Sources & verification
Every figure, with its publisher and date.
Cyber Ambush scenarios are written from public reporting. Each statistic, incident and framework reference below was checked against its primary publisher on September 8, 2026, and is reviewed quarterly. Where reporting is contested or a rule is still proposed, that is stated rather than smoothed over.
Threat and cost statistics
Figures quoted on the landing page and in exercise briefings.
IBM — Cost of a Data Breach Report 2026
Global average cost of a data breach $4.99M; United States average $11.5M; one in four malicious breaches AI-enabled.
Verizon — Data Breach Investigations Report (DBIR) 2026
Ransomware present in 48% of breaches; third-party involvement 48%; human element 62%; exploitation of vulnerabilities the top entry point at 31%.
Mandiant / Google Cloud — M-Trends 2026
Global median attacker dwell time 14 days.
CrowdStrike — 2026 Global Threat Report
Average eCrime breakout time 29 minutes.
FBI Internet Crime Complaint Center (IC3) — 2025 Internet Crime Report
Reported losses of $20.9B in 2025, including $3.05B from business email compromise (BEC).
FBI IC3 — 2025 Internet Crime Report
Financial Fraud Kill Chain 2025: 3,900 interventions covering $1.16 billion in attempted theft, with $679 million frozen — a 58 percent success rate.
Regulatory clocks
Notification deadlines used in injects and scored in the after action review.
United States Securities and Exchange Commission (SEC)
Form 8-K Item 1.05 material cybersecurity incident disclosure within 4 business days of a materiality determination.
General Data Protection Regulation (GDPR) Article 33
Personal data breach notification to the supervisory authority within 72 hours of becoming aware.
US Department of Health and Human Services (HHS) — HIPAA Breach Notification Rule
Breach notification without unreasonable delay and no later than 60 days from discovery.
New York Department of Financial Services (NYDFS) Part 500
Notice within 72 hours of determining a cybersecurity incident occurred; 24 hours after an extortion payment; a written explanation of the payment within 30 days.
EU Network and Information Security Directive 2 (NIS2)
Early warning within 24 hours, incident notification within 72 hours.
EU Digital Operational Resilience Act (DORA)
Initial notification of a major information and communications technology (ICT) incident within 4 hours of classification.
Cybersecurity and Infrastructure Security Agency (CISA) — CIRCIA
CIRCIA's 72-hour incident and 24-hour ransom-payment reports remain a PROPOSED rule (notice of proposed rulemaking April 4, 2024). CISA's target for the final rule is September 2026; as of September 8, 2026 no final rule has been published and reporting is voluntary until it takes effect.
State breach notification statutes (survey)
Where US states set a fixed deadline it ranges from 30 to 60 days (California, Colorado, Florida and Washington at 30 days; many at 45 to 60). Roughly 30 states require notice only without unreasonable delay.
Frameworks and exercise doctrine
The standards every objective, inject and finding is traced to.
NIST
NIST Cybersecurity Framework (CSF) 2.0 — six functions and their categories.
NIST Special Publication 800-61r3
Incident response recommendations mapped onto CSF 2.0 functions.
NIST Special Publication 800-84
Test, training and exercise program guidance, including required after action report content.
NIST Special Publication 800-53 Revision 5
Incident response (IR) control family and enhancements as named.
FEMA — Homeland Security Exercise and Evaluation Program (HSEEP)
HSEEP practice: draft after action report about 30 days after the exercise, final AAR/Improvement Plan typically within 60 to 90 days (older HSEEP guidance; agencies set their own deadlines).
CISA
Over 100 CISA Tabletop Exercise Packages (CTEP) available.
Incidents scenarios are modeled on
Each library scenario links here from its “Modeled on” line.
CNN
February 2024: engineering firm Arup's Hong Kong office lost HK$200M (about US$25.6M) after a finance employee joined a video call with deepfaked colleagues, including the CFO.
Replaces an earlier, single-sourced claim about a January 2026 $28M deepfake CFO call, which has been removed from the site.
The Register
Marks & Spencer: customer data of an undisclosed number of its roughly 9.4 million online customers was taken; online orders paused 46 days (April 25 to June 10, 2025); about GBP 300M profit impact.
BleepingComputer
Co-op: help-desk social engineering intrusion in the same 2025 campaign, with member data accessed and stock availability disrupted.
HIPAA Journal
Kettering Health: core Epic electronic health record restored June 2, 2025 (13 days after the May 20 attack); normal operations resumed June 10 (about 3 weeks); 1,695,382 individuals notified.
HIPAA Journal
Brockton Hospital: chemotherapy infusions canceled April 7, 2026, later resumed.
State of Nevada — after action report
Nevada restored services in 28 days after the August 24, 2025 attack and published its after action report on November 5, 2025 (about 10 weeks later); no group publicly claimed responsibility.
City of Saint Paul
Interlock is confirmed only for St. Paul, Minnesota (July 2025); it is not the confirmed actor for the Nevada attack.
Maine Attorney General breach filing
Allianz Life: about 1.5 million individuals affected (1,497,036 per the Maine Attorney General filing).
Huntress
CitrixBleed 2 (CVE-2025-5777), disclosed June 17, 2025; Huntress documented H1 2026 intrusions in which one actor went from exploitation to DragonForce ransomware in under an hour.
CERT Polska
Poland energy sector, December 29, 2025: CERT Polska attributed the activity to the Static Tundra cluster (also tracked as Berserk Bear / Dragonfly, widely linked to FSB Center 16); ESET and Dragos attributed it to Sandworm with medium confidence. No disruption of heat or power supply occurred.
SEC EDGAR — McKesson Form 8-K
McKesson (2026): data exfiltrated August 21 to 25, discovered August 25; attackers vished employees to compromise Okta single sign-on, then reached Salesforce and Snowflake. ShinyHunters claimed about 284 million records (not unique patients) and demanded about $55 million by September 1. McKesson's Form 8-K said materiality was not yet determined.
BleepingComputer
Foxconn: Nitrogen claimed responsibility May 11, 2026; Foxconn confirmed May 12-13; roughly two weeks of disrupted production at Mount Pleasant, Wisconsin and in Texas.
BleepingComputer
Jaguar Land Rover: attack disclosed September 2, 2025; phased production restart from October 8 (about 5 weeks); GBP 196M cost in the July-September quarter; GBP 1.5B UK government loan guarantee.
CISA cybersecurity advisories
CISA #StopRansomware joint advisory AA26-222A on Gunra ransomware (August 10, 2026): initial access via FortiOS/FortiProxy VPN flaws and exposed credentials, backup and log deletion before encryption.
Anomali
Salesloft Drift (UNC6395), August 8-18, 2025: stolen OAuth tokens used to query 700+ customers' Salesforce orgs; Salesforce revoked all Drift tokens August 20.
Palo Alto Networks Unit 42
Shai-Hulud npm worm: first wave September 15-16, 2025; second wave November 24, 2025 affected 25,000 to 27,000+ repositories across about 350 npm accounts.
Instructure
Instructure Canvas: about 8,800 to 9,000 institutions; initial detection April 29, 2026, second wave May 7; agreement including digital confirmation of data destruction announced May 12, 2026.
CISA cybersecurity advisories
Minnesota water utilities (July 26-27, 2026): exposed programmable logic controllers manipulated — Rockwell MicroLogix 1100/1400 and CompactLogix/Micro850, Schneider Modicon M340, Siemens S7-1200.
ConnectWise trust advisories
ConnectWise ScreenConnect advisory of September 3, 2026 on file-transfer behavior across Remote Access, Support and Access sessions (Cloud and On-Premise). Interim mitigation: deselect the TransferFiles / TransferFilesInSession scoped permission for each technician role. ConnectWise said a CVE and a fix would follow within a week, so check the vendor advisory for the CVE and fixed version. Huntress documented two incidents beginning August 20, 2026 and one on August 24, 2026, in which users were tricked into installing rogue clients. Status as of September 8, 2026.
BleepingComputer
Independent reporting on the rogue ScreenConnect clients and the four-stage VBScript chain.
Scenarios are training material, not attribution. Where a threat actor is named in a scenario it reflects the reporting cited here; where responsibility was never publicly claimed or is disputed, the scenario says so and the exercise treats attribution as an open question.