Visualização de leitura

Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ

Mathspace data breach

The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.  The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentication credentials were not. There is currently no evidence that the information has been published, sold, distributed, or otherwise misused. The attacker’s identity remains unknown. 

How the Mathspace Data Breach Happened? 

The security incident resulted from a vulnerability in Mathspace’s self-hosted Metabase installation, which was used for internal reporting. The flaw allowed attackers to obtain administrator access without a legitimate login.  Metabase issued a critical security advisory and patched versions on August 6. Mathspace said its vulnerability-notification process failed to identify and escalate that advisory. The company later updated its Metabase instance on August 29 after seeing a subsequent notice.  An investigation found unauthorized access dating to August 10, Australian Eastern Standard Time. Information was downloaded from Mathspace’s Australian reporting database on August 27. Historical log reviews confirmed the unauthorized access on September 3, before the update had been applied. Mathspace also acknowledged that it did not complete additional compromise checks recommended for potentially affected systems at the time of the update. 

What Information was Exposed? 

The exported data included user IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date and joining date. Not every field appeared for every affected person.  Mathspace said the exposure went beyond names and email addresses. User IDs are internal identifiers, including those linked to student accounts. However, no academic records, learning activities, results, assessments, password hashes, authentication tokens, SSO credentials or API credentials were exposed.  The data did not contain records directly linking accounts to schools, although Mathspace said school affiliations could potentially be inferred where identifiable email domains were used. Former or inactive users may also be affected because retained information could remain in the reporting database. 

What Users Should Know After the Security Incident? 

Names, email addresses, and account details could make phishing or impersonation attempts more convincing. Users have been advised to independently verify unexpected messages, avoid unfamiliar links and attachments, and never provide passwords or verification codes in response to unsolicited communications.  Mathspace is not requiring password resets because customer authentication credentials were not exposed. However, anyone who reused a Mathspace password elsewhere should change those reused passwords to unique ones and monitor accounts for unusual activity. 

Response to the Mathspace Data Breach 

After confirming the breach on September 3, Mathspace took Metabase offline, revoked its API keys, disabled Metabase database-access accounts in its Australian and US Snowflake environments, and changed passwords for its Metabase Cloud SQL databases. The company also copied the application database and exported access logs for investigation. Metabase remains offline while recovery and compromise checks continue.  Mathspace began notifying school contacts on September 4 and started notifying affected individuals on September 6, earlier than the date previously communicated to schools.  On September 4, the security incident was reported to Australia’s Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian Cyber Security Centre, New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre, as well as Australian state and territory education departments. 

Kentucky Appellate Court Data Caught in Multi-State Cyber Data Breach

Kentucky Appellate Court Data

The Kentucky Administrative Office of the Courts (AOC) has confirmed that Kentucky Appellate Court data was compromised in a cybersecurity breach traced to a third-party vendor. West Publishing Corporation, operating as Thomson Reuters Court Management Solutions (Thomson Reuters CMS), informed the AOC that the incident originated within file systems tied to its C-Track case management platform.  C-Track is the system relied upon by the Kentucky Supreme Court and the Kentucky Court of Appeals to manage case records. Because Kentucky does not currently use third-party vendors for trial court e-filing, trial-level records that were never part of an appeal remain unaffected. The exposure is limited to Kentucky Appellate Court data that had been stored within Thomson Reuters CMS/C-Track infrastructure.  According to Thomson Reuters CMS, an unauthorized third party gained access to and obtained court data from C-Track systems across several states, not Kentucky alone. The AOC noted that Kentucky's Appellate Courts continued to function normally throughout the incident and were not operationally disrupted. 

The Kentucky Appellate Court Data Breach Incident  

The AOC said it currently has no indication that the unauthorized party shared or distributed Kentucky's data with any outside individual or entity. Thomson Reuters CMS has stated it is coordinating with third-party cybersecurity specialists and law enforcement, and has assured every affected jurisdiction, including Kentucky, that mitigation measures have been implemented to reduce the risk of future unauthorized access.  Any individuals ultimately confirmed to be affected by the data breach will be contacted directly by Thomson Reuters CMS. Those notified will receive additional details about the incident along with 12 months of complimentary credit monitoring and identity theft protection, funded by the company. 

Scope of Impact Still Under Review 

Thomson Reuters CMS is currently working through each affected court system individually, reviewing what data was exposed and determining which people or organizations warrant notification. The company has indicated this review will take time given the multi-state scope of the breach.  The AOC, however, has pressed for a faster timeline, telling Thomson Reuters CMS that it expects prompt resolution and swift notification to anyone impacted. As of now, the total number of individuals or organizations affected — if any — has not been determined. Thomson Reuters CMS has committed to covering all costs associated with the breach and will handle notification once affected parties are identified. 

AOC Response and Oversight 

The AOC emphasized that safeguarding information entrusted to Kentucky's Judicial Branch remains a core responsibility. As the investigation proceeds, the office says it is closely tracking developments, evaluating any potential consequences for the Judicial Branch, and following its established cybersecurity protocols to protect the appellate case management system tied to the Kentucky Supreme Court and Court of Appeals.  The AOC is also taking part in ongoing status briefings with the National Center for State Courts and is coordinating with officials in other states affected by the same Thomson Reuters CMS/C-Track breach, as the response to this data breach continues to unfold on a multi-jurisdictional scale. 

DOJ Investigates Cyberattack Targeting Hundreds of Thousands of X Users

cyberattack on X users

A cyberattack on X users that targeted hundreds of thousands of accounts has prompted an investigation by the US Department of Justice (DOJ), with Attorney General Todd Blanche saying sophisticated cybercriminals attempted to exploit the platform's password-recovery system. The DOJ is working with Elon Musk's X, formerly known as Twitter, to identify those responsible for the attempted attack, according to Blanche's statement on Wednesday. The incident involved hundreds of thousands of X users and was disrupted before the targeted accounts could be captured, Blanche said.

Blanche Says DOJ Is Tracking Those Behind Cyberattack on X Users 

In a statement posted on X, Blanche described the incident as a password-recovery attack carried out by "sophisticated cyber criminals." He said X managed to disrupt the effort and prevent user accounts from being taken over.  Blanche wrote: 
This week, sophisticated cyber criminals attempted a password-recovery attack on hundreds of thousands of X users. X disrupted the attack to prevent user accounts from being captured. But, as we’ve shown, the Justice Department will stop at nothing in its pursuit of cyber fraudsters and scammers. We are working closely with @X to track down the criminals behind this week’s attack. There is no refuge for those that perpetrate their criminal schemes from behind computer screens." 
The attorney general did not disclose additional technical details about the cyberattack on X users, including how the attackers attempted to exploit the recovery system, whether any individual accounts were compromised, or where the suspected criminals were operating from.  The DOJ investigation is intended to identify those responsible for the attempted intrusion, with Blanche emphasizing that authorities would pursue individuals involved in cyber fraud and scams even when those activities are conducted remotely. 

How the Password-Recovery Attack Works 

A password-recovery attack generally targets the systems users rely on when they have forgotten their login credentials. These processes can include "forgot password" features, account-recovery forms, and other mechanisms designed to help legitimate users regain access to their accounts. Attackers may attempt to exploit weaknesses in those processes to obtain access to accounts. In the incident involving X, the platform was able to disrupt the effort before the targeted accounts were captured, according to Blanche. The scale of the attempted cyberattack on X users—hundreds of thousands of accounts—makes the incident notable, although the attorney general did not provide a breakdown of how many accounts were actually affected or whether any users suffered losses. 

AI-Driven Cyberattacks Add to Growing Security Concerns 

The X incident comes against a wider backdrop of increasing cybersecurity threats facing companies and organizations around the world.  Businesses have been dealing with a rise in AI-driven cyberattacks as well as ransomware campaigns capable of stealing sensitive information, interrupting operations, and creating significant financial and operational damage.  The growing use of artificial intelligence in cyber operations has raised concerns that attackers can automate or accelerate parts of their campaigns. At the same time, organizations are exploring ways to use AI-based systems to identify vulnerabilities and strengthen their defenses.  The DOJ has also been pursuing cases involving sophisticated cyber operations. Days before news of the cyberattack on X users, the department announced an operation targeting QTFY, described by US authorities as a Chinese cyberespionage platform. 

DOJ Previously Targeted QTFY Cyberespionage Platform 

According to the Justice Department, QTFY had targeted several US institutions and organizations. Those named by the department included the US Senate, the Federal Reserve, and NASA, among others.  The action against QTFY highlights the broader range of cyber threats confronting US institutions, from espionage operations to attacks aimed at obtaining access to online accounts.  The latest investigation involving X therefore comes amid a broader push by US authorities to identify and disrupt cyber criminals and state-linked cyber operations. 

The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown

The Cyber Express weekly roundup, podcast

This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement.   From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both technical systems and human trust.  The latest developments also show that cybersecurity risks are expanding alongside the rapid adoption of cloud services and artificial intelligence. Organizations are facing threats involving identity infrastructure, autonomous AI agents, software vulnerabilities, digital transactions, online fraud, and the misuse of emerging technologies. 

The Cyber Express Weekly Roundup 

Microsoft Confirms Exploited Entra ID Flaw 

Microsoft confirmed that a critical vulnerability in Entra ID, CVE-2026-69836, was exploited before the flaw was fixed server-side. The vulnerability carries a CVSS score of 10.0 and could allow unauthenticated attackers to achieve remote code execution, potentially affecting Microsoft’s cloud-based identity infrastructure. Read more... 

New Zealand Proposes Social Media Ban for Under-16s 

New Zealand has introduced legislation that would require high-risk social media platforms to prevent users under the age of 16 from accessing their services. Proposed age-verification methods could include digital identification, facial age estimation, or official identification documents. Read more... 

Cyble and DRONA Launch AI Cyber Defense Initiative in India 

Cyble and DRONA Cyber Solutions have launched an AI-powered cybersecurity initiative in Ahmedabad aimed at helping mid-sized businesses detect, investigate, and contain cyber threats. The initiative combines threat intelligence, AI-driven investigations, and endpoint enforcement to provide organizations with faster and more coordinated responses to security incidents. Read more... 

AI Agents Could Create New Cybersecurity Risks 

Adarsh Kant Sinha, CEO of ANVE.AI, warned that autonomous AI agents could introduce significant new cybersecurity risks as organizations increasingly allow them to interact with business-critical systems. AI agents may gain access to email, customer relationship management platforms, cloud infrastructure, and financial systems, potentially creating new avenues for misuse or compromise. Read more... 

Ledger Fixes Ethereum App Flaw Amid Disclosure Dispute 

Ledger said it fixed a clear-signing vulnerability in its Ethereum application approximately two weeks before security firm TestMachine publicly disclosed the issue. The vulnerability could potentially allow a malicious application to display one transaction to a user while preparing a different transaction for signing. Read more... 

Global Crackdown Nets 58 Arrests in West African Crime Networks 

An eight-month international law enforcement operation led by INTERPOL has resulted in 58 arrests and the identification of 263 suspects across 22 countries. Operation Jackal IV targeted West African criminal networks involved in cyber-enabled fraud, money laundering, romance scams, and investment scams. Read more... 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are crossing organizational, technological, and geographical boundaries, affecting cloud identity systems, artificial intelligence, digital platforms, cryptocurrency applications, and international financial crime.  Organizations should prioritize strong identity and access controls, rapid vulnerability remediation, careful management of AI-agent permissions, secure integrations, human oversight, and continuous threat monitoring.   As autonomous technologies become more deeply integrated into business operations and cybercriminal networks continue to operate across borders, security teams must adapt to a threat landscape that is becoming broader, more interconnected, and increasingly difficult to contain. 

The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw

The Cyber Express August 21 Weekly Roundup

This weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. The latest developments also show that cybersecurity risks are expanding beyond traditional attacks. Organizations are increasingly facing threats involving sensitive customer information, AI-powered systems, supply-chain risks, software vulnerabilities, and potential interference with critical operations.

The Cyber Express Weekly Roundup

French Tax Authority Data Breach Hits 678,000 People 

France’s tax authority, DGFiP, confirmed a cyberattack that exposed tax and cadastral information belonging to 678,000 individuals and professionals. The accessed information includes tax income, withholding rates, business details, addresses, and property information. DGFiP said online accounts and passwords were not compromised and is continuing to investigate the incident. Read more... 

Cyberattack Targets Ukraine Agency Ahead of Major Asset Tender 

Ukraine’s Asset Recovery and Management Agency (ARMA) suffered a suspected cyberattack shortly before a major deadline to select a manager for assets linked to sanctioned Russian oligarch Mikhail Fridman. ARMA said the incident, combined with earlier cyber activity and increased information pressure, could indicate a coordinated attempt to disrupt its operations or influence the tender. Read more... 

Oz Hair and Beauty Data Breach Exposes Customer Information 

Oz Hair and Beauty confirmed that an unauthorized party accessed customer information, including names, email addresses, phone numbers, and purchase history. The company said credit card, banking, and home-address information were not compromised. The number of affected customers remains undisclosed, while an investigation into the breach continues. Read more... 

Enterprise AI Is Expanding the Cybersecurity Risk 

Guild Group’s Mohammad Arif warned that the rapid adoption of enterprise AI is creating new cybersecurity challenges as AI systems gain access to sensitive data, applications, and business workflows. Key concerns include shadow AI, data leakage, insecure integrations, AI supply-chain attacks, prompt injection, and AI-powered phishingRead more... 

Critical GitLab Flaw Could Let Attackers Delete Public Projects 

GitLab patched a critical vulnerability, CVE-2026-19478, that could allow unauthenticated attackers to remotely modify or delete public projects and user data. The flaw carries a CVSS score of 9.4. GitLab also addressed a high-severity GraphQL CSRF vulnerability, CVE-2026-19650. Read more... 

Weekly Cybersecurity Takeaway 

This week’s incidents demonstrate that cybersecurity threats are increasingly crossing organizational and technological boundaries, affecting government systems, customer data, enterprise AI, and software development platforms. Organizations should prioritize strong access controls, rapid vulnerability patching, data protection, AI governance, employee awareness, and continuous monitoring. As attackers continue exploiting both human trust and technical weaknesses, security teams must adapt to a threat landscape that is becoming broader, faster, and increasingly interconnected.

Oz Hair and Beauty Data Breach Exposes Customer Information

Oz Hair and Beauty data breach

Oz Hair and Beauty has confirmed that customers’ personal information was accessed after an unauthorized third party briefly gained access to its online purchase and order platform. The company said the incident affected information connected to purchases made before August 2026. The potentially accessed data included customers’ full names, email addresses and/or mobile phone numbers, as well as purchase-history information such as transaction currency, total spending and broad location details, including city, state, country and postcode.

Oz Hair and Beauty Data Breach Involved Customer Information 

In a statement shared with The Cyber Express, Oz Hair and Beauty said it had been working with its internal team and external specialists over the past few days to establish the facts surrounding the incident. “We became aware of this and have been working with our internal team and external specialists to confirm all the facts over the last few days,” the company said. Oz Hair and Beauty confirmed that its website does not store credit card information. “The website does not store credit card information, so your payment details are completely safe,” the company said. The company also confirmed that banking details and home addresses had not been leaked. The company has not confirmed how many customers were affected.

Investigation Underway

Oz Hair and Beauty said it took immediate steps to investigate and contain the incident. The company commenced a forensic investigation with support from senior technical specialists from its cloud e-commerce platform provider. It is also reviewing and enhancing its cybersecurity posture and data retention policies to reduce the risk of similar incidents. The company said affected customers had been notified and that it was taking appropriate steps to support them. Oz Hair and Beauty is also preparing a full communication about the incident, which is currently being handled by its dedicated cyber team. “We want to make sure the right information goes out on something this important,” the company said.

Delay in Customer Notifications

Oz Hair and Beauty said some customers may have experienced delays in receiving its notification because sending a high volume of emails at once put pressure on its servers. The company apologized for the delay and asked customers who contact it directly to allow up to 48 hours for a response.

Customers Warned About Suspicious Communications

Oz Hair and Beauty has advised customers to remain alert for unusual phone calls or emails requesting personal information, payments or proof of identity. The company specifically warned customers to be cautious of: “any unusual communications by phone or email requesting information, payments or proof of identity.” Customers should avoid providing sensitive information in response to unsolicited requests and independently verify suspicious communications. The company has also advised customers who receive spam emails to use the relevant spam-reporting features provided by their email services.

Customers Can Continue Placing Orders

Oz Hair and Beauty has said customers can continue placing orders with the company. “You are safe to continue placing orders with us,” the company said. “We know this is unsettling and we appreciate you bearing with us while we work through it properly,” the company added.

UT San Antonio Shuts Systems, Delays Classes After Cyber Incident

UT San Antonio cyber incident

UT San Antonio cyber incident response efforts have prompted the university to delay the start of fall classes by three days, with the semester now scheduled to begin Monday, August 24. The university said the decision will give its teams additional time to restore technology systems and services following attempted unauthorized activity against its academic campus. The activity was detected over the weekend at the edge of the university's network. UT San Antonio said University Technology Solutions (UTS), working with expert partners, took immediate action to contain the activity and protect the campus technology environment.

UT San Antonio Cyber Incident Prompts Class Delay

The university said its investigation has found no evidence that university data was accessed or exfiltrated as a result of the activity. However, UT San Antonio proactively took some systems and services offline while teams evaluated the technology environment and reinforced security safeguards. The move temporarily disrupted access to several services, including connectivity and email. University President Taylor Eighmy said delaying classes until August 24 would allow teams to restore services carefully and ensure the systems students, faculty and staff rely on are operating properly at the beginning of the semester. University operations will continue as scheduled, with faculty and staff maintaining normal work schedules during the restoration process.

University Technology Systems Remain Under Review

The university technology systems affected by the response include connectivity, email and other essential services. UT San Antonio said restoring these services is being handled as a deliberate process while teams assess the environment and strengthen protections. The university's latest update on August 18 said its password reset system was experiencing delays, with further updates expected. The university also said its phone systems were temporarily unavailable, with service expected to return as technology services were restored. UT San Antonio said its technology teams and expert partners continue to work on restoring services and maintaining protections across the academic campus.

UT San Antonio Extends Student Deadlines

The technology disruption has also led UT San Antonio to adjust several deadlines and registration arrangements for Fall 2026. Thepayment deadline was extended to Friday, August 21 at 5 p.m. CT, giving students additional time to submit payments and allowing time for those payments to be processed. Waitlisting was scheduled to end Wednesday, August 19 at 8 a.m. CT. Students who received waitlist notifications to register on August 14 or 15 were automatically being re-added to the waitlist in their original order. Registration remains open, and students who can access their myUTSA Account can continue making changes to their Fall 2026 schedules. The university said One Stop will continue supporting students and providing updates as additional services become available.

Investigation Into Unauthorized Activity Continues

UT San Antonio said the attempted unauthorized activity was identified before reaching core systems. The university's response included taking systems offline as a precaution while its teams evaluated the environment and reinforced safeguards. The university has not disclosed additional details about the nature of the attempted unauthorized activity or identified those responsible. The investigation remains ongoing, while teams continue restoring technology services and assessing the university's environment. UT San Antonio said it will continue communicating directly with students, faculty and staff as services return to normal. Detailed information about the revised academic schedule, student services and other updates is available through the university's Fall 2026 information page. The university now expects to begin fall classes on August 24, three days later than originally scheduled, as it works to restore services and strengthen protections following the incident.

The Cyber Express Weekly Roundup: Corporate Cyberattacks, AI Security Risks, Zero-Days, and Data Theft

weekly roundup The Cyber Express cybersecurity 2026

This weekly roundup highlights the expanding range of threats facing businesses, technology platforms, and individuals. From social engineering attacks against corporate systems and vulnerabilities uncovered by AI agents to large-scale software patches and cyberattacks disrupting logistics operations, recent incidents demonstrate how quickly the threat landscape is evolving.  The latest developments also show that cybersecurity risks are no longer limited to traditional malware or ransomware. Attackers are increasingly exploiting human behavior, software weaknesses, interconnected supply chains, and personal online accounts. At the same time, artificial intelligence is emerging as both a defensive tool and a new way to identify security weaknesses. 

The Cyber Express Weekly Roundup 

Levi Strauss Targeted in Cyberattack, Corporate Files Accessed 

Levi Strauss & Co. disclosed a cybersecurity incident after attackers used social engineering techniques to gain access to three company-issued computers. The company believes certain corporate files were accessed and some information may have been exfiltrated. Levi Strauss said it moved quickly to contain the incident and terminate the unauthorized access, limiting the potential impact of the attack. Read more...

AI Agent Exploits Gym Booking Vulnerability 

An AI-powered agent reportedly identified an authentication weakness in an Australian gym’s online booking system. The agent, powered by Anthropic’s Claude and operated through OpenClaw, was originally instructed to help a user book a popular class. During the process, it was able to reserve classes months ahead and cancel another customer's booking. Read more...

AI Will Automate Cybersecurity Toil, Not Replace Security Professionals 

Harsha Reddy, Head of Information Security at Veterinary Emergency Group, argues that artificial intelligence is more likely to transform cybersecurity work than eliminate cybersecurity jobs. AI can assist with repetitive activities such as reviewing logs, triaging alerts, and collecting evidence, allowing security professionals to concentrate on investigation, strategy, and higher-value defensive operations. Read more...

Microsoft Fixes More Than 400 Security Flaws 

Microsoft’s August 2026 Patch Tuesday addresses roughly 400 vulnerabilities across its products, including three zero-days. One of the vulnerabilities was reportedly being actively exploited, while two others had been publicly disclosed before patches became available. The update includes 42 critical vulnerabilities, with 37 associated with remote code execution, reinforcing the importance of timely patching across enterprise environments. Read more...

CEVA Logistics Cyberattack Disrupts European Operations 

A cyberattack against CEVA Logistics disrupted activity at eight European warehouses on July 29, affecting shipments and exposing customer data connected to several major clients. The logistics company, part of the CMA CGM Group, has not publicly identified the attackers or provided detailed information about the technical nature of the incident. Read more...

FBI Warns of Theft of Explicit Content From Social Media 

The FBI has warned that cybercriminals are targeting social media and personal accounts to steal explicit images and videos, including non-consensual intimate images. Stolen material may subsequently be distributed or sold online, while associated personal information can expose victims to harassment, stalking, and sextortion. Read more...

Weekly Cybersecurity Takeaway 

This week’s incidents demonstrate that cybersecurity risks are expanding across corporate networks, software ecosystems, supply chains, AI-powered systems, and personal accounts.  Organizations should prioritize strong authentication, rapid vulnerability patching, employee awareness, third-party risk management, and continuous monitoring. At the same time, responsible use of AI could help security teams reduce repetitive workloads and respond more effectively to emerging threats.  As attackers continue finding new ways to exploit technology and human trust, organizations and individuals must strengthen security controls while remaining prepared for threats that increasingly cross traditional digital boundaries. 

💾

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

CEVA Logistics Cyberattack Disrupts European Warehouses, Exposes Customer Data

CEVA Logistics cyberattack

A CEVA Logistics cyberattack disrupted parts of the company's European operations on July 29, halting shipments at eight affected warehouses and exposing customer data tied to several major clients. CEVA Logistics, which operates in more than 170 countries, is part of the CMA CGM Group, one of the world's largest shipping and logistics conglomerates.  On August 1, CEVA notified affected customers that goods stored at the disrupted facilities could not be shipped, underscoring how the CEVA Logistics cyberattack directly hit supply chain and logistics operations tied to the CMA CGM Group network.   The company has not disclosed technical details about the intrusion or named a suspected threat actor. No ransomware group has claimed responsibility for the incident so far. 

What Data Was Exposed During the CEVA Logistics Cyberattack?

The breach exposed customer data connected to major CEVA clients, including gaming platform Valve and Dutch retailer Ajax. Valve stated that payment details, passwords, and Steam Guard codes were not compromised, as CEVA does not have access to that information. The company nonetheless cautioned that the exposed data could be leveraged by cybercriminals to build convincing phishing campaigns, and it urged users to remain alert to suspicious emails or messages attempting to impersonate trusted services.

De Bijenkorf Confirms Data Exposure 

Dutch premium department store chain De Bijenkorf, also affected by the CEVA Logistics cyberattack, said the breach may have exposed customer names, addresses, email addresses, phone numbers, and online order details. The retailer confirmed that no financial data was compromised.  In a statement, De Bijenkorf said the data potentially involved includes contact details such as email addresses, addresses, and telephone numbers, along with data regarding online orders such as products, prices, discounts, delivery information, and payment method descriptions.   The company added that for business customers, company names and VAT numbers may also be affected if entered in their account, and that severely outdated VAT numbers for freelancers and sole proprietors may be composed of a citizen service number.  De Bijenkorf attributed the breach to its logistics partner, stating: "A security incident has occurred at a logistics partner of de Bijenkorf. Unauthorized persons gained access to part of their systems. Our logistics partner intervened immediately, blocked access, and took additional security measures."  The retailer said order processing, returns, and refunds may take longer than usual, though its stores remain open and online orders can still be placed. It confirmed that no payment details, IBANs, credit card numbers, usernames, or passwords were involved, and that it has notified customers as a precaution and filed a report with the Dutch Data Protection Authority. An external party is currently investigating the cause and scope of the incident.  De Bijenkorf said affected customers would be contacted directly via email from its official address, and that anyone not yet notified cannot be ruled out as impacted while the investigation continues.  The CEVA Logistics cyberattack highlights the exposure risk facing large logistics networks tied to global conglomerates like the CMA CGM Group, where a single breach at one facility can ripple across multiple retail and enterprise clients. With no threat actor identified and investigations ongoing at both CEVA and its affected customers, the full scope of the data exposure remains unclear. 

Suisun City Declares Emergency After Cyberattack Disrupts Systems

Suisun City Emergency

The Suisun City emergency declared by local officials followed a cyberattack that forced the Northern California municipality to shut down its information technology network, disrupting some communications used by public safety agencies. The incident has placed the California city of roughly 30,000 residents among communities confronting the growing threat of cyberattacks against essential local services.  The Suisun City Council declared a state of emergency Saturday after the attack compromised the city's computer systems. Officials said the network shutdown was necessary to contain the threat and preserve potential evidence for a federal investigation into the incident.  Although the Suisun City cyberattack affected communications operations involving both the fire and police departments, city officials said there was no imminent danger to the public. They also emphasized that public safety services continued to operate despite the disruption.  One of the most significant effects involved the handling of emergency communications, including the routing of 911 calls. Suisun City dispatchers began receiving emergency police and fire calls through the Solano County dispatch center as officials worked around the damaged municipal network. 

Suisun City Emergency Response Shifts Dispatch Operations 

The Suisun City emergency response required officials to temporarily move some communications functions outside the city's own computer infrastructure. By Sunday morning, online city services and internal municipal operations remained unavailable while cybersecurity specialists investigated the attack.  Those experts were also working to restore the affected systems. The decision to take the network offline was intended not only to stop the cyberattack from spreading but also to protect evidence that could assist federal investigators in determining how the intrusion occurred and who was responsible.  City officials described the attack as apparently the first incident of its kind to affect Suisun City. The municipality is located about 55 miles north of San Francisco and has a population of approximately 30,000. 

California City Attack Highlights Broader Cyber Threats 

The California city incident also comes amid federal investigations into a separate wave of cyberattacks involving municipal water systems in a dozen states.  Late last month, the FBI, the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency warned that cyberattackers had remotely accessed online infrastructure used by water and wastewater systems in at least seven states. Federal agencies said the hackers believed to be affiliated with Iran were targeting internet-connected industrial controllers with the goal of “to cause disruptive effects within the United States.”  The risks became apparent in Minnesota, where 30 water systems were affected by a cyberattack. Officials reported dramatic declines in water levels before backup systems were activated to prevent further disruption.  While the water-system attacks are separate from the Suisun City cyberattack, the incidents illustrate the expanding range of public infrastructure that can be exposed when essential services depend on connected computer networks.

Suisun City Cyberattack Comes Amid Funding Concerns 

The recent attacks have also prompted calls for greater federal support for cybersecurity efforts. Last week, a bipartisan group of lawmakers urged the restoration of federal funding for Department of Homeland Security programs intended to coordinate cybersecurity efforts across multiple states.  The lawmakers' concerns reflect the increasingly interconnected nature of cyber threats. An attack may occur within one municipality or state, but the technology and infrastructure involved can be linked to broader systems and networks that cross jurisdictional boundaries.  Gov. Gavin Newsom's office, in a statement to The Times, said there was no evidence that California water systems were among those targeted in the recent series of attacks. The governor's office nevertheless argued that cybersecurity efforts conducted independently by individual states are less effective than a coordinated federal approach.  “Cyber threats do not stop at state lines, and no state can defend against them alone,” the governor's office said.  The statement also pointed to reductions in the federal cybersecurity workforce and cuts affecting critical programs. According to the governor's office, those changes have weakened partnerships, threat intelligence capabilities and technical assistance intended to protect essential services nationwide.  “Federal cuts to the nation’s cybersecurity workforce and critical programs have weakened the partnerships, threat intelligence and technical support that help protect essential services across the country,” the governor's office said. “Reducing these capabilities while cyber threats continue to grow leaves every state, and the nation, less prepared for the next attack.” 

Levi Strauss Hit by Cyberattack, Corporate Files Accessed

Levi Strauss cyberattack

Levi Strauss cyberattack has exposed certain corporate information after an unauthorized third party gained access to company files through compromised employee computers, according to a filing with the U.S. Securities and Exchange Commission. Levi Strauss & Co. said it recently detected a cybersecurity incident involving unauthorized access to three company-issued computers. The company said the access was enabled through social engineering techniques, allowing the attackers to reach company files. According to the filing, the company initiated its response protocols after detecting the incident and implemented containment measures. It also launched an investigation that remains ongoing and engaged third-party cybersecurity experts to assist with the response.

Levi Strauss Cyberattack Investigation Remains Ongoing

Based on preliminary findings, Levi Strauss said it believes certain corporate information was accessed and exfiltrated during the incident. However, the company said its rapid response efforts successfully contained and terminated the unauthorized access. The company also stated that no consumer data had been impacted as of the date of the filing. Levi Strauss said the incident has not interrupted its business operations and that, based on the information currently available, it does not believe the incident has had or is reasonably likely to have a material impact on its business strategy, operations, financial condition, or results of operations. The company said it has provided and will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law. Levi Strauss & Co., headquartered in San Francisco, is known for its Levi's denim brand. The company reported net revenues of $6.3 billion for 2025, up 4% compared with fiscal year 2024 and 7% on an organic basis. The company designs and markets jeans, casual wear and related accessories for men, women and children under the Levi's, Levi Strauss Signature, and Beyond Yoga brands. Its products are sold in approximately 120 countries through chain retailers, department stores, online sites, and approximately 3,300 retail stores and shop-in-shops.

Retail Cybersecurity Incidents Continue

The Levi Strauss cyberattack comes as several major retailers have reported cybersecurity incidents involving their own systems or third-party service providers. In the first week of August 2026, the De Bijenkorf cyberattack affected the Dutch luxury department store chain after an incident involving one of its external logistics partners. The disruption affected order processing, deliveries, returns, and refunds, while the company said there was no evidence that its own infrastructure had been compromised. In October 2025, Spanish fashion retailer Mango confirmed a Mango data breach after an external marketing service provider experienced unauthorized access to limited customer information. Mango said its corporate systems were not compromised and that financial or login details remained secure. The exposed information included customers’ first names, countries, postal codes, email addresses, and phone numbers. The company said last names, banking information, credit card details, and passwords were not affected. Retailers also faced law enforcement action following a series of attacks. In July 2025, the UK’s National Crime Agency arrested four people suspected of orchestrating cyberattacks against Marks & Spencer, Co-op, and Harrods. The suspects were detained in the West Midlands and London and faced charges under the Computer Misuse Act, blackmail, money laundering, and involvement in an organized crime group. Meanwhile, in May 2025, Victoria’s Secret took down its U.S. website and some in-store services following what it described as a Victoria’s Secret security incident. The company said the precautionary shutdown was intended to address the incident while its team worked to restore operations. Its Victoria’s Secret and PINK stores remained open. The latest incident involving Levi Strauss adds another case to a growing series of cybersecurity incidents affecting major retailers, with the company continuing its investigation into the access and information involved.

The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks

The Cyber Express weekly roundup H1

This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure.  The latest developments reinforce that cyber threats are no longer limited to direct attacks on organizations. Threat actors are exploiting ransomware-as-a-service ecosystems, compromising government registries, targeting law enforcement databases, and abusing third-party platforms that support retail and healthcare operations.   Organizations must strengthen third-party risk management, improve data protection measures, and enhance incident response capabilities to reduce the impact of evolving cyber threats. 

The Cyber Express Weekly Roundup 

Qilin Dominated Ransomware Attacks in H1 2026 

Qilin emerged as the most active ransomware group during the first half of 2026, targeting organizations worldwide through its ransomware-as-a-service (RaaS) operation. Manufacturing, healthcare, construction, and professional services were among the sectors most affected as the group continued expanding its global reach. Read more… 

Hackers Breach Beneficial Owners Registry, Expose Data of 31,000 Firms 

Hackers breached the Register of Beneficial Owners (VwbP), gaining unauthorized access to data associated with approximately 31,000 legal entities. Authorities temporarily took the registry offline, launched an investigation, and established a crisis response team, stating there is currently no evidence that records were altered or deleted. Read more… 

PNLD Data Breach Leaks Police and Government Contact Details 

A data breach involving the Police National Legal Database (PNLD) exposed names, organizations, and work email addresses belonging to police officers, government partners, criminal justice professionals, and some Ask the Police users after the information appeared on the dark web. Authorities are investigating the incident and assessing its potential impact. Read more… 

De Bijenkorf Logistics Cyberattack Delays Orders and Raises Data Exposure Concerns 

A cyberattack targeting a third-party logistics provider disrupted deliveries, returns, and refunds for Dutch retailer De Bijenkorf. While the retailer confirmed its internal systems were not compromised, investigators are assessing whether customer contact details and order information were exposed. Payment information, passwords, and financial data were not affected, and customers have been advised to remain vigilant against phishing attempts. Read more… 

Updoc Data Breach Exposes Customer Contact Information 

Australian telehealth provider Updoc disclosed a data breach after unauthorized access to a third-party operational platform exposed some customers' names, email addresses, and postal addresses. The company confirmed that its internal systems remained secure and that no medical records, payment information, or financial data were compromised. Read more… 

Weekly Cybersecurity Takeaway 

This week's incidents highlight the continued evolution of cyber threats across ransomware operations, government data breaches, and third-party supply chain compromises.  A common theme across these events is the growing risk posed by trusted third-party platforms and shared digital ecosystems. Attackers are targeting external service providers, government databases, and ransomware affiliate networks to expand their reach and maximize operational disruption.  Organizations should prioritize stronger third-party risk management, continuous monitoring, robust access controls, and timely incident response to reduce the impact of supply chain attacks and data breaches. As businesses become more interconnected, strengthening the security of partner ecosystems is becoming just as important as protecting internal infrastructure. 

Point72 Among Major Hedge Funds Targeted in Cyberattack on Wall Street Through Voice Phishing Campaign

Point72

A cyberattack on Wall Street recently targeted several leading hedge funds, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The attackers used voice phishing, or "vishing," to trick employees into revealing sensitive information or granting access to internal systems.  Cybersecurity experts say such attempts are common because financial institutions store highly sensitive data. However, the latest incidents highlight how cybercriminals are increasingly combining traditional social engineering tactics with artificial intelligence to make impersonation attempts more convincing. 

Point72 Says No Client Data Was Compromised 

According to reports, Point72 Asset Management informed investors on August 5 that it had been targeted in the latest cyberattack on Wall Street. Bloomberg first reported the communication, citing a source familiar with the matter.  The firm said it was reviewing the incident and that no client information had been stolen. Point72 declined to comment publicly.  The campaign extended beyond Point72, with hackers also attempting to breach the information systems of Millennium Management, Two Sigma Investments, and Citadel, according to sources. 

Voice Phishing Remains an Effective Attack Method 

The attackers relied on voice phishing, a social engineering technique in which criminals impersonate trusted individuals—often IT support staff—to persuade employees to disclose confidential information or provide system access.  Cybersecurity experts told Reuters that these attacks are routine because of the valuable information held by financial firms. Rather than exploiting software vulnerabilities, voice phishing succeeds by manipulating human behaviour.  The tactic has also been used successfully by the cybercriminal group "Scattered Spider," a loosely organized network of young hackers that has targeted numerous companies in recent years. 

AI Is Increasing the Sophistication of Cyberattacks 

Security experts say the attempted cyberattack on Wall Street demonstrates how artificial intelligence is making social engineering campaigns more persuasive and difficult to detect.  A similar trend was highlighted in June, when Google's cybersecurity unit published a report detailing a campaign targeting U.S. law firms and other professional and financial services organizations.   According to the report, attackers posed as IT support personnel through voice phishing calls and, in some cases, even visited offices while pretending to be IT maintenance staff. 

Growing Cyber Risks for Financial Firms 

The attempted cyberattack on Wall Street comes as organizations worldwide face a rise in AI-powered cyberattacks and ransomware incidents that disrupt operations and steal sensitive data.  In response to the growing threat, the White House announced a working group earlier this year that brings together AI developers and critical infrastructure operators to share threat intelligence and strengthen cyber defenses.  Although Point72 said no customer information was compromised, the attempted attacks on several prominent hedge funds underscore the persistent cybersecurity risks facing the financial sector and the increasing use of AI-enhanced social engineering by threat actors. 

Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident

Updoc data breach

The Updoc data breach has raised fresh concerns about cybersecurity in Australia's healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system.   The data breach at Updoc, disclosed on August 7, stemmed from a brief security incident involving a third-party platform that supports the company's operations. While the Updoc cyberattack did not expose medical or financial records, it is the latest cyber incident affecting Australia's healthcare sector. 

Updoc Data Breach Traced to Third-Party Platform 

Updoc, an Australian telehealth provider offering round-the-clock online healthcare services, including medical certificates, prescriptions, and specialist referrals, detected unauthorized access to a third-party operational system on Friday, July 31.  In a statement shared with The Cyber Express, the company said the incident was limited to an external system used to support its operations. The exposure was confined to customer contact information, which may have included account holders' names, email addresses, and postal addresses.  Updoc said its internal systems were not accessed during the incident and confirmed that no health records, financial information, or payment details were involved. The company added that it acted immediately to block the unauthorized access and found no evidence of any further activity after the initial event.  According to the company, customers are not required to take any immediate action because account logins and security remain unaffected. Updoc also apologized for any concern or inconvenience caused by the incident. 

Updoc Cyberattack Adds to Healthcare Sector Threats 

Founded in 2021, Updoc generates approximately $10 million in annual revenue. According to its founders, the platform has served more than one million patients since launch, while its website states that it has over 500,000 users.  The Updoc cyberattack follows a series of cybersecurity incidents targeting Australian healthcare and consumer-facing organizations. In June, clinic network Partnered Health disclosed a cyberattack in which hackers stole personal information and health records from patients across at least 21 clinics in five Australian states.  That breach exposed sensitive information, including medical records, Medicare numbers, consultation notes, referral letters, and pathology results. The attack affected clinics in Melbourne, Sydney, Canberra, the Gold Coast, Sunshine Coast, and Coffs Harbour. At the time, another five clinics, including several in Western Australia, remained under investigation.  Although the Updoc data breach was limited to contact information and did not compromise medical or payment data, the data breach at Updoc highlights the risks associated with third-party service providers. As healthcare organizations continue to depend on external platforms, the incident underscores how vulnerabilities outside a company's own infrastructure can still result in customer information being exposed. 

Amsterdam’s De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed

De Bijenkorf cyberattack

A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.

The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.

De Bijenkorf Confirms Third-Party Security Incident

According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional security measures.

An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.

As a precaution, De Bijenkorf has informed customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.

What Customer Data Could Be Affected in De Bijenkorf Cyberattack?

The retailer said investigators are still determining whether any personal information has been compromised.

Based on the information currently available, data that may be involved includes:

  • Customer names and contact details, including email addresses, postal addresses, and phone numbers.
  • Information related to online purchases, such as ordered products, pricing, discounts, delivery details, and the payment method used.
  • For business customers, company names and VAT numbers stored in My Account may also be involved.

De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.

Investigation Continues as Customers Await Confirmation

The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from info@debijenkorf.nl.

For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.

De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.

Retailer Warns Customers About Phishing Risk

Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible phishing risk if personal information is ultimately found to have been exposed.

The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.

The company said it will never request credit card details, gift card information, or other sensitive information via email.

Logistics Cyberattacks Continue to Disrupt Supply Chains

The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics cyberattack can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.

In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including Kentucky Fried Chicken. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.

For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.

PNLD Data Breach Exposes Police and Government Contact Details on Dark Web

PNLD data breach

The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks. 

PNLD Data Breach Exposes Police and Contact Details 

According to PNLD, the compromised data includes names, organizations and work email addresses of police officers, police staff, criminal justice professionals, government partners and customers. The incident also exposed the names and email addresses of some individuals who had previously submitted questions through Ask the Police. UK government guidance warns that such information could enable attackers to craft more convincing phishing emails targeting named officers and affected individuals.  In its official statement, PNLD said, "There is no evidence to suggest that passwords or other security credentials have been compromised." The organisation clarified that it provides legal information, products and services to UK police forces and criminal justice organisations. It also stressed that PNLD is not the Police National Computer or the Police National Database, is not a crime-recording system, and does not store confidential information relating to victims, witnesses or offenders. 

PNLD Notifies Authorities and Affected Users 

Following the PNLD data breach, the organization said it had contacted all affected organizations and provided additional guidance. Individuals impacted through Ask the Police have also received notification emails with further information PNLD confirmed that it has informed the Information Commissioner's Office (ICO) and is working with the National Crime Agency (NCA) and specialist cybersecurity organizations as the investigation continues.  Its statement noted: "We are continuing to investigate a data security incident affecting the Police National Legal Database (PNLD), which was identified on Sunday 26 July." It added that compromised information had been published on the dark web and reiterated that there is no evidence that passwords or other security credentials were accessed.  Regarding Ask the Police, PNLD said the platform was affected because it is hosted on the same infrastructure, resulting in the publication of some users' names and email addresses. 

Investigation Continues as Key Questions Remain 

As of August 3, 2026, PNLD had not disclosed how many people were affected by the data breach at PNLD, when the intrusion began, how long unauthorized access lasted or the total volume of data obtained. Its public breach notice lists the categories of exposed information but does not include a victim count.  PNLD's 2025-26 annual summary reported 108,429 police registrations and support for all 43 Home Office police forces. However, the organization emphasized that this figure represents its user base and should not be interpreted as the number of people affected by the breach.  The organization's 2023-24 annual summary stated that PNLD uses Microsoft Power Platform technology. On August 3, 2026, The Hacker News reported that the breach notification page referenced assets hosted on Microsoft's content.powerapps.com domain. While this supports the platform connection, it does not indicate how the attackers accessed or extracted the compromised data. 

Liechtenstein Cyberattack Exposes Data From Beneficial Ownership Register

VwbP

The Liechtenstein cyberattack has prompted authorities to investigate a major security breach after copies of sensitive data linked to around 31,000 legal entities were unlawfully accessed from the country's Register of Beneficial Owners (VwbP).   Following the cyberattack on Liechtenstein, officials temporarily suspended external access to the register while investigations continue. Although data was exfiltrated, the government said there is currently no evidence that records were altered or deleted. 

Cyberattack on Liechtenstein's VwbP Register 

According to the Liechtenstein government, the VwbP was targeted during the night of 29/30 July 2026, when unknown attackers gained unauthorized digital access to the system. Irregularities were detected by the Office of Justice on 30 July, prompting the Office of Information Technology to investigate, secure the affected systems, and immediately take the register offline.  In a statement, the government said, "Copies of data relating to around 31,000 legal entities were unlawfully exfiltrated." It added that the register would remain unavailable to external users through the llv.li website until further notice. "According to the current state of knowledge, there are no indications that data in the system was modified or deleted," the statement noted. 

Liechtenstein Cyberattack Triggers Government Response 

The cyberattack on Liechtenstein has highlighted the growing cybersecurity risks facing international financial centres that manage assets for wealthy individuals, businesses, trusts, and other institutions. The VwbP is maintained to support anti-money laundering and counter-terrorist financing efforts by recording the beneficial owners of companies, foundations, trusts, and other legal entities.  Authorities began reviewing the incident immediately after the suspicious activity was detected. On 31 July, the government was informed that the attack on the VwbP had likely succeeded. Preliminary investigation results were delivered on the afternoon of 1 August 2026, leading the government to establish a crisis unit that same Saturday evening. The unit, formally confirmed the following day, is headed by Prime Minister Brigitte Haas and Minister of Justice Emanuel Schädler. The Register of Beneficial Owners Act (VwbPG) came into force in 2021, implementing the requirements of the 5th EU Anti-Money Laundering Directive. The government also confirmed that the Liechtenstein cyberattack constitutes a personal data breach under the General Data Protection Regulation (GDPR). 

VwbP Breach Raises Concerns Over Digital Trust 

Commenting on the broader implications of the breach, Steve Lamb, CEO of Kyckr, said registries are becoming critical to Europe's evolving digital trust framework. "Under the digital trust model taking shape in Europe, the registry stops being a noticeboard we query and becomes the authentic source, a body that can sign a statement about who owns and controls a company, which thousands of institutions then rely on," he said.  Lamb added that as registries become trusted sources for verifying ownership, their security becomes fundamental to the wider financial ecosystem. "The debate can't only be about standards, schemas and interoperability. Registries are becoming critical financial infrastructure, and they should be resourced like it."   The digital trust model he referred to is the European Business Wallet, eIDAS 2.0. As investigations into the VwbP breach continue, officials are working to determine the full impact of the Liechtenstein cyberattack. 

Hackers Breach Beneficial Owners Registry, Access Data of 31,000 Firms

Beneficial Owners Register breach

A Beneficial Owners Register breach has exposed data copies linked to approximately 31,000 legal entities after unknown attackers gained unauthorized access to the Register of Beneficial Owners (VwbP). Authorities confirmed the cyberattack prompted an immediate response, including taking the affected system offline, launching a technical investigation, and establishing a government-led crisis team to manage the incident.

According to official information, the attackers digitally accessed the VwbP during the night of July 30, 2026. Irregularities were detected later that day by the Office of Justice, which then contacted the Office of Information Technology to investigate the incident. Based on the initial findings, the affected system was immediately secured and removed from external access while investigators began a detailed analysis.

Beneficial Owners Register Breach Confirmed After Investigation

On July 31, 2026, the government was informed that the Beneficial Owners Register breach may have been successful. The first confirmed findings from the preliminary investigation were submitted on the afternoon of August 1.

Authorities said the attackers unlawfully accessed the directory and stole data copies relating to approximately 31,000 legal entities. The Register of Beneficial Owners (VwbP) stores information about the beneficial owners of companies, foundations, and trusts.

Officials stated that the register has been temporarily taken offline for external users through the LLV.li website while investigations continue. Based on current findings, there is no indication that any information stored in the system was altered or deleted during the incident.

Government Establishes Crisis Team

Following confirmation of the incident, the government convened a crisis team on the evening of August 1, 2026. The team immediately began its work and was formally confirmed on August 2.

The crisis team is led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler. According to the government, its priorities are to fully investigate the incident, inform affected individuals, and implement appropriate countermeasures.

GDPR Data Breach Notification Process Underway

Authorities confirmed that the incident qualifies as a data breach involving personal information under Article 33 of the General Data Protection Regulation (GDPR).

The crisis team said it is working to notify affected individuals in accordance with Article 34 GDPR as quickly as possible. A central information point is also being established to respond to questions from those impacted by the breach.

What Is the Register of Beneficial Owners?

The Register of Beneficial Owners (VwbP) was established to support money laundering prevention and combat terrorist financing. It contains information identifying the beneficial owners of legal entities, including companies, foundations, and trusts.

The register operates under the Law on the Register of Beneficial Owners of Legal Entities (VwbPG), which came into force in 2021 to implement the requirements of the 5th EU Anti-Money Laundering Directive.

Authorities continue to investigate how the unauthorized access occurred and whether additional measures will be required to strengthen the security of the register. At this stage, officials have confirmed only that data copies were accessed and that there is currently no evidence suggesting records within the system were modified or deleted.

The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats

The Cyber Express weekly Roundup July 2026 new

This weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses.  The latest developments show that cyber risks are expanding beyond traditional network attacks. Threat actors are targeting identities, trusted platforms, software supply chains, and operational technology environments. Organizations must strengthen security controls, improve monitoring capabilities, and adopt proactive measures to protect sensitive data and critical services. 

The Cyber Express Weekly Roundup 

Four Men Admit to $2.2 Million Medicaid Fraud Scheme Using AI 

Four Minnesota men have pleaded guilty in connection with a Medicaid fraud scheme that allegedly generated approximately $2.2 million through fraudulent claims for housing-related services. Prosecutors stated that artificial intelligence tools, including ChatGPT, were used to create false documentation supporting fraudulent billing activity. Read more... 

Tribeca Data Leak Exposes Celebrity-Linked Information 

A reported data leak connected to the Tribeca Film Festival exposed nearly 666,000 records containing personal information associated with attendees, contacts, and individuals linked to the entertainment industry. The exposed data reportedly included names, email addresses, phone numbers, and limited device-related information. Read more... 

Origin Energy Data Breach Impacts Around 900,000 Customers 

Australian energy company Origin Energy confirmed a data breach affecting approximately 900,000 current and former customers. The exposed information may include customer names, contact details, dates of birth, and partial account information. The company is investigating the incident and has advised customers to remain alert for possible scams or suspicious communications. Read more... 

Joyfill npm Packages Found Distributing DEV#POPPER Malware 

Security researchers discovered that two beta versions of Joyfill npm packages were distributing DEV#POPPER, a remote access trojan (RAT) capable of stealing information, executing commands, and compromising developer environments. Read more... 

Student Accused of IIT Website Breaches Offered Technical Assessment 

A student accused of breaching parts of the IIT Kanpur and IIT Madras websites after being rejected from IIT Kanpur’s cybersecurity program will undergo a technical skills assessment rather than facing immediate legal action. The institute stated that admissions for the current session are closed but indicated that future opportunities may be considered if the student demonstrates strong cybersecurity abilities. Read more... 

FBI Warns of PLC Cyberattacks Targeting U.S. Water Utilities 

The FBI and the U.S. Environmental Protection Agency warned that cyberattacks targeting internet-connected programmable logic controllers (PLCs) have disrupted water utilities across multiple U.S. states. Attackers reportedly manipulated PLC settings, affecting monitoring and operational processes. Read more... 

Weekly Cybersecurity Takeaway

This week’s incidents demonstrate how cyber threats continue to evolve across multiple domains, including artificial intelligence abuse, personal data exposure, software supply chain attacks, and critical infrastructure targeting.  A common theme across these events is the exploitation of trust. Attackers are abusing trusted technologies, legitimate software ecosystems, customer databases, and connected infrastructure to achieve their objectives.  Organizations must focus on building cyber resilience through stronger identity protection, secure development practices, continuous monitoring, and effective incident response planning.  As emerging technologies such as artificial intelligence and connected industrial systems become more widespread, cybersecurity strategies must evolve alongside them. Protecting digital assets requires not only stronger technical defenses but also responsible for technology use, awareness, and proactive risk management. 

Origin Energy Data Breach Affects 900,000 Current and Former Customers

Origin Energy data breach

The Origin Energy data breach has affected approximately 900,000 current and former customers after Australia's largest energy retailer confirmed unauthorized access to customer information. The company also revealed it had received a warning about the potential breach weeks before it publicly disclosed the incident.  Origin Energy said a significant proportion of those affected by the data breach at Origin Energy were former customers. The compromised information may include names, addresses, dates of birth, phone numbers and account details, along with the last four digits of a credit card or the last three digits of a bank account.  The company said incomplete credit card and bank account details cannot be used to make purchases or access customer accounts.  Origin provides electricity, fossil gas, LPG and internet services to households and businesses across Australia and has approximately 4.8 million customer accounts. 

Frank Calabria Apologizes After Origin Energy Data Breach 

Origin Chief Executive Frank Calabria apologized to customers following confirmation of the breach and warned that affected individuals should remain alert to suspicious activity and a heightened risk of scams.  "We are sorry," Calabria said. "We don't take for granted the trust customers place in Origin, and we're here to support them."  Calabria said Origin first received emails on 2 July from an individual claiming to have accessed customer records. However, the company did not initially consider the threat credible because there was no evidence confirming customer data had been accessed.  The company received proof of customer data access on 22 July, after which Origin announced the incident publicly.  Calabria said the information accessed appeared to be historical customer data obtained "on an unauthorised basis". He said Origin had taken steps to secure its systems and prevent further unauthorised access, adding that the company did not believe any customer information had been published on the dark web. 

Timeline of the Data Breach at Origin Energy 

Origin said it had been reviewing a potential security threat since early July and had worked to assess its credibility and possible impact.  In its update, the company said the threat was not considered credible based on the information available at the time.  "On 22 July, new information emerged that indicated a potential security incident may have occurred. We acted immediately, providing updates to the market and notifying our customers as a precaution," Calabria said.  The Origin Energy data breach remains under investigation by relevant authorities. Calabria said the company could not provide further details about the incident because it was a criminal matter.  "It is a criminal matter which is under active investigation and, given that, we are constrained by the level of information we can provide at this time," he said.  Calabria declined to comment on several issues, including when the breach occurred, whether any employees were involved, whether a ransom had been demanded or paid, and whether there remained an active risk of further data leaks. 

Origin Confirms Investigation into Customer Data Breach 

In its first statement on 23 July 2026, Origin announced it was investigating a potential security incident involving unauthorized access to some customer data.  The company said it did not believe the affected information included customer credit card or bank account details.  "We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers," Origin said.  The company confirmed it had notified the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner.  A later update confirmed there had been unauthorised access and disclosure of customer information. Origin said it was working to identify all affected customers and would contact those whose information had been compromised. 

Around 900,000 Customers Affected by Origin Energy Data Breach 

Following an initial review, Origin confirmed that approximately 900,000 current and former customers had been affected by the breach.  "We have now completed the initial phase of our review into Origin's customer data security incident," Frank Calabria said.  "At this point in time, we believe the information of approximately 900,000 current and former customers was accessed."  Calabria again apologized to customers and said protecting affected individuals remained the company's priority.  "To our customers, I am sorry. We don't take for granted the trust customers place in Origin and our safeguarding of their information," he said.  "We are contacting those customers whose information has been accessed and are providing support to them."  Origin said it had extended customer support hours, established a dedicated contact number and was working with cybersecurity and forensic specialists to contain the incident.  The company also confirmed ongoing cooperation with government agencies, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police and the Office of the Australian Information Commissioner. 

Customers Warned about Scams Following Data Breach at Origin Energy 

Origin has made specialist identity and cybersecurity support services available to affected customers.  Customers with concerns can contact Origin through its dedicated support line on +61 8 9922 7000 or email hello@origin.com.au.  The company advised customers to be cautious of unexpected calls, emails or text messages referring to their Origin accounts. It recommended avoiding links in unsolicited messages, independently verifying callers through official channels, never sharing passwords, and not providing personal or financial information unless the recipient's identity is confirmed.  Origin also encouraged customers to use two-step authentication, such as authentication applications, for personal email accounts and other online services where available.  We are acutely aware that others may exploit this incident, including by impersonating Origin or through other scam activity," Calabria said.  "We recommend that all our customers remain vigilant to suspicious activity and a heightened risk of scams." 
❌