Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ Ashish Khaitan
    The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.  The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentica
     

Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ

7 de Setembro de 2026, 04:14

Mathspace data breach

The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.  The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentication credentials were not. There is currently no evidence that the information has been published, sold, distributed, or otherwise misused. The attacker’s identity remains unknown. 

How the Mathspace Data Breach Happened? 

The security incident resulted from a vulnerability in Mathspace’s self-hosted Metabase installation, which was used for internal reporting. The flaw allowed attackers to obtain administrator access without a legitimate login.  Metabase issued a critical security advisory and patched versions on August 6. Mathspace said its vulnerability-notification process failed to identify and escalate that advisory. The company later updated its Metabase instance on August 29 after seeing a subsequent notice.  An investigation found unauthorized access dating to August 10, Australian Eastern Standard Time. Information was downloaded from Mathspace’s Australian reporting database on August 27. Historical log reviews confirmed the unauthorized access on September 3, before the update had been applied. Mathspace also acknowledged that it did not complete additional compromise checks recommended for potentially affected systems at the time of the update. 

What Information was Exposed? 

The exported data included user IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date and joining date. Not every field appeared for every affected person.  Mathspace said the exposure went beyond names and email addresses. User IDs are internal identifiers, including those linked to student accounts. However, no academic records, learning activities, results, assessments, password hashes, authentication tokens, SSO credentials or API credentials were exposed.  The data did not contain records directly linking accounts to schools, although Mathspace said school affiliations could potentially be inferred where identifiable email domains were used. Former or inactive users may also be affected because retained information could remain in the reporting database. 

What Users Should Know After the Security Incident? 

Names, email addresses, and account details could make phishing or impersonation attempts more convincing. Users have been advised to independently verify unexpected messages, avoid unfamiliar links and attachments, and never provide passwords or verification codes in response to unsolicited communications.  Mathspace is not requiring password resets because customer authentication credentials were not exposed. However, anyone who reused a Mathspace password elsewhere should change those reused passwords to unique ones and monitor accounts for unusual activity. 

Response to the Mathspace Data Breach 

After confirming the breach on September 3, Mathspace took Metabase offline, revoked its API keys, disabled Metabase database-access accounts in its Australian and US Snowflake environments, and changed passwords for its Metabase Cloud SQL databases. The company also copied the application database and exported access logs for investigation. Metabase remains offline while recovery and compromise checks continue.  Mathspace began notifying school contacts on September 4 and started notifying affected individuals on September 6, earlier than the date previously communicated to schools.  On September 4, the security incident was reported to Australia’s Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian Cyber Security Centre, New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre, as well as Australian state and territory education departments. 

The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks

4 de Setembro de 2026, 08:48

Weekly Roundup September 2026

This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.  From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.  The latest developments also show that organizations face growing risks across AI services, on-premises systems, enterprise edge devices, and account recovery infrastructure. Security teams are being urged to respond quickly as attackers increasingly target exposed systems and authentication mechanisms. 

The Cyber Express Weekly Roundup 

Anthropic Warns of Claude Session Hijacking 

Anthropic has warned that common infostealer malware is being used to steal active Claude sessions, potentially allowing attackers to bypass passwords and two-factor authentication. The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer, which is often distributed through pirated software and illicit downloads. Attackers may also consume victims’ paid AI usage. Read more… 

PaperCut Releases Second Emergency Patch After First Fix Is Bypassed 

PaperCut has released a second emergency patch for two actively exploited vulnerabilities affecting its NG and MF print management servers. Researchers discovered ways to bypass the initial security fix, potentially allowing attackers to chain the flaws and achieve pre-authentication remote code execution on exposed systems. Read more… 

Boston Scientific Cyberattack Limited to Certain On-Premises Systems 

Boston Scientific says its ongoing cybersecurity incident is limited to certain on-premises systems, with no impact identified on its cloud-based applications. The company has also reported no confirmed data breach or evidence of unauthorized activity since August 25, as its investigation into the incident continues. Read more… 

DOJ Investigates Attempted Cyberattack on Hundreds of Thousands of X Users 

The U.S. Department of Justice is investigating a large-scale cyberattack targeting hundreds of thousands of X accounts through the platform’s password-recovery system. Attorney General Todd Blanche said X detected and disrupted the campaign before the targeted accounts could be captured, preventing the attempted account takeover operation from succeeding. Read more… 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk 

Two vulnerabilities in Citrix NetScaler ADC and Gateway have prompted an urgent patching warning from Australia’s cybersecurity agency. CVE-2026-19489, a memory overflow flaw, and CVE-2026-19490, an authentication bypass, can affect systems with specific configurations involving SIP ALG, SAML, or VPN gateway functionality. Read more… 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are increasingly targeting authentication systems, active user sessions, exposed enterprise infrastructure, and critical business applications. AI platforms, print management servers, healthcare environments, social media accounts, and network edge devices all remain potential targets for attackers.  Organizations should prioritize rapid security patching, protection of active sessions, strong authentication controls, careful monitoring of exposed infrastructure, and timely investigation of suspicious activity. Security teams should also review systems that rely on password-recovery mechanisms and identify enterprise devices operating with vulnerable configurations.  As businesses continue to rely on cloud services, AI platforms, remote access technologies, and internet-facing enterprise systems, attackers are finding new opportunities to exploit trusted sessions and security weaknesses. Organizations must maintain continuous monitoring and rapid response capabilities to reduce the impact of increasingly targeted cyberattacks. 

The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown

28 de Agosto de 2026, 08:17

The Cyber Express weekly roundup, podcast

This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement.   From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both technical systems and human trust.  The latest developments also show that cybersecurity risks are expanding alongside the rapid adoption of cloud services and artificial intelligence. Organizations are facing threats involving identity infrastructure, autonomous AI agents, software vulnerabilities, digital transactions, online fraud, and the misuse of emerging technologies. 

The Cyber Express Weekly Roundup 

Microsoft Confirms Exploited Entra ID Flaw 

Microsoft confirmed that a critical vulnerability in Entra ID, CVE-2026-69836, was exploited before the flaw was fixed server-side. The vulnerability carries a CVSS score of 10.0 and could allow unauthenticated attackers to achieve remote code execution, potentially affecting Microsoft’s cloud-based identity infrastructure. Read more... 

New Zealand Proposes Social Media Ban for Under-16s 

New Zealand has introduced legislation that would require high-risk social media platforms to prevent users under the age of 16 from accessing their services. Proposed age-verification methods could include digital identification, facial age estimation, or official identification documents. Read more... 

Cyble and DRONA Launch AI Cyber Defense Initiative in India 

Cyble and DRONA Cyber Solutions have launched an AI-powered cybersecurity initiative in Ahmedabad aimed at helping mid-sized businesses detect, investigate, and contain cyber threats. The initiative combines threat intelligence, AI-driven investigations, and endpoint enforcement to provide organizations with faster and more coordinated responses to security incidents. Read more... 

AI Agents Could Create New Cybersecurity Risks 

Adarsh Kant Sinha, CEO of ANVE.AI, warned that autonomous AI agents could introduce significant new cybersecurity risks as organizations increasingly allow them to interact with business-critical systems. AI agents may gain access to email, customer relationship management platforms, cloud infrastructure, and financial systems, potentially creating new avenues for misuse or compromise. Read more... 

Ledger Fixes Ethereum App Flaw Amid Disclosure Dispute 

Ledger said it fixed a clear-signing vulnerability in its Ethereum application approximately two weeks before security firm TestMachine publicly disclosed the issue. The vulnerability could potentially allow a malicious application to display one transaction to a user while preparing a different transaction for signing. Read more... 

Global Crackdown Nets 58 Arrests in West African Crime Networks 

An eight-month international law enforcement operation led by INTERPOL has resulted in 58 arrests and the identification of 263 suspects across 22 countries. Operation Jackal IV targeted West African criminal networks involved in cyber-enabled fraud, money laundering, romance scams, and investment scams. Read more... 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are crossing organizational, technological, and geographical boundaries, affecting cloud identity systems, artificial intelligence, digital platforms, cryptocurrency applications, and international financial crime.  Organizations should prioritize strong identity and access controls, rapid vulnerability remediation, careful management of AI-agent permissions, secure integrations, human oversight, and continuous threat monitoring.   As autonomous technologies become more deeply integrated into business operations and cybercriminal networks continue to operate across borders, security teams must adapt to a threat landscape that is becoming broader, more interconnected, and increasingly difficult to contain. 
  • ✇Firewall Daily – The Cyber Express
  • Oz Hair and Beauty Data Breach Exposes Customer Information Ashish Khaitan
    Oz Hair and Beauty has confirmed that customers’ personal information was accessed after an unauthorized third party briefly gained access to its online purchase and order platform. The company said the incident affected information connected to purchases made before August 2026. The potentially accessed data included customers’ full names, email addresses and/or mobile phone numbers, as well as purchase-history information such as transaction currency, total spending and broad location detai
     

Oz Hair and Beauty Data Breach Exposes Customer Information

20 de Agosto de 2026, 03:44

Oz Hair and Beauty data breach

Oz Hair and Beauty has confirmed that customers’ personal information was accessed after an unauthorized third party briefly gained access to its online purchase and order platform. The company said the incident affected information connected to purchases made before August 2026. The potentially accessed data included customers’ full names, email addresses and/or mobile phone numbers, as well as purchase-history information such as transaction currency, total spending and broad location details, including city, state, country and postcode.

Oz Hair and Beauty Data Breach Involved Customer Information 

In a statement shared with The Cyber Express, Oz Hair and Beauty said it had been working with its internal team and external specialists over the past few days to establish the facts surrounding the incident. “We became aware of this and have been working with our internal team and external specialists to confirm all the facts over the last few days,” the company said. Oz Hair and Beauty confirmed that its website does not store credit card information. “The website does not store credit card information, so your payment details are completely safe,” the company said. The company also confirmed that banking details and home addresses had not been leaked. The company has not confirmed how many customers were affected.

Investigation Underway

Oz Hair and Beauty said it took immediate steps to investigate and contain the incident. The company commenced a forensic investigation with support from senior technical specialists from its cloud e-commerce platform provider. It is also reviewing and enhancing its cybersecurity posture and data retention policies to reduce the risk of similar incidents. The company said affected customers had been notified and that it was taking appropriate steps to support them. Oz Hair and Beauty is also preparing a full communication about the incident, which is currently being handled by its dedicated cyber team. “We want to make sure the right information goes out on something this important,” the company said.

Delay in Customer Notifications

Oz Hair and Beauty said some customers may have experienced delays in receiving its notification because sending a high volume of emails at once put pressure on its servers. The company apologized for the delay and asked customers who contact it directly to allow up to 48 hours for a response.

Customers Warned About Suspicious Communications

Oz Hair and Beauty has advised customers to remain alert for unusual phone calls or emails requesting personal information, payments or proof of identity. The company specifically warned customers to be cautious of: “any unusual communications by phone or email requesting information, payments or proof of identity.” Customers should avoid providing sensitive information in response to unsolicited requests and independently verify suspicious communications. The company has also advised customers who receive spam emails to use the relevant spam-reporting features provided by their email services.

Customers Can Continue Placing Orders

Oz Hair and Beauty has said customers can continue placing orders with the company. “You are safe to continue placing orders with us,” the company said. “We know this is unsettling and we appreciate you bearing with us while we work through it properly,” the company added.
  • ✇Firewall Daily – The Cyber Express
  • 678,000 People Hit in French Tax Authority Data Breach Samiksha Jain
    A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate acces
     

678,000 People Hit in French Tax Authority Data Breach

18 de Agosto de 2026, 03:57

DGFiP cyberattack

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate access to the French tax authority's information system on August 12 and 13. DGFiP said the intrusions involved the usurpation of identifiers belonging to a DGFiP agent and an authorized third party.

DGFiP Cyberattack Exposed Taxpayer Information

After detecting the intrusions, DGFiP immediately suspended access to the accounts involved. Initial access controls did not identify data theft, which the authority attributed to the sophistication of the attack. A subsequent investigation established that the compromised access points had been used to consult and extract information concerning 678,000 individuals and professionals. The exposed information included reference tax income, family quotient and withholding tax rate for individuals. For businesses, the accessed information included company names and SIREN numbers. Cadastral data, including addresses and property sizes, was also accessed. DGFiP said online accounts belonging to individual and professional users were not compromised, and user IDs and passwords were not affected. The authority notified France's data protection regulator, CNIL, after identifying the data breaches.

Cadastral Data Leak Claim Targets DGFiP

Separately, a hacker using the alias ZeroBytes claimed an attack against DGFiP's Professional Cadastral Data Server (SPDC). According to the claim cited by FrenchBreaches, the alleged extraction contains 252,149 lines of data representing 2,041,778 people, with multiple holders potentially associated with the same property plot. The claimed dataset reportedly includes names, surnames, sex, dates and places of birth, addresses, land identifiers, cadastral sections and parcel numbers, as well as information about rights held on properties. The claim would therefore link individuals to personal information and real estate assets. However, the figures and technical details in this second claim remain allegations by the cybercriminal. The claim that the system could contain information relating to approximately 20 million citizens is also an estimate made by ZeroBytes and does not establish that this number of people was affected.

Investigation Into French Tax Authority Attack Continues

DGFiP said additional security measures were implemented after investigators uncovered new information. These included preventative shutdowns of access to sensitive information systems. Investigations remain underway to determine the precise nature and volume of data extracted and the number of users affected. DGFiP teams are working with France's economic and financial ministries, the High Official for Defence and Security and the National Agency for Information Systems Security, ANSSI. The authority said it will contact affected individuals and professionals directly from the following week by email or letter. Those notifications will identify the information that may have been accessed or extracted and outline any precautionary measures where applicable. DGFiP also said it will file a complaint and provide further information as the investigation progresses. The separate cadastral data breach claim remains subject to confirmation, including the alleged number of affected people, duration of access, methods used to bypass authentication, the full scope of extracted information and whether access remained active when the claim was published. The confirmed DGFiP investigation and the separate ZeroBytes claim therefore present different sets of figures and allegations, with the full scope of the incidents still being determined.

Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident

Updoc data breach

The Updoc data breach has raised fresh concerns about cybersecurity in Australia's healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system.   The data breach at Updoc, disclosed on August 7, stemmed from a brief security incident involving a third-party platform that supports the company's operations. While the Updoc cyberattack did not expose medical or financial records, it is the latest cyber incident affecting Australia's healthcare sector. 

Updoc Data Breach Traced to Third-Party Platform 

Updoc, an Australian telehealth provider offering round-the-clock online healthcare services, including medical certificates, prescriptions, and specialist referrals, detected unauthorized access to a third-party operational system on Friday, July 31.  In a statement shared with The Cyber Express, the company said the incident was limited to an external system used to support its operations. The exposure was confined to customer contact information, which may have included account holders' names, email addresses, and postal addresses.  Updoc said its internal systems were not accessed during the incident and confirmed that no health records, financial information, or payment details were involved. The company added that it acted immediately to block the unauthorized access and found no evidence of any further activity after the initial event.  According to the company, customers are not required to take any immediate action because account logins and security remain unaffected. Updoc also apologized for any concern or inconvenience caused by the incident. 

Updoc Cyberattack Adds to Healthcare Sector Threats 

Founded in 2021, Updoc generates approximately $10 million in annual revenue. According to its founders, the platform has served more than one million patients since launch, while its website states that it has over 500,000 users.  The Updoc cyberattack follows a series of cybersecurity incidents targeting Australian healthcare and consumer-facing organizations. In June, clinic network Partnered Health disclosed a cyberattack in which hackers stole personal information and health records from patients across at least 21 clinics in five Australian states.  That breach exposed sensitive information, including medical records, Medicare numbers, consultation notes, referral letters, and pathology results. The attack affected clinics in Melbourne, Sydney, Canberra, the Gold Coast, Sunshine Coast, and Coffs Harbour. At the time, another five clinics, including several in Western Australia, remained under investigation.  Although the Updoc data breach was limited to contact information and did not compromise medical or payment data, the data breach at Updoc highlights the risks associated with third-party service providers. As healthcare organizations continue to depend on external platforms, the incident underscores how vulnerabilities outside a company's own infrastructure can still result in customer information being exposed. 
  • ✇Firewall Daily – The Cyber Express
  • PNLD Data Breach Exposes Police and Government Contact Details on Dark Web Ashish Khaitan
    The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks.  PNLD Data Breach Exposes Police and Contact Details  According to PNLD, the compromised data includes names, or
     

PNLD Data Breach Exposes Police and Government Contact Details on Dark Web

PNLD data breach

The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks. 

PNLD Data Breach Exposes Police and Contact Details 

According to PNLD, the compromised data includes names, organizations and work email addresses of police officers, police staff, criminal justice professionals, government partners and customers. The incident also exposed the names and email addresses of some individuals who had previously submitted questions through Ask the Police. UK government guidance warns that such information could enable attackers to craft more convincing phishing emails targeting named officers and affected individuals.  In its official statement, PNLD said, "There is no evidence to suggest that passwords or other security credentials have been compromised." The organisation clarified that it provides legal information, products and services to UK police forces and criminal justice organisations. It also stressed that PNLD is not the Police National Computer or the Police National Database, is not a crime-recording system, and does not store confidential information relating to victims, witnesses or offenders. 

PNLD Notifies Authorities and Affected Users 

Following the PNLD data breach, the organization said it had contacted all affected organizations and provided additional guidance. Individuals impacted through Ask the Police have also received notification emails with further information PNLD confirmed that it has informed the Information Commissioner's Office (ICO) and is working with the National Crime Agency (NCA) and specialist cybersecurity organizations as the investigation continues.  Its statement noted: "We are continuing to investigate a data security incident affecting the Police National Legal Database (PNLD), which was identified on Sunday 26 July." It added that compromised information had been published on the dark web and reiterated that there is no evidence that passwords or other security credentials were accessed.  Regarding Ask the Police, PNLD said the platform was affected because it is hosted on the same infrastructure, resulting in the publication of some users' names and email addresses. 

Investigation Continues as Key Questions Remain 

As of August 3, 2026, PNLD had not disclosed how many people were affected by the data breach at PNLD, when the intrusion began, how long unauthorized access lasted or the total volume of data obtained. Its public breach notice lists the categories of exposed information but does not include a victim count.  PNLD's 2025-26 annual summary reported 108,429 police registrations and support for all 43 Home Office police forces. However, the organization emphasized that this figure represents its user base and should not be interpreted as the number of people affected by the breach.  The organization's 2023-24 annual summary stated that PNLD uses Microsoft Power Platform technology. On August 3, 2026, The Hacker News reported that the breach notification page referenced assets hosted on Microsoft's content.powerapps.com domain. While this supports the platform connection, it does not indicate how the attackers accessed or extracted the compromised data. 
  • ✇Firewall Daily – The Cyber Express
  • Hackers Breach Beneficial Owners Registry, Access Data of 31,000 Firms Samiksha Jain
    A Beneficial Owners Register breach has exposed data copies linked to approximately 31,000 legal entities after unknown attackers gained unauthorized access to the Register of Beneficial Owners (VwbP). Authorities confirmed the cyberattack prompted an immediate response, including taking the affected system offline, launching a technical investigation, and establishing a government-led crisis team to manage the incident. According to official information, the attackers digitally
     

Hackers Breach Beneficial Owners Registry, Access Data of 31,000 Firms

Beneficial Owners Register breach

A Beneficial Owners Register breach has exposed data copies linked to approximately 31,000 legal entities after unknown attackers gained unauthorized access to the Register of Beneficial Owners (VwbP). Authorities confirmed the cyberattack prompted an immediate response, including taking the affected system offline, launching a technical investigation, and establishing a government-led crisis team to manage the incident.

According to official information, the attackers digitally accessed the VwbP during the night of July 30, 2026. Irregularities were detected later that day by the Office of Justice, which then contacted the Office of Information Technology to investigate the incident. Based on the initial findings, the affected system was immediately secured and removed from external access while investigators began a detailed analysis.

Beneficial Owners Register Breach Confirmed After Investigation

On July 31, 2026, the government was informed that the Beneficial Owners Register breach may have been successful. The first confirmed findings from the preliminary investigation were submitted on the afternoon of August 1.

Authorities said the attackers unlawfully accessed the directory and stole data copies relating to approximately 31,000 legal entities. The Register of Beneficial Owners (VwbP) stores information about the beneficial owners of companies, foundations, and trusts.

Officials stated that the register has been temporarily taken offline for external users through the LLV.li website while investigations continue. Based on current findings, there is no indication that any information stored in the system was altered or deleted during the incident.

Government Establishes Crisis Team

Following confirmation of the incident, the government convened a crisis team on the evening of August 1, 2026. The team immediately began its work and was formally confirmed on August 2.

The crisis team is led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler. According to the government, its priorities are to fully investigate the incident, inform affected individuals, and implement appropriate countermeasures.

GDPR Data Breach Notification Process Underway

Authorities confirmed that the incident qualifies as a data breach involving personal information under Article 33 of the General Data Protection Regulation (GDPR).

The crisis team said it is working to notify affected individuals in accordance with Article 34 GDPR as quickly as possible. A central information point is also being established to respond to questions from those impacted by the breach.

What Is the Register of Beneficial Owners?

The Register of Beneficial Owners (VwbP) was established to support money laundering prevention and combat terrorist financing. It contains information identifying the beneficial owners of legal entities, including companies, foundations, and trusts.

The register operates under the Law on the Register of Beneficial Owners of Legal Entities (VwbPG), which came into force in 2021 to implement the requirements of the 5th EU Anti-Money Laundering Directive.

Authorities continue to investigate how the unauthorized access occurred and whether additional measures will be required to strengthen the security of the register. At this stage, officials have confirmed only that data copies were accessed and that there is currently no evidence suggesting records within the system were modified or deleted.

The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats

The Cyber Express weekly Roundup July 2026 new

This weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses.  The latest developments show that cyber risks are expanding beyond traditional network attacks. Threat actors are targeting identities, trusted platforms, software supply chains, and operational technology environments. Organizations must strengthen security controls, improve monitoring capabilities, and adopt proactive measures to protect sensitive data and critical services. 

The Cyber Express Weekly Roundup 

Four Men Admit to $2.2 Million Medicaid Fraud Scheme Using AI 

Four Minnesota men have pleaded guilty in connection with a Medicaid fraud scheme that allegedly generated approximately $2.2 million through fraudulent claims for housing-related services. Prosecutors stated that artificial intelligence tools, including ChatGPT, were used to create false documentation supporting fraudulent billing activity. Read more... 

Tribeca Data Leak Exposes Celebrity-Linked Information 

A reported data leak connected to the Tribeca Film Festival exposed nearly 666,000 records containing personal information associated with attendees, contacts, and individuals linked to the entertainment industry. The exposed data reportedly included names, email addresses, phone numbers, and limited device-related information. Read more... 

Origin Energy Data Breach Impacts Around 900,000 Customers 

Australian energy company Origin Energy confirmed a data breach affecting approximately 900,000 current and former customers. The exposed information may include customer names, contact details, dates of birth, and partial account information. The company is investigating the incident and has advised customers to remain alert for possible scams or suspicious communications. Read more... 

Joyfill npm Packages Found Distributing DEV#POPPER Malware 

Security researchers discovered that two beta versions of Joyfill npm packages were distributing DEV#POPPER, a remote access trojan (RAT) capable of stealing information, executing commands, and compromising developer environments. Read more... 

Student Accused of IIT Website Breaches Offered Technical Assessment 

A student accused of breaching parts of the IIT Kanpur and IIT Madras websites after being rejected from IIT Kanpur’s cybersecurity program will undergo a technical skills assessment rather than facing immediate legal action. The institute stated that admissions for the current session are closed but indicated that future opportunities may be considered if the student demonstrates strong cybersecurity abilities. Read more... 

FBI Warns of PLC Cyberattacks Targeting U.S. Water Utilities 

The FBI and the U.S. Environmental Protection Agency warned that cyberattacks targeting internet-connected programmable logic controllers (PLCs) have disrupted water utilities across multiple U.S. states. Attackers reportedly manipulated PLC settings, affecting monitoring and operational processes. Read more... 

Weekly Cybersecurity Takeaway

This week’s incidents demonstrate how cyber threats continue to evolve across multiple domains, including artificial intelligence abuse, personal data exposure, software supply chain attacks, and critical infrastructure targeting.  A common theme across these events is the exploitation of trust. Attackers are abusing trusted technologies, legitimate software ecosystems, customer databases, and connected infrastructure to achieve their objectives.  Organizations must focus on building cyber resilience through stronger identity protection, secure development practices, continuous monitoring, and effective incident response planning.  As emerging technologies such as artificial intelligence and connected industrial systems become more widespread, cybersecurity strategies must evolve alongside them. Protecting digital assets requires not only stronger technical defenses but also responsible for technology use, awareness, and proactive risk management. 
  • ✇Firewall Daily – The Cyber Express
  • Origin Energy Data Breach Affects 900,000 Current and Former Customers Ashish Khaitan
    The Origin Energy data breach has affected approximately 900,000 current and former customers after Australia's largest energy retailer confirmed unauthorized access to customer information. The company also revealed it had received a warning about the potential breach weeks before it publicly disclosed the incident.  Origin Energy said a significant proportion of those affected by the data breach at Origin Energy were former customers. The compromised information may include names, addresses
     

Origin Energy Data Breach Affects 900,000 Current and Former Customers

Origin Energy data breach

The Origin Energy data breach has affected approximately 900,000 current and former customers after Australia's largest energy retailer confirmed unauthorized access to customer information. The company also revealed it had received a warning about the potential breach weeks before it publicly disclosed the incident.  Origin Energy said a significant proportion of those affected by the data breach at Origin Energy were former customers. The compromised information may include names, addresses, dates of birth, phone numbers and account details, along with the last four digits of a credit card or the last three digits of a bank account.  The company said incomplete credit card and bank account details cannot be used to make purchases or access customer accounts.  Origin provides electricity, fossil gas, LPG and internet services to households and businesses across Australia and has approximately 4.8 million customer accounts. 

Frank Calabria Apologizes After Origin Energy Data Breach 

Origin Chief Executive Frank Calabria apologized to customers following confirmation of the breach and warned that affected individuals should remain alert to suspicious activity and a heightened risk of scams.  "We are sorry," Calabria said. "We don't take for granted the trust customers place in Origin, and we're here to support them."  Calabria said Origin first received emails on 2 July from an individual claiming to have accessed customer records. However, the company did not initially consider the threat credible because there was no evidence confirming customer data had been accessed.  The company received proof of customer data access on 22 July, after which Origin announced the incident publicly.  Calabria said the information accessed appeared to be historical customer data obtained "on an unauthorised basis". He said Origin had taken steps to secure its systems and prevent further unauthorised access, adding that the company did not believe any customer information had been published on the dark web. 

Timeline of the Data Breach at Origin Energy 

Origin said it had been reviewing a potential security threat since early July and had worked to assess its credibility and possible impact.  In its update, the company said the threat was not considered credible based on the information available at the time.  "On 22 July, new information emerged that indicated a potential security incident may have occurred. We acted immediately, providing updates to the market and notifying our customers as a precaution," Calabria said.  The Origin Energy data breach remains under investigation by relevant authorities. Calabria said the company could not provide further details about the incident because it was a criminal matter.  "It is a criminal matter which is under active investigation and, given that, we are constrained by the level of information we can provide at this time," he said.  Calabria declined to comment on several issues, including when the breach occurred, whether any employees were involved, whether a ransom had been demanded or paid, and whether there remained an active risk of further data leaks. 

Origin Confirms Investigation into Customer Data Breach 

In its first statement on 23 July 2026, Origin announced it was investigating a potential security incident involving unauthorized access to some customer data.  The company said it did not believe the affected information included customer credit card or bank account details.  "We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers," Origin said.  The company confirmed it had notified the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner.  A later update confirmed there had been unauthorised access and disclosure of customer information. Origin said it was working to identify all affected customers and would contact those whose information had been compromised. 

Around 900,000 Customers Affected by Origin Energy Data Breach 

Following an initial review, Origin confirmed that approximately 900,000 current and former customers had been affected by the breach.  "We have now completed the initial phase of our review into Origin's customer data security incident," Frank Calabria said.  "At this point in time, we believe the information of approximately 900,000 current and former customers was accessed."  Calabria again apologized to customers and said protecting affected individuals remained the company's priority.  "To our customers, I am sorry. We don't take for granted the trust customers place in Origin and our safeguarding of their information," he said.  "We are contacting those customers whose information has been accessed and are providing support to them."  Origin said it had extended customer support hours, established a dedicated contact number and was working with cybersecurity and forensic specialists to contain the incident.  The company also confirmed ongoing cooperation with government agencies, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police and the Office of the Australian Information Commissioner. 

Customers Warned about Scams Following Data Breach at Origin Energy 

Origin has made specialist identity and cybersecurity support services available to affected customers.  Customers with concerns can contact Origin through its dedicated support line on +61 8 9922 7000 or email hello@origin.com.au.  The company advised customers to be cautious of unexpected calls, emails or text messages referring to their Origin accounts. It recommended avoiding links in unsolicited messages, independently verifying callers through official channels, never sharing passwords, and not providing personal or financial information unless the recipient's identity is confirmed.  Origin also encouraged customers to use two-step authentication, such as authentication applications, for personal email accounts and other online services where available.  We are acutely aware that others may exploit this incident, including by impersonating Origin or through other scam activity," Calabria said.  "We recommend that all our customers remain vigilant to suspicious activity and a heightened risk of scams." 
  • ✇Firewall Daily – The Cyber Express
  • Angelina Jolie, Robert De Niro Among Hollywood Stars Hit by Tribeca Data Leak Samiksha Jain
    A Tribeca Film Festival data breach has reportedly exposed the contact information of Hollywood stars including Angelina Jolie, Robert De Niro and Martin Scorsese, alongside details linked to other prominent actors and filmmakers. Cybersecurity researcher Jeremiah Fowler reportedly identified nearly 666,000 records across four databases connected to the annual New York film festival, raising concerns over the exposure of personal and professional information. According to reports, the exposed
     

Angelina Jolie, Robert De Niro Among Hollywood Stars Hit by Tribeca Data Leak

Tribeca Film Festival Data Breach

A Tribeca Film Festival data breach has reportedly exposed the contact information of Hollywood stars including Angelina Jolie, Robert De Niro and Martin Scorsese, alongside details linked to other prominent actors and filmmakers. Cybersecurity researcher Jeremiah Fowler reportedly identified nearly 666,000 records across four databases connected to the annual New York film festival, raising concerns over the exposure of personal and professional information. According to reports, the exposed records included names, phone numbers and email addresses. While several high-profile celebrities were reportedly listed in the databases, sources cited in the reports said most of the leaked contact information belonged to managers and agents representing celebrities rather than the stars themselves.

Tribeca Film Festival Data Breach Exposes 666,000 Records

The alleged data breach was first flagged by Fowler after he discovered four databases containing nearly 666,000 records dating from 2019 through 2026. The information was reportedly connected to the Tribeca Film Festival, which was founded in New York by Robert De Niro and others. Fowler reportedly alerted the festival about the exposure shortly before its 12-day event began on June 3. The exposed information allegedly included contact details that could potentially be used by attackers for targeted phishing or malware campaigns. The researcher also reportedly found a folder containing device information associated with email addresses. The data allegedly indicated details such as the version of an iPhone being used, whether Safari was the browser in use and the software version installed on the device. According to Fowler, such information could provide attackers with additional details that may help them target individuals.

Angelina Jolie, Robert De Niro Among Names Reportedly Exposed

The alleged exposure reportedly involved contact information associated with several well-known Hollywood figures. The names mentioned in reports include Angelina Jolie, Robert De Niro, Martin Scorsese, George Lucas and Danny Boyle. Actors reportedly appearing in the records include Morgan Freeman, Jennifer Lawrence, Winona Ryder, Neil Patrick Harris, Rami Malek, Sharon Stone and Michael Douglas. However, the extent to which the celebrities' own private contact details were exposed remains unclear. A source cited in the reports said the majority of the information reportedly belonged to managers and agents who represent the celebrities. This distinction suggests the databases may have been used for professional communication and coordination connected to the film festival rather than containing direct personal accounts belonging to the celebrities.

Tribeca Film Festival Investigates Alleged Data Exposure

The Tribeca Film Festival reportedly responded after receiving the disclosure from Fowler, saying it takes data security seriously and was actively investigating the matter. The databases have since reportedly been removed from public access. However, it remains unclear how long the information was accessible online or whether unauthorized individuals accessed, copied or misused the exposed data before it was taken down. Jeremiah Fowler, the cybersecurity researcher who identified the exposed databases, told The Cyber Express that he found no evidence of malicious activity. “No, I didn't see any evidence like a ransomware message or something like that,” Fowler said. He added that the database contained “lots of non-sensitive documents like press releases and event details.” According to Fowler, “even if someone found it, they would probably see these type of documents and just ignore it.” However, he said the discovery of a backup file changed the situation. “When I discovered that the database contained a backup file, that's when things got serious,” Fowler said, adding, “It was likely human error why there was a backup file stored in this database.” The reports also clarified that there is no suggestion that the Tribeca Film Festival was directly responsible for the alleged exposure. The organisation has not reportedly provided further public details about the incident beyond its initial response.

Celebrity Data Breach Raises Security Concerns

The alleged celebrity data breach highlights the security risks surrounding databases containing information about public figures and the professionals who work with them. Even when exposed records primarily belong to managers and agents, such information can potentially reveal connections between celebrities and their representatives. The reported inclusion of device information could also provide additional context about the technology used by individuals associated with the records. The incident adds to concerns over how personal and professional data connected to major cultural events is stored, managed and secured online. With the investigation reportedly ongoing, questions remain about the source of the exposure, the duration of public access and whether any of the information was misused.

The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threats

The Cyber Express weekly roundup July 2026

This week’s cybersecurity landscape highlights the continued expansion of cyber risks across governments, businesses, and consumers. From ransomware campaigns targeting organizations worldwide to credential-based attacks, data breaches, online fraud, and digital piracy crackdowns, recent incidents show how threat actors are exploiting both technical vulnerabilities and human behavior.  The latest developments underline the need for stronger security practices, including improved identity protection, faster incident response, and greater awareness of evolving cyber threats. Organizations are increasingly dealing with attacks that go beyond data theft, affecting operations, customer trust, and critical services. 

The Cyber Express Weekly Roundup 

U.S. Accounts for Nearly Half of Global Ransomware Attacks in H1 2026 

The United States experienced 1,721 ransomware attacks during the first half of 2026, representing nearly 45% of all incidents tracked globally, according to research from Cyble Research and Intelligence Labs (CRIL). The report identified ransomware groups Qilin and Akira as among the most active threat actors during the period. Read more... 

Dubai Police Warns Against Online Visa Fraud Schemes 

Dubai Police has issued a warning about fraudulent online advertisements offering work, residency, and visit visas in exchange for payment. Scammers have reportedly used social media platforms and messaging applications to impersonate government entities or unauthorized service providers to trick victims. Read more... 

Craneware Data Breach Exposes Employee and Customer Information 

Healthcare technology company Craneware confirmed that unauthorized individuals accessed part of its data environment, resulting in the exposure of employee information as well as some customer and partner records. The company stated that the incident has been contained and has not disrupted business operations or customer services. Read more...  

U.S. Targets Illegal FIFA World Cup Streaming Networks 

The U.S. Department of Justice seized more than 1,000 domains allegedly involved in illegally streaming FIFA World Cup 2026 matches. The action was carried out under Operation Offsides, an initiative focused on combating online piracy and protecting intellectual property rights. Read more... 

Chick-fil-A Customer Accounts Targeted in Credential Attack 

Chick-fil-A confirmed that certain customer accounts were accessed during an automated credential-stuffing attack between June 17 and June 19, 2026. The attackers used account credentials obtained from an external source to gain unauthorized access. The company said affected information may have included customer names, email addresses, membership details, and limited payment-related data. Read more... 

South Korea Diplomatic System Breach Lasted Nearly 10 Months 

South Korea’s Ministry of Foreign Affairs revealed that attackers maintained access to the National Diplomatic Academy’s online education system for almost 10 months. The breach, which began in April 2025, exposed information linked to thousands of current and former ministry employees. Compromised data included user IDs, names, email addresses, and encrypted passwords. Read more... 

Weekly Cybersecurity Takeaway 

The week’s incidents demonstrate how cyber threats continue to evolve across multiple areas, from ransomware and account compromise to online scams and government-related breaches. Attackers are increasingly targeting weaknesses in identity management, user behavior, and digital infrastructure.  Organizations and individuals must focus on proactive security measures, including stronger authentication controls, regular monitoring, timely updates, and greater awareness of social engineering tactics. As cyber threats become more widespread and interconnected, improving resilience remains essential for protecting data, services, and public trust. 
  • ✇Firewall Daily – The Cyber Express
  • Hackers Lurked for 10 Months Inside South Korea Diplomatic System Ashish Khaitan
    The National Diplomatic Academy data breach has raised significant cybersecurity concerns in South Korea after the Ministry of Foreign Affairs confirmed that hackers maintained access to the academy's online education system for nearly 10 months. The cyberattack resulted in the exposure of personal information belonging to current and former ministry employees, including diplomats serving overseas.  According to the Ministry of Foreign Affairs, the attackers exploited a vulnerability in the N
     

Hackers Lurked for 10 Months Inside South Korea Diplomatic System

National Diplomatic Academy data breach

The National Diplomatic Academy data breach has raised significant cybersecurity concerns in South Korea after the Ministry of Foreign Affairs confirmed that hackers maintained access to the academy's online education system for nearly 10 months. The cyberattack resulted in the exposure of personal information belonging to current and former ministry employees, including diplomats serving overseas.  According to the Ministry of Foreign Affairs, the attackers exploited a vulnerability in the National Diplomatic Academy's online education platform in April 2025. The compromise remained active until February 2026, allowing unauthorized access to data linked to thousands of individuals before the incident was eventually discovered and contained. 

National Diplomatic Academy Data Breach Remained Active for Nearly 10 Months 

The National Diplomatic Academy data breach began in April 2025 after an unidentified threat actor exploited a security flaw in the academy's online education system. The platform, which was introduced in 2022 to support remote learning during the COVID-19 pandemic, has since been used for government employee training and video conferencing.  According to the Ministry of Foreign Affairs, personal information was exposed between April 2025 and February 2026.  In an official announcement, the ministry stated:  There was an unidentified attack exploiting a security vulnerability targeting the Korea National Diplomatic Academy's online education system, and it has been confirmed that personal information of former and current employees of the Ministry of Foreign Affairs headquarters and overseas missions, as well as other personnel, was leaked from April 2025 to February 2026."  The ministry said the attack affected current and former employees at its headquarters, overseas missions, and other personnel connected to the online education system. 

Thousands Impacted in South Korea Foreign Ministry Data Breach 

The National Diplomatic Academy data breach is estimated to have impacted at least 6,000 individuals, including approximately 350 government attachés currently stationed abroad. However, reports from Korean media suggest the number of affected individuals could be as high as 10,000, while other reports indicate lower figures.  In addition to personal information, local media reported that official job titles and departmental affiliations may also have been exposed during the incident.  The Ministry of Foreign Affairs has not confirmed the higher estimates but acknowledged that the breach affected a substantial number of current and former personnel associated with the diplomatic service. 

What Information was Exposed? 

According to the Ministry of Foreign Affairs, the information compromised during the National Diplomatic Academy data breach included: 
  • User IDs 
  • Names 
  • Email addresses 
  • Encrypted passwords 
The ministry emphasized that several categories of sensitive information were not exposed.  Its official notice stated:  "The personal information items involved in the leak include the ID, name, email, and encrypted password of the trainee in the Korea National Diplomatic Academy's online education system."  The notice further clarified:  "Unique identification information, sensitive information, mobile phone numbers, home addresses, and photos were not included."  This means national identification numbers, photographs, residential addresses, phone numbers, and other sensitive personal data were not part of the compromised dataset, according to the ministry. 
  • ✇Firewall Daily – The Cyber Express
  • Estée Lauder Confirms Cyberattack Affecting Personal Information Ashish Khaitan
    The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations.   The Estée Lauder cyberattack stemmed from unauthorized access that occurred on or around August 9, 2025, though the company said it identified the incident last month and confirmed the scope of the breach on June 19, 2026.  Estée Lauder Data Breach Exposed Sensitive Pers
     

Estée Lauder Confirms Cyberattack Affecting Personal Information

Estée Lauder data breach

The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations.   The Estée Lauder cyberattack stemmed from unauthorized access that occurred on or around August 9, 2025, though the company said it identified the incident last month and confirmed the scope of the breach on June 19, 2026. 

Estée Lauder Data Breach Exposed Sensitive Personal Information 

According to the company's notification letter, the attackers gained access to the Oracle E-Business Suite system and obtained personal information belonging to certain individuals.  We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes," the notice states.  It further adds: "On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals."  The exposed data in the incident includes full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSNs), passport numbers, financial account information, including bank account numbers, health information, and employment records such as payroll and performance reports. 

Oracle Vulnerability Tied to Estée Lauder Cyberattack 

Although Estée Lauder did not identify the specific vulnerability used in the attack, the timeline aligns with the widespread exploitation of the Oracle E-Business Suite flaw CVE-2025-61882.  In October 2025, researchers from Google warned that the Clop ransomware group had exploited the vulnerability as a zero-day to steal data. The flaw affected Oracle EBS versions 12.2.3 through 12.2.14, allowing attackers to bypass authentication and remotely execute code through the BI Publisher Integration component. Successful exploitation could provide access to sensitive HR and business information.  Oracle released security patches for CVE-2025-61882 on October 4, 2025. Soon after, cybersecurity company CrowdStrike confirmed that Clop had been exploiting the vulnerability since early August 2025. 

Company Offers Identity Monitoring 

Estée Lauder, headquartered in New York, generates annual revenue of $14.3 billion, employs around 57,000 people, and operates retail stores and online businesses worldwide, making it the world's second-largest cosmetics company.  Following the Estée Lauder data breach, the company is urging recipients of its notification letter to monitor for signs of identity theft and fraud. It is also providing 24 months of complimentary identity monitoring services through Kroll.  The Estée Lauder cyberattack is part of a broader campaign that affected several high-profile organizations, including Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and American Airlines subsidiary Envoy Air.  This is not the first time the company has been impacted by Clop. In 2023, Estée Lauder was also compromised after the ransomware group exploited a separate zero-day vulnerability in the MOVEit Transfer platform, one of the company's internal software tools. 
  • ✇Firewall Daily – The Cyber Express
  • Craneware Confirms Data Breach, Employee Records Among Exposed Data Ashish Khaitan
    Craneware plc has disclosed a Craneware data breach after detecting unauthorized access to a portion of its data environment. The company confirmed on 20 July 2026 that it is investigating the incident with the support of external cybersecurity and forensic experts.  Although the cyberattack on Craneware resulted in data being viewed and exfiltrated, the company said the incident has been contained and has not disrupted customer services or business operations.  Craneware Cyberattack Contain
     

Craneware Confirms Data Breach, Employee Records Among Exposed Data

Craneware data breach

Craneware plc has disclosed a Craneware data breach after detecting unauthorized access to a portion of its data environment. The company confirmed on 20 July 2026 that it is investigating the incident with the support of external cybersecurity and forensic experts.  Although the cyberattack on Craneware resulted in data being viewed and exfiltrated, the company said the incident has been contained and has not disrupted customer services or business operations. 

Craneware Cyberattack Contained, Investigation Underway 

According to the company's official notice, the Craneware cyberattack prompted the activation of its incident response plan immediately after the unauthorized access was identified. The Board appointed external cybersecurity and forensic specialists, who are working alongside Craneware's internal IT team and retained security providers to determine the full scope of the incident.  The company stated that investigators have found no remaining indicators of compromise within its systems. Despite the data breach at Craneware, normal operations have continued without interruption. 

Data Breach at Craneware Exposed Employee and Customer Records 

Initial findings indicate that attackers viewed and exfiltrated a significant volume of file names. Craneware's current assessment suggests that much of the affected information consists of non-sensitive or publicly available regulatory data. However, the investigation has also confirmed that a percentage of employee data, along with a subset of customer and partner records, was accessed and exfiltrated during the Craneware data breach.  The organization is continuing to examine the precise nature and extent of the compromised data. It is also working with advisers to identify affected individuals and organizations, prepare notifications where necessary, and meet all applicable regulatory obligations. Craneware added that it will provide further updates to the market as additional information becomes available.  As part of its response to the data breach at Craneware, the company has notified relevant regulators and law enforcement agencies. These include the UK's Information Commissioner's Office (ICO) and the US Federal Bureau of Investigation (FBI). 

Craneware to Notify Affected Parties as Assessment Continues 

In its official announcement, Craneware said: "The incident has been contained, and there has been no disruption to customer services or to the Company's operations. The external specialists have confirmed that there are no residual indicators of compromise arising from the cybersecurity incident in the Company's systems."  The company further stated: "Investigations so far have established that a significant volume of file names were viewed and exfiltrated. The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data. A percentage of Craneware employee data as well as a subset of customer and partner records, have been accessed and exfiltrated."  The notice also stated: "This announcement contains inside information as stipulated under the UK version of the Market Abuse Regulation No 596/2014, which is part of English Law by virtue of the European (Withdrawal) Act 2018, as amended. On publication of this announcement via a Regulatory Information Service, this information is considered to be in the public domain."  While the investigation into the cyberattack on Craneware remains ongoing, the company said it will continue assessing the impact of the cyberattack and issue further updates as appropriate. 
  • ✇Firewall Daily – The Cyber Express
  • Partnered Health Cyberattack Exposes Patient Data Across Australia Ashish Khaitan
    The Partnered Health cyberattack has exposed sensitive patient information across multiple Australian clinics, raising fresh concerns about healthcare cybersecurity. The Partnered Health data breach, involving clinics owned by healthcare provider Partnered Health, a company backed by Quadrant, affected facilities in New South Wales, Victoria, Queensland, Western Australia, and the ACT. The incident has also renewed scrutiny of the growing number of cyberattacks targeting Australia's health
     

Partnered Health Cyberattack Exposes Patient Data Across Australia

Partnered Health cyberattack

The Partnered Health cyberattack has exposed sensitive patient information across multiple Australian clinics, raising fresh concerns about healthcare cybersecurity. The Partnered Health data breach, involving clinics owned by healthcare provider Partnered Health, a company backed by Quadrant, affected facilities in New South Wales, Victoria, Queensland, Western Australia, and the ACT. The incident has also renewed scrutiny of the growing number of cyberattacks targeting Australia's healthcare sector.

Partnered Health Data Breach Impacted Medical and Personal Information 

Partnered Health confirmed that a malicious actor accessed its systems on 23 June, compromising data from 21 clinics across cities, including Sydney, Melbourne, and Canberra. The healthcare provider disclosed the breach more than three weeks later, informing patients that investigations had confirmed personal and health information had been taken from some clinics within its network. "Our investigations to date have confirmed that personal information (including health information) was taken from some of the clinics in our network," the company said. It added, "As a health services provider, we know our patients and our people trust us with personal and medical information, and we sincerely apologise for any concern and inconvenience this may cause them." The stolen information includes names, dates of birth, addresses, contact details, Medicare information, private health insurance details, concession card information, consultation notes, referral letters, pathology reports, diagnostic results, and other treatment records maintained by general practitioners.

Investigation into the Partnered Health Cyberattack Continues 

Partnered Health said the cyberattack has been reported to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and law enforcement authorities. The company has also secured an interim injunction from the NSW Supreme Court preventing the stolen information from being used or published. While investigations remain ongoing, the provider said the extent of the breach is still being determined at five clinics, including three in Western Australia and two in Victoria. "While there is no direct evidence that patient records have been viewed, as a precaution we have written to patients from these clinics to make them aware of this and provide details of steps that can be taken to protect their information," a Partnered Health spokesperson said. The spokesperson added, "We understand that this sort of news can cause concern. We sincerely apologize for any distress this may have caused our patients."

Quadrant-backed Healthcare Provider Faces Growing Scrutiny 

Established in 2013, Partnered Health operates more than 60 medical centres, along with skin cancer, allied health, and mental health clinics, providing services to more than 5 million people nationwide. The company is owned by Quadrant, while Bupa announced in June that it would acquire the healthcare provider. The Partnered Health data breach comes amid a record year for cybersecurity incidents in Australia. According to the Office of the Australian Information Commissioner, 1,205 data breach notifications were recorded in 2025, marking an 8% increase compared with 2024. Among the year's largest incidents was the cyberattack on Qantas, which compromised the information of 5.7 million customers and was reportedly leaked on the dark web. A spokesperson for the Department of Home Affairs said the federal government is aware of the Partnered Health cyberattack and confirmed that relevant agencies are engaged as investigations continue. Authorities have not yet disclosed how many patients were affected or the full scope of the stolen data.

Qantas Did Everything “Right” — And Got Breached Anyway. Regulators Say That’s the Point.

16 de Julho de 2026, 03:48

Qantas, Qantas Data Breach, Data Breach, Cyber aattack, Socail Engineering, OAIC, OAIC Report, Privacy Commissioner

A vishing call to an overseas contact center agent. A fake IT ticket. A default setting nobody thought to lock down. That's all it took to expose the personal data of roughly 5 million Australians — and now the country's privacy regulator has decided Qantas isn't to blame for it.

The Office of the Australian Information Commissioner (OAIC) closed the book this week on its year-long preliminary inquiry into the June 2025 Qantas data breach, and the conclusion cuts against the instinct to punish the victim of a cyberattack.

Also read: Australia’s Qantas Confirms Cyberattack: 6 Million Service Records Compromised

According to the OAIC's report, the evidence gathered did not indicate a likelihood that Qantas had "failed" to take reasonable steps to protect the personal information it held, nor that it failed to ensure its overseas third-party provider complied with Australia's privacy principles. No investigation. No enforcement action.

"After more than a year of making inquiries and obtaining information on the data breach, we're satisfied that the evidence does not support the likelihood that a breach of privacy law occurred. As a result, we've decided not to commence a full investigation of Qantas at this stage." - Carly Kind, Australian Privacy Commissioner.

How It Happened

The breach traces back to a single phone call. A threat actor posing as "Qantas IT help" convinced a contact center agent to visit a website tied to the customer relationship management platform used by Qantas agents, walking them through steps framed as necessary to close an IT support ticket. That interaction connected the agent's CRM session to a data extraction tool controlled by the attacker, who then pulled data from every contact profile the agent could access. It was pure social engineering — no malware, no exploited vulnerability, just a convincing lie.

Qantas caught it fast. A staff member spotted an unusual spike in login-attempt alerts on the morning of June 30, two days after the call, and escalated it to the cybersecurity team. Within hours, the company had frozen the compromised account, assessed for data exfiltration, and triggered its incident response process. Public disclosure followed on July 2.

What Was Exposed — And What Wasn't

The regulator's numbers are more precise than what circulated publicly last year. Roughly 5.67 million customer records were compromised, with about 4 million exposing names, phone numbers, email addresses and Frequent Flyer details, and a further 1.7 million records including combinations of home or business addresses, dates of birth, gender and meal preferences. Critically, no credit card numbers, financial information or passport details lived on the compromised platform, and customer passwords and login credentials were never touched.

Also read: Qantas Airways Cyberattack Update: Customer Data Released, Security Measures Enhanced

Why The Regulator Let It Go

The OAIC's reasoning is a rare, explicit acknowledgment that good controls don't guarantee immunity. Investigators found that social engineering training generally targets credential theft, not the rarer tactic of talking an employee into authorizing a legitimate-looking system connection — meaning the attack likely would have succeeded even with standard training in place. They also noted the flaw was structural: a default configuration let the agent authorize a third-party app connection, a setting the CRM vendor has since changed for all its customers.

Commissioner Carly Kind put the broader stakes plainly in the OAIC's statement announcing the report, warning that AI-driven threats are only raising the bar. As she framed it, agentic and advanced AI will keep escalating the cybersecurity risks businesses face, making continuous review of security posture non-negotiable — not optional.

“Data breaches are a persistent feature of today’s digital world, and can occur despite organisations taking steps to protect personal information,” Commissioner Carly said. “Agentic and advanced AI will only increase the cybersecurity risks that businesses face, and it is critical that all organisations continuously review and enhance their security to protect against this growing threat.”

The takeaway here isn't that Qantas got a pass. It's that a regulator has now drawn, in writing, the line between negligence and the limits of what training and access controls can realistically stop.

Mount Royal University Data Breach Confirmed After June Cyberattack Exposes Student and Employee Files

Mount Royal University Cyberattack

The Mount Royal University data breach has been confirmed following a cyber incident that disrupted multiple university services in June. The Mount Royal University cyberattack, which occurred on June 18, has now been identified as a targeted attack in which an unauthorized actor accessed, stole, and deleted data stored on the university’s internal systems.   As the investigation into the cyberattack on Mount Royal University continues, the institution has begun taking steps to notify affected individuals, strengthen its response, and provide identity protection services to employees. 

Mount Royal University Cyberattack Led to Data Theft and Deletion 

Mount Royal University (MRU) in Calgary announced that its ongoing investigation has confirmed the cyber incident reported on June 18 was more than a service disruption. According to the university, an unauthorized actor gained access to specific folders within the institution’s H drive, a file storage system used by employees and students.  Investigators determined that the threat actor not only accessed and stole data from those folders but also deleted the contents afterward in an apparent attempt to hinder recovery efforts. The university emphasized that only certain folders on the H drive were affected, rather than the entire storage system.  The Mount Royal University data breach affected files belonging to both students and staff, although the full scope of the compromised information remains under investigation. 

Certain Employees and Students Impacted 

According to MRU, the H drive serves as a storage location for files belonging to individual employees and students. While the university stated that only specific folders were compromised, it will begin notifying impacted individuals within the week.  The institution has not disclosed the exact number of people affected by the Mount Royal University cyberattack, but confirmed that those whose information may have been exposed will receive direct communication regarding the incident.  As a precautionary measure, Mount Royal University will provide two years of credit monitoring and identity theft protection services to all current employees, as well as anyone who has been employed by the university within the past five years. Instructions for accessing these services will be distributed through both email and physical mail. 

Departmental Files Also Affected During the Cyberattack on Mount Royal University 

In addition to compromising the H drive, the threat actor also deleted the university’s J drive, which stores departmental files.  Although investigators confirmed that the J drive was erased, they stated there is currently no evidence indicating that its contents were accessed or copied before being deleted. Recovery efforts are underway; however, the university acknowledged that restoring all deleted departmental data may not be possible. 

Investigation Expected to Continue for Weeks or Months 

Mount Royal University said its investigation into the incident remains active and could take weeks or even months to complete. Digital forensic experts continue to examine the compromised systems to determine the full extent of the data breach and identify exactly what information was accessed.  The university indicated it will continue providing updates as new information becomes available. Officials are also working to restore affected systems following the Mount Royal University data breach, although recovery efforts remain ongoing due to the deletion of critical files. 
  • ✇Firewall Daily – The Cyber Express
  • KDDI Data Breach May Have Exposed Up to 14.22 Million Email Accounts Ashish Khaitan
    Japanese telecommunications company KDDI has disclosed a major cybersecurity incident in which up to 14.22 million email addresses and passwords may have been exposed through systems used by multiple internet service providers. The KDDI data breach has now become one of the most recent security events involving shared ISP infrastructure in Japan.  The company confirmed that the data breach at KDDI was detected on June 17, 2026, after unauthorized access was identified in an email system provi
     

KDDI Data Breach May Have Exposed Up to 14.22 Million Email Accounts

KDDI data breach

Japanese telecommunications company KDDI has disclosed a major cybersecurity incident in which up to 14.22 million email addresses and passwords may have been exposed through systems used by multiple internet service providers. The KDDI data breach has now become one of the most recent security events involving shared ISP infrastructure in Japan.  The company confirmed that the data breach at KDDI was detected on June 17, 2026, after unauthorized access was identified in an email system provided to ISP operators. KDDI said it immediately took steps to modify the affected system and deployed protective measures after identifying the entry point used by a threat actor. 

KDDI Data Breach Linked to Third-Party Software Vulnerability 

The data breach at KDDI impacted email services operated through six internet service providers: STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe. Affected services include Pikara Hikari Service, Pikara Mobile Service, Oshigoto Pikara Service, CPI rental server email services, J:COM NET, Commufa Hikari, Business Commufa, @nifty Mail, and BIGLOBE Mail.  KDDI’s investigation found that the threat actor exploited vulnerabilities in third-party software integrated into the email system. This allowed unauthorized access to information associated with user mailboxes, potentially exposing credentials needed to operate email accounts.  According to the company, the compromised data may include email addresses and passwords linked to user accounts created across the affected services. The maximum number of records potentially exposed is estimated at 14.22 million. This figure includes inactive accounts and users who had previously closed their services. Some passwords were stored in hashed or encrypted form, though KDDI emphasized that the number represents a worst-case estimate while investigations continue.  In its official disclosure, KDDI apologized to ISP partners, customers, and stakeholders for the disruption caused by the incident. The company also confirmed that it is cooperating with Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications in line with legal and regulatory obligations related to the KDDI data breach. 

KDDI Data Breach Prompts Password Reset Measures and Ongoing Response 

Following the detection of the data breach at KDDI, the company has been working with affected ISPs to notify users and encourage them to change their passwords immediately. KDDI stated that although security controls have been strengthened, there remains a possibility that email credentials were obtained by a threat actor, making user action necessary to reduce ongoing risk.  The company has been contacting affected providers since June 17 and continues to coordinate mitigation efforts, including customer alerts and system-level countermeasures. It has also urged users to follow guidance issued by their respective ISPs and update login credentials without delay. 

Rising Cybersecurity Risks Highlighted by KDDI Data Breach 

The KDDI data breach has emerged amid a broader increase in cyberattacks affecting Japanese organizations. According to Tokyo Shoko Research, listed companies and their subsidiaries reported 180 personal information breach cases in 2025, exposing data tied to approximately 30.6 million individuals. More than 60% of these incidents involved unauthorized access or malware infections.  Ransomware activity has also continued to rise, with Japanese police confirming 226 cases of ransomware-related incidents last year, marking the second-highest total on record. While small and midsize firms accounted for roughly 60% of victims, several large organizations also suffered significant operational disruption.  Among them, Asahi Group Holdings reported that a ransomware attack in September exposed 115,513 personal records and disrupted production and distribution across most domestic facilities, forcing manual order processing for an extended period. Similarly, Askul disclosed that a ransomware incident discovered in October resulted in the exposure of approximately 740,000 records involving customers, corporate clients, and employees. 

The Cyber Express Weekly Roundup: Cybersecurity Weekly Round on Emerging Threats, Data Breaches, and Global Policy Shifts

weekly roundup TCE

This week’s weekly roundup of cybersecurity developments highlights an expanding intersection of cyber risk, regulatory action, and enterprise vulnerability. Across healthcare, technology platforms, gaming companies, and government policy, organizations continue to confront a rapidly evolving cybersecurity landscape where data exposure, advanced intrusion tactics, and platform security failures are interconnected.  The overarching theme in this weekly roundup is the growing strain on digital ecosystems as attackers refine stealth techniques while institutions attempt to secure distributed systems. From cloud-based email exploitation to AI-related enterprise vulnerabilities, this week’s cybersecurity incidents underscore the difficulty of maintaining visibility and control across modern infrastructure. 

The Cyber Express Weekly Roundup 

Novo Nordisk Security Incident Exposes Limited Patient and HCP Data 

Novo Nordisk reported an unauthorized intrusion into internal systems that resulted in the external copying of limited clinical trial data along with healthcare professional contact details. According to the disclosure, core operational systems were not disrupted during the incident, and the breach did not affect ongoing business continuity. Read more... 

UNC6508 Used Google Workspace Trick to Spy on U.S. Medical Research 

A threat group identified as UNC6508, linked to China, reportedly conducted a long-term espionage campaign targeting North American medical and research institutions. Over a period described as exceeding two years, attackers infiltrated research environments and accessed sensitive systems related to medical and defense-linked projects. Read more... 

Critical SearchLeak Flaw in Microsoft 365 Copilot Exposed Enterprise Data 

A newly addressed vulnerability, identified as CVE-2026-42824, affected Microsoft 365 Copilot and carried the potential for significant enterprise data exposure. Researchers found that a chain of weaknesses—including prompt injection, HTML rendering issues, and server-side request forgery—could be exploited to extract sensitive data. Read more... 

UK Plans Social Media Ban for Under-16s by 2027 

The United Kingdom has proposed a policy restricting social media access for users under the age of 16, with implementation potentially targeted for spring 2027. If enacted, the ban would apply to major platforms including TikTok, Instagram, Snapchat, Facebook, YouTube, and X. Read more... 

Operation Endgame Disrupts SocGholish Malware Network 

International law enforcement agencies, operating under “Operation Endgame,” dismantled significant parts of the SocGholish malware infrastructure. The operation resulted in the cleanup of nearly 15,000 compromised websites and the takedown of multiple servers associated with cybercriminal activity. Read more... 

Nintendo Confirms Limited Employee Data Exposed in TinyPulse Attack 

Nintendo confirmed that employee survey data was exposed following a cyberattack involving the third-party platform TinyPulse. The company clarified that its internal systems and customer-facing data were not impacted by the incident. Read more... 

Weekly Cybersecurity Takeaway 

This week’s weekly roundup reflects a cybersecurity environment increasingly shaped by cloud exploitation, AI-driven vulnerabilities, and cross-border espionage campaigns. From healthcare breaches like Novo Nordisk’s limited data exposure to long-running intrusions such as UNC6508’s email-forwarding operations, attackers continue to prioritize stealth and persistence over direct system disruption.  At the same time, critical vulnerabilities like the Microsoft 365 Copilot SearchLeak flaw demonstrate how AI integration is expanding enterprise risk surfaces. Meanwhile, enforcement actions under Operation Endgame and policy shifts such as the UK’s proposed under-16 social media restrictions show that both technical and regulatory responses are evolving in parallel. 
❌
❌