Visualização de leitura

The EU AI Act just gave you a breach notification clock you didn’t know about

Most security teams already have a breach clock memorized. GDPR gives you 72 hours. SEC rules give public companies four business days after determining an incident is material. Those numbers get built into incident response runbooks, tabletop exercises and escalation paths, because the clock starts the moment the team confirms something happened.

Article 73 of the EU AI Act adds a third clock, and in my work advising enterprise clients on AI governance, I have yet to see one with a runbook for it.

The obligation took effect on August 2, and it did so alone. The EU’s Digital Omnibus on AI, in force since late July, pushed the rest of the Act’s high-risk enforcement wave — classification, conformity assessment, technical documentation — back to December 2027. Article 73 was not part of that reprieve, though the extra time elsewhere is worth using to get ready. It requires providers of high-risk AI systems to report serious incidents to national market surveillance authorities within 15 days by default, 10 days if a death is involved and just 2 days for incidents the Act classifies as widespread or as a serious disruption to critical infrastructure. Coverage of Article 73 so far has treated it as a legal filing requirement, handled through the same channel as a data protection filing. That framing misses what the obligation is. It is an incident response deadline, and it runs on a different trigger than the breach clocks most security teams already know.

A client once asked me, almost as an aside, whether their customer-facing AI tool would trigger a reporting duty if it simply gave someone bad information rather than getting hacked. At the time, the honest answer was probably not, under any framework they were tracking. Article 73 changes that, and most organizations building or buying AI for the EU market have not caught up yet.

What counts as a trigger here is broader than most teams expect

GDPR’s 72-hour clock starts when you become aware of a personal data breach. That is a bounded question. Did data leave the environment? Was it accessed without authorization? Article 73 asks something harder. The European Commission’s draft guidance takes the position that an indirect causal link between an AI system and a downstream harm is enough to trigger the reporting duty. Their example is a loan denial that traces back to a flawed AI credit assessment. The AI system does not cause harm the moment it produces the assessment, only once a human acts on it and denies the loan. The fundamental rights category requires the infringement to interfere with Charter-protected rights at scale, which is why the Commission illustrates that threshold with patterns, a recruitment tool that discriminates systematically or a credit system that categorically rejects an entire neighborhood. Under the Commission’s reading, once a pattern like that exists, the clock starts when the provider becomes aware of it, not when the system generated the output.

Here’s a plainer version of that pattern. A public benefits agency uses an AI system to match applicants against its records. A flaw in the matching logic occasionally conflates applicants, and over several weeks it happens to a run of different people, each flagged as already receiving the same benefit elsewhere and suspended. Nobody catches the pattern at the time, because each flag looks unremarkable on its own. Applicants don’t find out until their payments stop arriving, weeks after the first mismatch. The system never malfunctioned in any way security tooling would catch. It just produced bad matches until people started missing payments.

That is a different kind of determination than “Did we get breached?” It requires tracing a causal chain from a model output through a downstream decision to an actual harm, then judging how confident you are in that link before you are required to report it. Most incident response teams have a well-practiced instinct for confirming unauthorized access, but few have one for confirming that an AI system caused a harm that surfaced elsewhere in the business, days or weeks later. I have watched security leaders confidently answer, “Were we breached?” in minutes, then go quiet when asked, “Did our AI system cause this?” because nobody owns that second question yet.

Why this does not fit into an existing IR playbook

Most incident response programs are built around a single moment: detection. Something trips an alert, a SOC analyst confirms it and the clock starts. Article 73 incidents will not look like that at all. The AI system that produced the flawed output may show no signs of compromise. Nothing gets flagged by a SIEM. The first sign might come from a customer complaint, an internal audit finding or a pattern a compliance analyst notices months after the AI system made the decision.

That means the “becoming aware” clause in Article 73 is doing real work, and most organizations have not decided who is responsible for noticing. Is it the team monitoring the AI system’s technical performance, the business unit acting on its outputs, or whoever eventually hears the complaint? Under Article 73, the clock starts when any of them establishes, or suspects, the causal link, and 15 days is not a long runway if the first internal conversation about “is this our incident” does not happen until day six or seven. I have seen governance structures where a business unit head, a model risk team and security each assumed someone else owned this judgment call. In practice nobody did, and that gap is where a 15-day clock burns down to five.

Some security teams are already mapping agent governance to a maturity model, arguing that oversight must scale with autonomy, moving from agent identities that are barely inventoried toward ones that are bounded, monitored and revocable in real time. Article 73 raises the stakes on that model considerably. The less a human reviews an AI system’s output before it reaches a customer, the more likely a downstream harm surfaces without anyone watching for it in real time, which is exactly the blind spot Article 73 is designed to close.

What needs to change

A few additions belong in an existing incident response program before this becomes a live problem instead of a paper requirement.

First, a defined owner for the causal link determination. Data breach response usually has a clear owner: security confirms the technical facts, legal makes the materiality call. Article 73 needs an equivalent split: Someone technical enough to trace an AI system’s output to a downstream decision and someone with authority to make the reporting call once that link looks plausible rather than certain. In practice, I recommend naming this owner in the incident response plan, not leaving it to be sorted out during the first real incident, when the clock is already running.

Second, a lower bar for opening an investigation. If GDPR taught teams to investigate the moment unauthorized access is suspected, Article 73 requires investigating the moment a downstream harm is suspected to trace back to an AI system, when the system looks normal to security monitoring. That means feeding business unit complaints and customer escalations into the same triage process that currently only starts from technical alerts.

Third, a documented decision log for the indirect link judgment call. Given how broadly the Commission has defined what counts as reportable, organizations will make defensible calls not to report many ambiguous situations. Those decisions need to be documented with the reasoning behind them, the way a security team documents a false positive call, because a regulator revisiting that judgment months later will expect to see how it was made rather than take the outcome on faith.

Fourth, controls built into the AI system, not bolted on after the fact. A defined owner and a lower investigation bar help catch a problem once it surfaces, but neither reduces how often a flawed output reaches a customer first. Scoped credentials, tool allowlists and pre-action approval hooks cut down on how many incidents exist to report.

The AI Act’s high-risk obligations have absorbed most of the attention this year, because conformity assessments and technical documentation are heavy lifts with long lead times. Article 73 looks lighter by comparison, a reporting duty rather than a certification process. It is not lighter. It asks security and compliance teams to build a new kind of judgment into their incident response programs, on a clock as tight as anything GDPR or the SEC have required. Treat the deferral on the rest of the high-risk package as what it actually is, extra runway to build that judgment and name its owner, because the conformity paperwork still gives you months and Article 73 still gives you days.

US Puts $10 Million Bounty on Alleged Iranian Cyber Chief

$10 Million Reward for Amir Yaryab

The U.S. State Department has posted a $10 million reward for Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) Cyber Operations Command and directing multiple hacking groups targeting critical infrastructure across the United States, Europe and the Middle East. According to the Rewards for Justice program, Yaryab allegedly oversees cyber operations conducted by IRGC-CEC-affiliated groups including CyberAv3ngers, Dadeh Afzar Arman (DAA) and Mehrsam Andisheh Saz Nik (MASN). U.S. officials accuse these groups of using malware and conducting cyber and cyber-enabled information operations against civilian infrastructure worldwide.

$10 Million Reward for Amir Yaryab

The $10 million reward for Amir Yaryab seeks information leading to his identification or location. The offer applies to individuals acting at the direction or under the control of a foreign government who participate in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act. [caption id="attachment_113961" align="aligncenter" width="600"]$10 million reward for Amir Yaryab Image Source: https://rewardsforjustice.net/[/caption] Yaryab is also accused of directing Shahid Hemmat and Shahid Shushtari, two groups linked to cyberattacks against U.S. organizations. The sectors allegedly targeted include defense, news, shipping, travel, energy, financial services and telecommunications. The six Iranian officials named in the advisory are linked to Iran's Islamic Revolutionary Guard Corps and its Cyber-Electronic Command.

Iranian Cyberattacks Target PLCs

The allegations also involve attacks against programmable logic controllers (PLCs), highlighting concerns around Iranian cyberattacks targeting industrial systems rather than focusing only on data theft. U.S. officials said Iranian-linked hackers compromised industrial control systems, specifically targeting the Vision series of PLCs manufactured by Israel-based Unitronics. These devices are used across water and wastewater, energy, food and beverage, manufacturing and healthcare sectors. The attackers exploited default credentials on the devices and left anti-Israel messages. Some of the compromises reportedly rendered the PLCs inoperative. The CyberAv3ngers group, which is linked to the IRGC-CEC, claimed responsibility for attacks against Unitronics Vision PLCs in October 2023. Beginning in November 2023, the group compromised default credentials in PLCs across the United States and left messages on the devices' digital screens.

CyberAv3ngers Attacks Critical Infrastructure

CyberAv3ngers has also claimed responsibility for attacks affecting other infrastructure. In October 2023, the group claimed it had breached ORPAK Systems, a provider of gas station solutions in Israel. The group said it had obtained the company's database and intended to publish it through its Telegram channel. The attack was reported to have disconnected 200 gasoline pumps from the system in the occupied Palestinian territories. In December 2023, CyberAv3ngers also claimed to possess and sell 1TB of data allegedly linked to Israel's electricity infrastructure. The group advertised the dataset for 5 Bitcoin, with an initial 100GB portion also offered at the same price.

U.S. Agencies Warn of PLC Cyberattacks

Concerns over critical infrastructure attacks involving PLCs continued into 2026. A joint advisory issued on April 7 by the FBI, CISA, NSA and other agencies warned that Iran-linked threat actors were actively exploiting internet-facing PLCs. The advisory said several organizations had experienced operational disruptions and financial losses after attackers interfered with industrial processes. The developments come amid broader U.S. actions against Iranian-linked cyber activity. The Justice Department accused Iran-connected hackers of breaching employee email accounts associated with the Department of Labor, the Federal Energy Regulatory Commission and multiple United Nations organizations. The Treasury Department also sanctioned Iranian nationals over cyberattacks targeting critical infrastructure. The State Department's reward offer places Amir Yaryab and the alleged activities of IRGC-CEC-linked groups at the center of the U.S. effort to identify individuals responsible for malicious cyber activity targeting critical infrastructure.

Cyber resilience is a very human decision problem, not just a technology one

Organizations today are not short of data, particularly in the domain of cyber. What many lack is a timely, trusted assessment that can help leaders act with greater confidence.

When a cyber incident begins, the technical questions surface first. What happened? Which systems are affected? Is the activity contained? But the questions that often shape the outcome are rarely technical alone. Who is behind the activity? What are they trying to achieve? Is this an isolated event or part of a broader campaign? Which customers, suppliers, assets or services are exposed? Is there a sanction, legal, regulatory or reputational dimension? And what is a proportionate immediate response while the facts are still incomplete?

This is why cyber is, in a meaningful sense, as much a human decision-making problem as a technological one. The OECD argues that digital security risk should be integrated into broader decision-making, rather than treated only as a technical issue. Tools can detect signals, spot patterns, correlate events and flag anomalies, but it takes people to decide what those signals mean, when to escalate, which trade-offs matter and what action the organization should take. In Moody’s recent whitepaper on supporting decision dominance through financial, corporate and trade intelligence, we make the case that the decisive moments in a cyber incident belong not only to systems, but to judgement.

That matters for CIOs and other technology decision-makers, because theirs is one of the most demanding decision environments in the enterprise. Reporting lines and structures vary by organization, but common themes tend to recur: technical complexity, compressed timelines, uncertain attribution and fragmented responsibility. Security teams may see indicators before they understand intent. Legal teams may need to assess obligations before the full scope of an incident is known. Communications teams often must prepare for scrutiny while operations are still working through containment. Business leaders may first need to decide when a decision must be made, then whether to pause a service, isolate a supplier, notify a regulator, issue a public statement or accept some temporary disruption to prevent greater harm.

The result can be a gap between signal and action, at a time when many organizations are experiencing a growing volume of cyber signals and alerts. Organizations commonly track mean time to detect and respond. But a less visible but equally consequential metric is decision latency: the time it takes to move from a technical signal to a shared understanding of what matters, and a decision about what to do. An organization can identify a threat quickly and still act too slowly if it cannot interpret the signal, convene the relevant stakeholders or agree on a proportionate response. The challenge is not simply speed — decisions made quickly but poorly can amplify harm. It is reducing decision latency without sacrificing judgement. This urgency is not theoretical and shouldn’t simply be admired. In her 2026 GCHQ Annual Lecture at Bletchley Park, Director Anne Keast-Butler described “a moment of consequence” shaped by the radical uncertainty. Her wider point is key for CIOs and their peers across the board: cyber security is a critical priority, and resilience depends on the ability to act with urgency, judgement and trusted partnerships.

From signal to context

Technical signals tend to become more useful when connected to wider context. A malicious domain, an unusual login, a compromised account or malware signature may tell a security team that something is happening. On its own, that signal rarely tells an executive what the organization should do next. Context reframes the question from “what does this indicator mean?” to “what decision should we make?”

That context can take several forms. Payment flows may provide additional context regarding the financial networks associated with an event or risk scenario. Ownership structures can help identify relationships between suppliers, counterparties or entities that may merit further review. Sanctions exposure may change the legal and compliance implications of a response. Adverse media may provide indicators of potential reputational or integrity concerns. Corporate linkages may reveal that what looks like a narrow technical event is in fact connected to a wider network of actors, assets or interests.

None of this removes uncertainty altogether, and no decision-maker should wait for perfect information before acting. What broader context does is improve the conditions under which judgement is exercised. Two incidents may look similar at the technical level but demand different leadership responses. One may be opportunistic criminal activity with limited broader consequence. Another may involve connections to a sanctioned entity, an organized crime network, a critical supplier or a state-linked ecosystem. The signal may look similar, but the appropriate response is not.

A cross-discipline exercise

This distinction matters because cyber response is often not contained within the security function, especially in a learning organization. A serious incident typically draws in teams from across multiple disciplines, such as security, IT, legal, risk, compliance, finance, procurement, communications and business operations. It may also involve external parties such as law enforcement, intelligence agencies, regulators, financial institutions, infrastructure operators and key suppliers. The CIO will not own every lever in this environment, and organizational structure will influence how close to the centre of the systems they sit, dependencies and information flows that affect the organization’s ability to respond effectively. Is the CIO supported or supporting during an incident? What leeway is afforded the CIO to act when required?

A common challenge in cyber response is not the absence of technical capability, but the absence, or fragility, of a shared decision model. Teams will have data, dashboards and incident playbooks in place, but still lack clarity on who decides, what information is needed, which trade-offs are acceptable and how quickly business context can be brought to bear. Ensuring a common operating picture — one that gives the leadership team a shared understanding of the same facts — tends to be a differentiator between organizations that respond coherently and those that do not.

For CIOs and CEOs, this is an organizational design problem as much as a technology one. Experience suggests that a cyber strategy that stands alone may be less effective than one integrated into the organization’s broader strategy from the outset. Cyber maturity should not be judged only by the number of controls deployed, alerts processed or systems monitored, but also by the quality of the decisions an organization can make under pressure. Using scenarios to test decision making can help refine organizational design, highlight blockers that may emerge at critical times, and improve leaders’ understanding of the potential consequences of poor decision making. That wider coordination challenge is reflected in CISA’s incident response guidance, which treats serious cyber incidents as events requiring coordination across multiple stakeholders.

Where integrated intelligence adds value

This is where integrated intelligence has a role to play. Its value lies less in the sheer volume of information it provides — most organizations already have more data than they can absorb — and more in its ability to help prioritize, separating signal from noise. It can help distinguish activity that is technically interesting from activity that may be strategically material. Used well, it can help identify enabling networks associated with an attack, inform disruption options and help focus scarce defensive resources on the assets, relationships and dependencies most likely to matter.

The aim is not to know everything. It is to develop sufficient understanding of the most relevant factors early enough to support timely actions while meaningful response options remain available.

CIOs can make this practical by asking five questions:

  1. Which cyber decisions must be made in the first moments, the first hour, first day and first week of a serious incident?
  2. Who is authorized to make them, what is their availability 24/7 and who deputizes in their absence?
  3. Can technical indicators be linked quickly to business impact, financial exposure, legal risk, supplier dependency and external context?
  4. Can security teams escalate without creating unnecessary alarm?
  5. Can the CEO and board be briefed in decision-ready language, with recommendations rather than technical detail alone?

These questions move the conversation from reporting to leadership, and they reflect the human reality of cyber defence. Employees, analysts, managers and executives are asked to make repeated judgement calls under uncertainty, often with too much noise and too little time. Attackers are often well placed to exploit that reality; resilient organizations tend to design around it

Beyond visibility

Cybersecurity has spent years improving visibility, and that work remains essential. But visibility alone does not create resilience. The next challenge is decision quality.

For CIOs, the strategic shift is that cyber signals become most valuable when connected to real-world consequences: financial, operational, legal, reputational and geopolitical. In a fast-moving incident, the critical question is rarely whether the organization has more data. It is whether leaders can understand what matters, decide what to do and act while meaningful response options remain available.

The organizations that are often most effective in this environment are not necessarily those with the most dashboards. They are often those that have worked to reduce decision latency without sacrificing judgement, often through rehearsal, scenario testing and learning from gaps identified during those exercises. In an environment shaped by ambiguity, compressed timelines and interconnected risk, the ability to make better decisions faster may become one of the defining measures of not just cyber resilience, but of leadership itself.

Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco.

The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, attacking dating sites in January and Oracle in June, and there are fears that they could have found a new target.

Reco has named the latest campaign of attacks “City-Forum,” after a domain name associated with the attackers’ IP address. While it bears similarities to Shiny Hunters’ past exploits, there are also differences. This time around the attacker penetrated the systems through the UI-API layer, an attack point that Reco had not seen used before, and had also created its own toolset to carry out the attack. It is also targeting a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open-source tools.

The threat is particularly noteworthy, Reco said, as the attackers have studied the services to map different common data-leak vectors, a sign of an advanced approach.

A Salesforce spokesperson said that it was aware of the campaign in which malicious actors are exploiting customers’ overly permissive Experience Cloud guest user configurations in the campaign to potentially access more data than targeted organizations intended.

“This issue highlights risks stemming from misconfigurations, such as overly permissive guest user profiles, and not from a Salesforce vulnerability,” the spokesperson said.

Regardless of who the attackers were and how the attack was carried out, one thing should be clear: Organizations should be increasingly careful about who they give login credentials to.

This article first appeared on CSO.

US, South Korea Warn of Growing Gunra Ransomware Threat

U.S. and South Korean authorities warn about the growing Gunra ransomware threat as the operation expands its capabilities and affiliate network.

The post US, South Korea Warn of Growing Gunra Ransomware Threat appeared first on TechRepublic.

Introducing ResOps, the operating discipline built for quick, clean recovery

Organizations have spent years and billions of dollars hardening their defenses against cyberattacks, but prevention alone no longer settles the question that matters most to a board. Accenture’s State of Cybersecurity Resilience 2025 report stated that organizations had faced an average of 1,876 cyberattacks in a single quarter, a 75% increase over the prior year. What’s more, 63% of the surveyed executives cited a rapidly evolving threat landscape as their biggest challenge. In such a dangerous environment, organizations must assume that eventually an attack will succeed, so IT has to be able to prove that it can recover cleanly once an attacker gets in.

Attackers already understand this shift. Mandiant, a Google subsidiary, reported in its M-Trends 2026 Report that “adversaries are systematically targeting infrastructure such as backups, identity services, and virtualization layers to deny recovery, putting immense pressure on organizations to pay ransom demands or risk losing the ability to recover.” Backup systems have become a primary target.

Demonstrating recoverability has been difficult for IT, because backup, recovery, cybersecurity, and disaster recovery all evolved as separate disciplines, with each solving its own piece of the problem essentially independently. That fragmentation leaves organizations unable to answer basic questions about their own ability to bounce back.

A new discipline, resilience operations (ResOps) has emerged to close the gap between performing backups and proving that an organization can actually use them to recover. ResOps functions as an operating discipline that focuses business, security, and infrastructure teams on recovering critical functions quickly while avoiding reinfection. This discipline also provides the teams with a common framework so they can pivot away from assumptions and anecdotes to instead quantify resilience in a repeatable, sustainable way. Spot-testing of discrete systems is not enough. Organizations need to perform regular tests of the entire system if it is to pivot away from assumptions and anecdotes to quantify resilience in a repeatable, sustainable way.

Additionally, to measure the effectiveness of recovery, the industry needs an updated resilience metric, mean time to clean recovery (MTCR). Metrics such as recovery time objective (RTO) and recovery point objective (RPO) still matter, but neither confirms that restored data is free of compromise. MTCR closes that gap, by measuring how long it takes to validate that a recovered system is both online and clean, giving CIOs, CISOs, and boards a single evidence-based answer during an attack.

Building that kind of resilience starts with architecture. Depending on a single vendor or platform across multiple heterogeneous environments introduces a single point of failure. Diversity is a strength, especially when it comes to the identity infrastructure. Recovery systems that share the same identity layer with production will fail if the identity systems are compromised, so more and more organizations now stand up an independent identity infrastructure solely for recovery. Immutable air-gapped storage rounds out the picture, but it remains rare among organizations, even for their most critical workloads. Finally, during recovery execution, backups should be paired with clean room validation of workloads before anything returns to production.

“For years the industry measured resilience by how fast we could restore data,” says Bill O’Connell, chief security officer at Commvault. “Now the measure that matters is whether we can prove, with evidence, that what we restored is actually clean.”

Vendors such as Commvault are building the infrastructure to support this shift, giving organizations the tools for testing recovery as a complete system rather than a collection of individual failure scenarios and to walk into the boardroom with proof instead of assumptions. But whatever the underlying backup-and-recovery infrastructure in this increasingly dangerous threat environment, organizations need to make attaining clean recovery their goal.

Build real resilience
Learn how organizations are proving recoverability and achieving clean recovery when it matters most.

Snowflake attacker pleads guilty to hack of 165 companies’ data

A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars.

Industry sources have identified Moucka as one of the main players in attacks on data hosted by cloud data warehouse Snowflake. Companies affected by the hacks include the likes of AT&T, Ticketmaster and the Neiman Marcus Group.

He worked with two other hackers: John Edward Binns and Cameron John Wagenius. Binns was not in US custody as of April 2026, while Wagenius, going by the name of Kiberphant0m, was arrested in January 2025 and pleaded guilty in July that year

Moucka and other members of the group used stolen login credentials to compromise data belonging to at least 165 customers of a US-based software-as-a-service company. This unauthorized access was used to steal billions of sensitive customer records and download terabytes of information,

“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars. Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice,” said assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division

The trial is the result of a coordinated worldwide action against the Snowflake group. The investigation was led by the FBI but benefited from contributions from the Royal Canadian Mounted Police, the Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine and the Turkish National Police.

This article first appeared on CSO.

Amsterdam’s De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed

De Bijenkorf cyberattack

A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.

The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.

De Bijenkorf Confirms Third-Party Security Incident

According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional security measures.

An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.

As a precaution, De Bijenkorf has informed customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.

What Customer Data Could Be Affected in De Bijenkorf Cyberattack?

The retailer said investigators are still determining whether any personal information has been compromised.

Based on the information currently available, data that may be involved includes:

  • Customer names and contact details, including email addresses, postal addresses, and phone numbers.
  • Information related to online purchases, such as ordered products, pricing, discounts, delivery details, and the payment method used.
  • For business customers, company names and VAT numbers stored in My Account may also be involved.

De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.

Investigation Continues as Customers Await Confirmation

The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from info@debijenkorf.nl.

For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.

De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.

Retailer Warns Customers About Phishing Risk

Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible phishing risk if personal information is ultimately found to have been exposed.

The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.

The company said it will never request credit card details, gift card information, or other sensitive information via email.

Logistics Cyberattacks Continue to Disrupt Supply Chains

The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics cyberattack can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.

In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including Kentucky Fried Chicken. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.

For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.

The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats

The Cyber Express weekly Roundup July 2026 new

This weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses.  The latest developments show that cyber risks are expanding beyond traditional network attacks. Threat actors are targeting identities, trusted platforms, software supply chains, and operational technology environments. Organizations must strengthen security controls, improve monitoring capabilities, and adopt proactive measures to protect sensitive data and critical services. 

The Cyber Express Weekly Roundup 

Four Men Admit to $2.2 Million Medicaid Fraud Scheme Using AI 

Four Minnesota men have pleaded guilty in connection with a Medicaid fraud scheme that allegedly generated approximately $2.2 million through fraudulent claims for housing-related services. Prosecutors stated that artificial intelligence tools, including ChatGPT, were used to create false documentation supporting fraudulent billing activity. Read more... 

Tribeca Data Leak Exposes Celebrity-Linked Information 

A reported data leak connected to the Tribeca Film Festival exposed nearly 666,000 records containing personal information associated with attendees, contacts, and individuals linked to the entertainment industry. The exposed data reportedly included names, email addresses, phone numbers, and limited device-related information. Read more... 

Origin Energy Data Breach Impacts Around 900,000 Customers 

Australian energy company Origin Energy confirmed a data breach affecting approximately 900,000 current and former customers. The exposed information may include customer names, contact details, dates of birth, and partial account information. The company is investigating the incident and has advised customers to remain alert for possible scams or suspicious communications. Read more... 

Joyfill npm Packages Found Distributing DEV#POPPER Malware 

Security researchers discovered that two beta versions of Joyfill npm packages were distributing DEV#POPPER, a remote access trojan (RAT) capable of stealing information, executing commands, and compromising developer environments. Read more... 

Student Accused of IIT Website Breaches Offered Technical Assessment 

A student accused of breaching parts of the IIT Kanpur and IIT Madras websites after being rejected from IIT Kanpur’s cybersecurity program will undergo a technical skills assessment rather than facing immediate legal action. The institute stated that admissions for the current session are closed but indicated that future opportunities may be considered if the student demonstrates strong cybersecurity abilities. Read more... 

FBI Warns of PLC Cyberattacks Targeting U.S. Water Utilities 

The FBI and the U.S. Environmental Protection Agency warned that cyberattacks targeting internet-connected programmable logic controllers (PLCs) have disrupted water utilities across multiple U.S. states. Attackers reportedly manipulated PLC settings, affecting monitoring and operational processes. Read more... 

Weekly Cybersecurity Takeaway

This week’s incidents demonstrate how cyber threats continue to evolve across multiple domains, including artificial intelligence abuse, personal data exposure, software supply chain attacks, and critical infrastructure targeting.  A common theme across these events is the exploitation of trust. Attackers are abusing trusted technologies, legitimate software ecosystems, customer databases, and connected infrastructure to achieve their objectives.  Organizations must focus on building cyber resilience through stronger identity protection, secure development practices, continuous monitoring, and effective incident response planning.  As emerging technologies such as artificial intelligence and connected industrial systems become more widespread, cybersecurity strategies must evolve alongside them. Protecting digital assets requires not only stronger technical defenses but also responsible for technology use, awareness, and proactive risk management. 

Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA

Seized Crypto Assets

Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States.

According to Ukrainian authorities, the transferred cryptocurrency is valued at more than 372 million hryvnias and represents a milestone in the country's efforts to manage digital assets linked to criminal investigations.

Seized Crypto Assets Moved to ARMA After Court Order

The State Bureau of Investigation said the transfer was completed as part of an ongoing criminal investigation conducted in cooperation with the DVB of the National Police and U.S. law enforcement agencies.

Investigators determined that the virtual assets were stored in crypto wallets controlled by a member of the organized hacking group. Following a court order, more than 8.3 million USDT was transferred to ARMA's official crypto wallet.

Authorities said this is the first practical case in Ukraine where seized digital assets have been transferred to ARMA for management, demonstrating the country's ability to handle new categories of assets within the legal system.

Investigation Links Cryptocurrency to International Hacking Group

According to investigators, members of the international hacking group carried out large-scale cyberattacks against individuals and companies in Europe and the United States.

The investigation alleges the group stole confidential information, demanded ransom payments, and laundered criminal proceeds in Ukraine through the purchase of residential properties, vehicles, and other high-value assets.

Authorities estimate that the criminal group's activities caused losses exceeding $100 million.

As part of the pre-trial investigation, four members of the group, including its alleged organizer, were detained and placed in custody.

More Than $11 Million in Assets Seized

The investigation resulted in the cryptocurrency seizure and the confiscation of additional assets with a combined value exceeding $11.1 million.

According to the State Bureau of Investigation, the seized property includes residential buildings, apartments, vehicles, approximately $1 million in cash, and digital assets equivalent to more than $8.3 million.

The Office of the Prosecutor General is providing procedural oversight for the criminal proceedings.

Authorities Plan to Convert Crypto Into Military Bonds

The State Bureau of Investigation said that after converting the cryptocurrency into fiat currency, authorities plan to purchase military bonds.

According to the agency, the initiative is intended to support Ukraine's economy during martial law while ensuring that assets obtained through criminal activity are redirected for state purposes.

Officials described countering transnational cybercrime and ensuring effective mechanisms for the seizure and management of criminal assets as key priorities.

ARMA Expands Digital Asset Management

ARMA said receiving the cryptocurrency marks an important step in the evolution of Ukraine's asset management system.

The agency stated that the successful transfer reflects coordinated efforts between the State Bureau of Investigation and the Office of the Prosecutor General, enabling the execution of the court's decision and preserving the value of the seized assets.

ARMA added that it is continuing to develop mechanisms for managing all categories of seized property, including real estate, corporate rights, and virtual assets, to ensure their preservation in the interests of the state and society.

The agency said the case demonstrates that as cybercriminals increasingly use digital technologies to conceal illicit proceeds, authorities must also strengthen their ability to manage and preserve cryptocurrency and other digital assets seized during criminal investigations.

US Telecom Giants Launch Private ISAC to Counter AI-Powered Cyberattacks

private ISAC

The U.S. telecom sector is strengthening its cybersecurity coordination efforts with the launch of a new private ISAC designed to help major communications companies respond more effectively to AI-powered cyberattacks, state-backed espionage campaigns, and emerging threats targeting national communications infrastructure.  The Communications Cybersecurity Information Sharing and Analysis Center, known as the C2 ISAC, was created by some of the country’s largest telecommunications providers to establish a more confidential environment for exchanging cybersecurity intelligence. The founding members include AT&T, Charter, Comcast, Cox, Lumen, T-Mobile, Verizon, and Zayo. The chief information security officers from these companies will serve on the organization’s board.  The newly formed private ISAC will be led by Valerie Moon, a former senior official with both the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI’s Cyber Division, who has been appointed executive director.  According to Mark Clancy, chief security officer at T-Mobile and a board member of the C2 ISAC, the evolving threat landscape was a major factor behind the creation of the private ISAC.  “The main driver for us is our recognition that the threat environment has evolved, and we as a sector and private entities need to evolve and really keep up with the pace and velocity [at which] that’s happening,” Clancy said in an interview with Cybersecurity Dive.  Clancy explained that telecom companies recognized the need for more direct collaboration during the industry’s response to Salt Typhoon. “The need for us to collaborate on a private-to-private basis really became amplified,” he added. 

Telecom Sector Pushes for Faster Intelligence

Although the telecom sector already participates in information-sharing initiatives through the Communications ISAC, also referred to as the National Coordinating Center for Communications, that organization differs from most ISACs because it operates within the federal government under CISA rather than as an independent private entity.  According to Clancy, that government affiliation created hesitation among some telecom companies when it came to sharing sensitive cybersecurity intelligence.  “There’s been concerns and hesitations about it,” he said.  The new private ISAC aims to address those concerns by limiting participation to industry members and excluding government agencies from its internal discussion channels. Organizers believe this structure will encourage companies to exchange threat intelligence more openly and at earlier stages of investigations.  “When you have public-sector entities involved, there’s more review and deliberation about what gets put into that channel,” Clancy explained, adding that the new arrangement allows companies to be “a little more raw and early in sharing information.”  Over time, telecom providers realized they had become overly cautious in the information they shared through the existing Communications ISAC. Clancy acknowledged that companies often withheld lower-level threat indicators that later turned out to be connected to broader malicious campaigns.  “We were being too restrictive in what we were sharing,” he said, noting that some seemingly isolated activities were “actually tethered to bigger activity.”  Moon emphasized that the private ISAC is not intended to replace the existing Communications ISAC. Instead, both organizations are expected to operate alongside each other, with the older structure continuing to focus on broader operational concerns such as physical infrastructure threats.  “We really see this as a complementary effort,” Moon said. “When you think about each of these companies and their adherence to ensuring that the privacy of their data is very much at the forefront of their minds, they see this as a trusted space.” 

Private ISAC May Expand Beyond Threat Sharing

Information-sharing efforts within the telecom sector have already proven valuable in combating cybercrime and network abuse. One example involved the detection of SIM boxes — devices commonly used by cybercriminals to generate large volumes of difficult-to-block spam calls and text messages.  After T-Mobile identified indicators connected to SIM box activity, the company shared those findings with other telecom providers, enabling them to locate and block similar operations on their own networks.  Clancy noted that addressing such threats requires coordinated action because malicious infrastructure often spans multiple providers. “In order to figure out what’s happening, you’ve got to look at both sides,” he said.  Beyond direct threat intelligence, telecom companies have also exchanged operational strategies and defensive techniques through existing partnerships. Clancy recalled learning an effective method for handling residential proxy networks from another telecom operator.  “I learned a technique for dealing with some of the residential proxy networks from another operator that was really clever,” he said. “And I’m, like, ‘Yeah, we’re going to go do that.’”  While the immediate focus of the private ISAC is improving information sharing related to AI-powered cyberattacks and network threats, its leaders are also considering broader future capabilities. Clancy suggested the group could eventually develop shared automation platforms and collaborative technologies that would be easier to coordinate privately than through government-led regulatory frameworks.  The organization may also explore involvement in coordinated cybersecurity operations such as botnet disruptions, though Moon said those discussions are still in early stages.  “It just depends on what the operation is and where the authorities lie and what we are trying to accomplish,” she said.  Moon described the private ISAC as being “in its nascent stages,” adding that several long-term objectives remain under discussion.  Membership expansion is another unresolved issue. Although the current founding members represent some of the largest companies in the telecom sector, Clancy acknowledged that broader participation will be necessary for maximum effectiveness.  “There are more than eight companies in the communications sector, and so we won’t be fully effective until we increase that membership base,” he said.  The launch of the private ISAC also coincides with significant uncertainty surrounding federal cybersecurity programs. Budget reductions, staffing cuts, and shifting priorities across government agencies have forced many private-sector organizations to reconsider how they coordinate cybersecurity defense efforts.  “Obviously, what’s happening in the public sector informs what we need to do,” Clancy said, referencing challenges involving government funding, agencies, and legislative processes.  He also encouraged the Department of Homeland Security to accelerate efforts to replace the now-defunct Critical Infrastructure Partnership Advisory Council framework, which previously supported confidential discussions between industry and government stakeholders. Despite operating independently, the private ISAC still plans to maintain communication with federal agencies. According to Clancy, the group intends to share relevant intelligence either directly with government partners or through the existing Communications ISAC framework. “We could have a more freewheeling private-to-private conversation [and] we could distill the useful, important bits and push them … over to the government side,” he said.

AI Cyberattacks Are Escalating Across the Americas. This Webinar Explains Why

Americas cyber threat landscape

The Americas cyber threat landscape saw a significant rise in AI-powered cyberattacks, ransomware campaigns, and critical infrastructure targeting during the first quarter of 2026, reflecting how rapidly cyber threats are evolving across the region. Security researchers observed that threat actors increasingly used generative AI to automate phishing campaigns, create convincing deepfakes, and accelerate exploitation techniques. At the same time, ransomware groups, hacktivists, and nation-state actors intensified attacks against organizations operating in healthcare, manufacturing, utilities, energy, and government sectors across North and Latin America. To help cybersecurity professionals better understand these evolving risks, Cyble will host a live webinar on May 28, 2026, focused on the key cyber threats, adversary tactics, and emerging attack trends shaping the Americas cyber threat landscape in Q1 2026. Americas cyber threat landscape

AI-Powered Cyber Threats Continue to Grow

One of the most notable developments during Q1 2026 was the increasing use of artificial intelligence by cybercriminals and advanced threat groups. Threat actors are now leveraging generative AI to produce highly targeted phishing emails, fake identities, deepfake content, and automated social engineering campaigns at scale. Security analysts warn that these AI-driven techniques are making attacks more difficult to identify and increasing the success rate of phishing and credential theft operations. Researchers also observed that attackers are using AI to accelerate reconnaissance and exploitation activities, enabling cybercriminals to move faster and target larger numbers of victims simultaneously. As AI-powered attacks become more sophisticated, organizations are facing growing pressure to strengthen detection capabilities and improve incident response readiness.

Critical Infrastructure Remains a Primary Target

The Americas cyber threat landscape also highlighted the continued targeting of critical infrastructure sectors during Q1 2026. Healthcare providers, energy operators, utilities, manufacturing organizations, and public sector institutions experienced persistent cyber threats from ransomware operators, hacktivist groups, and nation-state actors. Security researchers noted increasing concerns around operational technology environments and attacks designed to disrupt essential services. Supply chain vulnerabilities and third-party risks also remained major challenges for organizations responsible for maintaining critical infrastructure. Experts believe these attacks are no longer solely focused on financial extortion. Many campaigns are increasingly linked to geopolitical tensions, intelligence gathering, and disruption-focused objectives targeting national infrastructure and strategic industries. Cybersecurity professionals looking for deeper insights into infrastructure threats and AI-driven attack trends can register for the upcoming webinar hosted by Cyble.
Register Here

Nation-State Cyber Operations Intensify

Threat intelligence findings from Q1 2026 also revealed growing activity from nation-state groups associated with China, Russia, Iran, and North Korea. These groups continued targeting organizations across the Americas through espionage campaigns, vulnerability exploitation, credential theft, and malware deployment. Researchers observed that government entities, infrastructure operators, and large enterprises remained among the primary targets of these advanced cyber operations. Security experts warn that geopolitical developments continue to influence cyber activity, increasing the need for organizations to monitor emerging risks and strengthen resilience against sophisticated attacks.

Ransomware and Dark Web Activity Continue

Despite the growing attention around AI-driven threats, ransomware remained one of the most disruptive elements of the Americas cyber threat landscape in Q1 2026. Threat actors continued targeting organizations across multiple industries using double extortion tactics, data theft, and operational disruption strategies. Researchers also identified ongoing activity across dark web marketplaces and underground forums supporting cybercriminal operations through the sale of stolen credentials, access data, and attack tools. Hacktivist groups also remained active during the quarter, particularly in campaigns linked to political and regional conflicts. Security teams are increasingly prioritizing real-time threat intelligence and attack surface visibility to identify risks earlier and respond more effectively to emerging threats. The upcoming webinar will feature insights from Kaustubh Medhe, Head of Research & Intelligence at Cyble, Brian Osterman, Senior Solutions Engineer for the US region, and moderator Mihir Bagwe. The session will explore ransomware trends, AI-powered attacks, nation-state cyber operations, and practical recommendations for strengthening cyber resilience in 2026. Registered attendees will also receive a complimentary copy of the Americas Threat Landscape Report – Q1 2026. Webinar Details Date: Wednesday, May 28, 2026 Time: 1:00 PM ET Duration: 45 Minutes

Registration Link: Click Here

CISA Launches CI Fortify to Defend Critical Infrastructure From Nation-State Cyber Threats

CI Fortify

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has launched a new initiative called “CI Fortify” aimed at helping critical infrastructure operators prepare for disruptive cyberattacks linked to geopolitical conflicts. The initiative comes amid growing concerns over nation-state cyber threats targeting operational technology (OT) systems that support essential services across the United States. The CI Fortify initiative focuses on improving critical infrastructure resilience through two key objectives: isolation and recovery. CISA said the effort is designed to help operators maintain essential operations even if adversaries compromise telecommunications networks, internet services, or industrial control systems. According to the agency, nation-state actors are no longer limiting their activities to espionage. Instead, threat groups have increasingly been pre-positioning themselves inside critical infrastructure environments to potentially disrupt or destroy systems during future geopolitical conflicts.

CI Fortify Initiative Focuses on Isolation and Recovery

Under the CI Fortify initiative, CISA is urging critical infrastructure organizations to assume that third-party communications and service providers may become unreliable during a crisis. Operators are also being asked to plan under the assumption that threat actors may already have some level of access to OT networks. Nick Andersen, Acting Director at CISA, emphasized the need for organizations to prepare for worst-case operational scenarios. “In a geopolitical crisis, the critical infrastructure organizations Americans rely on must be able to continue delivering, at a minimum, crucial services,” Andersen said. “They must be able to isolate vital systems from harm, continue operating in that isolated state, and quickly recover any systems that an adversary may successfully compromise.” The isolation strategy outlined under CI Fortify involves proactively disconnecting operational technology systems from external business networks and third-party connections. CISA said this approach is intended to prevent cyber impacts from spreading into OT environments while allowing organizations to continue delivering essential services in a degraded communications environment. The agency advised operators to identify critical customers, including military infrastructure and other lifeline services, and determine the minimum operational capabilities needed to support them during emergencies. CISA also recommended updating engineering processes and business continuity plans to support safe operations for extended periods while systems remain isolated.

Recovery Planning Central to Critical Infrastructure Resilience

Alongside isolation, the CI Fortify initiative places strong emphasis on recovery planning. CISA urged operators to maintain updated system documentation, create secure backups of critical files, and regularly practice system replacement or manual operational transitions. The agency noted that organizations should also identify communications dependencies that could complicate recovery efforts, such as licensing servers, remote vendor access, or upstream network connections. CISA encouraged operators to work closely with managed service providers, system integrators, and vendors to understand potential failure points and establish alternative recovery pathways. The initiative also highlights broader benefits of emergency planning beyond cybersecurity incidents. According to CISA, the same planning processes can help organizations maintain operations during weather-related disruptions, equipment failures, and safety emergencies. The agency said isolation planning can help cut off command-and-control access to compromised systems, while strong recovery preparation can reduce incident response costs and shorten recovery timelines.

Security Vendors and Service Providers Asked to Support CI Fortify

The CI Fortify initiative extends beyond infrastructure operators and calls on cybersecurity vendors, industrial automation suppliers, and managed service providers to support resilience planning efforts. Industrial control system vendors are being encouraged to identify barriers that could interfere with isolation and recovery procedures, including licensing restrictions and server dependency issues. Managed service providers and integrators are expected to assist organizations in engineering updates, local backup collection, and recovery documentation planning. Meanwhile, security vendors are being asked to support threat monitoring and provide intelligence if nation-state actors shift from espionage-focused activity to destructive cyber operations. CISA also requested vendors share information related to tactics that could undermine recovery or bypass isolation protections, including malicious firmware updates and vulnerabilities affecting software-based data diodes.

Volt Typhoon Cyberattacks Continue to Shape U.S. Cybersecurity Strategy

The launch of CI Fortify is closely tied to ongoing concerns surrounding the Volt Typhoon cyberattacks, which U.S. officials have linked to Chinese state-sponsored threat actors. CISA’s initiative specifically references the Volt Typhoon campaign as an example of how adversaries have attempted to establish long-term access inside U.S. critical infrastructure systems to potentially support disruptive actions during military conflicts. The Volt Typhoon operation first became public in 2023, when U.S. authorities revealed that Chinese hackers had infiltrated multiple sectors of American critical infrastructure. Former CISA Director Jen Easterly stated in 2024 that the agency had identified and removed Volt Typhoon intrusions across several sectors. She later reiterated in 2025 that efforts continued to focus on identifying and evicting Chinese cyber actors from critical infrastructure environments. Despite these operations, cybersecurity researchers and some government officials have warned that Chinese threat actors may still retain access to portions of critical infrastructure networks. Several experts have argued that nation-state groups remain deeply embedded in certain environments despite years of remediation efforts. With the CI Fortify initiative, CISA appears to be shifting focus toward operational resilience, recognizing that prevention alone may not be sufficient against sophisticated nation-state cyber threats targeting U.S. critical infrastructure.

North Korea’s Enormous Crypto Hacks Redefine Scale and Strategy

A pair of tightly executed cyberattacks have become milestones in cryptocurrency theft in 2026 due to their sheer size. These two incidents, targeting Drift Protocol and KelpDAO, account for roughly three quarters of all recorded crypto losses through April, revealing a shift toward fewer, higher-dollar operations. Based on a report from TRM Labs, security researchers..

The post North Korea’s Enormous Crypto Hacks Redefine Scale and Strategy appeared first on Security Boulevard.

CERT-In Warns of AI-Driven Cyber Threat Surge, MSMEs at Highest Risk

CERT-In advisory

India’s cybersecurity watchdog, CERT-In, has raised concerns of the nature of modern cyber threats, particularly those driven by artificial intelligence. In its latest advisory, the cybersecurity watchdog has highlighted how frontier AI technologies are reshaping the threat landscape, making cyberattacks faster, more scalable, and far more accessible, even to less skilled attackers. The warning places a special emphasis on Micro, Small, and Medium Enterprises (MSMEs), which are becoming prime targets due to their comparatively weaker security frameworks.  According to CERT-In, the rise of AI-powered tools marks a significant turning point in how cyberattacks are conceived and executed. What once required advanced technical expertise and hours of manual effort can now be accomplished in a fraction of the time through automation. The cybersecurity watchdog noted that modern AI systems are capable of independently scanning large volumes of source code, identifying deeply embedded vulnerabilities, and even launching coordinated, multi-stage cyberattacks. This shift has introduced what the agency describes as an era of “automation and scale” in cybercrime. 

From Manual Intrusion to AI-led Cyberattacks 

CERT-In’s advisory explains that traditional hacking methods involve painstaking manual processes and highly specialized knowledge. Attackers would typically spend hours, if not days, probing systems for weaknesses before exploiting them. However, AI has fundamentally altered this dynamic. Frontier AI systems can now detect “zero-day” vulnerabilities, previously unknown flaws, in mere seconds.  More concerning is the ability of these systems to “chain” multiple vulnerabilities together. By linking weaknesses across different applications or platforms, attackers can orchestrate comprehensive attacks that compromise entire networks from end to end. This level of sophistication was once limited to highly skilled professionals or state-sponsored actors. Today, however, the cybersecurity watchdog warns that such capabilities are accessible, effectively lowering the barrier to entry for cybercriminals. 

MSMEs Under Heightened Risk 

The advisory stresses that MSMEs are particularly vulnerable in this new threat environment. Unlike large enterprises, MSMEs often operate with limited budgets and lack dedicated cybersecurity teams or advanced monitoring systems. This makes it easier for attackers to leverage AI-driven tools.  CERT-In has pointed out that because AI simplifies and automates many aspects of cyberattacks, even individuals with minimal technical expertise can now carry out highly precise and damaging operations. As a result, MSMEs face a disproportionate level of risk. A successful breach could lead to severe consequences, including data theft, operational disruptions, or ransomware attacks that many smaller businesses are ill-prepared to manage.  The cybersecurity watchdog has cautioned that without immediate and meaningful improvements in their security posture, MSMEs could suffer significant financial and reputational damage. The growing accessibility of AI-powered attack tools means that the threat is no longer hypothetical but immediate and widespread. 

Recommended Security Measures 

In response to these emerging risks, CERT-In has outlined several critical steps that organizations, especially MSMEs, should take to strengthen their defenses. One of the primary recommendations is the deployment of robust threat detection systems combined with continuous network monitoring. These measures can help identify unusual activity early and prevent attacks from escalating.  Another key focus area highlighted by the cybersecurity watchdog is patch management. As AI tools enable attackers to quickly identify and exploit unpatched vulnerabilities, delays in updating software can create significant security gaps. CERT-In stresses that the timely application of patches is essential to minimizing exposure.  Additionally, maintaining comprehensive system logs is strongly advised. Detailed logs play a crucial role in forensic investigations, helping organizations understand how an attack occurred and what vulnerabilities were exploited. This information is vital for preventing future incidents and strengthening overall cybersecurity resilience. 

The Cyber Express Weekly Roundup: Data Breaches, Malware Campaigns, and Cyber Fraud Investigations

weekly roundup TCE cybersecurity news

In this week’s edition of The Cyber Express weekly roundup, we explore the latest developments in the world of cybersecurity, focusing on high-profile data breaches, growing malware campaigns, and law enforcement actions against cybercriminals.   As the digital threat landscape continues to evolve, attackers are targeting sensitive personal and organizational data, from health records to financial credentials. Meanwhile, government regulators are ramping efforts to protect minors and combat harmful content on social platforms, while cybercriminals continue to exploit vulnerabilities in both public and private sectors.  This weekly roundup highlights how various industries, from healthcare and social media to finance and government, are grappling with rising threats, making it clear that the intersection of data security, regulation, and cybercrime is more critical than ever.  

The Cyber Express Weekly Roundup 

UK Biobank Data Breach Triggers Urgent Review of Data Security Measures 

A significant data breach at the UK Biobank has raised major concerns over the security of health-related data used in scientific research. In April 2026, de-identified participant information was discovered being sold on a Chinese consumer platform, sparking widespread alarm among the research community. Read more... 

Vercel CEO Reveals Expansion of Malware Campaign Affecting Multiple Targets 

Vercel's CEO, Guillermo Rauch, confirmed that the recent breach involving Context.ai was part of a much larger malware campaign affecting multiple targets. Following a review of network logs, Vercel’s security team uncovered evidence of malware distribution that compromised several customer accounts, including access to valuable Vercel account keys. Read more... 

Ofcom Investigates Telegram and Teen Platforms 

In the UK, Ofcom has launched an investigation into Telegram and several popular teen chat platforms, such as Teen Chat and Chat Avenue, after reports surfaced of online grooming and child sexual abuse material (CSAM) on these services. Under the Online Safety Act, platforms are required to take proactive steps to prevent harmful content and protect minors from exploitation. Read more... 

Personal Data Exposed in Breach of France’s ANTS Portal 

A recent breach of France’s ANTS (Agence Nationale des Titres Sécurisés) portal has compromised personal data, including names, email addresses, and birthdates, although no documents or sensitive attachments were affected. The breach, which occurred on April 15, 2026, raises significant concerns about identity theft and phishing risks, as the exposed data could be used to target individuals. Read more... 

Bluesky Faces Coordinated DDoS Attack 

Bluesky, the rapidly expanding social media platform, suffered a major disruption on April 15, 2026, when it was targeted by a sophisticated distributed denial-of-service (DDoS) attack. The attack caused widespread outages, impacting core platform functions such as user feeds, notifications, and search capabilities. Read more... 

Indian Authorities Arrest Key SIM Card Supplier in Cyber Fraud Crackdown 

India’s Central Bureau of Investigation (CBI) has arrested a key conspirator in a major cyber fraud operation as part of Operation Chakra-V. The suspect, arrested in Guwahati, is accused of supplying fraudulent SIM cards used in various cybercrime schemes, including extortion and fake loan scams. The SIM cards were acquired using fake identities and distributed to cybercriminal networks. Read more... 

Weekly Takeaway 

This week’s roundup highlights the diverse and evolving nature of cyber threats. From the exposure of sensitive health data and sophisticated malware campaigns to DDoS attacks and SIM card fraud schemes, the cybersecurity landscape remains fraught with challenges. Regulatory bodies and companies alike continue to grapple with emerging risks, particularly in sectors like public health data, social media platforms, and digital content safety. As these incidents unfold, it’s clear that both technical vulnerabilities and human factors, such as social engineering, continue to be central targets for attackers.  With regulatory frameworks like the Online Safety Act and increased investigative efforts in places like India and France, the pressure on platforms and authorities to act quickly and decisively is higher than ever. As the cyber threat landscape becomes more interconnected, the need for enhanced security protocols, improved monitoring, and greater accountability in digital spaces remains critical. 
❌