Visualização de leitura

Berlin Ransomware Leak Exposes State Secrets

Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web.

When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom.

At the end of August, Berlin’s state government confirmed it was dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.

Rhysida claimed it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes:

  • Personal data: 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs.
  • Sensitive records: more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information.
  • Credentials: plaintext passwords and credentials for systems including GebäudAtlas, the ePayment PAYONE database and Z_ADMIN accounts.
  • Government and legal material: disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols.
  • Classified information: data related to classified-material handling and documents allegedly containing state secrets.
  • Critical infrastructure: vulnerability analyses concerning Berlin’s water supply.
  • Identity documents: passports and ID cards from personnel records.
  • Other material: contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL/PST archives.

The group also claimed that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements. These are Rhysida’s claims and have not been independently verified.

The scale of the breach is staggering. Investigators are now looking at roughly 1.4 million files containing personal details of civil servants, internal infrastructure records, and critical government data.

The fallout goes far beyond routine data theft. Investigative journalist Lars Winkelsdorf pointed out the gravity of the situation on social media.

Die absolute Vollkatastrophe ist eingetreten

Dieses Datenleck ist schlimmer als alle bisherigen Terroranschläge zusammen 1/xhttps://t.co/epU4mCYgew

— Lars Winkelsdorf (@winkelsdorf) September 4, 2026

“In addition to LKA documents related to investigations, the files also include plans concerning national defense—ranging from the federal government’s secret communication channels in the event of an apocalypse to defense-related companies and emergency plans developed by government agencies,” Winkelsdorf wrote.

Exposing crisis response plans and secret communication channels turns a financial shakedown into a national security headache.

Worse still, the leaked material includes files concerning chemical, biological, radiological, and nuclear threats.

“Among the published files is a folder titled “AG CBRN-Rahmenplanung.” CBRN stands for chemical, biological, radiological and nuclear threats,” notes the Euronews report

Having that kind of operational data floating around public forums gives hostile actors a blueprint for disaster.

Refusing to pay ransoms is the right policy, but it rarely stops the bleeding once the network is compromised. Governments keep treating cybersecurity like an IT expense rather than an existential line of defense.

Until boards start treating network segmentation with the same seriousness as physical security, we will keep watching expensive countdown timers tick down to zero.

Berlin’s state government announced the launch of a crisis response after the threat actors published the stolen data.

“A ‌central ⁠crisis unit will oversee the review, verification and assessment of the leaked data and support efforts to inform affected citizens and ​businesses, said the ​city.” Reuters reports.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Berlin)

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts

Fire Ant Evolves: From Hypervisors to Trusted Infrastructure      

Gryxa: The AI-Built Toolkit That Watches How You Remove It

ValleyRAT masquerading as adware  

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds  

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Uncovering StreamRat: From Meta Ads to Full Device Takeover  

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon September 2, 2026

Mini Shai-Hulud’s Latest Wave: 280 New Places It Hunts for Your Secrets  

Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist 

Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem

Peer Pressure: Inside the Sality Botnet Disruption Operation

Graph-Based Learning for Android Authorship Attribution: A Comparative Analysis of GNN Models

Stability and Hopf Criteria in a Malware Dissemination Model for Wireless Sensor Networks with Distributed Recovery Delays

PhantomCall: Evading ML Malware Detectors via Function Call Graph Perturbation

REPLICANT: Learning Policies for Evading and Hardening Malware Detectors

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign
Google fixes the sixth actively exploited Chrome zero-day of 2026
Dark Web Service Nexus Sells 153M+ Driver’s Licenses
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
$536 and 8 Hours: AI Learns to Attack a Different PLC
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Hackers Target Langflow in CVE-2026-0768 Attacks
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague
Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt
North Korea-linked IT Workers Are Getting Hired Inside Western Companies
Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
China-linked Fire Ant Hides Inside Trusted Infrastructure
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

International Press – Newsletter

Cybercrime

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation  

FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs  

FBI Probes Service Selling 153M+ Drivers Licenses

Two Nigerian Nationals Extradited from Nigeria to the United States to Face Sextortion Charges in North Carolina and Mississippi  

The Town 2025 ticketing data sold as a Ticketmaster breach 

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon September 2, 2026  

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal   

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Malware

Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts

Gryxa: The AI-Built Toolkit That Watches How You Remove It

ValleyRAT masquerading as adware  

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds  

Mini Shai-Hulud’s Latest Wave: 280 New Places It Hunts for Your Secrets  

Hacking

Eclypsium flags 1,051 CVEs in infrastructure advisories 

Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP  

Kaspersky zero-day exploit HardBreacher 

PrettyPrague: GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability  

Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack 

Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet  

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon 

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking  

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

When Sorting Leads To Confusion  

Intelligence and Information Warfare  

Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist

Fire Ant Evolves: From Hypervisors to Trusted Infrastructure

Insights into Suspected DPRK Workers: Red Flags to Look Out For   

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set  

Leaked Russian Cyber-Operations Training Materials  

Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline  

Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia

How the Russians Got Inside My Phone

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors    

Cybersecurity

Judge says Pentagon’s measures against Anthropic were ‘illegal and baseless’  

How AI could make it harder for governments to use hacking tools  

Own a gun? Go to church? Do yoga? AI can find out in seconds        

Path to Astra: critical capabilities and frontier safeguards  

PostGREShell: The database powering much of the internet had an open door for 12 years 

Fighting AI with AI: The US’s New Cyber Rules of Engagement 

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people.

Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not affected, but the incident has exposed data that can make fraud far more convincing.

The data related to parking, lounge and Fast Track bookings, as well as airport Wi-Fi sign-ups. MAG said attackers took email addresses, phone numbers, vehicle registration details and postcodes, while payment-card data was not accessed.

The group disclosed the incident on 27 August and said it had contained the risk, engaged specialist advisers and notified relevant authorities.

The extortion group FulcrumSec claimed responsibility for the intrusion and leaked the data after MAG had refused its ransom demand.

“Today we are releasing the Manchester Airports Group dataset: every customer, event, configuration that serves Manchester Airport, London Stansted and East Midlands Airport. Half a terabyte, and every byte of it is pure PII. However, we have decided to withhold the most dangerous part of the breach : the nearly 200,000 passengers whose entire upcoming travel schedules were exposed by MAG’s negligence, which, when linked with their full PII and vehicle information, creates an ideal opportunity for burglars, stalkers, and worse.” FulcrumSec wrote on its data leak site. “Unfortunately for them, MAG made zero effort to protect all their data they’d been collecting. The way we gained access was so simple it is tragi-comical: Iterable admin keys in the frontend JavaScript of each of its three airports’ websites: manchesterairport.co.uk, stanstedairport.com, and eastmidlandsairport.com. Each site had its own key hardcoded into it that provided access to millions of passengers who had passed through that airport. That means for this breach to have occurred at the scale it did, MAG had to make a catastrophic security mistake not once, not twice, but THREE times.”

FulcrumSec claims it accessed MAG’s systems using administrator keys exposed in the JavaScript of its three airport websites. MAG hasn’t confirmed this, and SecurityWeek hasn’t independently verified it, so the claim remains unproven. Still, the case highlights a basic security rule: keep secrets off client-side code, rotate them regularly, limit access and scan code, repositories, logs and configurations for accidental exposure.

The group then published roughly 550 GB of uncompressed data it says came from the airport operator’s systems.

“These exposed keys gave us access to the following:

  • 8,672,291 customer profiles with email, name, mobile, home town, postal region, and the residential IP address the account last connected from
  • 1,169,302,811 events, of which 1,160,120,195 are email-channel events: 611,629,550 sends, 463,286,223 opens, 36,878,965 clicks, plus every subscribe, unsubscribe, bounce and complaint
  • 2,482,763 purchases — every booking every customer of its parking, lounge, and fast-track products has ever made. An analysed subset of 1,154,675 transactions, from 877,754 identified purchasers, totals £83,413,317.89
  • 461,433 SMS messages rendered with a passenger’s booking date, car park and vehicle registration spelled out in plain text
  • 108,077 unique UK vehicle registration plates tied to the owner’s email, mobile, airport, car park and dated booking
  • The complete platform configuration: every campaign, every journey, every list, every segment and every template, all as live JSON” FulcrumSec added.

The announcement claims that a leaked MAG database exposes 190,849 future bookings, including 142,755 linked to vehicle registrations, potentially revealing when homes will be empty.

It also claims the data includes thousands of government, judicial, military, police, NHS and defence-industry employees, creating significant security risks. The attackers say they removed the most sensitive travel details before publishing, while accusing MAG of downplaying the breach.

Databreach notification service Have I Been Pwned processed the available dataset and added the incident to its breach database. The service reports that approximately 8.8 million email addresses and phone numbers were compromised, alongside names, IP addresses, browser user-agent details, geographic information, purchases and vehicle registration plates.

That is not just a list of email addresses. It is a working fraud kit: a criminal can link a person to an airport, a booking type, a car, a location and a contact number. They don’t need to guess much after that.

What affected people should do

Anyone who has used MAG’s parking, lounge, Fast Track or airport Wi-Fi services should assume that phishing attempts may become more tailored. They should be cautious with messages claiming to concern a booking, refund, parking penalty, account problem or payment request.

Users should change passwords if they reused one associated with these services elsewhere, especially on email accounts. They should also enable multi-factor authentication, review account-recovery methods and avoid clicking links in unexpected messages.

A legitimate organisation will not ask for a password, a banking PIN or a one-time authentication code by email, SMS or phone. If a message refers to a booking, open the relevant airport or provider site manually rather than following the link it contains.

The Have I Been Pwned breach entry allows users to check whether their email address appears in the published dataset.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Manchester Airports Group)

Dark Web Service Nexus Sells 153M+ Driver’s Licenses

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans.

A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada.

The FBI’s New Orleans field office opened a formal investigation the same day. Brian Krebs at KrebsOnSecurity, who broke the story, traced the source to idscan.net, a New Orleans-based identity verification company whose clients include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and the financial services firm Jack Henry.

“On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.” wrote Krebs. “The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.”

The record total was also increasing by roughly 400,000 per day at the time of publication, which the operators attributed to ongoing active exfiltration from a live breach they claim has been running for over a year.

Krebs found his own driver’s license in the database after a source alerted him to the service. The operators had posted his Virginia license as a free sample on the Russian cybercrime forum Exploit. Each record contains six images of the license, showing the front and back in visible, infrared, and ultraviolet light, with a timestamp. Krebs’ timestamp matched a June 2025 flight and car rental.

He then checked nine friends and relatives, and everyone who found their license confirmed traveling or renting a car around the same date. His license and his mother’s, who rented a Hertz car with him that day, had timestamps just seconds apart.

Security researcher Zach Edwards, whose license also appeared in Nexus, narrowed the source further. His timestamp matched a trip to Las Vegas for DEF CON in August. He hadn’t rented a car, but he had shown his license at a marijuana dispensary: Planet13, a multi-state chain. In 2022, idscan.net published a press release announcing an exclusive identity verification partnership with Planet13’s dispensaries nationally. The company now serves more than 1,000 marijuana dispensaries in 19 states, and its own documentation confirms that its technology scans IDs with both infrared and ultraviolet light, precisely the format of the images appearing in Nexus.

Idscan.net performs more than 21 million verifications per month at more than 20,000 locations globally. Its client list spans car rentals, retailers, hotels, financial services, and dispensaries, which explains both the volume and the geographic spread of the records. The dataset also includes marijuana dispensary cards and records marked with the notation “CAC,” which may refer to Common Access Cards, the government-issued credentials used to enter federal buildings and secure facilities. If confirmed, that would significantly expand the security implications beyond consumer identity theft.

The database reportedly contained the driver’s licenses of U.S. Defense Secretary Pete Hegseth and the FBI’s assistant director, but not FBI Director Kash Patel’s.

Idscan.net said Krebs’ findings would help its internal investigation but gave no further details. The company later said it was working with law enforcement and forensic experts. Soon after the story became public, the Nexus service went offline.

Identity verification systems that require driver’s licenses are spreading sensitive data across an expanding network of third-party vendors, and oversight mechanisms haven’t kept pace. Every bar, hotel, car rental counter, dispensary, and age-verification system that scans an ID is creating a copy of that image in a system whose security posture the cardholder has no way to assess.

The idscan.net incident, if confirmed at the reported scale, would be among the largest exposures of government-issued identity document images ever recorded.

Krebs reports that Nexus shut down after his article, while the FBI opened an investigation after learning that stolen IDs may include licenses belonging to FBI agents.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Nexus)

412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration.

A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. Ransomnews’s analysis confirms the sample is genuine ticket-buyer data from The Town 2025, the São Paulo music festival, though who actually lost the data and how remains unconfirmed.

“The listing is headed “SELLING NEW TICKETMASTER DATABASE” and describes a global ticketing platform, Latin America region, with an internal ticketing database as the source and a breach date of 28 August 2026. It advertises 412,192 rows across 34 columns.” reported Ransomnews. “The country breakdown is dominated by Brazil at 251,557 records, or 61%, with Argentina at 219, Chile 155, Colombia 144, Peru 123 and Paraguay 72, plus nine more countries not itemised.”

The seller is asking $10,000 for the full database, or $80 for every 1,000 records, with escrow available. The 251,557 Brazilian records make up about 61% of the database, meaning the seller is effectively asking around four cents per person.

The data includes names, email addresses, CPF numbers, phone numbers, neighborhoods, ticket types, and payment details. Together, these details provide a detailed profile that could be used for identity theft and fraud.

“The seller’s own notes are the part that should concern Brazilian readers most. Alongside the sales copy, the listing states that the CPF numbers work “for Brazilian bank fraud, loan apps and SIM registration”.” continues the report.”That is not our characterisation of the risk. It is the seller describing the intended use of the file.”

Ransomnews ran the kind of checks that usually expose fake listings within minutes, and this one kept passing. Purchase IDs across the sample rise in strict chronological order, exactly what an auto-incrementing database key produces and something close to statistically impossible to fake by chance. Every CPF number in the sample passes Brazil’s official check-digit validation, phone area codes correctly match the state listed on each row rather than defaulting to a single city, and neighborhood names map precisely onto their stated cities, the kind of granular accuracy a random data generator simply doesn’t produce.

The ticket prices provide another strong sign that the database is genuine. Full-price tickets cost exactly 975 reais, while discounted tickets cost 487.50 reais, matching Brazil’s legal student discount. The database also lists Pix and Elo as payment methods, both widely used in Brazil.

Even the incomplete records look realistic. Complimentary tickets issued by the festival’s back office contain no name or CPF, only the ticket type and date. These kinds of inconsistencies are common in real databases but would be unusual in fabricated data.

However, there is an important detail that challenges the claim of a direct Ticketmaster breach. Every record in the sample has exactly the same processing timestamp: October 1, 2025 at 23:05:41, about two weeks after the festival ended.

A live database dump would normally contain different timestamps. The identical timestamp instead suggests that the data may have been exported in a single batch after the event and then shared with a promoter, sponsor, payment provider, or another partner. Ransomnews therefore warns that blaming Ticketmaster directly would go beyond what the available evidence currently shows.

That distinction matters more than it might seem, because it points at an industry-wide blind spot rather than one company’s failure. Brazilian ticketing requires CPF collection to enforce discount eligibility rules, which means live-events companies routinely end up holding a national identity number, a verified phone, and a home neighborhood for hundreds of thousands of people, data with the sensitivity of a bank record sitting inside an industry with nothing like a bank’s security requirements. The moment that data gets exported into a spreadsheet to reconcile ticket sales with a partner, which happens constantly and rarely makes headlines, it becomes dramatically easier to lose.

“If you bought tickets to The Town 2025, treat your CPF as exposed.” concludes the report. “A CPF cannot be reissued the way a password can, and the seller is explicitly marketing these numbers for credit and telecoms fraud.”

If you bought tickets to The Town 2025, the practical response here isn’t panic, it’s specific vigilance. A CPF can’t be reissued the way a password gets reset, so treat it as permanently exposed and check your credit record through Brazil’s Central Bank registry or services like Serasa for accounts you didn’t open. Watch closely for SIM swap attempts given the seller’s explicit mention of telecom fraud, and be skeptical of any inbound call or message referencing your actual festival purchase, since whoever holds this file knows exactly which days you attended and how you paid, more than enough detail to make a scam call sound completely legitimate.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, The Town 2025)

Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records

Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure.

Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, after attackers gained access to part of its Amazon Web Services infrastructure.

Aesto Health is a U.S. healthcare technology company based in Birmingham, Alabama. It helps healthcare providers manage and protect electronic health records and other legacy medical data. Its services include secure data migration, electronic health record (EHR) exchanges and long-term data archiving. Aesto works with medical practices and healthcare organizations that need to move, store or access patient information securely.

“On or about December 18, 2025, Aesto experienced a network security incident that impacted a limited portion of our Amazon Web Services infrastructure.” reads the Notice of Data Security Incident. “After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or acquired by an unauthorized actor.”

The company launched an investigation into the incident with external leading cybersecurity experts.

The network security incident affected part of its Amazon Web Services infrastructure between December 2 and 18, 2025. On May 26, 2026, Aesto confirmed that an unauthorized actor may have accessed or acquired protected health information stored in its network. Exposed data may include names, birth dates, medical and insurance information, driver’s license and government ID numbers, financial account details, taxpayer IDs and, for a limited number of people, Social Security numbers.

Aesto says it found no evidence of identity theft or financial fraud linked to the breach. Starting June 26, 2026, it notified affected healthcare clients whose patients’ data may have been accessed.

The company announced it has already implemented measures to strengthen security and set up a dedicated helpline for questions.

The healthcare firm also notified the US Department of Health and Human Services (HHS), reporting that the incident impacted 9540683 individuals.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Aesto Health)

Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft

Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript.

Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole roughly 86GB of data, considerably more detailed than what MAG’s original disclosure suggested.

MAG’s own statement describes a relatively limited set of exposed data. It says the breach affected car park, lounge, Fast Track bookings, and airport WiFi registrations, exposing email addresses, phone numbers, vehicle registrations, and postcodes.

MAG disclosed that the data breach impacted 8.7 million customers, however, the company says most of those customers had only their email addresses exposed.

FulcrumSec tells a different story. The group shared samples with BleepingComputer that included a 21.5GB export of Manchester customer data, with personal identifiers, historical booking details, and marketing information. BleepingComputer checked one record against a real traveler’s purchase history and found matching Fast Track bookings, arrival times, terminal information, and payment amounts.

The alleged way into the system is particularly concerning. FulcrumSec says it found airport-specific Iterable API credentials inside client-side JavaScript. That code runs in users’ browsers, so anyone inspecting the website with developer tools could potentially see those credentials.

“The group claims it obtained access using airport-specific Iterable API credentials exposed in client-side JavaScript and that the stolen material includes nearly 200,000 records related to upcoming travel during the remainder of 2026.” states the report. These records allegedly contain dates, times and booking information linked to personally identifiable information. FulcrumSec says it intends to publish the stolen data and a technical account of the intrusion. If the claim is accurate, attackers did not need a highly sophisticated technique. They simply found sensitive API credentials exposed in code that the website sent directly to customers’ browsers.”

The most concerning specific claim is nearly 200,000 records tied to upcoming travel through the rest of 2026, complete with dates, times, and booking details linked to identifiable individuals. BleepingComputer couldn’t independently verify that number or the full scope of what was actually taken, and MAG declined to directly address FulcrumSec’s specific claims when asked, instead pointing to its existing statement that affected customers with upcoming bookings had already been contacted. MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, a spokesperson said, without engaging with the 86GB figure or the exposed-credentials claim directly.

FulcrumSec plans to publish the stolen data but may redact upcoming travel records because of the risk of real-world harm. UK postcodes can identify very small groups of addresses, and combined with vehicle registrations, parking dates and booking details, the data could enable highly convincing phishing messages targeting people with upcoming trips.

UK postcodes make this exposure sharper than the equivalent breach might be in the US. Unlike American ZIP codes covering broad delivery areas, a full UK postcode typically identifies a small cluster of neighboring addresses, sometimes a single property, according to the Office for National Statistics. Combined with vehicle registrations, parking dates, and specific booking references, that’s more than enough raw material for a phishing message referencing a real upcoming trip that would be very hard to distinguish from a genuine MAG communication.

Security researchers commenting on the broader incident have flagged a supply-chain angle worth watching. Airport operations increasingly run through third-party platforms for booking, parking, and loyalty services rather than systems the airport itself directly controls, and Iterable, the marketing platform whose API credentials FulcrumSec claims to have abused, is exactly that kind of outsourced dependency. This also isn’t aviation’s first bad year: a September 2025 ransomware attack on Collins Aerospace‘s check-in software had already grounded systems at Heathrow, Brussels, and Berlin, meaning UK and European aviation infrastructure has now taken two significant hits inside twelve months.

MAG says no payment card or banking data was exposed, however, travelers who recently booked parking, lounge access or Fast Track should assume more travel data may be exposed and treat messages citing real booking details with caution.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Manchester Airports Group (MAG))

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

Hack One Robot, Reach the Next: Unitree G1 Security Flaws
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
Love Electric Breach: 877,000 Driver Records Offered for $600
Trump Targets Foreign Technology in New U.S. Power Grid Security Order
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
PaperCut Zero-Day Under Active Attack: Emergency Patch Released
U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Australian Police Charge Two Over TeamPCP Credential Theft
Meta to Pay Up to $18B Over Teen Social Media Use
CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do
OpenAI banned Russian ChatGPT accounts backing covert influence operation
CISA Red Team Fully Compromised Two Critical Infrastructure Orgs
FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
88 ID Verification Breaches Show the Cost of Collecting Identity Data
WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion
Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams
Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack
When the Algorithm Fires You: Uber Faces €825M Fine
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
Cybercriminals Turn GTA VI Leaks Into Malware Bait
Slovakia Warns of Cyber Risks in Road Speed Cameras
TikTok Settles U.S. Child Privacy Case for $400 Million
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

International Press – Newsletter

Cybercrime

iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets     

Fake GTA VI ISO circulates on the internet a few days after leak, internet sleuths claim 113GB download is padded malware        

Taiwan charges 9 over illegal AI server exports to China, including Nvidia and Super Micro staff  

Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly

58 arrests in global effort to dismantle West African organized crime groups

Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain       

RTM Locker interview: a ransomware actor on the RaaS market 

Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate  

Love Electric driver data for sale: NI, licence numbers 

Ransomware group says it stole Berlin data, offers it for auction  

Malware 

FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution     

19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads  

SLEEPWALKER: A Passive Backdoor With Its Own Command Language  

Hacking

One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin  

A Tale of Two SOCs: Insights From Two Red Team Assessments  

Three UK airports hit by cyber-attack with data of 8.7m customers accessed   

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

PaperCut Releases Emergency Patch for Exploited Zero-Day

Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities   

The Hugging Face incident and the road ahead

Power Leak: Amazon Kiro IDE Prompt Injection Enables Data Exfiltration      

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests

UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range  

PaperCut Actively Exploited: A Pre-Auth RCE Chain  

Intelligence and Information Warfare  

Iranian hackers shut down UK power plant  

Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor    

Digdir stabilizes solutions after cyberattack  

Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure

The infrastructure quartermaster: inside a China-nexus state enablement model     

Disrupting a new covert influence campaign from Russia 

Tortoiseshell: New Toolset and Operational Infrastructure Exposed

Treasury Launches Unprecedented Campaign Against Iranian Regime on Economic D-Day

Dark Caracal Reloaded: New Malware, Same Hunting Grounds  

Cambodia-focused cluster uses multistage infection chain with localized lures

BlueDelta Targets Defense and Diplomacy with HOOKEDGE

Cybersecurity

Warning about the risks of road meters  

One billion people are now protected with passkeys on WhatsApp, plus more account security features

An ID Check Breach Timeline: 2011–2026 

Internet Exposure Reduction Guidance 

Meta agrees to pay $18 billion to settle US lawsuits over children’s social media addiction  

DECLARING A NATIONAL EMERGENCY TO SECURE THE UNITED STATES BULK-POWER SYSTEM  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft.

Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.

Rhysida claims it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes:

  • Personal data: 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs.
  • Sensitive records: more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information.
  • Credentials: plaintext passwords and credentials for systems including GebäudAtlas, the ePayment PAYONE database and Z_ADMIN accounts.
  • Government and legal material: disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols.
  • Classified information: data related to classified-material handling and documents allegedly containing state secrets.
  • Critical infrastructure: vulnerability analyses concerning Berlin’s water supply.
  • Identity documents: passports and ID cards from personnel records.
  • Other material: contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL/PST archives.

The group also claims that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements. These are Rhysida’s claims and have not been independently verified.

The timing makes this attack especially sensitive. Berlin will elect its state parliament on September 20, less than a month after the breach, so an attack on government systems just before the vote was bound to raise questions. Interior Senator Iris Spranger said the election remains secure and that, so far, the attackers haven’t taken any election-related data. Security officials support that assessment.

Broadcaster RBB first reported on Thursday that Berlin had received ransom demands.

“The state ​of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin’s interior senator, ​Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack ‌on ⁠their Tor data leak site.

That position follows long-standing advice from US federal agencies, which warn that paying a ransom doesn’t guarantee data recovery and can encourage more attacks. Saying no to the ransom is one thing; dealing with the consequences if the attackers publish the stolen data is another.

Berlin first disclosed the compromise on August 17, isolating the Senate Department for Mobility, Transport, Climate Protection and Environment along with a second department from the network. Forensic investigators later found the actual data exfiltration happened earlier than the public disclosure, sometime between August 7 and August 12, with the affected department having flagged an initial outflow internally on August 7, a full week before the network got cut off. That gap between first internal detection and actual network isolation is the kind of detail that tends to get scrutinized hardest once the immediate crisis passes.

Rhysida isn’t a new name to anyone tracking ransomware against government targets. The group has claimed roughly 280 victims since emerging in 2023, according to tracking services cited by Reuters, including nine in Germany alone and headline targets like the British Library and Chile’s army. Roughly half its victims sit in the US, with the UK, Canada, and Italy rounding out the next tier, a spread that suggests Rhysida isn’t picking targets based on geography so much as opportunity.

A joint advisory from CISA, the FBI, and the Multi-State Information Sharing and Analysis Center, first published in November 2023, lays out exactly how Rhysida typically gets in: compromised VPN credentials at organizations without multi-factor authentication, exploitation of the Zerologon vulnerability that Microsoft patched back in 2020, and old-fashioned phishing. None of those entry points are exotic or new, which is precisely the point; Rhysida doesn’t need novel techniques when so many organizations still haven’t closed gaps that have been publicly known for years.

Berlin reconnected all Senate departments to the network on August 23, but forensic teams are still checking the systems. The state’s data protection commissioner and Germany’s federal cybersecurity agency, the BSI, are following the investigation.

As of publication, neither Berlin’s data protection office nor the Senate Chancellery had given specific advice to the roughly 12,000 people whose data Rhysida claims to have stolen. If you’re among them and haven’t received any official message yet, don’t assume that means you’re safe. Investigators are still working to establish exactly what the attackers accessed and took.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Rhysida Ransomware)

Love Electric Breach: 877,000 Driver Records Offered for $600

Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers.

A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the name “seraphims”, offered 877,000 records for $600 in cryptocurrency, with the price negotiable.

That headline number needs a qualification. Ransomnews researchers examined a 999-row sample published with the listing and found strong evidence that the sample came from a genuine production database, but the claimed 877,000 records remain unverified. Love Electric had been contacted for comment at the time of publication.

“The 999 rows split into 731 primary drivers and 268 additional named drivers. There are exactly 731 distinct quote IDs, and every quote has exactly one primary driver, 731 out of 731. All 268 additional drivers reference a quote that exists in the file, with no orphans.” reads the Ransomnews’s report. “The consent flag governing National Insurance processing is empty for precisely the 268 additional drivers and populated for every one of the 731 primary drivers. National Insurance numbers appear on primary drivers only. Those are constraints enforced by whatever application wrote the data, and they hold across all 999 rows without exception.”

That matters because fabricated breach databases often fall apart when researchers examine the relationships between records. Here, the relationships hold: additional drivers point to existing quotes, the National Insurance processing flag appears where the underlying application logic would expect it, and National Insurance numbers appear only on primary drivers.

Love Electric Financial Services Limited is an Edinburgh-based company that provides EV salary sacrifice administration, credit broking and related services to employers across the UK. Companies House identifies it as an active Scottish company, registered under number SC374952, while Love Electric’s own documentation confirms that it operates as a salary sacrifice administrator and FCA-regulated credit broker.

The business model explains why its systems can contain information that many people would normally associate with payroll departments. Salary sacrifice arrangements require the broker to identify employees, process the scheme and support insurance and tax-related requirements, so the underlying records can include National Insurance numbers and driving licence information. Love Electric’s privacy policy also says it processes personal information under UK data protection law.

“The seller published a free sample as a 999-row CSV with 24 columns, named in a way that indicates an export of a dbo.drivers table from a Microsoft SQL Server database.” continues the report. “The columns are: id, quote_id, user_id, title, first_name, last_name, email, phone_number, date_of_birth, address, address2, city, country, postcode, national_insurance_number, driving_licence_number, driving_licence_country, allow_processing_national_insurance, primary, created_at, updated_at, deleted_at, weekly_hours and occupation_id.”

The fields included names, email addresses, phone numbers, dates of birth, addresses, postcodes, National Insurance numbers, driving licence numbers, quote IDs and consent-related fields.

The data wasn’t uniformly populated, which is another reason the sample looks like a real production export rather than a synthetic dataset. Around 71% of the rows lacked a name, address or city, 74% had no phone number, and 85% had no National Insurance number, while 147 records contained a National Insurance number and 287 contained a driving licence number.

The geography also made sense. Postcodes clustered around Edinburgh and central Scotland, with records extending into England, while dates of birth ranged from 1946 to 1999 and concentrated around people born in the 1970s and 1980s.

Ransomnews then tested the driving licence numbers against the structure used by UK licences. Of the 108 full-length licence numbers in the sample, 98.1% had a surname block matching the surname in the corresponding record, 97.2% had an initial matching the first name, and 78.7% contained a date-of-birth encoding that matched the stored date of birth.

The imperfections were just as interesting. Licence numbers appeared in many different lengths, only 53% of the National Insurance numbers present matched the expected HMRC format, and phone numbers appeared in three different formats. That kind of mess is exactly what you’d expect from users entering information into a live form, abandoning fields or making mistakes.

“A UK driving licence number is not random. Characters one to five are the holder’s surname padded with the digit 9, characters six to eleven encode the date of birth with 50 added to the month for female holders, and character twelve is the first-name initial. Of the 108 full-length licence numbers in the sample, 98.1% have a surname block matching the record’s own surname field and 97.2% have an initial matching the first-name field. 78.7% carry an encoded date of birth matching the date_of_birth column.” state the researchers. “The roughly one in five that disagree are consistent with people mistyping a sixteen-character string into a web form, which is exactly the error rate real self-reported data carries and synthetic data does not.”

The email addresses provided another useful check. Most belonged to corporate domains associated with identifiable UK employers, Love Electric itself or a European software consultancy, rather than being dominated by Gmail and other consumer providers. That fits the way workplace salary sacrifice schemes operate because employees generally enter through their employer.

The database structure also looked normal. It included a soft-delete field, integer foreign keys for quotes and occupations, regional values for Scotland, England, Wales and Northern Ireland, and even a Jane Doe test record that appears to have survived from the system’s setup. Real databases leave fingerprints like these. Synthetic ones tend to be suspiciously tidy.

The seller’s own history is less convincing than the database evidence. The “seraphims” account was created on July 22, 2026 and had published nine data listings by August 26, roughly two per week, but several of those listings were described by the seller as scrapes rather than breaches.

The Love Electric listing had attracted no replies and only 52 views when Ransomnews checked it. The account’s reputation score of 30 came from a single positive vote posted on August 17 with the comment “keep scrapping”, which says more about the seller’s scraping activity than about a track record of selling verified breach data.

That doesn’t make the Love Electric sample fake. The technical evidence points in the opposite direction. It does mean we should separate two questions: whether the sample appears genuine, and whether the seller really controls 877,000 records.

The second claim is much harder to establish. Ransomnews saw only 0.11% of the alleged dataset, and the sample shows that database rows don’t map directly to individual people. The 999 rows corresponded to 731 quotes and only 58 distinct surname-and-date-of-birth combinations, with one person appearing 48 times.

There’s another clue in the filename. The db2_ prefix suggests that the table may belong to one database among several, so the seller’s 877,000 figure could refer to a larger collection rather than this particular driver table. At this point, treating 877,000 as a confirmed number would go beyond the evidence.

The timeline also deserves caution. The seller claimed an August 2026 attack involving a zero-day in a third-party system, but every sample row carries a created_at timestamp within a six-second window on August 14, 2022. That pattern looks like a bulk migration into a newer platform rather than 999 people signing up within six seconds.

It tells us that the database contains legacy records. It doesn’t tell us when someone took them, how they obtained them or whether the seller’s claimed zero-day played any role.

That last point matters for incident response. “Third-party zero-day” is a claim made by the seller, not an established fact, and attackers have plenty of reasons to make an access story sound more sophisticated than it was. Ransomnews says it has not verified that route.

For the people potentially affected, the more immediate issue is the nature of the exposed information. A password can be replaced. A National Insurance number and a driving licence number can’t simply be rotated because someone has posted them for sale.

That creates an obvious phishing risk. Someone who has a person’s name, date of birth, address, employer and National Insurance number can construct a much more convincing message pretending to be HMRC, a payroll team, an employer or a vehicle leasing provider.

Drivers who used Love Electric should therefore treat unexpected messages about their vehicle scheme, payroll or tax affairs with suspicion. They should verify the sender through a phone number or website they already trust rather than using contact details contained in the message.

Love Electric’s current public material says it works with more than 1,500 companies, which gives some sense of the scale of the service’s employer-facing footprint.

That makes supplier security worth treating as an operational issue rather than a procurement checkbox. If a third-party provider holds National Insurance numbers, driving licence numbers, employment information and contact data, its security controls deserve the same level of scrutiny as any other system handling high-value identity information.

The seller’s alleged third-party entry point is therefore worth investigating, but it shouldn’t become the centre of the story before someone verifies it. The useful evidence is already sitting in the sample: a production-style schema, consistent relationships, realistic user errors and identifiers that line up with real-world records.

The other important detail is the price. $600 for a database containing National Insurance and driving licence numbers isn’t a serious valuation of the data. It’s a price designed to make a quick sale.

And if the seller really has more than the published sample, multiple buyers could obtain the same information. That’s where the risk gets worse: the exposure doesn’t end with the first person who downloads it.

Ransomnews says it did not access or probe Love Electric’s systems, purchase the full dataset, or validate the exposed identifiers against live services. It analysed the free sample, removed identifying information from its publication and notified Love Electric before publication, offering to share the listing and sample with the company’s incident-response team.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)

Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports

A cyberattack on Manchester Airports Group exposed data of 8.7 million customers across Manchester, Stansted, and East Midlands airports.

Manchester Airports Group disclosed that an unauthorised third party accessed customer data belonging to approximately 8.7 million people across three of England’s busiest airports: Manchester, London Stansted, and East Midlands.

“Manchester, London Stansted and East Midlands airports have been hit by a cyber-attack in which hackers accessed the data of about 8.7 million customers.” reads the report published by The Guardian.

“The incident involved data related to “car park, lounge and fast-track bookings and in-airport wifi sign-ups”, and the hackers obtained email addresses, phone numbers, vehicle registration numbers and postcodes, said Manchester Airports Group (MAG), which operates the three hubs.”

MAG says it learned about the incident on Tuesday, August 25, after attackers breached the system over the weekend.

The affected data included car park bookings, lounge and fast-track security reservations, and airport Wi-Fi sign-ups. Attackers accessed email addresses, phone numbers, vehicle registration numbers, and postcodes. The system did not store bank or payment details. According to MAG, most of the 8.7 million affected customers only lost their email addresses, while the impact varies depending on which services they used.

The attack did not disrupt airport operations or flights. As a precaution, MAG temporarily suspended its Manage My Booking service, but all existing reservations remain valid. Customers who need to change a booking within the next 72 hours can use a dedicated phone line.

“We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information. We apologise for any inconvenience or concern this may cause.” reads the email sent by Stansted to affected customers.

That warning is relevant because the combination of an email address, a phone number, and the knowledge that someone recently made a parking or lounge booking gives a convincing starting point for a targeted phishing message. Attackers don’t need payment data if they can impersonate the airport convincingly enough to obtain it themselves.

The timing adds pressure. The attack landed during the peak summer travel season, with millions of families flying back into the UK before the school year begins. The three airports combined handled around 54 million passengers last year, and MAG recently reported a record 66 million passengers across its network. The scale of the data exposure reflects the sheer volume of ancillary services these airports sell, and how much personal data those services routinely collect.

The wifi registration system is the detail worth noting: signing into airport wifi typically requires a name, email, and phone number at minimum, and that information now belongs to whoever executed this breach.

MAG says it quickly contained the incident, brought in external cybersecurity experts and notified the relevant authorities. No group has claimed responsibility, and investigators have not publicly linked the attack to any specific actor.

The incident adds to a growing list of cyberattacks against UK infrastructure. Earlier in August, Iran-linked hackers took a British power plant offline for four days, marking the first confirmed case of Iranian actors shutting down a UK generator. Last year, attacks disrupted production at Jaguar Land Rover and targeted Marks & Spencer, Harrods and the Co-op. Heathrow also faced flight delays and cancellations after attackers disrupted check-in and boarding systems used by several European airports.

MAG’s breach adds further pressure on UK infrastructure operators to strengthen their cyber defenses.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, UK Airport Operator MAG)

88 ID Verification Breaches Show the Cost of Collecting Identity Data

88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data.

A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records, with attacker and seller claims piling another 4.54 billion on top of that.

The most uncomfortable number in the whole dataset isn’t the total record count, it’s how much of it can’t be fixed after the fact. In 41 of the 88 incidents, what actually leaked included the source documents themselves: ID scans, verification selfies, fingerprints, full biometric templates. A password gets reset in thirty seconds. A face doesn’t.

The timing makes the report especially concerning. Of the 88 incidents, 37, or 42%, happened between January 2024 and August 2026, when mandatory identity and age checks were spreading quickly around the world. The message is simple: the systems that collect your ID can be breached just like any other online service.

“The pattern of this era is specific: the wall you are forced to hand your ID to is exactly as breachable as everything else on the internet.” reads the report.

Some recent cases are particularly worrying. The Tea app, created as a women-only safety platform, exposed verification selfies through an open storage bucket, and the images later appeared on 4chan. Discord users who challenged age-verification decisions also had around 70,000 government IDs exposed through a third-party support provider, even as Discord continued expanding age checks.

What makes this particularly damning is who’s actually running the verification layer for the internet’s biggest platforms. AU10TIX, which verifies identity for TikTok, Uber, and X, left admin credentials exposed for over a year. Sumsub disclosed a support-system intrusion that went undetected for 18 months. Persona, which handles age verification for Discord and Roblox, exposed its own frontend configuration.

“In 41 of the 88 incidents, what leaked included the actual documents: ID scans, verification selfies, fingerprints, biometric templates. Unlike a password, none of that can be changed.” states the report. “Every major identity-verification vendor from the current era — AU10TIX, IDMerit, Sumsub, Persona, inVOID — has appeared in this timeline. The companies the internet now relies on to hold everyone’s identity documents safely haven’t demonstrated they can do it.”

Governments haven’t fared any better with their own centralized registries. Argentina’s national identity system leaked 45 million records including ID scans and selfies. France’s ANTS, the agency that literally issues French identity documents, confirmed 11.7 million people affected in a 2026 breach. India’s Aadhaar system, Thailand’s visitor database, the Philippines’ voter rolls, Brazil’s tax registry, the pattern repeats at country scale roughly as often as it does at startup scale.

The report isn’t blaming one company or one mistake. Its main point is that the growing use of ID and age checks is creating more opportunities for sensitive data to be exposed.

Every new law that requires ID checks, every platform that adds age verification, and every company that stores identity data creates another valuable target. Putting permanent and highly sensitive information into systems with different levels of security creates a risk that’s hard to ignore.

This doesn’t mean ID and age verification have no value. They can serve legitimate purposes. But companies deciding whether to build or outsource these systems should study this history carefully. Relying on a “reputable” third-party provider clearly isn’t enough.

“The timeline makes something visible that individual breach reports obscure: this isn’t a series of unrelated failures. It’s one failure mode, repeated across 88 incidents, fifteen years, and every type of organization that has ever decided to collect this category of data.” concludes the report. “What varies is the victim. Sometimes, it’s a startup with inadequate security. Sometimes, it’s a national government that built a country-scale identity registry and watched it walk out the door. Sometimes, it’s a verification vendor that became the single point of failure for a dozen companies that outsourced their compliance obligations to them. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ID Verification Breaches)

Cybercriminals Turn GTA VI Leaks Into Malware Bait

A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload.

GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the team” and test a 113GB file claiming to be a playable Grand Theft Auto VI build, according to Tom’s Hardware’s reporting. Someone did, and the results were exactly what you’d expect.

A user that goes online with the handler @Aidas29506493 analyzed the file and found that it was completely fake and contained malware. Almost all of its 113GB consisted of empty data, with a tiny malicious payload hidden inside.

did some reverse engineering.
it is fully fake and full of viruses pic.twitter.com/An6VnSNTkd

— Aidas (@Aidas29506493) August 22, 2026

“The decompiled bytecode literally contains commands to whitelist the entire C:\ drive in Windows Defender (powershell Add-MpPreference -ExclusionPath %SystemDrive%\) and kill security software (taskkill -f),” The researcher added in a post on X. They also added in another response, “It’s not 100 GB of actual code—it’s just a tiny 50 KB virus padded with 99.99% empty junk (literally endless zeroes).”

It’s not 100 GB of actual code—it’s just a tiny 50 KB virus padded with 99.99% empty junk (literally endless zeroes).

— Aidas (@Aidas29506493) August 22, 2026

The malware became obvious when researchers examined its code. It included commands to exclude the entire C: drive from Windows Defender and shut down other security software. Anyone who ran it could effectively disable their antivirus before the malware launched its next stage. This was not an accidental side effect, it was a deliberate step to prepare the system for further attacks.

This particular fake didn’t appear in a vacuum. According to to the website IGN, that fake GTA 6 downloads have flooded piracy and torrent sites throughout the recent leak wave, riding genuine momentum from a leaker going by CyberLeek, who’s been releasing real gameplay clips and map footage in protest of Rockstar’s digital pre-order plans. That real leak activity is exactly what makes the fake downloads believable, since fans searching for CyberLeek’s actual content are primed to trust whatever else shows up alongside it.

Every time GTA 6 appears in the news because of leaked footage, people quickly share it across Discord, mirror sites and other platforms. This creates the perfect conditions to trick users with fake downloads and phishing pages. With real and fake content mixed together, it becomes harder for users to tell what is safe.

The scams go beyond huge fake game files. Researchers have found fake GTA 6 websites offering Windows installers that use DLL side-loading to run malware. They also found a fake “GTA 6 Mobile” app that redirects users to a domain linked to infostealers and ransomware. Other fake Rockstar Social Club login pages try to steal users’ account credentials.

None of this should be surprising given the numbers involved. Kaspersky separately documented over 19 million attempted downloads of malware disguised as popular game titles across a single year, with GTA, Minecraft, and Call of Duty topping the list of abused brands specifically because of their large, dedicated communities. Big anticipated titles are a magnet for this stuff regardless of whether there’s an active leak cycle happening, and GTA VI right now has both the hype and the leak chaos simultaneously.

There is no legitimate playable build of GTA VI circulating anywhere, full stop. The game launches November 19 on consoles, with a PC version to follow, and the only responsible move for anyone tempted by a torrent claiming otherwise is to close the tab. If the file looks too good to be true and it’s a hundred gigabytes of an unreleased AAA game showing up on a torrent site months early, it’s not a leak, it’s bait.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, GTA VI Leaks)

Hackers Expose Data of 1.2 Million Heights Finance Customers

A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform.

Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance Holdings Co.

Heights Finance Holdings is notifying more than 1.2 million people that on May 7, 2026, Heights Finance discovered unauthorized access to a third-party cloud platform storing customer data. The company launched an investigation with external cybersecurity experts and notified federal law enforcement.

“On May 7, 2026, Heights discovered that an unauthorized actor gained access to a cloud-based platform hosted by a third party that we use to store certain customer data. This activity was limited to the cloud-based platform only—it did not affect any of our loan management systems or other computer systems or networks. We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement.” reads the notice of data breach.

“We have since confirmed that the cloud-based platform is secure and that there is no ongoing security threat. Our operations were not impacted by this incident and have continued safely and securely.”

Heights said its internal systems and operations were not affected, the platform has been secured, and there is no ongoing threat.

The compromised customer information included contact details, financial and bank account data, government IDs and dates of birth. The affected data varies by person and may involve Heights Finance customers, loan applicants, people who inquired about its products, or former borrowers of Curo Management and related brands.

Heights Finance is offering affected individuals 24 months of free credit monitoring and identity protection. The company said dark web monitoring has found no evidence that the stolen data has been published.

No threat actor has claimed responsibility, and no known ransomware or extortion group has been linked to the breach so far.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Heights Finance)

SafePal Says 39,798 Customers Hit by Data Breach

SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information.

SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed information linked to orders placed between March 2, 2025, and April 11, 2026, including names, addresses, email addresses, phone numbers and order details.

“Recently, the team identified an authorization flaw in the order-tracking function for a plug-in associated with customer order information. Under certain conditions, the flaw allowed unauthorized access to another customer’s order information.” reads the notice published by the company. “We are extremely sorry to inform the community that order information for customers who placed orders between March 2, 2025 and April 11, 2026. Information including name, email address, shipping address, phone number, and purchase details, was accessed externally without authorization due to the flaw. The affected data involves approximately 39,798 customers.”

SafePal is a Singapore-based company focused on cryptocurrency security. It develops hardware and software wallets that let users securely store and manage digital assets. Its products include hardware wallets, a mobile app and browser-based tools supporting multiple blockchains and cryptocurrencies.

The disclosure came as a threat actor began advertising the stolen data on a cybercrime forum, claiming the same number of affected customers.

SafePal confirmed the security breach incident, while warning users about the exposure of their personal and order-related information.

The company said all affected customers were notified individually by email on August 16 and urged them to check their status. The exposed order data could enable more convincing phishing attempts, including fake support calls, emails, refund offers, firmware updates or malicious websites designed to steal additional information.

SafePal stressed that seed phrases, private keys and wallet passwords were not exposed, so customers do not need to move their assets solely because of the breach. However, anyone who has shared a seed phrase or private key with an attacker should consider the wallet compromised, create a new one using a trusted device or official app, and immediately transfer the remaining funds.

The crypto firm said the breach did not expose seed phrases, private keys, wallet passwords or other wallet credentials. Bank details, payment card numbers and government IDs were also not involved. The company pointed out it does not collect or store such information and found no evidence that the incident compromised access to customer wallets or funds.

“However, if you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised.” continyes the notice. “Create a new wallet using a trusted SafePal device or official SafePal application, and move your remaining assets to the new wallet immediately. Lastly, contact SafePal through our official support channel.”

SafePal said it has fixed the vulnerability and added further security measures, with an independent security firm reviewing the fix and order-processing systems. The company also reduced data retention to 90 days, contacted affected customers and logistics partners, and opened a dedicated support channel.

The firm identified more than 30 fraudulent websites and phishing links and removed them. It will continue monitoring scams, investigating potential risks and sharing updates through its official channels.

SafePal urges customers who suffered financial losses linked to the breach to contact the company, which is working with specialists to trace stolen on-chain assets.

“For more FAQs and details, we will keep updating the dedicated webpage for this incident.” concludes the notice.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SafePal)

McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen

A seller claims 1.7M McDonald’s employee records were stolen from Azure. An 8,000-row sample appears genuine, but its age and full size remain unconfirmed.

A seller on a data-trading forum posted an 8,000-row sample this week claiming it came from McDonald’s own Azure tenant, part of a supposed 1.7 million-record employee directory obtained using stolen credentials. Ransomnews’s technical breakdown found the sample holds up as genuine on every test that can be run against it. What it can’t confirm, notably, is exactly how old the data is or whether the full 1.7 million figure is real.

“The listing is a straightforward private sale, posted at 4:08 AM forum time under the title “McDonalds 1.7M+ Azure Internal Employee Dump”. The seller, an account called TheHatman, writes that the data was “downloaded directly from Azure Tenant using compromised credentials” and that it contains “employee accounts, service accounts, and other tenant account records”. No price is named. Buyers are invited to make offers.” reads the report published by Ransomnews.

“To evidence the claim, the seller attached a free 8,000-record sample. That file is the entire basis for what follows. Ransomnews analysed it offline. We did not access, probe or authenticate against any McDonald’s system, and we have redacted the sample’s download location from the screenshot below because it still resolves to real people’s contact details.”

The file’s structure gives away exactly what it is before you even read a single row. Column names like FacsimileTelephoneNumber and PhysicalDeliveryOfficeName aren’t something anyone invents; they’re the exact property names Microsoft’s own PowerShell directory tools return when an administrator exports a user list from Entra ID, the modern name for Azure Active Directory. Whoever produced this file ran a standard Microsoft export command and saved the output, nothing more exotic than that.

Every one of the 50 email domains found in the sample is genuinely McDonald’s-controlled, spanning corporate staff, restaurant crew accounts, franchisee logins, and vendor guest access across more than thirty countries. Three rows even carry the tenant’s own built-in Microsoft address, mcdonaldscorp.onmicrosoft.com, something that’s invisible from outside the organization and simply isn’t guessable or scrapeable.

Add in 233 rows with the exact kind of garbled text encoding that happens when someone forgets to specify UTF-8 during an export, plus 85 job titles cut off at precisely 30 characters mid-word, the unmistakable fingerprint of a fixed-width HR system field bleeding into the directory, and you get a picture consistent with a real export rather than something assembled from public sources.

The file is broken in the ways real exports are broken. 233 rows contain mangled characters: Königswinter appears as “Königswinter”, München as “München”, and Ukrainian job titles are rendered as unreadable strings of Cyrillic run through the wrong character set. This is what happens when somebody runs Export-Csv without specifying UTF-8 encoding.” continues the report. “It’s a mistake, and it is not the kind of mistake anybody makes on purpose. A fabricated dataset doesn’t come with authentic encoding damage.”

One detail actually reaches outside the file entirely. A restaurant entry for “556 Upton” on Upton By-Pass in Wirral, complete with phone number, matches a real, publicly listed McDonald’s location down to the digit. That’s a small anchor, but it’s the kind of anchor fabricated data doesn’t usually survive contact with.

What the sample genuinely can’t settle is timing. There isn’t a single date field anywhere in the schema, no creation date, no last login, nothing to age a row by. “We can say with confidence that the data came out of McDonald’s directory. We cannot say from the file alone when it came out.” The best clue available is McDonald’s own market footprint: no Russian records at all, consistent with the company’s 2022 exit, and no Kazakh ones either, which points to sometime in 2023 or later, a wide window rather than a firm date.

The 1.7 million headline number also isn’t something 8,000 rows can verify. That sample is under half a percent of the claim, and while nothing in it looks implausible given McDonald’s global workforce size, plausible isn’t the same thing as confirmed. A seller running a volume trade across multiple companies has every incentive to round the number up in the listing title.

This McDonald’s post wasn’t an isolated event either. The same account, going by TheHatman, posted nine listings in total over sixteen days, claiming roughly 3.6 million records combined across McDonald’s, Vodafone, Gap, two hotel chains, and four major IT outsourcing firms including Kyndryl and Tata Consultancy Services.

Every listing uses an identical 19-column schema and nearly identical wording, the kind of consistency you get from one person running the same export script against whatever tenant they currently hold a working login for, not from someone fabricating nine separate datasets by hand.

That pattern points toward something fairly mundane and fairly common: infostealer malware harvesting saved credentials at scale, feeding a resale market that lets one operator walk into tenant after tenant using logins nobody bothered to protect with multi-factor authentication. Reading an entire company directory doesn’t require a sophisticated intrusion; it requires one working account in a tenant that hasn’t restricted user enumeration, which is Entra ID’s default setting unless an administrator has explicitly locked it down.

For anyone at McDonald’s or one of the other eight listed companies, the real risk here isn’t account takeover, since there are no passwords or hashes in the sample at all. It’s social engineering: full names, job titles, direct phone numbers, and internal email formats are more than enough to make a fake helpdesk call or a fraudulent invoice sound completely legitimate. Treat unsolicited contact that already knows your role and your location with more suspicion than usual, because that’s precisely the kind of detail this file was built to hand someone.

“For individuals named in the data, there is no action that removes the exposure.” concludes the report.”The realistic response is scepticism about unsolicited contact that arrives already knowing your role and your store, and a refusal to act on instructions that arrive by phone or email without out-of-band confirmation.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, McDonald’s)

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM

ShieldBreak – August 2026 disclosure  

Kimwolf v7: An Evolution of the Kimwolf Botnet 

CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors 

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers  

Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme  

PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection  

Concept Drift Detection and Adaptive Retraining of Malware Classification Models

A Comparison of Malware Image Transformations Using Grad-CAM and Hybrid Learning Models

C-GUARD: Context-Adaptive Conformal Gating for Improving Robustness Against Evasive Windows PE Malware

An Explainable Deep Learning Pipeline for Malware Family Classification: GAF Image Encoding and API-Grounded LLM Interpretation

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack.

A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit of the Paris Public Prosecutor’s Office has opened a probe and handed it to OFAC, France’s dedicated cybercrime fighting office. Tax officials described the attack as more sophisticated than anything they’d faced before.

“The attack allowed hackers to extract data relating to 678,000 users of France’s tax system, including both private individuals and companies.” reports French media RFI. “Tax authorities said the incident was more complex than cyberattacks they had faced in the past, potentially renewing concerns over the security of government information systems following a series of recent breaches involving other public bodies.”

The Directorate-General for Public Finances (DGFiP) stressed that the stolen data doesn’t grant access to taxpayers’ secure accounts on impots.gouv.fr. That’s a meaningful distinction, but income figures, tax rates, and family circumstances are exactly what an attacker needs to make a phishing email or phone call sound credible enough to extract a password or bank account number.

“Officials said those affected would be contacted from early next week, with particular emphasis on alerting them to the potential risk of identity theft and fraudulent attempts to obtain further personal information.” continues RFI.

French authorities did not disclose technical details about the cyberattack or its motivation.

The breach follows recent attacks on systems linked to ANTS, the national secure documents agency, and INSEE, France’s statistics authority. Three government bodies hit in quick succession is a pattern, not a coincidence.

For businesses, the exposed data was considered less sensitive, SIREN registration numbers, business addresses, and the address of the authorized representative. Public Accounts Minister David Amiel has asked the DGFiP to start notifying affected taxpayers from Monday and requested proposals on how to strengthen security procedures.

Investigators still need to establish how the attackers got in, who they are, and whether the data has already been sold or used. Anyone contacted about this breach should treat follow-up requests for passwords or banking information as fraudulent regardless of how official they sound.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, France’s tax agency)

❌