customers and expects to resume normal operations within days.
Nova Scotia Power Breach Exposes Sensitive Customer Data
Nova Scotia Power confirmed a cyberattack that led to the theft of sensitive customer data, including names, contact details, account history, and—in some cases—driver’s license numbers, Social Insurance Numbers, and bank account info. Although electricity services were unaffected, internal systems were disrupted. The breach, discovered in late April, actually occurred on March 19, 2025, delaying notification to affected customers. The utility is offering two years of free credit monitoring and warns users to stay alert for phishing attempts. No threat actor has claimed responsibility for the attack.
Cyberattack Forces Production Disruptions at Nucor Corporation
Nucor Corporation, the largest steel producer in the U.S., confirmed a cyberattack that led to unauthorized access and forced parts of its network offline. The company temporarily suspended production at multiple sites and initiated containment measures, including system shutdowns and engaging external cybersecurity experts. While the full impact remains unclear, operations are gradually resuming. Nucor has not disclosed if data was stolen or encrypted, and no ransomware group has claimed responsibility.
Dior Confirms Data Breach Impacting Fashion and Accessories Customers
Luxury brand Dior disclosed a cyberattack that exposed customer data from its Fashion and Accessories division. The breach, discovered on May 7, affected contact information, purchase history, and customer preferences—but not passwords or payment data. Confirmed regions impacted include South Korea and China. Dior is working with cybersecurity experts to investigate and has begun notifying regulators and affected customers. Legal scrutiny has followed in South Korea over delayed disclosures. Customers are advised to watch for phishing attempts and report any suspicious activity.
Findings vs. RiskRecon, UpGuard, and Panorays: A Better Way to Monitor Vendor Risk
As threat actors continue to exploit vulnerabilities across every industry, the need for real-time, continuous risk monitoring has never been more urgent. From ransomware halting steel production to SIM data breaches compromising millions, May’s incidents prove cybersecurity is no longer just an IT issue, it’s a business-critical priority. While legacy platforms like BitSight, SecurityScorecard, RiskRecon, and UpGuard rely heavily on surface-level scans and point-in-time risk scores, Findings takes a fundamentally different approach: real-time telemetry, full cloud visibility, and direct collaboration with vendors. Unlike Panorays or Archer, Findings doesn’t stop at assessments—we automate them, verify evidence, and continuously monitor for drift or exposure. Whether you need visibility into your own environment or across thousands of third-party cloud vendors, Findings CloudVRM gives you instant insight where traditional tools fall short. Ready to upgrade your vendor security? Learn more below!