
Image via Fortune
Last updated
Michigan Department of Environment, Great Lakes, and Energy: Cybersecurity Incident
Nine water systems in Michigan were targeted by cyberattacks, with nine systems impacted. Attacks involved operational technology and remote monitoring systems. Incident follows similar attacks on 30+ Minnesota water systems. Iranian hackers suspected by federal agencies.
Source: Fortune
The leadership read
A breach is a governance event before it is a technical one. For Michigan Department of Environment, Great Lakes, and Energy in the sector, the hiring consequence is rarely more engineers; it is senior accountability, security, risk and data governance reporting high enough to change decisions. Across Americas, watch whether the response is a hire or a contractor; that distinction says how the board has read it.
Market context: The wider read — a Talent Market Index of 102.5 (Warm), down 1.7 month-on-month — shows Americas signal flow easing (-2.3pts).
Michigan Department of Environment, Great Lakes, and Energy: 1 signal in the last 90 days.
More signals across Americas
Cybersecurity Incident · Americas
Sentry →Publicly exposed Sentry Data Source Names (DSNs) were exploited as an attack vector via AI coding agents (Claude Code, Cursor) through Model Context Protocol integrations to achieve remote code execution and credential exfiltration. Attack succeeded 85% of the time across 100+ organizations; 2,388 organizations identified with publicly discoverable DSNs including 71 in Tranco top-1M and ~27% of Fortune 1000 via Cloudflare MCP alone. Sentry notified June 3, 2026; deployed content filter by June 12 but declined platform-level root-cause remediation.
Cybersecurity Incident · Americas
Kaiser Permanente →Kaiser Permanente patient suffered wrongful hysterectomy due to pathology lab sample labeling error and misidentification, resulting in false cancer diagnosis and months of unnecessary treatment
Cybersecurity Incident · Americas
Point72 →Point72 was targeted in a social engineering campaign by threat actor UNC6671, in which attackers impersonated IT help desk staff via phone calls to employees' personal devices, attempting to steal credentials and MFA tokens for unauthorized cloud access.
Cybersecurity Incident · Americas
Two Sigma →Two Sigma was targeted in a social engineering campaign by threat actor UNC6671, in which attackers impersonated IT help desk staff via phone calls to employees' personal devices, attempting to steal credentials and MFA tokens for unauthorized cloud access.
Cybersecurity Incident · Americas
CME Group →Hackers devised phishing websites targeting employee credentials at CME Group and multiple other major financial institutions and private equity firms. Attack coordinated by threat actors operating under names including Redact, Pink, Falcon and Helix.
Cybersecurity Incident · Americas
Levi Strauss & Co. →Levi Strauss & Co. confirmed that hackers used social engineering to compromise three employees and steal corporate data from their machines.
Intelligence powered by Autonodal ↗
