Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.
0
Data-Leaking Ransomware Attacks Tracked This Month
0
Data-Leaking Ransomware Attacks Tracked This Year



Tuesday, 25 August 2026

Ransomware Operator Claims - Week 34 2026

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 17th August and 23rd August 2026, kindly assisted by our partners.

DBD discovered and researched 251 Ransomware Victims over 48 Countries and Islands claimed by 48 Data-Leaking Ransomware Operators, including 3 Newly Discovered Ransomware Operators last week.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Monday, 24 August 2026

Data Breaches Digest - Week 35 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 24th August and 30th August 2026.


📅 29th August

Cl0p Ransomware Hits Shell, GE, Philips via PTC Bug

Critical Gogs Path Traversal Flaw Enables Remote Code Execution via Git Hooks

Hackers Steal €152,000 From Crete Regional Authority in Elaborate Bank Fraud Scheme

Second-hand ticket marketplace Tixel confirms customer information stolen in data breach

Microsoft Warns TerminalFix ClickFix Campaign Uses Fake CAPTCHA to Deploy Reverse Tunnel

Over 335 Million records breached as cyber attacks rise in the Philippines in H1 2026

Ransomware group says it stole Berlin data, offers it for auction

Supply Chain Worm Hits Popular TanStack Query Code Generator to Steal Developer Credentials

TA4922 Hackers Use Tax Phishing to Deploy PackClient RAT Across Asia

📅 28th August

8.7 million customers’ data accessed in cyber attack against three UK airports - including one in the Midlands

8.7 million people exposed in Manchester Airports Group cyber attack

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

700 OpenAI AI Agents Coordinate Hugging Face Hack and Achieve Remote Code Execution

A Backup Isn’t Enough: How Small Businesses Can Recover From Ransomware

AI Agent Instruction Files Let Attackers Execute Code Inside Fortune 500 Networks

AI Ransomware Can Now Run Much of an Attack Without Human Help

AI scams make phishing harder to spot

Alan Gordon Data Breach Exposes Social Security Numbers

American Vision Partners Settles Data Breach Litigation for $1.75 Million

Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping

Android 17 Adds OS-Wide Encrypted Client Hello (ECH) to Hide Website Visits From Network Providers

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Arrests Hinder TeamPCP, But the Threat is Still Out There, Researchers Say

ATF Confirms Cyber Incident After Ransomware Group Claims Attack

ATF confirms cyberattack hit system containing info on its investigation targets

ATF Confirms Major Cyber Incident Amid Qilin Claim

ATF declares cyberattack a ‘major incident’ after ransomware claim

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Aurora ransomware actors leverage AI tool for exploitation campaigns

Aurora ransomware gang used Cursor to speed up attacks: 30% to 50% faster intrusions

Aur0ra ransomware tricked Cursor's AI agent into hacking seven companies

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Castle Point Council sees personal information data breach

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Chinese-Speaking Hackers Target Indian Firms With Hindi Tax Phishing

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

Cyber Attack Hits Manchester Airport Group as Data of 8.7 Million Customers Accessed

Cyber attack targeted customers at Stansted Airport

Cyber Threats Explained: What They Are and Why They’re Growing

Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers

Cyberattack on UK Airport Operator Manchester Airports Group (MAG) Exposes Data of 8.7 Million Customers Across Three Airports

Cybersecurity alert: phishing campaigns increasingly target hotel staff

East Midlands Airport hackers demand ransom after passenger data stolen

Encryption Expiration: How AI and Quantum are Defining New Boundaries for Data Security

Epic MyChart Phishing Scam Hits Health Systems: What Providers Should Do

Europe’s Cyber Risk: Ransomware and Critical Systems

Fake Indeed apps infecting Android-using job seekers with malware

Fake North Korean IT workers are rampant: Here’s how to spot the telltale signs a new hire is a hacker

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

Fraud alert: Phishing emails purporting to be from the Law Society of Scotland

GiveWP WordPress donation plugin flaw lets hackers execute server commands

Hackers Exploit AI and Deepfakes to Breach Fiji Businesses, Expert Warns

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers say they know where nearly half a million diamond customers live

Hackers steal data linked to 8.7 million customers across three UK airports

Hackers steal personal data of 8.7 million customers in cyber attack on three UK airports

Health systems warn of phishing scams using Epic’s MyChart name and logo

How Recruitment Phishing Puts Employee Credentials at Risk on Smaller Mobile Screens

Hungry Lion fast food chain hit by ransomware attack claimed by MeduzaLocker

Identity-Based Attacks Drive 85% of Education Ransomware

Is Your Home-Based Business Ready for a Cyber Attack

Latvia: Huge cyberattack affects two-thirds of country’s population

Linux accounts for half of CISA’s latest actively exploited flaws

Love Electric Breach: 877,000 Driver Records Offered for $600

Over 8,300 Gitea servers vulnerable to code execution attacks

Manchester Airport Data Breach Exposes 8.7 Million Travellers

Manchester Airport Group Suffers Data Breach of Customer Info

Manchester Airport hackers demand ransom after 8.7 million passengers' data stolen in major cyber attack

Manchester Airports Breach Impacts 8.7 Million

Manchester Airports Group breached, millions of customers’ data stolen

Manchester and Stansted owner claims hackers demanded ransom during cyber-attack

Manchester HIV charity George House Trust warns users of data breach

Manchester, Stansted and East Midlands airports hit by cyber attack

Manchester, Stansted and East Midlands cyber attack: Operational Technology (OT) security lessons for engineers

McKesson discloses breach after ShinyHunters claims patient data theft

Millions of patients warned after DNA testing data breach

Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover

Morocco's DGSN-DGST security hub formally refutes data breach allegations

MP gives update on cyber attack at East Midlands Airport impacting millions of travellers

MyChart patient portal users warned of phishing scams

National Cyber Security Centre (NCSC) warns of growing cyber threat to exposed OT and edge devices

New campaign targets Cambodia with Spark RAT using Bring Your Own Vulnerable Driver (BYOVD) technique

New exploit tricks Claude Code into running malicious code despite Auto Mode

North Korean remote workers are broadening their job hunt beyond IT

Nvidia’s Error Correction Code (ECC) was supposed to stop memory corruption, but attackers can hammer their way to root

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Palo Alto Networks Researchers Say First Wave of AI-Enabled Attacks Has Begun

PaperCut releases second emergency patch for exploited flaws

PaperCut warns of hackers using printer management software flaw in attacks

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

Pennsylvania Attorney General Warns of MyChart Phishing Scam

Phishing and ransomware attacks rise in the Philippines during 1H 2026

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

Punch & Associates Data Breach Exposes Financial Information

Ransomware Activity Hits 2026 High as Attacks Rise 22%

Ransomware attack targets Norcross city computer systems, officials say

Ransomware Attacks on Industrial Control Systems Rose in Q2 2026

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

Ransomware group auctions stolen Berlin data after ransom refusal

Ransomware Is Changing Shape. What India’s Threat Landscape Reveal

Report Finds AI Security Fails to Match AI Usage

RMM Phishing Campaign Spans 46 Countries as Attackers Abuse Trusted IT Tools

Russian-Linked Hacker Group Breaches Seven Companies by Exploiting AI From SpaceX-Backed Cursor

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow warns of three max severity security vulnerabilities

Sharp Motor Group confirms third-party cyber incident in wake of ransomware claims

ShinyHunters claims McKesson data breach exposing 284 million patient records

South Korea: Phone Numbers Used in Voice Phishing and Other Crimes to Be Suspended Within 24 Hours

Spectrum Laboratory Data Breach Exposes Social Security Numbers

St. Luke’s University Health Network warns patients of phishing scam using MyChart name, branding

Stansted Airport cyber attack: Millions of passengers' details accessed by hackers

SVG attachments used in widespread phishing campaign

TA4922 uses PackClient malware in tax phishing attacks

The ATF Was Just Hit by a ‘Major’ Hacker Breach - And Investigation Targets Were Exposed

Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

Toy-making giant Hasbro disclose data breach affecting employees

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

UK airport operator confirms data breach affecting 8.7 million customers

Unitree G1 Humanoid Robot Flaws Enable Unauthenticated Root RCE Over Bluetooth

US Disrupts Global Botnet Used by China-Linked QTFY Hackers

US government alcohol and firearms agency ATF declares ‘major incident’ after ransomware gang claims cyberattack

US thwarts major Chinese hacker cyberattack targeting Senate and NASA

What the NHS Cyber Attack Taught Us About Business Continuity

When does a cyber attack count as an act of war?

White River Junction Veterans Affairs (VA) reports data breach of veterans’ information

Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn

Winona County Confirms $128,539 Ransomware Payment After January Cyberattack

📅 27th August

8.7 million customers affected by data breach at Manchester, Stansted and East Midlands airports

8.7 million customers hit as Manchester Airports Group breach exposes airport WiFi sign-ups

8.7 million customers’ data accessed in cyber attack against three UK airports

8.7 million passengers affected by cyber attack on three UK airports

8.7 million people exposed in Manchester Airports Group cyber attack

12.9 Million Exposed by Carhartt Data Breach

A cyber attack affected three airports in the United Kingdom, compromising the personal data of 8.7 million customers

Account Takeover Flaw Hits TranslatePress Plugin Used on 400K WordPress Sites

Aerospace Alloys Data Breach Exposes Social Security Numbers

Africa Faces 3,008 Cyberattacks Weekly as Ransomware Groups Hit Record 93

AI a 'force multiplier' for low-skilled threat actors: 4 ways organizations should respond

AI Models are Finding Vulnerabilities Faster

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Android 17 adds Encrypted Client Hello (ECH) support to make web browsing harder to track

Applebee's Franchisee in Independence Sued Over Employee Data Breach Cover-Up Claims

ATF Confirms Major Cyberattack After Qilin Claim - Were Gun-Owner Records Exposed?

ATF confirms “major incident” after recent Qilin breach claims

ATF declares ‘major incident’ as ransomware gang claims hack

ATF investigates ‘major’ cybersecurity incident as ransomware group claims attack

ATF investigating ‘major’ cybersecurity incident

ATF investigating ‘major’ cyber incident after ransomware group claim

ATF responds to 'major' cybersecurity incident after ransomware gang's claims

Attackers are moving faster than security experts can patch, Microsoft warns

Aurora Ransomware Affiliate Uses Cursor AI to Plan Attacks Against 20+ Organizations

Australia Arrests 2 Alleged TeamPCP Hackers

Australia arrests alleged TeamPCP hackers behind supply-chain attacks

Australia charges two men for TeamPCP supply-chain hacking spree

Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others

Barracuda Ransomware Syndicate Leaks 850,000 Files from US Water Infrastructure Supplier Micro-Comm

Bell American Group Data Breach Exposes SSNs and Medical Records

Beyond the Hype: AI, Ransomware and Business Models

Boston Scientific Confirms Cyberattack That Affected Network Communications, Disrupting Global Operations

Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide

Boston Scientific Reveals Global Disruption After Cyber Incident

Boston Scientific's IT team continues its 'recovery efforts' after cyber attack

Carhartt data breach exposes information of 12.9 million accounts

Carhartt hit by data breach claimed by hacking group ShinyHunters

Chinese and Russian spies stepping up cyberattacks, German companies report

Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns

Chinese Hacking Operation Targeted U.S. Senate, NASA, Federal Reserve

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products

Claude Opus 4.6 Found a Gym API Flaw - Then Exploited It in 9 of 10 Tests

Customer data accessed in cyber attack affecting East Midlands Airport

Cyber attack at Windsor-Essex Children's Aid Society under investigation

Cyber attack hits Manchester, Stansted and East Midlands airports as customer data stolen

Cyber Attack Hits Three UK Airports, Exposes Millions Of Customers’ Data

Cyber attack targeting Hachette Australia subsidiary hurts bookshops and authors

Cyberattack causes network outage at Boston Scientific, disrupts global operations

Cyberattack on Manchester Airports Group exposes data of 8.7 million customers

Data Breach Affects 8.7 Million Customers of Three UK Airports

Data of 8.7 million customers stolen in cyber attack on Manchester, Stansted and East Midlands Airports

Data stolen from 8.7 million customers after three airports targeted in cyber attack

Department of Justice (DOJ) and FBI Seize Chinese Hacking Platforms QScan and QTRouter

Department of Justice (DOJ) Confirms Ransomware Attack On ATF Claimed By Russian Cyber Gang

Department of Justice (DOJ) firearms agency says hackers breached system containing investigation targets

Department of Justice (DOJ), NASA, Others Among Victims of Chinese State-Sponsored Hack

E.ON Energie Romania warns about a phishing campaign with false messages regarding "unpaid bills"

East Midlands Airport hit by cyber attack, millions of customers affected

East Midlands Airport issues advice to customers after cyber attack affecting millions

Everything we know about the Boston Scientific cyber attack so far

Exposed Aurora ransomware server reveals AI-assisted attacks, stolen credentials and crypto laundering

FBI Seizes China State-Sponsored Hacker Platforms Used to Target U.S. Critical Infrastructure

FBI Seizes Chinese Hacker Platforms That Targeted NASA And The Senate

Former Los Angeles County Museum of Art (LACMA) Curator Sues Museum, Says It Sat on Data Breach for a Year

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

HD Hyundai Units Fined Over Employee Data Breach

HIV charity warns users of data breach after cyber attack

How Threat Research and MDR Help SMBs Build a Defensive Edge

Huge cyber-attack sees 8.7 million UK airport passenger details stolen

Is Stansted Airport parking affected by the cyber attack?

Life Bridges Data Breach Exposes Personal and Medical Information

Los Angeles County Museum of Art (LACMA) Data Breach Exposed Social Security and Medical Data

Los Angeles County Museum of Art (LACMA) Sued Over Extensive Data Breach

Major cyber attack at UK airports with 8.7 million customers' data compromised

Major cyber attack on Manchester Airports Group sees 8.7 million customer's data stolen

Major Manchester Airports Group cyber attack as 8.7 million customers' data accessed

Manchester Airport Breach Hits 8.7 Million Customers

Manchester Airport cyber attack: What you must do if you think you're affected

Manchester Airport Data Breach: Manchester Airport Cyber Attacked 8.7 Million Customers’ Data - Check Current Status, Customer Guidance & What to do If Affected

Manchester Airport Group hit by cyber attack

Manchester Airport Group Hit By Cyber Attack With 8.7 Million Customers’ Data Stolen

Manchester Airport group hit with data breach as millions of passengers impacted

Manchester Airports Group Hit by Cyber Incident

Manchester Airports Group says hackers stole travelers' data

Manchester Airports Group (MAG) confirms cyber attack exposed customer emails, phone numbers and vehicle details

Manchester Airports Group cyber attack - all we know so far as 8.7 million customers affected

Manchester Airports Group hit by major cyber attack as 8.7 million customers affected

Manchester Airports Group suffers data breach exposing customer data

Manchester, East Midlands and Stansted airport cyber attack: Data of 9 million passengers 'obtained' by hackers as warning issued

Manchester, Stansted and East Midlands Airports Hacked in Major Data Breach

Medical Device Manufacturer Boston Scientific Faces Cyberattack

Millions of customers hit by cyber attack on East Midlands Airport owner

Millions of customers' data accessed after cyber attack on Manchester Airports Group

Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover

Mobile networks expose IMEI and other phone data to attackers

mTrade Data Breach Exposes Social Security Numbers

NCC Group logs record July ransomware cases as AI rises

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

Nearly nine million holidaymakers' data stolen after cyber attack on three UK airports - including Stansted and Manchester - with phone numbers, vehicle registrations and postcodes among seized data

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Nutex Health Data Breach - Hackers Gained Access to Network and Exfiltrated Data

OpenAI: Hugging Face Incident a “Warning Shot” to the World

OpenAI Report Explains How Its AI Agents Breached Hugging Face Systems

OpenAI reveals the true scale of AI cyberattack on Hugging Face

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

OpenAI, Anthropic, Warn of ‘Limited Window’ for AI Cyber Defense

Pan American Group Data Breach Exposes Social Security Numbers

Pan American Group discloses data breach after suspicious network activity

PaperCut warns of NG, MF flaw exploited in zero-day attacks

Passenger data stolen in Manchester Airports Group (MAG) data breach

Phishing scam targets Edmond Santa Fe High School

Pokémon Responds After Hacker Compromises Its X Account to Hawk MemeCoin

Poland Accuses Meta of Poor Handling of Scams and False Ads, Seeks €250 Million EU Fine

Police Arrest Two Alleged TeamPCP Members Linked to Shai-Hulud Attacks

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)

Pro-Russian hackers claim cyberattack on Norway

Qilin Ransomware Gang claims Cyber Attack on U.S. ATF

Ransomware Attack on three UK Airports leads to Data Breach affecting 8.7 Million customers

Ransomware attacks hit 894 as AI boosts cyber crime

Ransomware Gang Qilin Claims To Have Hacked ATF - But Where’s the Proof?

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations

Ransomware Operator Ran Cursor Agent Inside Ten Victim Networks

Rhodes, Young, Black & Duncan Data Breach Exposes Financial Info

Rockwood Data Breach Compromises Medical Information

Rogue Fabrication Data Breach Impacts 35,000 Individuals

Rookie Mistake: Hacker's Attachment to Screen Name Made Him Easy to Catch

Russia-Linked Cyber Espionage Clusters Use OAuth Phishing to Target U.S. and European Organizations

Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts

Russian Hackers Claim ATF Breach, Agency Says Investigation Files Were Hit

Russian hackers unleashed Cursor AI agent to infiltrate nearly a dozen corporate networks

Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account

Russian-Speaking Hackers Told Cursor AI It Was a 'Test,' Then Used It To Attack Seven Companies

Secret Neighbor taken offline after hacker deletes player data and blackmails publisher

Slack and Teams phishing surges, Unit 42 finds

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Stansted Airport cyber attack: Millions of passengers' details accessed by hackers

Stansted Airport data breach exposes customer contact details

Stansted Airport hit by cyber attack exposing customer data

Stansted Airport owner hit with cyber attack as millions of customers’ data stolen

Suspected TeamPCP hackers arrested over supply chain attacks

Swarms of OpenAI Agents Collaborated in Attack on Hugging Face

The Apollo Global Management Data Breach and the UNC6671 / Cordial Spider Campaign

The Hacker That Never Sleeps: AI Is Changing Cyberattacks

The notice regarding a personal data breach has taken effect

Three major UK airports are hit by cyber attack with millions of passengers affected

Three major UK airports hacked as 8.7 million customer records stolen in cyber attack

Three UK airports hit by cyber-attack with data of 8.7 million customers accessed

Travala Discloses Data Breach Exposing Customer Profile and Passport Details

Travala Reports Data Breach Exposing Customer Names, Emails and Hashed Passwords

Two alleged TeamPCP hackers arrested over global supply chain attacks

U.S. Dismantles Chinese Hacker Network Targeting Department of Justice (DOJ), Senate and NASA

UK Airports Hacked: Millions of Passengers’ Data Accessed in Major Cyber Attack

Unknown PaperCut NG/MF vulnerability is under active attack

US federal agency confirms data breach in wake of claims by ransomware group

US Probe into 850,000-File Breach at Kansas Water Infrastructure Firm

What to do if your personal information was exposed in a data breach

White House bans foreign-made equipment for power generation over cyber backdoor concerns

Why Ransomware Economics Favor Volume Over Prestige Attacks

Your AI agent can be hijacked just by visiting a website

📅 26th August

24 Malicious npm Packages Abuse Mirror Infrastructure to Host Obfuscated ClickFix Phishing Pages

24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages

100+ Internet-Exposed Water Systems Faced Cyberattacks Last Month

A Look Inside the Phishing Service Attacking Organizations

A massive phishing campaign has hit over 9,000 organizations worldwide

AI-Powered Balonx Sistema Phishing-as-a-Service (PhaaS) Harvests Credentials From Over 1,100 Banking Users

AI vulnerability discovery scores the highest impact of 20 emerging risks

AnonyMousKIT phishing service targets Apple credentials and Activation Lock

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

ATF confirms breach hours after Qilin ransomware gang claims US firearms agency

ATF hit by ransomware attack, Department of Justice (DOJ) says

Atlanta Law Giant Troutman Pepper Locke Hit by Breach, Faces 37,000-Person Suit

Average Cyber Insurance Losses Increase Despite Fewer Claims

Balonx Sistema Phishing-as-a-Service (PhaaS) Targets 20+ Mexican Banks With AI Vishing and Android RAT

Bogus recruiters go after high-value corporate credentials on mobile

Boston Scientific hit by massive cyber attack as shares plummet

Boston Scientific says cyberattack disrupted operations globally

CareCloud data breach now affects personal data of 3.75 Million patients

Carhartt data breach affects 12.9 Million, half of what ShinyHunters claimed

Carhartt data breach claims inflated by synthetic data, analysis finds

Carhartt’s ShinyHunters Breach Was Almost Half What It First Looked Like, Exposing 13 Million Emails - Here’s Why

Central Maine Healthcare Reaches $1.3 Million Settlement in Data Breach Lawsuit

Check Point Blocks Massive Debt-Relief Phishing Campaign Targeting 9,000+ Organizations

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Comcast Paying $117,500,000 To Settle Data Breach Claims Affecting 31,700,000 Customers

Critical Avada WordPress theme flaw enables zero-click RCE

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Cyber-attack on oil parastatal exposes Malawi vulnerabilities

DDoS Attack Hits Norwegian Government Services

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Fake Cloudflare CAPTCHA Campaign Abuses npm Mirrors to Push ClickFix Phishing

Fake Grand Theft Auto 6 (GTA 6) Demo Spreads Malware: How to Spot the Scam

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI disrupts proxy network enabling Chinese espionage operations

Federal Reserve, NASA and Department of Justice (DOJ) among victims of Chinese state-sponsored hacker group, FBI says

Former Los Angeles County Museum of Art (LACMA) Employee Sues Over Recently Announced Data Breach

Four in Five AI Tools Run with No IT Oversight, New Research Finds

Global Crackdown on West African Crime Networks Leads to 58 Arrests

Hack of Water Sector Supplier in Kansas Draws FBI Scrutiny

Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access

Hackers claim massive 4TB haul from AI firm serving OpenAI, Google, and Meta

Hackers now exploit critical Gitea flaw in code injection attacks

Hackers target Microsoft SharePoint RCE chain with Proof-of-Concept (PoC) exploit

Hackers Targeted Over 100 Internet-Exposed Water Systems

Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam

India tops APAC in mobile threat detections as attacks turn more targeted

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects

Ireland: Cyber attack delays sports grants for Kilkenny but clubs told 'don't panic!'

'It is significant, and it’s something many organisations haven't accounted for': The phishing threats hiding in your calendar invites

Jabaroot, the hacker who has dealt the biggest blow to Morocco

July was the worst month for ransomware victim claims in 2026 - or was it?

Los Angeles County Museum of Art (LACMA) data breach exposes customer and employee information

Massive security flaws plague Ubiquiti’s UniFi ecosystem: 22 vulnerabilities, 21 critical

Medical device firm Boston Scientific says cyberattack has disrupted shipment processes

Meta adds three new features to keep WhatsApp accounts secure

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls

New GPUThor attack defeats NVIDIA ECC protection for root access

Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Nutex investigating data breach after unauthorized access to servers

Paylogix TPA data breach puts benefits brokers on notice

Pro-Russian hackers claim responsibility for major cyberattack on Norway’s public digital services

Ransomware Hits 2026 Peak: Is Your Channel Ready for AI-Driven Attacks?

Ransomware surges as criminals deploy AI tools

Rockstar breaks silence after Grand Theft Auto 6 (GTA 6) is plagued with leaks and hacker warnings ahead of extended look

Russian hacker group claims responsibility for cyberattack targeting Norway

Sensitive Information Exposed in Nutex Health Data Breach

Taco Bell, and Pizza Hut operator discloses breach after suspicious network activity

TeamSystem Data Breach Exposes Customer IBANs and Accounting Records

This Android toolkit turns selfies into live photos to hijack KYC verification

Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel

Ubiquiti patches three max severity security vulnerabilities

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

US Navy tells 600,000 sailors and staff to scrub socials of military ties

US water sector supplier hack draws FBI scrutiny as Iran-linked cyber concerns grow

Your Firewall Benchmarks Are Reassuring, That's the Problem

📅 25th August

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24,700 Fake Debt Relief Emails Target Over 9,000 Organizations in 14 Days

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

AI supply chain risk is showing up in developer workflows first

Alabama subpoenas OpenAI over alleged data breach

Amazon’s New Order Confirmation Emails Seen Boosting Phishing Risk

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Apollo Global Management data breach exposes personal information

Apple rescues Hide My Email feature from the privacy scrap heap

ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australia’s transport sector under-prepared for risk of cyber attack

Bankwest: Phishing accounting for majority of banking scam activity

Can You Hear Me Now? Show Me Your Papers

Charlotte-based parking company data breach impacts more than 61,000 North Carolinians

Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations

Chinese Hackers Accelerate Cyberattacks Using Low-Cost AI Tools

CISA and the FBI Are Sounding the Alarm on Ransomware

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Employee benefits platform Paylogix says hackers stole financial and health data

Epic, American Hospital Association (AHA) warn of phishing schemes in MyChart

Epic’s MyChart phishing wave is pushing patient-access teams to treat portal identity as a security perimeter

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

Fake OpenAI Codex download tricks macOS users into installing malware

Fake Recruiter Scams Target Corporate Credentials on Mobile

FBI, CISA, and HHS Warn about Medusa Ransomware Targeting Over 500 Critical Infrastructure Organizations

Gig Harbor council member’s email locked down after suspicious message Tuesday

Hacker Group Claims Identities Of 70,381 Moroccan Agents

Hackers abuse npm mirrors to host phishing redirect pages

Hackers breached over 270 Zimbra servers in ongoing attacks

Hackers litter NPM with packages that don’t infect computers - they host phishing pages instead

Health data of North Dakota developmental disability clients potentially exposed in phishing attack

Hospital operator Nutex Health says data stolen in cyberattack

How Much Does a Data Breach Cost? IBM’s 2026 Report Puts the US Average at $11.5 Million

INTERPOL crackdown on West African crime rings uncovers troubling new trend

Iran-linked cyber attack on UK power plant was inevitable

Join a lobby, get pwned: critical remote code execution bug found in Konami’s Metal Gear Online 3

Large DDoS attack knocks Norwegian public services offline

Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed

Los Angeles County Museum of Art (LACMA) data breach last year exposed social security and medical data

Malicious Firefox extensions steal your crypto wallet seed phrases and browser credentials

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Massive DDoS attack disrupts Norway’s government digital services

Microsoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots

Microsoft’s and Meta’s data center may have been breached in $13 million extortion attempt

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

North Carolina: Latest Charlotte data breach ensnares about 73,000 Preferred Parking customers

NVIDIA NemoClaw Flaw Lets Malicious Websites Hijack OpenClaw AI Agents

PavinLoader Is Everywhere: One Malware Family Is Powering ClickFix Scams, Fake Games, and Fake Software Downloads

Phishing Ring That Even Intercepted 112 Emergency Calls Busted for Stealing 10 Billion Won Using Check Cards as Bait

Phishing, data breaches surge in the Philippines in first half of 2026

Police arrests dozens of suspects in global cybercrime crackdown

RecruitTrap Scam Uses Fake Interview Invites to Steal Corporate Logins

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

SickKids Data Breach Exposes Employee and Job Applicant Records

Sometimes Even a Great Cybersecurity Pedigree Can’t Save a Pedestrian Business Model

South Korea: Police bust China-based phishing ring with local police

South Korea: Voice Phishing Gang Arrested for Stealing 10.2 Billion Won via Call Interception

Surgeons Choice Data Breach Exposes Social Security Numbers

That fake Grand Theft Auto VI demo is actually just malware

The Grand Theft Auto VI (GTA VI) leaks are breaking the internet. Security researchers have seen this before

The Health Trust Data Breach: Personal and Health Information Exposed

The Netherlands: New phishing scam alert - Fake email from iDeal-Wero doing the rounds

Third-Party Website Scripts Can Become a Hidden Payment-Skimming Risk

TikTok phishing: How to spot fake login and verification pages

Traditional Security Training is Obsolete in the Age of AI

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

UK government seeks powers to secretly block risky tech suppliers

UK seeks supply chain security overhaul following Iran-linked cyber attack

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

US cities rush to replace Flock with Verkada cameras: Are they any better?

US jails ATM thief behind $3.5 Million heist amid investigation into violent cybercrime conspiracy

US sanctions Iranian cyber actors as UK discloses power plant attack

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

US Treasury Launches Major Campaign to Disrupt Iran’s Global Networks

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

WhatsApp adds stronger two-step verification, multiple passkeys

WhatsApp tightens account security with stronger two-step verification and more

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

Your stolen iPhone can now call you back - pretending to be Apple Support

Zero-click email attacks: What businesses need to know

ZeroTokens Phishing Platform Steers Attacks in Real Time

📅 24th August

Actively Exploited Zimbra Flaw Lets Unauthenticated Attackers Execute Shell Commands

After targeting water infrastructure in US, report claims Iran-linked hackers behind cyber attack on power plant in UK

Alibaba’s AliExpress caught tracking user audio systems

Android car head units infected with proxy botnet malware through built-in software updaters

Apollo Confirms Data Breach Amid Cyberattacks Targeting Financial Firms

Apollo Confirms Data Breach as Wall Street Hacking Wave Widens

Apollo Global hit by hacker attack, personal data leaked?

Apollo Global reveals data breach after hackers target financial firms

Associated Endocrinologists Data Breach Affects 4,979 Individuals

Barracuda Networks Analysis Finds 20 Vulnerabilities on Average Per Web App

British energy firms put on alert

California Department of Financial Protection and Innovation (DFPI) orders mortgage company to pay $825K for alleged cybersecurity failures preceding ransomware attack

Canvas Ransomware Attack Locks Out University of Manchester Students

Central Maine Healthcare reaches $1.3 million settlement agreement for data breach

Chinese hacker who broke into stock account of BTS's Jungkook gets 20 years

CISA orders urgent patching of actively exploited Zimbra flaw

CISA’s logging guidance works beyond government

“Cognizable damage” required for data breach claims, Massachusetts appeals court says in a first

Connecticut Medicaid data breach exposes payment information of 41,000 HUSKY Health members

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical Node.js Sandbox Flaw Exposes AI Agents to Host Code Execution

Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access

Cudy WR3000 Router Flaws Can Be Chained to Gain Root Access

Cyber attack on North Wales mental health charity sees sensitive data accessed

Cybersecurity job ads demanding AI skills double in a year

Data breach notifications in Australia rise by 8%

Data breach reported by Grafton City Hospital officials

Data Breach Settlement Deadline Nears for Central Maine Healthcare Patients

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

Does AI Create New Cybersecurity Risks? What Actually Changes

Egypt’s Financial Regulatory Authority (FRA) pursues criminal charges and suspends consumer finance firm over data breach

Employee Databases from Multiple Fortune 500 Companies Affecting 3.6 Million Employees Listed on the Dark Web

Encrypted Prompts Defeat Grok and Gemini Guardrails; Chat Histories Stolen

Experts Weigh in on the Medusa Ransomware Gang

Fake bank websites play dead to evade security scanners

Fake Codex Download Uses Google Sites to Deliver macOS Malware

Fake Minecraft Clients Spread WeedHack Malware on Windows to Steal Passwords

FBI, HHS warn against Medusa ransomware

Genesis Healthcare Data Breach Exposes Sensitive Patient Info

German Digital Rights Group Takes Aim at Meta Glasses in Criminal Complaint

Golf Canada Breach Exposes Nearly 570,000 Accounts, the Governing Body Isn’t Talking

Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages

Google Threat Intelligence Group (GTIG), Doppel & Gigamon: The Apollo Data Breach Explained

Hacker group claims 6 million Bangladeshi CVs for sale on dark web

Hackers infecting Android car systems to build proxy botnet

Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers Use Chameleon SEO Poisoning to Hide Banking Phishing Pages From Security Scanners

Health systems warn of coordinated phishing targeting Epic’s patient portal

Health systems warn patients of MyChart phishing scam

Hospitals warn of phishing scam targeting 'MyChart' patient portal

How email masking prevents phishing & spam attacks across the workforce

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset

Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly

Integrative Emergency Services (IES) Data Breach Exposes Medical Records of Patients

Iran hackers vow to target US allies after 4-day UK power plant attack

Iran-linked cyber attack reportedly shuts UK energy generator for four days

Iranian Cyber Attack: Are UK Power Plants Safe from Hackers?

Iranian cyber attack on power plant was "warning shot" amid threat to critical British national infrastructure

Iranian cyber attack on UK power plant ‘should concern every organization responsible for keeping this country running’

Iranian Cyberattack Shuts Down UK Power Generator

Iranian-linked cyber attack exposes UK energy flaws

Iranian-Linked Hackers Disrupt UK Energy Infrastructure in Four-Day Attack

Ireland: Survey finds consumers receive more than five scam or phishing communications per month

Kern Psychiatric Data Breach Exposes Social Security Numbers and Medical Info

Latvia: The hacker who attacked the Road Traffic Safety Directorate attempted to penetrate other government systems

Latvian Road Traffic Safety Directorate (CSDD) was late to report cyber attack

Medical Data Breach on Medical Technology Firm MyDr Impacts Half of Polish Population

Medusa Ransomware Targets Healthcare Sector Through Unpatched Software Vulnerabilities

Microsoft Reverses Its Own ‘Exploitation’ Warning on Entra ID Flaw CVE-2026-69836

Microsoft Teams Phishing Deploys New SynkLoader Malware to Steal Windows Passwords

Monitor, microphone, webcam, light – all gadgets can be hacked, researcher shows

MyChart warns of phishing schemes using fraudulent emails, other messages

National Institute of Standards and Technology (NIST) Warns of Unique Security Risks in Multi-Cloud Environments

New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

North Dakota Health and Human Services (HHS) warns Developmental Disabilities clients of data breach after phishing attack

North Dakotans receiving developmental disability services affected by phishing attack on state

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Organizations turn to AI as data breach costs jump 12%

Origin Energy cyber attack traced to former Accenture employee in Manila

Oz Hair & Beauty hit by data breach, customer names and contact details exposed

Patient data was breached in AnMed attack

Personal Information Exposed in Apollo Global Data Breach

Phishing Emails Impersonating South Korean Government Agencies Target Naver Accounts - 'Do Not Click Links'

Practical Privacy Habits That Reduce Everyday Exposure

Preferred Parking breach exposes credit card data

Premier Medical Group Data Breach Exposed Sensitive PHI and PII

Private equity giant Apollo confirms data breach saw personal info stolen

Ransomware Affiliate Poses as Recovery Firm to Steal Ransom Payments

Ransomware attackers are zeroing in on mid-market companies

Ransomware Is Changing Even When Crypto Payments Fall

Ransomware’s Real Target Isn’t the Giants. It’s the Squeezed Middle

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest Says Device Trust Held Against Phishing Attack

Researchers Uncover Thousands of Leaked Amazon Web Services (AWS) Keys

Scammers exploit hype around Grand Theft Auto 6 (GTA 6), post fake pre-release build to spread malware

Shell Confirms Investigation Following Cl0p Ransomware Data Theft Claims Tied to PTC Windchill Zero-Day

ShinyHunters Claims CyrusOne Breach, Demands $13 Million for 640+ GB of Data

Social Engineering Scheme Led to Apollo Data Breach

South Korea: Loan-Baited Accounts Launder Voice Phishing Proceeds

South Korea: Phishing Emails Impersonate Government Agencies to Target Naver

South Korea: Phishing emails mimic Korea agencies to steal Naver accounts, Naver warns

South Korea: Phishing Emails Targeting Naver Accounts Prompt Warning

South Korea: Seoul bike users sue after massive Ttareungi data breach

South Korea: Seoul Bike-Share Data Breach Victims Seek 300,000 Won Each

South Korea Data Breach Exposes Startup Applicants’ Personal Data

Southern Illinois University (SIU) Data Breach: Addresses and Social Security Numbers Exposed

Suspected Iran-linked attack knocked UK power plant offline for days

SynkLoader Malware Spreads Through Microsoft Teams Phishing and Steals Windows Passwords

The Asthma Center Data Breach: PHI and PII Exposed

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Town of Pittsboro Alerts Public to Phishing Scam

Town of Pittsboro Alerts Residents to Phishing Scam Targeting Developers

Tricky 'SynkLoader' Multitool May Herald Ransomware

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

UK briefs energy chiefs after Iran-linked cyber attack reports

UK energy alert issued after Iranian cyber attack on power plant

UK informs energy chiefs on Iran cyber attack

UK power plant cyber attack

United Language Group Data Breach Exposes Social Security Numbers

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Wake-Up Call for Critical National Infrastructure (CNI) After Iranian Attack Shuts Down UK Power Plant

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Westco Motors Cairns suffers alleged ransomware attack

What The Ransomware Business Model Means For Your Risk Strategy

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords