Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Data Breach. Show all posts

Trezor Data Breach Rises to 67,000 US Customers


Hardware cryptocurrency wallet organization Trezor has disclosed that additional 67,000 customers in the US have been impacted by a data breach consisting of its shipping provider, ShipMonk. 

The recent news has notably increased the number of consumers potentially exposed in the incident.  “We're deeply saddened to share the news that the recent data breach affects more customers than originally thought,” Trezor said on X. 

As per Trezor, the additional 67000 customers placed orders from November 2019 to August 2021. 

What is leaked?

The leaked data consists of customers' email, phone numbers, names, addresses, order numbers, and shipping addresses. According to Trezor, the data was stored by ShipMonk even though Trezor had earlier received assurance that previous consumer data had been erased. 

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said.

According to experts, the breach is not impacting Trezor’s own systems. 

Who are impacted?

Trezor said its hardware wallets are safe and there are no signs that customers’ recovery seed phrases or private keys were breached in the leak. 

As per Trezor, “All affected customers have been emailed directly. If you didn’t receive an email, then you are not affected.”

Potential impact

But Trezor and cybersecurity experts are worried that the stolen data could be exploited for social engineering and targeted phishing attacks. Threat actors could misuse customers’ details regarding their Trezor purchases to create scam phone calls or fraud messages.

This can be a serious problem for cryptocurrency users. A threat actor could mimic a company employee if they know someone owns a Trezor wallet and ask the target to verify their wallet or account. 

User advisory

If successful, the attacker could steal the target’s recovery seed phrase, which can allow access to cryptocurrency funds. “Trezor systems were not compromised, and your device is secure. But please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security,” the company added. 

The announcement comes after the August incident when 13,689 customers had been impacted by the same shipping-provider. At the time, Trezor estimated around 14,000 customers to have been affected by the breach. The recent disclosure of 67,000 suggests the scope of the incident was larger than expected.

Dropbox Says 5,000 Accounts Compromised After Flaw in Lenovo Login System

 


Dropbox has confirmed that hackers broke into roughly 5,000 user accounts last month by exploiting a weakness in how Lenovo verifies email addresses, allowing intruders to log into victims' cloud storage without ever knowing their passwords.

The cloud storage company began notifying affected users this week, telling them that an "unauthorized party" had accessed their accounts between August 4 and August 21. In some cases, the notification said, the attacker viewed or downloaded files stored in the account.

What makes the incident unusual is that Dropbox's own systems were never breached. The company lets users sign in with a Lenovo ID, a login credential tied to Lenovo's Identity Provider Services, as an alternative to a Dropbox password. According to Dropbox, a flaw in Lenovo's email verification process let an outside party register a Lenovo ID using someone else's email address. Once that fraudulent ID was created, the attacker could use it to log straight into the Dropbox account tied to that same email, bypassing the account's actual password entirely.

Dropbox's system trusted Lenovo's confirmation that the attacker owned the email address and did not ask for any additional check through the user's normal Dropbox login. Some of the people affected told Dropbox they had never signed up for a Lenovo ID in the first place, yet their accounts were still reachable through the integration.

A handful of users noticed something was off before Dropbox sent out its warning. One person, posting on Hacker News under the handle xaphod, said they had gotten alerts about suspicious sign-ins roughly two weeks earlier and changed their password and turned on two-factor authentication right away. They also noted that the Dropbox login page had started showing a "Continue with SSO" option tied to their email, despite never having created a Lenovo account.

Dropbox told Reuters that about 5,000 accounts were affected in total, and that none of them had two-factor authentication switched on, which is part of why the fraudulent logins went through unchallenged. Files were viewed or downloaded in fewer than a third of those accounts, a company spokesperson said. Bloomberg, which first reported the breach, cited Dropbox statements and internal records describing hackers browsing and pulling material that users had stored on the platform. Shares of Dropbox slipped about 2.4% in after-hours trading once the news broke.

Lenovo, for its part, described the problem as tied to a "legacy integration" between Lenovo ID and Dropbox that could be misused to improperly authenticate certain Dropbox accounts. A company spokesperson said Lenovo and Dropbox worked together to contain the issue once it was identified, and that Lenovo's own customer accounts were not compromised as a result. Both companies said their investigations are continuing.

Once it understood what was happening, Dropbox expired every session that had been authenticated through a Lenovo ID and cut the link between the two systems altogether. Going forward, anyone signing in through a Lenovo ID will also have to enter their Dropbox password, closing the gap that let the fraudulent logins succeed without one. The company said it has reported the incident to data protection regulators, as required in jurisdictions covered by breach notification rules.

For affected users, Dropbox's advice mirrors standard breach guidance: change the Dropbox password, change the password on the linked email account, and enable two-step verification if it isn't already on. Security researchers reviewing the incident have also suggested checking active sessions, connected third-party apps, shared links, and recent file activity for anything unfamiliar, along with account recovery settings that an attacker could have altered while inside.

The breach adds to a run of recent incidents built around federated login systems rather than direct server intrusions. Security teams have flagged this pattern for years: as more services link their sign-in process to outside identity providers to make logging in more convenient, a flaw in any one partner can end up exposing accounts across the whole chain, even for users who never signed up with that partner directly.

Dropbox has not said whether it plans to end the Lenovo ID integration entirely or continue it under the new password requirement. The company said users who did not receive a direct notification from Dropbox were not affected by the incident.

Thomson Reuters Court Records Breach Exposes Sensitive Data Across North America

 

Sensitive court records and personal information were spilled from a data breach in the court system, which impacts at least 12 states in the U.S., including the U.S. Virgin Islands and Canada, Thomson Reuters announced on Wednesday. The breach occurred in C-Track, a court case management software, run by one of Thomson Reuters’ subsidiaries. 

The company remains silent on how the hackers accessed the program, who was responsible and how much data was compromised, as well as the number of individuals impacted. Thomson Reuters stressed that the breach was within their own environment and “not related to security vulnerabilities in the networks, systems or data of the courts.” The company discovered unauthorized access to its system on June 30, and it initiated an investigation alongside outside cyber security experts and law enforcement. 

Their probe established that unauthorized intruders accessed some C-Track files in March. Meanwhile, a separate disclosure by the Montana Supreme Court revealed that Thomson Reuters advised the state court officials that unauthorized access to C-Track persisted up to June, which means that hackers may have remained undetected within the system for several months. The sensitive information spilled includes names, Social Security numbers, driver licenses, medical information, dates of birth, and health insurance. 

Thomson Reuters added that confidential, redacted, or otherwise restricted information from court records may have been accessed in some jurisdictions, but the company confirmed that no abuse of the situation has occurred. The data breach did not impact the operations of C-Track, which continues to function normally. Thomson Reuters implemented additional security measures, following the breach, after they were approved by outside cybersecurity experts, although the company did not disclose who they were. 

The courts in the U.S. whose data is at risk, according to the company, are the appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, and Wyoming. In addition, several Pennsylvania courts, 10 Ohio district courts of appeals, the Supreme Court, and the Superior Court of the U.S. Virgin Islands are also on the list. The breach in Oregon Judicial Department added another state to the list, expanding the reach to at least 12 states. 

Nevada officials reminded their residents that the types of data compromised differs from state to state, and that not all the data in each state is necessarily confidential or protected. They added that, for example, in Montana, most of the data already was publicly available, but the state’s court system acknowledged the breach of the drivers’ licenses and dates of birth. 

In addition, several of the jurisdictions were notified weeks after Thomson Reuters became aware of the security threat. For example, the court administrator of Montana and the Ontario Ministry of the Attorney General were notified of the unauthorized access to the data on July 23. The chief justices of Ontario agreed that it still remains unclear what information was at risk and how many people were impacted. Thomson Reuters notifies affected individuals that they can receive 12 months of free of credit monitoring and identity theft protection.

FBI Investigates Dark Web Service Offering 153 Million Driver’s Licenses

 



The FBI has opened an investigation into an apparent breach involving identity verification provider IDScan.net after a newly launched dark web service began advertising access to more than 153 million U.S. and Canadian driver’s license records.

The service, named Nexus, appeared on the Russian cybercrime forum Exploit on August 31, claiming access to identity documents belonging to more than 170 million people across North America. Its advertised database includes more than 153 million driver’s licenses, over 10 million identification cards, more than three million travel or international identity documents, and at least 579,000 medical cards.

An examination of the service indicates that the claimed volume may be credible. A search without filters reportedly produced about 11.5 million pages of records, with approximately 15 results per page. Canadian licenses accounted for roughly 1.1 million results, including 473,673 records from Ontario, while most listings originated from the United States.

The dataset also contains marijuana dispensary cards, commercial driver’s licenses and records marked “CAC,” potentially referring to U.S. government Common Access Cards. Nexus operators claim the information is being obtained through an ongoing compromise of a major identity verification company serving Fortune 500 customers. They claim to have continuously extracted new records for more than a year.

Evidence examined by KrebsOnSecurity also indicates that the database may still be receiving stolen information. The number of available driver’s license records reportedly increased by nearly 400,000 within 24 hours.

The exposed records are unusually detailed. One license examined by Krebs contained six image files showing the front and back of the document, including standard, infrared and ultraviolet captures. Each file carried a timestamp. In several cases, those timestamps corresponded closely with victims’ real-world activities.

Krebs tested the apparent pattern by obtaining permission to search for licenses belonging to more than a dozen acquaintances. Nine licenses were located, and each individual confirmed travelling on or around the dates associated with the image timestamps. Further comparison with rental records indicated the timestamps appeared consistent with Greenwich Mean Time.

The evidence initially pointed toward airports, but that theory weakened because the database contained no passports and several individuals had not presented their licenses at airport security. Two federal employees who appeared in the dataset said they used other government identification at airport checkpoints, but later handed their state licenses to Hertz when renting vehicles.

A particularly revealing comparison involved Krebs’ own license and his mother’s. Their records carried timestamps only seconds apart, corresponding to the time both licenses were handed to a Hertz representative. Another exposed license belonged to security researcher Zach Edwards, whose timestamp matched a trip to Las Vegas for DEF CON. Edwards said he showed his license to TSA, his hotel and Planet 13, but identified the dispensary as the only location that definitely scanned it.

That connection is notable because Planet 13 announced in 2022 that it had deployed IDScan.net’s VeriScan technology across 16 check-in stations at its Las Vegas SuperStore. The system captures government-issued identification, performs document authentication and can use white-light, infrared and ultraviolet imagery. IDScan.net says its technology performs more than 21 million identity verifications each month across more than 20,000 locations.

IDScan.net also publicly lists major organizations using its technology, including Hertz, Target, FedEx and Caesars Entertainment. Its current platform supports ID scanning, document authentication, data parsing and integrations through APIs and software development kits.

IDScan.net told KrebsOnSecurity that it was investigating but had not provided a substantive public explanation of the suspected incident. Its documentation shows that its systems can retain raw files generated during scans, while its security documentation describes encryption for data at rest and in transit.

The FBI’s New Orleans field office subsequently opened an official investigation into the suspected breach. The development adds a law-enforcement dimension to an incident that could expose highly sensitive identity information at unprecedented scale.

The potential consequences extend beyond conventional credential theft. Driver’s license information is legally recognized as identifying information, and stolen identity data can be used to open accounts, obtain services, commit financial fraud or impersonate victims.

The incident also exposes a difficult security trade-off in modern identity verification. Organizations increasingly depend on third-party systems to scan government credentials for travel, rentals, retail, financial services and age verification. TSA began enforcing REAL ID requirements for domestic air travel in May 2025, further embedding government-issued identification into everyday verification processes.

For now, the precise intrusion path, affected customers and total number of compromised individuals remain unconfirmed. However, the combination of detailed document images, matching timestamps, apparent fresh data collection and the FBI investigation makes Nexus a serious warning about the risks created when sensitive identity documents are concentrated within third-party verification infrastructure.

Berlin Defies Hackers After Data Theft From State Network


A Berlin state government official has confirmed that hackers are attempting to extort the city after its administrative network was compromised earlier this month. Berlin has refused to pay the ransom demand, saying that Berlin will not be paying the attackers. The Senate Department for Mobility, Transport, Climate Protection, and Environment was affected by the incident. 

An initial data leak was detected on August 7, followed by forensic analysis that detected additional exfiltrations between August 7 and August 12. On August 14, authorities took down the company's network as a result of the breach. As part of the response, the Senate Department for Urban Development, Construction, and Housing network was also shut down. There is currently no indication as to how much data has been stolen. 

Senate Chancellery officials have reported that the investigation is still in progress and that the extent and nature of the data removed from the network cannot be ruled out. A figure circulating from the attackers claims that more than 5.7 TB of data has been stolen, including records relating to more than 12,000 individuals. 

The city has not disclosed the extent of the data exfiltrated. On August 28, the ransomware group published the claim on their leak site. Berlin has not independently verified those figures, but the threat actor has also claimed that the stolen material included financial documents, contracts, human resources files, legal documents, complaints, passwords, and other confidential information.

More than 16,000 email addresses and nearly 12,000 phone numbers are reported in the claimed haul. Despite not publicly identifying the attackers, the Rhysida ransomware group has claimed responsibility, briefly listing the city on its Tor-based leak site. The group has reportedly requested 30 Bitcoins, worth approximately $2.3 million, in exchange for not disclosing the unauthorized data. 

Investigation Continues as Scope of Breach Remains Unclear Until the full scope of the compromise has been established, forensic investigators confirmed that additional data was collected from the Senate Department for Mobility, Transport, Climate Protection and the Environment between August 7 and August 12, before the affected departments were disconnected from Berlin's state network on August 14. 

Rhysida has provided an extensive list of alleged stolen information, however, their claims have not been fully verified. Around 1.44 million files are reportedly contained within the claimed 5.79 TB haul, including government, legal, financial, contractual, and human resources documents. Also included in the list are identity documents, payroll information, email archives, database dumps, banking information, credentials, and more. 

The group has also tried to press Berlin into paying through the alleged exposure of sensitive records. According to Rhysida, she threatened to publish the stolen files, citing potential GDPR violations as a further means of leverage. The Berlin Senate's Iris Spranger asserted that, despite the extent of the claims, no evidence has been provided to support election-related systems. There has been no evidence that election data has been compromised, according to Spranger. 

Rhysida's initial access method has not been disclosed. As a result of the lack of details, there is no clear indication of the entry point and the circumstances under which the attackers gained access to the administrative network. Investigations are continuing by Berlin's State Criminal Police Office, the Public Prosecutors' Office, and federal security agencies. 

Since its inception in 2023, Rhysida has been targeting government bodies, healthcare providers, educational institutions and critical infrastructure organizations. Researchers have linked the group to hundreds of attacks, making its claim against Berlin part of a broader pattern of attacks against public networks. It is still unclear whether Berlin has determined the full extent of the data theft or verified all information allegedly released by the attackers as part of the ongoing investigation.

Hasbro Data Breach Impacts Employee Personal Information


The Hasbro Company has notified its employees that their personal information could have been exposed as a result of a data breach involving one of their compromised employee accounts. The company informed the Massachusetts Attorney General's Office of the incident in breach notification letters. 

As indicated in the notices, the information involved varies according to the individual and can include names, email addresses, postal addresses, phone numbers, national identification numbers, and financial information. Hasbro has not provided any information about the number of individuals affected or the date of discovery of the breach. It has been reported that, according to records published by the Massachusetts Attorney General's Office, 436 residents of the state were affected. 

The company has approximately 4,600 employees worldwide, with a significant number based in the United States. Hasbro may have suffered a cyber attack in late March that resulted in the company shutting down several systems. While working to contain the cyberattack, the disruption affected its operations. 

Immediately following the incident, Hasbro disabled the compromised employee account, terminated unauthorized access, and implemented additional security measures. There has been no public disclosure of how the account was compromised or whether attackers were able to access the exposed information. Among the information affected by the breach in Massachusetts was the social security number of the employee, financial account details, credit card information, and driver's license data. 

Details of Hasbro Breach Remain Limited 

It has not been disclosed by Hasbro how the employee account was compromised, the duration of the unauthorized access, or whether the information was actually removed from its systems. Based on the company's notification, it appears that the information involved differs between affected individuals, making it difficult to establish the exact scope of the exposure. Furthermore, it has been raised that the incident may have extended beyond employee records. 

Public reporting has not established whether customer information was accessed, nor has a ransom demand or the identity of the attackers been confirmed. The employee data incident occurs months after Hasbro released a separate cyberattack on March 28 that compromised its data. Due to that attack, some of the company's systems were taken offline, disrupting manufacturing, shipping and order processing. 

Hasbro warned that delays could continue for weeks and hired third-party forensic specialists to investigate the incident. Although there is no indication that the March attack was directly related to the employee data breach, the available reporting does not suggest a direct link. If Hasbro does not provide evidence linking the two incidents, it is more accurate to treat the two incidents as separate events. 

Hasbro's disruption extended beyond corporate systems, affecting the company's ability to produce products, ship orders, and process new orders as well. However, the March attack nonetheless illustrates the broader impact a compromise can have on a major manufacturer. In the case of employees whose Social Security numbers, financial details, payment card information, or driver's license data was compromised, the consequences could extend beyond the initial disclosure.

Identity theft, fraudulent transactions, targeted phishing campaigns, and attempts to gain access to other accounts can all be perpetrated using this information. As a result of the compromised employee account being disabled, unauthorized access was ended, and additional safeguards were implemented. There have been no additional public details provided by the company regarding the technical cause of this compromise or the procedure used to determine the full extent to which the data was exposed. 

Hasbro Provides Protection Services to Affected Employees

Upon conducting an investigation with the assistance of external cybersecurity specialists, Hasbro concluded that personal information belonging to current and former employees may have been accessed during the incident. Hasbro reported that there are no indications of misuse of the exposed information at the time. As a precaution, Hasbro is offering identity protection services to affected individuals through a third-party provider. 

The company advised those affected to monitor their account statements as well as obtain their free credit reports in order to detect any unusual activity. Following the investigation, Hasbro said additional safeguards were implemented. The circumstances surrounding the exposure remain unclear. Hasbro has not confirmed whether customer information was exposed, nor has it made any disclosure as to whether ransom was demanded by the attackers. 

A threat actor has also not been publicly identified by the company. A question was made regarding whether the employee-data exposure was related to the March cyberattack, but Hasbro did not confirm an association between the two incidents. Hasbro suffered significant financial losses as a result of the earlier attack. Approximately $25 million was lost from revenue as a result of operational disruptions, and approximately $11 million was spent responding to and cleaning up the incident directly. 

As no further information has been released regarding the compromised account or the number of individuals affected, it is unclear as to the extent of the employee-data exposure. Despite Hasbro's latest disclosure confirming employee information was compromised, key questions about the intrusion and its relationship with the earlier cyberattack remain unanswered. 

In light of this incident, it becomes evident that compromised employee accounts pose serious risks as well as the potential impact of unauthorized access to sensitive workforce data. In order to determine the full scope of the breach, Hasbro will need to conduct a thorough investigation and implement protective measures.

Berlin Confirms Extortion Attempt After Network Compromise as Manchester Airports Group Reports Customer Data Theft

 

The state of Berlin confirms that it is the victim of an extortion attempt after allegedly having its network hacked back in August. Authorities say they will not give in to the hackers’ demands. 

Forensic analyses of the network of the Senate Department of Mobility, Transport, Climate Protection and the Environment have revealed additional data thefts outside the network in the period between August 7 and 12. The department had first noticed data loss on August 7 and had been cut off on August 14. Berlin is currently still investigating the extent and scope of the data loss, saying that it is possible that personal data or other confidential information had been accessed. 

The amount of data stolen in the cyber-attack on Berlin has not been disclosed officially; however, one entry on the dark web by the hackers’ group Rhysida, published on August 28, claims that 5,79 TB of data containing personal information of 12,076 people were stolen. The entry also stated that approximately 1,44 million files had been scanned. 

According to the post, the target of the attack was Berlin, Germany, without specifying any ransom value. Der Spiegel revealed that the ransom note was published by the hacker collective Rhysida, citing the group’s dark web blog and security sources. According to the report, a monitoring service confirmed on Friday that a post titled “Berlin, Germany” appeared on the leak site of Rhysida on August 28. Berlin has not officially attributed the attack to any hacker group. 

A joint security advisory released by the U.S. Cybersecurity and Infrastructure Security Agency, the FBI and the Multi-State Information Sharing and Analysis Center highlights that Rhysida has been abusing compromised legitimate usernames and passwords from remote access services and has been using phishing and the Zerologon vulnerability (CVE-2020-1472). The advisory recommends prioritizing the response to known exploited vulnerabilities, implementing multi-factor authentication and network segmentation. 

Berlin’s data protection commissioner and the Federal Office for Information Security have been informed of the attack. Interior Minister Iris Spranger stated that, according to preliminary information, no data from the election-relevant IT systems were removed from the network. Thus far, no election functions have been interrupted. Meanwhile, Manchester Airports Group (MAG) has announced that a cyber-security incident involving the unauthorized collection of customer data occurred at its UK airports. 

The personal data of passengers who booked car parking, lounges, or Fast Track services or who subscribed to in-airport WiFi were affected. The data compromised in the breach include customers’ email addresses, phone numbers, vehicle registration numbers, and postcode details. According to MAG, the data do not include customers’ payment or bank details, and no impact has been made on passengers’ safety or aviation safety or airport operations.

As of August 29, the online booking system, called Manage My Booking, has been temporarily offline for security reasons. It has been reported that affected customers have been contacted directly and have been warned to be vigilant of further communication attempts from unauthorized third parties.

McKesson Probes Data Theft After ShinyHunters Claims Access to Patient Records




McKesson Corporation is investigating a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration, while the ShinyHunters extortion group claims it stole approximately 284 million patient-related records from the healthcare and pharmaceutical distribution company.

McKesson said it discovered the incident on August 25 and immediately activated its incident-response procedures. The company has brought in external cybersecurity specialists to assist with the investigation, which it said remains in its early stages.

In a filing with the U.S. Securities and Exchange Commission, McKesson said it has not determined that the incident is material or that it has had, or is reasonably likely to have, a material impact on its financial condition or operations.

The company confirmed in a separate customer notice that the incident involved unauthorized access to third-party applications and the exfiltration of data. McKesson has not identified the affected applications, disclosed how the attackers obtained access, or confirmed what information was taken.

Customers could also experience intermittent service degradation believed to be related to the incident. McKesson said it was not proactively disconnecting systems within its environment.


ShinyHunters claims employee accounts were compromised

ShinyHunters claims it obtained initial access through voice-phishing, or vishing, attacks targeting multiple McKesson employees.

According to the group, the attacks resulted in the compromise of several employee Okta single sign-on accounts. Those accounts were allegedly used to access McKesson's Salesforce and Snowflake environments.

The group claims it obtained extensive access to Salesforce, including support cases, and extracted a larger volume of patient-related information from Snowflake.

ShinyHunters alleges that approximately 1 TB of data was removed over four days, from August 21 through August 25.

The group has claimed that the Snowflake data contained roughly 284 million patient-related records. However, it later clarified that this figure represents individual database records or lines, rather than 284 million unique patients.

ShinyHunters also said it has not completed its analysis of the stolen material and therefore cannot determine how many individuals are represented in the dataset.

The alleged information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers and medical record numbers. The group also claims the data contains medication and allergy information, illnesses, disabilities, appointments, physician details, prescriptions and medication shipments.

Other allegedly stolen material includes information relating to deceased and terminally ill patients, invoices, employee data, Salesforce records, internal communications, and information about healthcare providers and clinics using McKesson's services.

McKesson has not confirmed any of these specific data categories, and the claims about the stolen information have not been independently verified.


McKesson domain follows ShinyHunters pattern

The alleged campaign also involved the "mckesson[.]claims" domain.

The domain follows a pattern previously associated with ShinyHunters activity. ReliaQuest has documented campaigns in which domains using a targeted company's name or abbreviation alongside the ".claims" top-level domain were used to impersonate help-desk or IT personnel.

The technique is particularly relevant to the alleged McKesson attack because social engineering is increasingly being used to obtain legitimate employee credentials rather than deploying malware directly against an organization's infrastructure.

ReliaQuest recently documented an attempted attack against its own employees in which an attacker used a lookalike domain, impersonated a security employee and attempted to persuade staff to authenticate through a fraudulent SSO page. Additional security controls prevented the attacker from reaching business applications or customer information.

Health-ISAC has also warned healthcare organizations about an increase in ShinyHunters activity involving social engineering, identity compromise and subsequent access to cloud and SaaS platforms.

Its analysis describes an attack chain in which threat actors use vishing or help-desk manipulation to compromise identity-provider accounts before moving into connected services. Such access can allow attackers to retrieve large volumes of information through legitimate cloud applications.

Research from the Retail & Hospitality ISAC has further linked ShinyHunters to the abuse of OAuth relationships and SaaS applications. By operating through legitimate identities or application permissions, attackers can make unauthorized activity more difficult to distinguish from ordinary cloud usage.

The alleged McKesson intrusion has not been independently confirmed to have followed this entire sequence, but the claimed compromise of employee SSO accounts followed by access to Salesforce and Snowflake is consistent with the identity-focused tactics researchers have been tracking.


$55 million ransom demand claimed

ShinyHunters claims it contacted McKesson after completing the alleged data theft on August 25 and demanded $55,236,150 in ransom, giving the company 72 hours to respond.

The group claims McKesson did not negotiate over the demand.

McKesson has not publicly confirmed the ransom demand or its alleged communications with the extortion group.

The incident comes as ShinyHunters-linked attacks continue to target healthcare and health-technology organizations. Recent organizations reportedly targeted by the group include Medtronic, DentaQuest, iRhythm, One Medical and AdaptHealth.

For McKesson, the immediate question remains the actual scope of the incident. The company has confirmed unauthorized access to third-party applications and data exfiltration, but has not established which systems were affected, what information was taken or how many individuals may ultimately be impacted.

Until McKesson completes its investigation, the 284 million-record figure and the specific claims surrounding the alleged Snowflake and Salesforce compromise remain unverified.

Supreme Court to Hear Case Over 1.5 Lakh Medical Records Breach





The Supreme Court has issued notice on a petition seeking a Central Bureau of Investigation (CBI) probe into an alleged cyberattack that Vitraya Technologies claims resulted in the theft of medical, insurance and other sensitive personal information belonging to nearly 1.5 lakh Indian citizens.

A three-judge bench comprising Chief Justice of India Surya Kant and Justices Joymalya Bagchi and V Mohana agreed to examine the petition filed by Vitraya Technologies Pvt Ltd, a health-tech company that operates a technology platform for automating and settling health insurance claims.

The case places the alleged compromise of highly sensitive healthcare information alongside questions about the adequacy of the police investigation and the protection of informational privacy. The company has approached the court under Article 32 of the Constitution, arguing that the alleged breach has implications for the fundamental right to privacy protected under Article 21.

During the hearing, senior advocate K Parameshwar, appearing for Vitraya, told the court that the alleged intrusion affected data across six states and that the company had been approaching authorities since the incident was reported in 2025.

Parameshwar said Vitraya submitted its initial complaint in March 2025 but that an FIR was not registered until August 29, 2025. He also questioned why the case continued to name unknown persons despite the company claiming that it had supplied investigators with technical information concerning the suspected intrusion.

The counsel told the bench that Vitraya had also provided information concerning a server in Singapore to which the company's investigation allegedly traced medical records belonging to almost 1.5 lakh Indians.

The petition seeks transfer of the investigation to the CBI. In the alternative, Vitraya has asked the Supreme Court to order a court-monitored Special Investigation Team (SIT).


Alleged attack began with unauthorised access

According to the petition, Vitraya detected what it described as a coordinated cyberattack in February 2025.

The alleged activity included repeated brute-force login attempts against the company's systems, unauthorised access to its digital infrastructure, bulk downloading of confidential records and the extraction of sensitive customer information.

The data allegedly exposed in the incident includes medical records, health insurance claim information, Aadhaar-linked details and other personally identifiable information.

The combination of medical information with identity and insurance data makes the alleged incident particularly sensitive. Medical records can contain information about an individual's diagnoses, treatment history and health conditions, while Aadhaar-linked information can connect those records to an identifiable individual.

Vitraya's own platform is designed to handle this type of information. The company says its technology automates health insurance claims using artificial intelligence, machine learning, medical natural-language processing and blockchain-based smart contracts. It describes its platform as being used by more than 6,000 hospitals and says it processes approximately 10 million claims worth around $2 billion annually.

The company's technology infrastructure therefore sits within a data-intensive part of the healthcare and insurance ecosystem, where information can move between healthcare providers, insurers and technology platforms during the claims process.


Vitraya alleges attack was linked to rival companies

Following an internal forensic investigation, Vitraya claims that its security team identified suspicious IP addresses, server activity and other digital footprints that it says were associated with Remedinet Technologies Pvt Ltd and IHX Pvt Ltd.

The petition further alleges that these entities were connected to Bessemer Venture Partners and that the alleged activity involved Bessemer, Medi Assist, Perfios Software Solutions Pvt Ltd and other entities described by Vitraya as competitors.

These allegations have not been established by the Supreme Court. The companies named in the petition should not be treated as responsible for the breach unless an investigation establishes their involvement.

Vitraya says its forensic examination produced technical material that it subsequently supplied to investigators. The company claims this included server information, IP addresses, technical logs, details concerning the alleged actors and other documentary evidence.

The company approached Punjab's cybercrime authorities on March 5, 2025, according to the petition.

However, Vitraya alleges that its repeated representations and cooperation during the preliminary inquiry did not result in an FIR for almost six months.

The FIR was ultimately registered on August 29, 2025, at the Punjab State Cyber Crime Police Station in SAS Nagar. According to the petition, the case was registered under Sections 66 and 66B of the Information Technology Act and against unknown persons.

Under the IT Act, Section 66 addresses computer-related offences committed dishonestly or fraudulently, while Section 66B deals with dishonestly receiving or retaining stolen computer resources or communication devices while knowing, or having reason to believe, that they are stolen.

Vitraya has argued that the provisions used in the FIR do not adequately reflect the scale and complexity of the alleged incident. The company has also questioned why the FIR continued to identify the suspects as unknown despite the technical material it says had already been provided to police.


Company questions progress of investigation

The petition alleges that the investigation has not involved sufficient forensic examination or preservation of the digital evidence relevant to the alleged attack.

Vitraya claims that investigators have not undertaken substantial measures such as examining or seizing relevant digital infrastructure, preserving electronic evidence or conducting custodial interrogation of suspected individuals.

The company argues that these alleged shortcomings are particularly important because the incident involves systems and entities operating across multiple jurisdictions.

According to Vitraya, the alleged breach spans six states, involves multiple corporate entities and includes digital infrastructure located outside India. The company has specifically referred to a Singapore-based server where it alleges that the compromised medical information was transferred.

The cross-border element could complicate an investigation because digital evidence may be distributed across different jurisdictions, requiring investigators to establish where systems and data were located, identify the parties controlling those systems and preserve evidence before it can be deleted, altered or moved.

The company therefore argues that the investigation requires an agency with the technical capacity and jurisdictional reach to examine the alleged attack.


Privacy concerns form central part of petition

Vitraya has also framed the alleged breach as a constitutional privacy issue rather than solely a dispute between competing businesses.

The petition relies on the Supreme Court's 2017 judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India, in which a nine-judge Constitution Bench recognised privacy as a fundamental right protected under Article 21. The court held that privacy is intrinsic to the protection of life and personal liberty.

That constitutional framework is relevant to a case involving medical information because the alleged data does not merely concern commercial records. It potentially connects individuals with information about their health, treatment and insurance claims.

The petition consequently argues that the alleged unauthorised disclosure of such information affects citizens' informational privacy and digital autonomy.


India's data protection framework adds another layer

The case also arrives as India moves toward implementing its newer personal-data protection regime.

The Digital Personal Data Protection Act, 2023 establishes a framework governing the processing of digital personal data and creates obligations for organisations handling such information. The Act also provides for a Data Protection Board of India and includes provisions addressing data-fiduciary obligations, individual rights, grievance redressal and penalties.

However, the timing matters. The DPDP framework is being implemented in phases. The government notified the DPDP Rules in November 2025, while several substantive provisions of the Act and Rules are scheduled to take effect 18 months after the notification.

The alleged Vitraya intrusion was identified in February 2025, before those later implementation stages. The investigation therefore cannot simply be described as a test of the fully operational DPDP regime. Instead, the case sits at the intersection of India's existing cybercrime laws, constitutional privacy protections and the country's transition toward a dedicated personal-data protection framework.

Separately, CERT-In's directions under the Information Technology Act identify unauthorised access to IT systems or data, data breaches and data leaks among cybersecurity incidents that covered organisations are required to report.


Supreme Court seeks response on proposed CBI investigation

The Supreme Court's immediate action is limited to issuing notice on the petition. The court has not made a finding that the alleged breach occurred in the manner claimed by Vitraya, nor has it established the involvement of the companies named in the petition.

The petitioner is asking the court to transfer the investigation to the CBI because it considers the existing police investigation inadequate.

Alternatively, Vitraya has proposed a court-monitored SIT involving agencies with relevant cybersecurity expertise, including the CBI and CERT-In.

The company's argument is that the combination of alleged cross-state activity, foreign-hosted infrastructure, sensitive medical information, multiple corporate entities and digital forensic evidence makes the case unsuitable for a routine investigation.

The Supreme Court's notice now places the investigation and the requested transfer before the respondents, including the Union government, the CBI and the Punjab government.

The case could therefore become an important test of how Indian authorities investigate alleged large-scale breaches involving healthcare data, cross-border infrastructure and competing corporate entities, particularly when the affected information includes medical records and government-linked identifiers.

For now, however, the allegations remain subject to investigation and judicial consideration.

Microsoft Copilot Flaws Could Expose User Data With One Click

 


Microsoft Copilot Personal contains three vulnerabilities that could allow an attacker to execute a malicious prompt with one click and exfiltrate data from connected applications, according to Varonis Threat Labs.

The researchers collectively named the flaws CoSnitch and reported them to Microsoft in December 2025. Microsoft patched the vulnerabilities on August 18, 2026, with the issue tracked as CVE-2026-24301. Varonis said it found no evidence of exploitation in the wild. The research concerns the consumer Copilot service at copilot.microsoft.com and does not establish that the same behavior affected Microsoft 365 Copilot.


Copilot Revealed Its Own Attack Path

Varonis discovered the vulnerability through what it calls "meta-hacking," repeatedly asking Copilot why a prompt could not execute without user interaction. After several refusals containing technical explanations, Copilot eventually disclosed an undocumented "autorun=1" URL parameter, including the conditions and safeguards associated with it.

Researchers constructed the URL as described and found that the supposedly disabled parameter still executed. They combined "autorun=1" with Copilot's existing "q" parameter, which pre-fills the prompt. While "q" alone requires user interaction, the combination automatically triggered the prompt when the page loaded.

Varonis said the prompt then continued executing even if the victim immediately closed the Copilot tab. Its earlier Reprompt research had also used "q" as a one-click Parameter-to-Prompt mechanism.


Existing Permissions Enable Data Theft

The first two CoSnitch flaws form the one-click exfiltration chain. The injected instruction operates with the same capabilities available to a legitimate user prompt and does not grant Copilot additional permissions.

Researchers demonstrated access to connected mail messages, subject lines and sender and recipient metadata; calendar titles, attendees, times and locations; Google Drive filenames and metadata summaries; previous Copilot conversations; and stored memory instructions and user-defined rules.

The retrieved information could be encoded, including with Base64, and transmitted through Copilot's built-in URL-fetching capability to an attacker-controlled webhook. Varonis said the resulting request could resemble Copilot's ordinary web retrieval traffic, potentially making network-level detection difficult.


Separate Memory Poisoning Path

The third vulnerability involves indirect prompt injection through web summarization. A malicious webpage could contain attacker-controlled instructions that Copilot processed and wrote into its persistent memory.

Varonis said such injected memories could survive password changes, session revocation and device re-enrollment until manually removed. The modification reportedly generated no process, file or network activity that conventional security tooling would necessarily flag, although the change remained visible in Copilot's memory interface.

The finding follows earlier Microsoft 365 Copilot memory research by Håkon Måløy and Johann Rehberger. Microsoft has separately said M365 Copilot applies sanitization and prompt-injection checks to memory writes, performs Task Adherence checks on explicit memory updates, and records those changes for security monitoring through audit data and the "MemoryUpdated" field.

Varonis recommends reviewing connected applications, disconnecting unnecessary services, monitoring AI assistants as privileged systems and exercising caution with links that open AI assistants.

The disclosure follows Varonis's RovoBlast research, which identified another one-click attack involving Atlassian's Rovo assistant. Together, the findings demonstrate how URL handling, authorized application access, external content and persistent AI memory can combine into an attack chain without directly compromising the victim's underlying accounts.

Clop-Linked Web Shell Targets PTC Windchill Servers in Data Theft Attacks

 

A custom Java web shell, associated with the Clop ransomware group, was created to target the PTC Windchill and FlexPLM servers by decrypting their credentials, enumerating file repositories, and stealing data. Researchers at cybersecurity firm ReliaQuest discovered the web shell after analyzing the recent data-theft campaign that abused the critical remote code execution vulnerability, CVE-2026-12569, affecting PTC Windchill. 

According to the researchers, the attackers did not use a traditional web shell to gain persistent access to the targeted servers. Instead, they used a custom component that demonstrated an in-depth understanding of the target application’s internal API, database schema, keystore, and file-vault structure. ReliaQuest notes that the discovered resource is an application-specific variation of the Clop ransomware group’s known mass exploitation framework. The web shell was linked to the Clop ransomware group because of extortion e-mails sent by the threat actors using the e-mail addresses associated with the data-leakage web site operated by Clop. 

In addition, the researchers identified X-windchill-req headers used by the web shell, which were also used by the Clop ransomware group in the past, as well as similar tactics, techniques, and procedures (TTPs). Earlier this year, Clop ransomware group’s infrastructure was found to target enterprise business software solutions such as Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. This campaign, which affected the MOVEit Transfer application, compromised more than 2,770 organizations worldwide. 

The web shell is implemented as JavaServer Pages (JSP), which directly imports the PTC Windchill-specific classes such as MethodContext, WTConnection, and WTKeyStoreUtil, giving the threat actors’ access to PTC Windchill’s native functions, including the database, encrypted credentials decryption, and locating files stored in the application’s vaults. The web shell’s command execution capability was established using the custom protocol that utilizes the HTTP X-windchill-req header. 

Overall, the custom component allowed the attackers to achieve multiple malicious objectives, including Windchill secrets and configuration data theft, file vault discovery and enumeration, directory listing, file retrieval and deletion, executing additional Java classes, and identifying the server’s operating system. Besides that, ReliaQuest reports that the web shell’s implementation contains the Windchill vault enumeration code that queries multiple Windchill database tables, namely ApplicationData, FVITEM, FVMOUNT, and MasteredOnReplicaItem. 

The PTC released a set of security updates to address CVE-2026-12569 on June 17. Additionally, the vulnerability was included in the CISA’s Known Exploited Vulnerabilities catalog earlier this week after the PTC reported active exploitation attempts in the wild. Ransom-ISAC confirmed that ransomware group Clop was behind the attacks by sending extortion emails to the employees of the targeted organizations. ReliaQuest recommends that all the JSP files found in the PTC Windchill directories should be investigated for any suspicious content and that the researchers should look for the X-windchill-req string. 

Moreover, the organizations that determined that their Windchill servers were compromised by the ransomware group should change the LDAP manager’s password and other user credentials because they are considered insecure and may have been leaked.

Amgen Data Breach Exposes Patient Health and Proprietary Cloud Data

 

Amgen has disclosed a serious cloud-related data breach that exposed patient health information and proprietary company data, highlighting how third-party cloud services can become a weak point even for large biopharmaceutical firms. The company said it detected unauthorized activity in July 2026 and immediately activated its cybersecurity response plan, contained the incident, and brought in independent forensic experts to investigate. 

According to Amgen’s filing, attackers exfiltrated data from cloud environments operated by third-party service providers. The stolen information reportedly included proprietary data, protected health information, and other records, while the company continues to determine whether confidential business information, intellectual property, research and development data, or additional patient data was also accessed. 

Amgen has not identified which cloud providers were involved, how the compromise happened, or whether a known threat actor was responsible. It has also not disclosed how many people may be affected, but said the incident was considered material on July 29 after reviewing the volume of impacted files and the possibility that sensitive information was among them. 

The company said it does not currently believe the breach is likely to materially affect its financial condition or operating results, and it has not seen an impact on products, manufacturing, financial reporting systems, or its ability to meet patient needs. Even so, the exposure of protected health information creates long-term privacy and compliance concerns, especially if personal medical or insurance details were included in the stolen files. 

Amgen is still working with third-party cybersecurity experts and reviewing legal and regulatory notification requirements, including obligations under health privacy rules. The case is another reminder that cloud security is only as strong as the controls, monitoring, and vendor oversight behind it, and that incidents involving patient data can carry consequences long after the initial breach is contained.

RingCentral Breach Exposes Personal Data of 1.6 Million Accounts


 

An attack on RingCentral, which was targeted at social engineering, has led to a data breach that could have exposed personal information of around 1.6 million individuals. In July, RingCentral detected the unauthorized activity during a campaign. The company said it immediately responded to the incident and launched an investigation with the assistance of an external forensic firm in order to contain the unauthorized activity. 

In light of the remediation measures implemented, RingCentral has not detected any further unauthorized activity. In addition, RingCentral clarified that only a limited number of its customers were affected by the incident and that those who were potentially affected were contacted directly. Furthermore, the company clarified that its services remain operational, and that its core platform was unharmed. 

Despite the lack of identification of the threat actor by the company, the ShinyHunters extortion group reportedly listed RingCentral on its Tor-based leak site in late July. As a result of the group's claim that they obtained over 623GB of data, there is further concern about the size of the attack. After investigating the leaked data, Have I Been Pwned confirmed that the dataset contains information associated with approximately 1.6 million accounts, including names, email addresses, telephone numbers, and physical addresses. 

The disclosure supports ShinyHunters' claims, even though RingCentral has not publicly attributed the incident to the group or provided details concerning how the attackers gained access to their system. A broader pattern of data theft attacks has been claimed by ShinyHunters against customers of major cloud and SaaS providers, including Salesforce and Snowflake, as well as the incident described above. This group has targeted third-party platforms and integrations increasingly, using stolen corporate data to extort companies. 

A recent lawsuit against Oracle PeopleSoft underscores the extent and persistence of the data theft operations of the organization. It has been possible for independent researchers to assess the scope of the exposure after publishing the 280GB archive. Has I Been Pwned reported approximately 1.6 million unique email addresses in the leaked data, along with names, telephone numbers, and physical addresses. 

A RingCentral representative has not independently verified the attacker's claims or disclosed the number of people affected. The incident also illustrates the effectiveness of voice-based social engineering, a strategy increasingly associated with ShinyHunters. Threat actors conduct these attacks by impersonating IT personnel and leading employees to a convincing login page with the intent of capturing passwords and authentication codes. It is possible that conventional one-time-password MFA will not be sufficient to prevent account compromise due to the attack's reliance on manipulating the employee rather than breaking the underlying security technology. 

As a result, security experts are increasingly recommending phishing-resistant methods, such as FIDO2 passkeys. These passkeys bind authentication to a legitimate website, preventing credentials from being regenerated through a fraudulent website. 

The details of the authentication method used by the compromised account have not been disclosed, nor have any controls been implemented to prevent phishing attacks. It is imperative to note that exposing names, phone numbers and physical addresses poses a risk beyond the initial compromise. These disclosures can provide attackers with sufficient context to carry out further impersonations and phishing attempts in a convincing manner. 

ShinyHunters has continued to focus on data theft and extortion rather than traditional ransomware, as demonstrated by the RingCentral incident, which illustrates how a single successful social engineering attack can lead to a much larger privacy and security issue as it progresses. 

The RingCentral incident has raised several questions, primarily regarding the extent of the exposure and the means by which the accounts were compromised. Have I Been Pwned has identified approximately 1.6 million email addresses in the leaked dataset, whereas RingCentral has described the customer base as limited. 

To determine the full impact of this incident, it is critical to reconcile those figures, along with more information about the compromised accounts, in order to determine the full extent. In organizations using RingCentral or similar cloud communication platforms, it is critical to establish strong defenses against social engineering at the earliest opportunity. During security awareness training, attention should be paid to suspicious calls, credential-harvesting websites, and requests for authentication codes. 

Organizations handling sensitive or regulated information should assess notification and compliance requirements for phishing attacks, multiple factor authentication, credential resets for potentially compromised accounts, and monitoring for follow-up phishing attacks and business email compromises. A wider question is raised by the incident about security at the intersection of technology and individuals. 

Even organizations with well-established security controls can be exposed if an attacker convinces an employee to bypass these controls. The breach thus serves as a reminder to RingCentral customers that safeguarding communication systems requires not only strong technical controls, but also preparation for social engineering tactics that are becoming increasingly convincing in order to target employees.

Trezor Data Breach Exposes Personal Information of Nearly 14,000 Customers

 

Hardware cryptocurrency wallet maker Trezor has disclosed a data breach involving the personal information of nearly 14,000 customers, after an unauthorized party gained access to data held by its third-party fulfillment provider, ShipMonk.

Trezor said its own infrastructure was not compromised and that the incident was discovered after the company was informed of the attack on August 10. The affected customers are located in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal and placed orders between May 10 and August 8.

According to Trezor, the breach exposed the names, phone numbers, email addresses and shipping addresses of 11,742 customers. Information belonging to another 1,947 customers included their names, cities and email addresses. The data had been provided to ShipMonk solely to facilitate order fulfillment and delivery.

“We’re extremely sorry to inform our community that customer personal information, including full names, phone numbers, email addresses, and shipping addresses, has been accessed by an unauthorized actor during this breach,” Trezor said in its security notice.

The company attributed the limited scope of the exposure to its 90-day data retention policy, which it said is also followed by its fulfillment partners. However, Trezor warned that older orders may have been accessible for some of the customers whose information was partially exposed.

Trezor stressed that the incident did not affect its internal systems or the security of its hardware wallets. “To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts,” the company said.

All customers believed to be affected have been contacted directly by email. Trezor urged them to remain cautious of unexpected messages, particularly those asking for personal details, cryptocurrency information or immediate action.

The company is working with ShipMonk to establish when the compromise occurred and determine the complete extent of the incident.

Reports indicate that ShipMonk informed customers that the attackers gained access to its systems by exploiting a vulnerability in Metabase, a data analytics platform. The incident may be connected to a recently patched SQL injection zero-day affecting Metabase.

The cybercrime group ShinyHunters has also claimed responsibility for an attack on Metabase and subsequently published data it alleged was stolen from the analytics provider. However, the connection between that incident and the ShipMonk breach has not been independently established.

ShipMonk has not publicly confirmed the breach. It also remains unclear whether other organizations or individuals were affected, how much information may have been accessed, and who was ultimately responsible for the attack.

Hackers Steal 607,000 Records in Cyber-Attack on UK Department for Education

 



Hackers have stolen around 607,000 records from England's Department for Education (DfE) after compromising systems used to handle enquiries and administer international education funding.

The department confirmed the cyber incident after attackers accessed data held through the DfE's online help desk and the portal supporting the Turing Scheme. The compromised information includes telephone numbers and email addresses associated with individuals and organisations that had interacted with the department.

Reports have also identified names and job titles among the exposed information, including details belonging to school leaders, university staff and government officials. However, the DfE said the affected information was limited to customer-service contact details and that bank details and other sensitive information were not accessed.

The department has stressed that the figure of 607,000 refers to records rather than the number of individuals affected. A single person or organisation may therefore account for multiple records across the affected systems.


Social Engineering Reportedly Used Against DfE Helpdesk

The breach reportedly involved a social-engineering attack against an external-facing DfE helpdesk used by education-sector organisations and local authorities.

Computer Weekly reported that the attackers targeted the department's helpdesk and obtained more than 600,000 records containing personally identifiable information, while the affected systems were taken offline as the department investigated the incident. The Times also reported that it had verified the authenticity of some of the leaked information.

The incident illustrates why customer-facing systems can represent an attractive target. Helpdesks routinely process legitimate requests from large numbers of users and may contain historical enquiries and account-linked information. If an attacker can manipulate a support process or gain access to an account with sufficient privileges, information held outside an organisation's core systems can become exposed.

The DfE has not publicly disclosed a complete technical account of how the attackers gained access or which specific vulnerability was exploited. It would therefore be premature to attribute the breach to a particular software flaw or compromised credential without further evidence.

A group calling itself ExfilSquad has claimed responsibility for the attack and has reportedly published or advertised stolen information online. The group's claims should be treated as claims by the alleged attackers, although multiple reports have examined samples of the data and reported that some information was authentic.


DfE Moves to Contain the Incident

The DfE said it acted quickly after identifying the incident and has been working with the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) to establish what happened and assess the impact.

The department has also referred itself to the Information Commissioner's Office (ICO), the UK's data protection regulator.

A DfE spokesperson said the department had "robust processes" to protect information and had taken swift action to contain the incident. The department maintained that the information involved was restricted to customer-service contact details and that no other data had been accessed.

The NCA separately confirmed that it was aware of the incident and was working with partners to understand the circumstances and its impact.

The DfE has also temporarily affected the operation of the services involved while remediation work is carried out. Reports said the department switched to telephone support while the affected systems were being addressed, with normal operation expected to resume after the disruption.

The department has assessed the data-protection risk to affected individuals as low. However, the exposure of professional contact information can still create opportunities for follow-on attacks, particularly phishing and impersonation campaigns that use legitimate names, job titles, organisations or previous interactions to make fraudulent communications appear credible.


Education Sector Continues Being Prime Target

The DfE breach comes as education organisations across the UK continue to report high levels of cyber incidents.

The latest UK government's Cyber Security Breaches Survey 2025/26 found that 49% of primary schools, 73% of secondary schools, 88% of further-education colleges and 98% of higher-education institutions had identified a breach or cyber attack during the previous 12 months. The comparable figure for UK businesses was 43%.

The frequency of attacks was also high among colleges and universities. Around 24% of further-education colleges and 29% of higher-education institutions reported experiencing a breach or attack at least weekly. The survey found that 14% of primary schools and 20% of secondary schools experienced attacks at least weekly.

Phishing remained the dominant threat. Among institutions that had identified a breach or attack, 90% of primary schools and 96% of secondary schools reported phishing incidents. The same figure was 96% for further- and higher-education institutions combined.

The government survey also identified higher levels of other attack types across further and higher education. These included impersonation, reported by 79% of affected further- and higher-education institutions, viruses, spyware or malware at 51%, and denial-of-service attacks at 49%. Unauthorised access to files or networks by staff was reported by 29%, while 23% reported unauthorised access by students.

The consequences extend beyond the initial compromise. Almost half, or 49%, of further- and higher-education institutions that identified a breach or attack reported at least one negative outcome for their systems. Compromised accounts or systems being used for illicit purposes accounted for 23%, while 16% reported websites, applications or online services being slowed or taken down and 14% reported losing access to files or networks.


Contact Data Can Become a Launchpad for Further Attacks

Although the DfE maintains that highly sensitive information was not accessed, the exposed records still have security implications.

Names, job titles, work email addresses and telephone numbers can provide attackers with the information required to make subsequent phishing or impersonation attempts appear legitimate. A message addressed to a known employee, referencing their role or organisation, can be considerably more convincing than an unsolicited generic email.

This risk is particularly relevant in education, where senior school leaders, university staff and government officials may have access to wider organisational systems or sensitive information.

The latest government survey indicates that impersonation is already a recurring problem in the sector. Among further- and higher-education institutions that identified breaches or attacks, 79% reported attempts involving people impersonating their organisation or staff.

The DfE incident therefore demonstrates that the consequences of a data breach do not necessarily end when the initial intrusion is contained. Exposed contact information can potentially become useful in later social-engineering campaigns, while disruption to public-facing services can continue during investigation and recovery.

For organisations handling large volumes of education-sector data, securing customer support infrastructure is therefore part of protecting the wider attack surface. Access controls, strong identity verification, monitoring and rapid incident response can limit how far an attacker can move after compromising an externally accessible service.

The DfE investigation remains ongoing, with the department working alongside the NCSC and NCA and having notified the ICO. The full circumstances of the intrusion, including how the attackers gained access and the precise extent of the exposed information, are expected to become clearer as the investigation progresses.

Tanaka Emerges as Leading Data Leak Broker as Stolen Information Fuels Cybercrime

 

Ransomware attacks are undoubtedly one of the most notorious security threats today. Yet it seems that information itself has become a very popular target among cybercriminals. Particularly, the threat actor called Tanaka has appeared to be the most successful data dealer during the first half of 2026, according to the research conducted by Cyble. Overall, 367 confirmed cases of corporate data leaks or breaches happened worldwide during the first half of 2026, the experts from Cyble have found. 

While the activity of Tanaka appeared to be less prominent than that of many well-known ransomware groups, he has been the most active data dealer according to Cyble research. His activity has resulted in 25 leak posts, which is more than double than the number of posts of other famous data-leak organizations. The threat actor has been targeting organizations in various fields, pursuing different goals. While the Banking, Financial Services and Insurance sector remained the most attractive for criminals with 38 data breach incidents recorded, governments and technology companies have also been frequently targeted by Tanaka. 

It implies that data theft is no more limited by regional or economic factors and can happen to organizations of any size or any industry. In particular, Tanaka has been very active in North America, where 7 leak posts related to the criminal have been discovered this year. Meanwhile, Europe and the UK have witnessed 6 leak posts related to Tanaka, as well. In these regions, financial services, telecom, and retail companies have experienced the most significant challenges, as customer and financial data of these organizations are highly attractive to data prospectors. 

In general, data prospecting has become a significant threat to organizations worldwide, as there are now more opportunities to benefit from the data belonging to other organizations. It is a part of the ransomware attack chain, as ransomware criminals can use the data belonging to the victim as leverage to demand more significant ransoms. However, data extortion is not the only way to monetize data theft, as leaked databases can be further sold on dark web forums and marketplaces. 

In addition, the stolen data can be used for extortion, reconnaissance, and other nefarious purposes. It is necessary for companies to realize that the detection of one’s data being sold or showcased on underground forums should be treated as a serious security incident. It can be a sign of the potential ransomware attack, which should be responded to accordingly. Monitoring the dark web for signs of reconnaissance activities is one of the essential aspects of cybersecurity, which is why professionals may want to consider detecting their organization’s potential exposure to ransomware attackers.