Sources & verification

Every figure, with its publisher and date.

Cyber Ambush scenarios are written from public reporting. Each statistic, incident and framework reference below was checked against its primary publisher on September 8, 2026, and is reviewed quarterly. Where reporting is contested or a rule is still proposed, that is stated rather than smoothed over.

Threat and cost statistics

Figures quoted on the landing page and in exercise briefings.

IBM — Cost of a Data Breach Report 2026

Published July 29, 2026Verified September 8, 2026

Global average cost of a data breach $4.99M; United States average $11.5M; one in four malicious breaches AI-enabled.

Verizon — Data Breach Investigations Report (DBIR) 2026

Published May 19, 2026Verified September 8, 2026

Ransomware present in 48% of breaches; third-party involvement 48%; human element 62%; exploitation of vulnerabilities the top entry point at 31%.

Mandiant / Google Cloud — M-Trends 2026

Published March 23, 2026Verified September 8, 2026

Global median attacker dwell time 14 days.

CrowdStrike — 2026 Global Threat Report

Published February 24, 2026Verified September 8, 2026

Average eCrime breakout time 29 minutes.

FBI Internet Crime Complaint Center (IC3) — 2025 Internet Crime Report

Published April 7, 2026Verified September 8, 2026

Reported losses of $20.9B in 2025, including $3.05B from business email compromise (BEC).

FBI IC3 — 2025 Internet Crime Report

Published April 7, 2026Verified September 8, 2026

Financial Fraud Kill Chain 2025: 3,900 interventions covering $1.16 billion in attempted theft, with $679 million frozen — a 58 percent success rate.

Regulatory clocks

Notification deadlines used in injects and scored in the after action review.

United States Securities and Exchange Commission (SEC)

Published Final rule, 2023Verified September 8, 2026

Form 8-K Item 1.05 material cybersecurity incident disclosure within 4 business days of a materiality determination.

General Data Protection Regulation (GDPR) Article 33

Published In force since 2018Verified September 8, 2026

Personal data breach notification to the supervisory authority within 72 hours of becoming aware.

US Department of Health and Human Services (HHS) — HIPAA Breach Notification Rule

Published Current ruleVerified September 8, 2026

Breach notification without unreasonable delay and no later than 60 days from discovery.

New York Department of Financial Services (NYDFS) Part 500

Published Amended rule, currentVerified September 8, 2026

Notice within 72 hours of determining a cybersecurity incident occurred; 24 hours after an extortion payment; a written explanation of the payment within 30 days.

EU Network and Information Security Directive 2 (NIS2)

Published Directive (EU) 2022/2555Verified September 8, 2026

Early warning within 24 hours, incident notification within 72 hours.

EU Digital Operational Resilience Act (DORA)

Published Regulation (EU) 2022/2554Verified September 8, 2026

Initial notification of a major information and communications technology (ICT) incident within 4 hours of classification.

Cybersecurity and Infrastructure Security Agency (CISA) — CIRCIA

Published NPRM April 4, 2024Verified September 8, 2026

CIRCIA's 72-hour incident and 24-hour ransom-payment reports remain a PROPOSED rule (notice of proposed rulemaking April 4, 2024). CISA's target for the final rule is September 2026; as of September 8, 2026 no final rule has been published and reporting is voluntary until it takes effect.

State breach notification statutes (survey)

Published Current statutesVerified September 8, 2026

Where US states set a fixed deadline it ranges from 30 to 60 days (California, Colorado, Florida and Washington at 30 days; many at 45 to 60). Roughly 30 states require notice only without unreasonable delay.

Frameworks and exercise doctrine

The standards every objective, inject and finding is traced to.

NIST

Published February 26, 2024Verified September 8, 2026

NIST Cybersecurity Framework (CSF) 2.0 — six functions and their categories.

NIST Special Publication 800-61r3

Published April 2025Verified September 8, 2026

Incident response recommendations mapped onto CSF 2.0 functions.

NIST Special Publication 800-84

Published 2006, still currentVerified September 8, 2026

Test, training and exercise program guidance, including required after action report content.

NIST Special Publication 800-53 Revision 5

Published Current revisionVerified September 8, 2026

Incident response (IR) control family and enhancements as named.

FEMA — Homeland Security Exercise and Evaluation Program (HSEEP)

Published Current doctrineVerified September 8, 2026

HSEEP practice: draft after action report about 30 days after the exercise, final AAR/Improvement Plan typically within 60 to 90 days (older HSEEP guidance; agencies set their own deadlines).

CISA

Published Current catalogVerified September 8, 2026

Over 100 CISA Tabletop Exercise Packages (CTEP) available.

Incidents scenarios are modeled on

Each library scenario links here from its “Modeled on” line.

CNN

Published May 16, 2024Verified September 8, 2026

February 2024: engineering firm Arup's Hong Kong office lost HK$200M (about US$25.6M) after a finance employee joined a video call with deepfaked colleagues, including the CFO.

Replaces an earlier, single-sourced claim about a January 2026 $28M deepfake CFO call, which has been removed from the site.

The Register

Published 2025 reportingVerified September 8, 2026

Marks & Spencer: customer data of an undisclosed number of its roughly 9.4 million online customers was taken; online orders paused 46 days (April 25 to June 10, 2025); about GBP 300M profit impact.

BleepingComputer

Published 2025 reportingVerified September 8, 2026

Co-op: help-desk social engineering intrusion in the same 2025 campaign, with member data accessed and stock availability disrupted.

HIPAA Journal

Published 2025 reportingVerified September 8, 2026

Kettering Health: core Epic electronic health record restored June 2, 2025 (13 days after the May 20 attack); normal operations resumed June 10 (about 3 weeks); 1,695,382 individuals notified.

HIPAA Journal

Published 2026 reportingVerified September 8, 2026

Brockton Hospital: chemotherapy infusions canceled April 7, 2026, later resumed.

State of Nevada — after action report

Published November 5, 2025Verified September 8, 2026

Nevada restored services in 28 days after the August 24, 2025 attack and published its after action report on November 5, 2025 (about 10 weeks later); no group publicly claimed responsibility.

City of Saint Paul

Published July 2025Verified September 8, 2026

Interlock is confirmed only for St. Paul, Minnesota (July 2025); it is not the confirmed actor for the Nevada attack.

Maine Attorney General breach filing

Published 2025 filingVerified September 8, 2026

Allianz Life: about 1.5 million individuals affected (1,497,036 per the Maine Attorney General filing).

Huntress

Published 2026 reportingVerified September 8, 2026

CitrixBleed 2 (CVE-2025-5777), disclosed June 17, 2025; Huntress documented H1 2026 intrusions in which one actor went from exploitation to DragonForce ransomware in under an hour.

CERT Polska

Published December 2025 / January 2026Verified September 8, 2026

Poland energy sector, December 29, 2025: CERT Polska attributed the activity to the Static Tundra cluster (also tracked as Berserk Bear / Dragonfly, widely linked to FSB Center 16); ESET and Dragos attributed it to Sandworm with medium confidence. No disruption of heat or power supply occurred.

SEC EDGAR — McKesson Form 8-K

Published September 2026Verified September 8, 2026

McKesson (2026): data exfiltrated August 21 to 25, discovered August 25; attackers vished employees to compromise Okta single sign-on, then reached Salesforce and Snowflake. ShinyHunters claimed about 284 million records (not unique patients) and demanded about $55 million by September 1. McKesson's Form 8-K said materiality was not yet determined.

BleepingComputer

Published May 2026Verified September 8, 2026

Foxconn: Nitrogen claimed responsibility May 11, 2026; Foxconn confirmed May 12-13; roughly two weeks of disrupted production at Mount Pleasant, Wisconsin and in Texas.

BleepingComputer

Published September-October 2025Verified September 8, 2026

Jaguar Land Rover: attack disclosed September 2, 2025; phased production restart from October 8 (about 5 weeks); GBP 196M cost in the July-September quarter; GBP 1.5B UK government loan guarantee.

CISA cybersecurity advisories

Published August 2026Verified September 8, 2026

CISA #StopRansomware joint advisory AA26-222A on Gunra ransomware (August 10, 2026): initial access via FortiOS/FortiProxy VPN flaws and exposed credentials, backup and log deletion before encryption.

Anomali

Published August 2025Verified September 8, 2026

Salesloft Drift (UNC6395), August 8-18, 2025: stolen OAuth tokens used to query 700+ customers' Salesforce orgs; Salesforce revoked all Drift tokens August 20.

Palo Alto Networks Unit 42

Published 2025 reportingVerified September 8, 2026

Shai-Hulud npm worm: first wave September 15-16, 2025; second wave November 24, 2025 affected 25,000 to 27,000+ repositories across about 350 npm accounts.

Instructure

Published May 12, 2026Verified September 8, 2026

Instructure Canvas: about 8,800 to 9,000 institutions; initial detection April 29, 2026, second wave May 7; agreement including digital confirmation of data destruction announced May 12, 2026.

CISA cybersecurity advisories

Published July 2026Verified September 8, 2026

Minnesota water utilities (July 26-27, 2026): exposed programmable logic controllers manipulated — Rockwell MicroLogix 1100/1400 and CompactLogix/Micro850, Schneider Modicon M340, Siemens S7-1200.

ConnectWise trust advisories

Published September 3, 2026Verified September 8, 2026

ConnectWise ScreenConnect advisory of September 3, 2026 on file-transfer behavior across Remote Access, Support and Access sessions (Cloud and On-Premise). Interim mitigation: deselect the TransferFiles / TransferFilesInSession scoped permission for each technician role. ConnectWise said a CVE and a fix would follow within a week, so check the vendor advisory for the CVE and fixed version. Huntress documented two incidents beginning August 20, 2026 and one on August 24, 2026, in which users were tricked into installing rogue clients. Status as of September 8, 2026.

BleepingComputer

Published September 2026Verified September 8, 2026

Independent reporting on the rogue ScreenConnect clients and the four-stage VBScript chain.

Scenarios are training material, not attribution. Where a threat actor is named in a scenario it reflects the reporting cited here; where responsibility was never publicly claimed or is disputed, the scenario says so and the exercise treats attribution as an open question.