Entertainment & Media — Cyber Threat Activity
Entertainment and media holds no recorded incidents in our log and the thinnest actor graph of any sector here, with 5 groups carrying a researched association including Lazarus Group, ShinyHunters, FIN8 and Fog Ransomware. Treat this page as a sparse view rather than an assessment. The sector's documented history is nonetheless distinctive, because it produced the clearest example of a state attacking a company over content: North Korean operators destroyed systems at a film studio and leaked its internal material in retaliation for a film, which established that a media company's editorial decisions can themselves provoke a national-level response. The commercial threat is more ordinary and more constant. Studios and production companies hold unreleased films, series and games whose value collapses the moment they leak, which gives extortion crews leverage that does not depend on encryption at all, and post-production, visual effects, dubbing and distribution partners hold the same assets with far weaker controls. Streaming platforms and ticketing operators concentrate consumer payment and identity data at a scale that attracts credential-stuffing and bulk exfiltration rather than ransomware. Talent agencies and management firms hold personal information about individuals who are themselves targets. The near-absence of records for this sector reflects a classification gap in our corpus as much as anything else, since many entertainment victims are recorded under technology, retail or business services, and the malware and actor associations shown are drawn from published research on each group rather than from incidents we have attributed.
- Recorded incidents: 186
- Incidents, trailing 180 days: 8
- Tracked threat actors: 29
- Malware families: 38
Recent incidents
- Ceska filharmonie 2026-07-23
- Phi 2026-07-17
- Immling 2026-07-01
- Madison Square Garden Sports 2026-06-05
- My Lovely AI 2026-04-07
- Fondation Boghossian 2026-03-27
- Irec Sas 2026-03-13
- Crunchyroll 2026-03-12
- NEW GENERATION MEDIA 2026-03-04
- IDH Entertainment 2026-03-02
- Phoenix Art Museum 2026-02-12
- De Gruyter Brill 2026-02-07
- Parente Fireworks 2026-02-06
- MBC 2026-01-30
- VERTIGORELEASING.COM 2026-01-25
- veenkoloniaalmuseum.nl 2026-01-20
- Wild Bunch Distribution 2026-01-05
- Scenic Solutions 2025-12-22
- Club Atlético River Plate 2025-12-19
- SoundCloud 2025-12-15
Threat actors targeting Entertainment & Media
- Qilin 11 incidents
- Akira 5 incidents
- Play Ransomware 4 incidents
- RansomHub 4 incidents
- FunkSec 3 incidents
- INC Ransom 3 incidents
- KillSec 3 incidents
- Medusa Ransomware 3 incidents
- BlackSuit 2 incidents
- Cactus 2 incidents
- Cl0p 2 incidents
- Hunters International 2 incidents
- LockBit 2 incidents
- Lynx Ransomware 2 incidents
- Rhysida 2 incidents
- The Gentlemen 2 incidents
- Fog Ransomware 1 incident
- 8Base 1 incident
- DragonForce 1 incident
- Handala 1 incident
- Meow 1 incident
- Nova 1 incident
- RansomHouse 1 incident
- SafePay 1 incident
Where these victims are
- United States 24
- United Kingdom 6
- France 5
- Italy 4
- Germany 3
- Netherlands 3
- Australia 2
- Canada 2
- Japan 2
- Argentina 1
- Belgium 1
- Bulgaria 1
Malware used against Entertainment & Media
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Impacket Tool
- PsExec Tool
- WannaCry Malware
- Responder Tool
- AppleJeus Malware
- AuditCred Malware
- BADCALL Malware
- BADHATCH Malware
- Bankshot Malware
- BLINDINGCAN Malware
- Cryptoistic Malware
- Dacls Malware
Coverage. 95.5% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.