Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 31st August and 6th September 2026.📅 31st August
85% of Education Ransomware Starts with Stolen Identities
'128 Billion Won Fine' GS Retail Apologizes for Data Breach, Vows to Strengthen Security System
AI agent in Cursor linked to ransomware breaches at 7 companies
AI agents read legitimate llms.txt files from trusted companies and proceed to install malware
AI AppSec tools agree on just 5% of security findings
Anthropic locks out Claude users after infostealers hijack login sessions
Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage
AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Australian app developer DigiGround investigating ransomware claims
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin Won’t Pay Extortion Group Claiming Data Theft
Blind Eagle-Linked Loader Uses GitHub, VBScript, PowerShell and InstallUtil to Deploy AsyncRAT
CareCloud data breach affects more than 3.75 million people
CarGurus Data Breach Exposes 12.5 Million Accounts; Here's What Hackers Got
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Court upholds firing of Korea Food Research Institute (KFRI) executive for crypto mining and data breach in Korea
Darksiders Publisher THQ Nordic Named on DireWolf Ransomware Leak Site
Data Breach & Blind Spots: The Cyber Risk for Supply Chains
Department of Justice (DoJ) Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
Extortion Group Claims Manchester Airports Group Data Breach
Fidelity’s $2.5 Million Data-Breach Settlement Puts A Price On Losing Control Of Customer Data
Free Cloudflare DNS Tweak Blocks Malware and Phishing Across Home Networks
Free Router DNS Tweak Blocks Malware and Phishing Across Home Networks
GS Retail fined 12.8 billion won over data breach affecting 1.66 million users
Guernsey: Doctor's appointment phone call led to data breach
Hacker puts data of 820 million Alipay users up for sale
Hackers demand €2 million from Berlin, threaten data leak
Hackers Steal Identity, Vehicle Data from Latvia’s Road Traffic Safety Directorate
Hackers threaten to spill the secrets behind America’s food safety giant Neogen
Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure
Hong Kong police arrest two men allegedly linked to HK$500,000 phishing scam
Human Rights Writers Association of Nigeria (HURIWA) faults police, National Data Protection Commission (NDPC) over delay in probe of alleged National Institute for Policy and Strategic Studies (NIPSS) data breach involving naval officer
Identity-Based Attacks Are Responsible for 85% of Ransomware in Education
India: Hyderabad publisher hit by ransomware, €20m ransom sought
Infostealer Malware Steals Claude Session Cookies to Hijack Accounts and Bypass 2FA
Iranian-Linked Cyber Attack Shuts Down a UK Power Plant
Law Society of Scotland issues fraud alert after phishing email
Ledger Phishing Scam: Fake Wallet Website Targets Crypto Users - What You Need to Know
Manchester Airports Group Data Breach: FulcrumSec Claims the Theft of 86 GB via Exposed Iterable API Credentials
McKesson Confirms Data Breach as Attacker Deadline Looms
Microsoft Warns of TerminalFix Campaign Hiding Malware in PNG Images
Nigeria: Rights Group Decries Delay In Probe Of Alleged Data Breach By National Institute for Policy and Strategic Studies (NIPSS)
Nigerians extradited to US for sextortion, deaths of two teens
OpenAI Warns Astra AI Could Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
P&O Ferries data blunder as it sends out passengers' personal details by text message
Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack
Ransomware Gang Names ATF; Department of Justice (DOJ) Calls Breach ‘Major’
Rhysida Ransomware puts Berlin Government Data up for sale for 30 BTC
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails
ShinyHunters claims it stole 284 million patient records from McKesson
ShinyHunters Claims Theft of 284 Million Records from Healthcare Giant McKesson
Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices
Slovenian casinos reopen after cyberattack knocked gaming systems offline
Small businesses and cyberattacks: why phishing is still the threat to watch
South Korea fines GS Retail $9.2 million over data breach affecting 1.66 million customers
Steam Data Breach Exposes Over 12TB of Source Code, Unreleased Projects
Steam leak that exposed a decade of game history wasn’t even a hack
TerminalFix Attack Uses Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks
US cities cancel Flock contracts at record pace in August
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
Wippy Data Breach Exposes 736 Users' Height, Blood Type; South Korea Fines nRiZE ₩118 Million
Your Money and Data Are at Risk as Phishing Attacks Rise
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 17th August and 23rd August 2026, kindly assisted by our partners.

