Visualização de leitura

Kentucky Appellate Court Data Caught in Multi-State Cyber Data Breach

Kentucky Appellate Court Data

The Kentucky Administrative Office of the Courts (AOC) has confirmed that Kentucky Appellate Court data was compromised in a cybersecurity breach traced to a third-party vendor. West Publishing Corporation, operating as Thomson Reuters Court Management Solutions (Thomson Reuters CMS), informed the AOC that the incident originated within file systems tied to its C-Track case management platform.  C-Track is the system relied upon by the Kentucky Supreme Court and the Kentucky Court of Appeals to manage case records. Because Kentucky does not currently use third-party vendors for trial court e-filing, trial-level records that were never part of an appeal remain unaffected. The exposure is limited to Kentucky Appellate Court data that had been stored within Thomson Reuters CMS/C-Track infrastructure.  According to Thomson Reuters CMS, an unauthorized third party gained access to and obtained court data from C-Track systems across several states, not Kentucky alone. The AOC noted that Kentucky's Appellate Courts continued to function normally throughout the incident and were not operationally disrupted. 

The Kentucky Appellate Court Data Breach Incident  

The AOC said it currently has no indication that the unauthorized party shared or distributed Kentucky's data with any outside individual or entity. Thomson Reuters CMS has stated it is coordinating with third-party cybersecurity specialists and law enforcement, and has assured every affected jurisdiction, including Kentucky, that mitigation measures have been implemented to reduce the risk of future unauthorized access.  Any individuals ultimately confirmed to be affected by the data breach will be contacted directly by Thomson Reuters CMS. Those notified will receive additional details about the incident along with 12 months of complimentary credit monitoring and identity theft protection, funded by the company. 

Scope of Impact Still Under Review 

Thomson Reuters CMS is currently working through each affected court system individually, reviewing what data was exposed and determining which people or organizations warrant notification. The company has indicated this review will take time given the multi-state scope of the breach.  The AOC, however, has pressed for a faster timeline, telling Thomson Reuters CMS that it expects prompt resolution and swift notification to anyone impacted. As of now, the total number of individuals or organizations affected — if any — has not been determined. Thomson Reuters CMS has committed to covering all costs associated with the breach and will handle notification once affected parties are identified. 

AOC Response and Oversight 

The AOC emphasized that safeguarding information entrusted to Kentucky's Judicial Branch remains a core responsibility. As the investigation proceeds, the office says it is closely tracking developments, evaluating any potential consequences for the Judicial Branch, and following its established cybersecurity protocols to protect the appellate case management system tied to the Kentucky Supreme Court and Court of Appeals.  The AOC is also taking part in ongoing status briefings with the National Center for State Courts and is coordinating with officials in other states affected by the same Thomson Reuters CMS/C-Track breach, as the response to this data breach continues to unfold on a multi-jurisdictional scale. 

678,000 People Hit in French Tax Authority Data Breach

DGFiP cyberattack

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate access to the French tax authority's information system on August 12 and 13. DGFiP said the intrusions involved the usurpation of identifiers belonging to a DGFiP agent and an authorized third party.

DGFiP Cyberattack Exposed Taxpayer Information

After detecting the intrusions, DGFiP immediately suspended access to the accounts involved. Initial access controls did not identify data theft, which the authority attributed to the sophistication of the attack. A subsequent investigation established that the compromised access points had been used to consult and extract information concerning 678,000 individuals and professionals. The exposed information included reference tax income, family quotient and withholding tax rate for individuals. For businesses, the accessed information included company names and SIREN numbers. Cadastral data, including addresses and property sizes, was also accessed. DGFiP said online accounts belonging to individual and professional users were not compromised, and user IDs and passwords were not affected. The authority notified France's data protection regulator, CNIL, after identifying the data breaches.

Cadastral Data Leak Claim Targets DGFiP

Separately, a hacker using the alias ZeroBytes claimed an attack against DGFiP's Professional Cadastral Data Server (SPDC). According to the claim cited by FrenchBreaches, the alleged extraction contains 252,149 lines of data representing 2,041,778 people, with multiple holders potentially associated with the same property plot. The claimed dataset reportedly includes names, surnames, sex, dates and places of birth, addresses, land identifiers, cadastral sections and parcel numbers, as well as information about rights held on properties. The claim would therefore link individuals to personal information and real estate assets. However, the figures and technical details in this second claim remain allegations by the cybercriminal. The claim that the system could contain information relating to approximately 20 million citizens is also an estimate made by ZeroBytes and does not establish that this number of people was affected.

Investigation Into French Tax Authority Attack Continues

DGFiP said additional security measures were implemented after investigators uncovered new information. These included preventative shutdowns of access to sensitive information systems. Investigations remain underway to determine the precise nature and volume of data extracted and the number of users affected. DGFiP teams are working with France's economic and financial ministries, the High Official for Defence and Security and the National Agency for Information Systems Security, ANSSI. The authority said it will contact affected individuals and professionals directly from the following week by email or letter. Those notifications will identify the information that may have been accessed or extracted and outline any precautionary measures where applicable. DGFiP also said it will file a complaint and provide further information as the investigation progresses. The separate cadastral data breach claim remains subject to confirmation, including the alleged number of affected people, duration of access, methods used to bypass authentication, the full scope of extracted information and whether access remained active when the claim was published. The confirmed DGFiP investigation and the separate ZeroBytes claim therefore present different sets of figures and allegations, with the full scope of the incidents still being determined.

The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threats

The Cyber Express weekly roundup July 2026

This week’s cybersecurity landscape highlights the continued expansion of cyber risks across governments, businesses, and consumers. From ransomware campaigns targeting organizations worldwide to credential-based attacks, data breaches, online fraud, and digital piracy crackdowns, recent incidents show how threat actors are exploiting both technical vulnerabilities and human behavior.  The latest developments underline the need for stronger security practices, including improved identity protection, faster incident response, and greater awareness of evolving cyber threats. Organizations are increasingly dealing with attacks that go beyond data theft, affecting operations, customer trust, and critical services. 

The Cyber Express Weekly Roundup 

U.S. Accounts for Nearly Half of Global Ransomware Attacks in H1 2026 

The United States experienced 1,721 ransomware attacks during the first half of 2026, representing nearly 45% of all incidents tracked globally, according to research from Cyble Research and Intelligence Labs (CRIL). The report identified ransomware groups Qilin and Akira as among the most active threat actors during the period. Read more... 

Dubai Police Warns Against Online Visa Fraud Schemes 

Dubai Police has issued a warning about fraudulent online advertisements offering work, residency, and visit visas in exchange for payment. Scammers have reportedly used social media platforms and messaging applications to impersonate government entities or unauthorized service providers to trick victims. Read more... 

Craneware Data Breach Exposes Employee and Customer Information 

Healthcare technology company Craneware confirmed that unauthorized individuals accessed part of its data environment, resulting in the exposure of employee information as well as some customer and partner records. The company stated that the incident has been contained and has not disrupted business operations or customer services. Read more...  

U.S. Targets Illegal FIFA World Cup Streaming Networks 

The U.S. Department of Justice seized more than 1,000 domains allegedly involved in illegally streaming FIFA World Cup 2026 matches. The action was carried out under Operation Offsides, an initiative focused on combating online piracy and protecting intellectual property rights. Read more... 

Chick-fil-A Customer Accounts Targeted in Credential Attack 

Chick-fil-A confirmed that certain customer accounts were accessed during an automated credential-stuffing attack between June 17 and June 19, 2026. The attackers used account credentials obtained from an external source to gain unauthorized access. The company said affected information may have included customer names, email addresses, membership details, and limited payment-related data. Read more... 

South Korea Diplomatic System Breach Lasted Nearly 10 Months 

South Korea’s Ministry of Foreign Affairs revealed that attackers maintained access to the National Diplomatic Academy’s online education system for almost 10 months. The breach, which began in April 2025, exposed information linked to thousands of current and former ministry employees. Compromised data included user IDs, names, email addresses, and encrypted passwords. Read more... 

Weekly Cybersecurity Takeaway 

The week’s incidents demonstrate how cyber threats continue to evolve across multiple areas, from ransomware and account compromise to online scams and government-related breaches. Attackers are increasingly targeting weaknesses in identity management, user behavior, and digital infrastructure.  Organizations and individuals must focus on proactive security measures, including stronger authentication controls, regular monitoring, timely updates, and greater awareness of social engineering tactics. As cyber threats become more widespread and interconnected, improving resilience remains essential for protecting data, services, and public trust. 

Novo Nordisk IT Security Incident Exposes Limited Patient and HCP Data

Novo Nordisk IT Security Incident

The Novo Nordisk IT Security Incident has resulted in unauthorized access to a limited number of the pharmaceutical company's internal IT systems, leading to the exposure of certain non-public information, including personal data related to clinical trial participants and healthcare professionals. The Denmark-based healthcare company confirmed that an investigation is underway with support from external cybersecurity experts and relevant authorities. According to Novo Nordisk, certain data was copied externally without authorization during the incident. In response, the company temporarily took some internal systems offline and is gradually restoring affected environments in a controlled manner. The company stated that its core business operations remain unaffected.

Novo Nordisk IT Security Incident Under Investigation

Novo Nordisk disclosed that it identified unauthorized access to a limited number of internal IT systems and immediately launched an investigation into the matter. The company said multiple security measures were implemented following the discovery, including taking selected systems offline to protect its environment. While recovery efforts continue, Novo Nordisk emphasized that business operations remain operational and that the delivery of products and support to patients has not been disrupted. "As part of our response, multiple security measures have been taken, including temporarily taking certain internal IT systems offline to protect our environment. We are working to bring the affected systems back online in a controlled and safe manner; however, we acknowledge this process takes time," reads the official statement. Novo Nordisk IT Security Incident Exposes Limited Patient and HCP Data The healthcare company also confirmed that non-public data, including personal information, was copied externally without authorization. Impacted parties are being notified as appropriate.

Patient Data Included Clinical Trial Information

Information provided by Novo Nordisk to affected patients shows that the exposed data involved a limited amount of information related to participants in certain clinical trials. The affected categories of personal data may include:
  • Patient ID and information on trial participation
  • Sex
  • Year of birth
  • Biomarkers
  • Health and immunogenicity data
  • Lifestyle factors, including smoking, alcohol use, and BMI
The company stated that the exposed information was pseudonymized and not directly linked to patient names or other direct identifiers. According to Novo Nordisk, identifying individual patients would require access to additional information that was not exposed during the incident. As a result, the company said it does not believe the incident presents any immediate risk to affected patients. However, patients have been advised to remain vigilant and report any unusual activity that may be connected to the breach.

Healthcare Professional Data Also Affected

Novo Nordisk also issued separate notifications to affected healthcare professionals, confirming that a limited amount of Healthcare Professional (HCP) Data had been copied as part of the incident. The categories of affected information include:
  • Name and registration number
  • Email address
  • Phone number
  • WhatsApp details
  • Office location
The company warned that the exposure of this information could increase the risk of Phishing Attacks, fraudulent communications, and impersonation attempts targeting healthcare professionals through email, phone calls, or messaging applications. Affected individuals have been advised to remain cautious when responding to unexpected communications and to report suspicious activity.

Response and Recovery Efforts Continue

Following the discovery of the Data Breach, Novo Nordisk engaged cybersecurity experts to assist with investigation and remediation efforts. The company said it has implemented additional security measures and is working to restore affected systems safely. While acknowledging that the recovery process may take time, Novo Nordisk reiterated that protecting the security and integrity of systems used by employees, customers, patients, and stakeholders remains a top priority. The organization stated that there is no need for affected patients or healthcare professionals to take any specific action as a direct result of the incident beyond remaining alert to unusual communications. Novo Nordisk, founded in 1923 and headquartered in Denmark, employs approximately 67,900 people across 80 countries and markets its products in around 170 countries worldwide. The Cyber Express Team has reached out to Novo Nordisk for additional information regarding the incident, including the scope of affected records and the nature of the unauthorized access. However, the company had not responded at the time of publication.

UK Biobank Leak Prompts Urgent Review of Data Protection in Biomedical Research

UK Biobank data breach

The UK Biobank data breach has intensified scrutiny around the handling and protection of sensitive health information, even when such data is stripped of personally identifiable details. Widely regarded as one of the most significant biomedical research resources in the world, UK Biobank holds extensive genetic, lifestyle, and medical data contributed by around 500,000 volunteers.   The recent data breach at UK Biobank, which involved the unauthorized listing of participant data for sale on a Chinese consumer website linked to Alibaba, has sparked concern among participants, researchers, and cybersecurity experts alike. 

The UK Biobank Data Breach 

The data breach at UK Biobank came to light in April 2026, when officials discovered that de-identified data belonging to participants had been listed for sale online. The listings appeared on a consumer platform owned by Alibaba, sparking immediate concern among researchers and participants alike.  UK Biobank, a biomedical database established in 2003, contains extensive genetic, lifestyle, and health data from around 500,000 UK volunteers. This dataset has been a cornerstone for global medical research, contributing to thousands of discoveries since access was opened to scientists in 2012.  Professor Sir Rory Collins, chief executive and principal investigator of UK Biobank, confirmed the breach in an official statement. He said, “Last week, we found that de-identified participant data made available to researchers at three academic institutions were listed for sale on a consumer website in China, owned by Alibaba.”  He added that with support from UK and Chinese authorities, Alibaba “swiftly removed those listings before any sales were made.” 

Nature of the Exposed Data 

Despite the seriousness of the UK Biobank data breach, officials stressed that the compromised information did not include personally identifiable details. According to Collins, the dataset did not contain names, addresses, dates of birth, or NHS numbers.  “All the data are de-identified,” he said, emphasising that there is no evidence that participants were directly identified as a result of the breach.  However, the incident still represents a violation of strict data access agreements. The data had been shared with three academic institutions under contracts that require secure handling and prohibit unauthorized distribution. Collins described the situation as “a clear breach of the contract,” noting that the institutions and individuals involved have had their access suspended. 

Immediate Response to the Data Breach at UK Biobank 

In response to the data breach at UK Biobank, the organization moved quickly to contain the risk and reassure participants. Access to its research platform has been temporarily suspended while new protection methods are implemented.  Among the measures introduced: 
  • Strict limits on the size of files that researchers can export  
  • Daily monitoring of all exported files for suspicious activity  
  • A comprehensive, board-led forensic investigation  
“These security measures will further minimise the potential for misuse of UK Biobank data,” Collins said.  Researchers typically access the data through a restricted, cloud-based platform hosted in the UK. The system is designed to ensure that sensitive information remains secure while still enabling scientific discovery. Following the breach, additional controls are being layered onto this infrastructure. 
❌