Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 10th August and 16th August 2026.11th August
12% increase in ransomware incidents affecting industrial organisations worldwide
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Can your internet search history be accessed through WiFi?
Cisco warns of high-severity ClamAV flaws with public exploits
Europe Ransomware Attacks Up 29%
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Hackers hit Levi Strauss in cyberattack, corporate data stolen
Hackers target social media accounts to steal intimate images, FBI says
HCLTech says stolen data may be years-old after hacker’s data breach claims
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Microsoft SharePoint flaw now exploited in ransomware attacks
Previously unseen entry vector used to breach Polish energy plant
Ransomware Attack disrupts Hospital Doors, Elevators, Ventilation and Air Conditioning in Canada
Ransomware gangs don’t need control system access to disrupt industrial production
Samsung Patched 176 App Flaws, Including Camera Recording and Data Theft Bugs
Security hole in HP thin client disk encryption: key available with a single script
South Korea: Voice Phishing Scammers Impersonate Public Institutions With Forged Documents
South Korea, US warn of Gunra ransomware targeting healthcare, finance and critical infrastructure
This open-source VPN manager is secretly owned by an attacker, researchers warn
US and South Korea warn of Gunra ransomware targeting government agencies
Valve Warns European Hardware Buyers Following Logistics Data Breach
10th August
71% of CISOs spend 10+ hours on board reports
77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data
A data breach at one of Steam's logistics partners may have exposed customer data in Europe
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
AI Agent Exploits Gym System Vulnerability, Cancels Waitlist Booking in Australia
AI assistant hacks gym website in first known Australian autonomous cyber attack
AI, mobile fraud drive Africa’s cybercrime losses to $484 million
Ajax caught in CEVA hack fallout, fans left waiting
Anesthesia Group of Albany Data Breach Exposes Protected Health Info
ANIBC Association Data Breach Exposes SSNs and Health Information
Armenian police warn of new phishing scheme purporting to be a bank
At A Loss - Courts Struggle to Define “Loss” Under Computer Hacking Law
BdThemes plugins supply-chain hack creates rogue WordPress admins
Brinks Home data breach puts 1 Million customers on alert
Can AI Distillation be treated as a Cyber Attack
Canadian Hacker Pleads Guilty in 2024 Ticketmaster Hack and Snowflake Inc. Breach
Cass Health Warns Patients of MyChart Phishing Scam
CEVA Cyberattack Hits Eight European Warehouses as Retailers Face Data Breach and Delivery Delays
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
China-Linked Hackers Exploit N-able Flaw in Ransomware Attacks
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
China-Linked Hacking Group Weaponizes N-central Flaw in New Ransomware Wave
Clover Health faces four class-action lawsuits over data breach
Critical Progress LoadMaster flaw now actively exploited in attacks
Cyber Attack Sparks California City Emergency
Cyberattack hits North Carolina ports, raising supply chain risks
Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Data Breach Cost Climbs to ₹25.5 Crore in India
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock Ransomware Puts Its Negotiation Portal On-Chain
Defense supplier IEH Corporation discloses Microsoft 365 mailbox breach via phishing
European Steam Hardware Customers Hit by Cyber Attack
"Expect fake messages" - Valve's EU shipping partner suffers a data breach, so if you bought a Steam Machine or Steam Controller, you may need to be on guard
Fake The Odyssey Downloads Are Hiding Password-Stealing Malware
Fake Zoom Installer Targets Mac and Windows With Overlord RAT
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
Framework Computer Data Breach: US-Based PC Brand Warns Users After Metabase Zero-Day Exploit Exposes Personal Details
Framework discloses data breach tied to Metabase zero-day attack
Framework Laptop Data Breach Traces Back to a Metabase Zero Day
“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls
Gila Health Resources Data Breach Exposes SSNs
GitHub Dependabot malware alerts now cover eight ecosystems
Go-Based macOS Malware Steals Crypto and Secrets
Guernsey: Charities hit by data breach involving software provider
Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data
Hacker Linked to Ticketmaster Snowflake Breach Pleads Guilty in 165-Company Attack
Hackers Are Building ChatGPT-Like AI To Read Stolen Files And Create Phishing Scams
Hackers Are Going Phishing For European Steam Machine And Controller Owners
Hackers breached a small Polish energy plant via private Access Point Name (APN) last year
Hackers phish their way into US defense manufacturer’s Microsoft 365 account
Health Sciences Centre investigating ransomware incident affecting facility systems
Independent Solutions Wealth Management Data Breach Exposes Personal Information
ING and Ace & Tate report security incident at logistics partner
Interlock Ransomware Abuses Volatility3 and WinPmem to Dump Windows Credentials From Memory
Isle of Man: Election letter data breach lands Cabinet Office a reprimand
Isle of Man: School caused potential safeguarding issue with data breach
James C. Standring, DDS Data Breach Exposes Information for 6,658 Patients
Kimsuky Advances Attacks with Local LLMs, AI
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
Kimsuky hackers weaponize AI-generated crypto documents in spear-phishing campaign
Kimsuky Testing Leaves Internal IP and Attack Infrastructure Artifacts Exposed
Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers
Korea's data-breach wave hits creator media, 3Pro TV latest target
LawCare warns contacts of scam risk after data breach
Levi Strauss Hit by Cyberattack, Corporate Files Accessed
Levi Strauss Hit by Cyberattack, Hackers Use Social Engineering to Steal Corporate Data
LexisNexis shuts down services after suspicious activity on servers
Major data breach at Unlimited Technology Systems exposes data of 3.8 million
Mental health charity LawCare urges vigilance after data breach
Metabase zero-day exploited to access Framework customer data
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
New StormEncryptor ransomware used by former Medusa affiliate
New Zealand sanctions Russian hackers, propaganda groups over Ukraine war
Newcastle University confirms data breach after ExfilSquad claims 440k records
NHS Tayside investigates alleged data breach
Nichirei Hit by Cyberattack; Russian Hacker Group Leaks Stolen Data on Dark Web
North Korea’s hackers using AI for attacks, cybersecurity firm says
North Korea's Kimsuky Deploys AI in Spear-Phishing Attacks
North Korea's Kimsuky integrates AI into cyberattacks targeting crypto and finance
North Korean cyber group deploys AI tools to automate attacks and phishing campaigns
North Korean Hacker Group 'Kimsuky' Suspected of Independently Developing AI Tools for Cyberattacks
North Korean hackers are upgrading their tactics, using AI to develop more sophisticated cyberattack tools and phishing attacks
North Korean Hackers Build Local AI Tools For Attacks
North Korean Hackers Deploy AI to Refine Spear Phishing Attacks
North Korean hacking group builds AI tools for cyberattacks, report says
North Korean spies are running local LLMs to cause AI mischief
Northern California City Enacts Emergency Measures After Ransomware Cripples Municipal IT and 911 Routing
OpenAI locks down Astra over potential critical cyber capabilities
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenClaw agent independently hacks gym website to move its owner up the queue
Origin Energy data leak cybersecurity lessons have experts worried
OSF Healthcare Settles with HHS Over HIPAA Violations Following Ransomware Attack
Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA
Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise
Payroll Pirates AiTM Campaign Hijacks Microsoft 365 Sessions to Hunt Payroll and Finance Mailboxes
Payroll Pirates AiTM Phishing Hijacks Microsoft 365 Sessions and Targets Payroll Emails
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Poland uncovers second heat plant cyberattack that went hidden for months
Princeton Family Eye Care Data Breach Exposes PHI and PII
Ransomware attack on Health Sciences Centre affects doors, ventilation and air-conditioning
Ransomware attacks increasingly target managers, not just CEOs
Ransomware Attacks on K-12 Trend Down, Higher Education Trend Up in 2026
Ransomware Attackers Compromise Multiple Employees Inside the Same Company
Ransomware Hackers Are Going After Your Managers. 62% of Victims Hold Senior Roles
Ransomware Kingpin Gets 16 Years for Global Cyberattacks
Ransomware Operators Disable EDR, Backup Software and Windows Telemetry Before Encryption
Ransomware, cloud attacks remain key threats in 2026
Researchers find cyber attack risk in SIM-controlled IOT devices
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
Romance scams get a new twist: fake girls invading DMs to promote OnlyFans accounts
Russian military hackers pose as recruiters to target Ukrainian IT workers
Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity
Shropshire hospital charity supporters put on alert after Beacon data breach
Signed up for Klaviyo? Dozens of advertisers may have seen your password
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
SonicWall SMA1000 flaws now exploited by ransomware gangs
South Korea warns of new voice-phishing scam laundering stolen funds
South Korea’s Financial Supervisory Service (FSS) targets crypto voice phishing scams in system upgrade
Steam contacts users after cyber attack leaves personal details compromised
Steam Data Breach: Valve Warns EU Hardware Buyers
Steam hardware purchasers in Europe exposed: data breach hits Valve’s logistics partner
Steam Machine and Steam Controller Customers in Europe Hit by Cyber Attack
Steam Machine and Steam Controller Hit By Cyber Attack In Europe
Storm-1175 actor deploys new StormEncryptor ransomware after N-central vulnerability exploitation
Suisun City Declares Emergency After Cyberattack Disrupts Systems
Suisun City, California, Shutters Network Following Cyber Attack
Tata Consultancy Services (TCS) Says No Customer Data Breach After Claims Of Employee Information Leak
Tata Consultancy Services (TCS) says no customer data breach, continues threat monitoring
Tech industry is buzzing after a Claude agent hacked into a gym
The Crime Began Well Before the Breach
The Financial Guys Data Breach Compromises Social Security Numbers
The Next AI Safety Challenge Isn't Intelligence, it's Authority
Think before you click: Why phishing remains one of the biggest cyber threats
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Two class action lawsuits filed against Frontier Airlines over data breach
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
Understanding Spam: What It Is, Why You Get It, and How to Stop It
US Sanctions Iranian $6 billion Crypto “Exchange” Shelbit
Valve confirms that Steam users are affected by Ceva Logistics data breach
Valve informs customers about data breach, personal data stolen
Valve Issues Warning To Steam Machine Customers Following Cyber Attack
Valve notifies Steam hardware customers of a data breach
Valve Steam Hardware Buyers Hit by CEVA Logistics Data Breach
Valve tells Steam hardware customers in Europe their personal data ‘was likely compromised’ in a cyber attack
Valve User Data Leaks In Cyber Attack On European Supplier
Valve Warns Steam Hardware Owners After Vendor Data Breach
Valve warns Steam Machine and Controller users about scam emails after data breach
Valve warns Steam users in Europe of data breach at shipping partner
Wellpoint Data Breach Affects 101,047 Texans
Why India’s Ransomware Risk Is Becoming A Business Risk
Why managers are ransomware's top targets now - and 6 ways to stay safe
Why ransomware is increasingly becoming an operational threat
WordPress Plugins Compromised Without a Single File Change
XSS2Shell Vulnerability Puts 500 Million WordPress Sites at Risk of RCE
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 27th July and 2nd August 2026, kindly assisted by our partners.
