Visualização de leitura

The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks

Weekly Roundup September 2026

This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.  From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.  The latest developments also show that organizations face growing risks across AI services, on-premises systems, enterprise edge devices, and account recovery infrastructure. Security teams are being urged to respond quickly as attackers increasingly target exposed systems and authentication mechanisms. 

The Cyber Express Weekly Roundup 

Anthropic Warns of Claude Session Hijacking 

Anthropic has warned that common infostealer malware is being used to steal active Claude sessions, potentially allowing attackers to bypass passwords and two-factor authentication. The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer, which is often distributed through pirated software and illicit downloads. Attackers may also consume victims’ paid AI usage. Read more… 

PaperCut Releases Second Emergency Patch After First Fix Is Bypassed 

PaperCut has released a second emergency patch for two actively exploited vulnerabilities affecting its NG and MF print management servers. Researchers discovered ways to bypass the initial security fix, potentially allowing attackers to chain the flaws and achieve pre-authentication remote code execution on exposed systems. Read more… 

Boston Scientific Cyberattack Limited to Certain On-Premises Systems 

Boston Scientific says its ongoing cybersecurity incident is limited to certain on-premises systems, with no impact identified on its cloud-based applications. The company has also reported no confirmed data breach or evidence of unauthorized activity since August 25, as its investigation into the incident continues. Read more… 

DOJ Investigates Attempted Cyberattack on Hundreds of Thousands of X Users 

The U.S. Department of Justice is investigating a large-scale cyberattack targeting hundreds of thousands of X accounts through the platform’s password-recovery system. Attorney General Todd Blanche said X detected and disrupted the campaign before the targeted accounts could be captured, preventing the attempted account takeover operation from succeeding. Read more… 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk 

Two vulnerabilities in Citrix NetScaler ADC and Gateway have prompted an urgent patching warning from Australia’s cybersecurity agency. CVE-2026-19489, a memory overflow flaw, and CVE-2026-19490, an authentication bypass, can affect systems with specific configurations involving SIP ALG, SAML, or VPN gateway functionality. Read more… 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are increasingly targeting authentication systems, active user sessions, exposed enterprise infrastructure, and critical business applications. AI platforms, print management servers, healthcare environments, social media accounts, and network edge devices all remain potential targets for attackers.  Organizations should prioritize rapid security patching, protection of active sessions, strong authentication controls, careful monitoring of exposed infrastructure, and timely investigation of suspicious activity. Security teams should also review systems that rely on password-recovery mechanisms and identify enterprise devices operating with vulnerable configurations.  As businesses continue to rely on cloud services, AI platforms, remote access technologies, and internet-facing enterprise systems, attackers are finding new opportunities to exploit trusted sessions and security weaknesses. Organizations must maintain continuous monitoring and rapid response capabilities to reduce the impact of increasingly targeted cyberattacks. 

The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown

The Cyber Express weekly roundup, podcast

This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement.   From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both technical systems and human trust.  The latest developments also show that cybersecurity risks are expanding alongside the rapid adoption of cloud services and artificial intelligence. Organizations are facing threats involving identity infrastructure, autonomous AI agents, software vulnerabilities, digital transactions, online fraud, and the misuse of emerging technologies. 

The Cyber Express Weekly Roundup 

Microsoft Confirms Exploited Entra ID Flaw 

Microsoft confirmed that a critical vulnerability in Entra ID, CVE-2026-69836, was exploited before the flaw was fixed server-side. The vulnerability carries a CVSS score of 10.0 and could allow unauthenticated attackers to achieve remote code execution, potentially affecting Microsoft’s cloud-based identity infrastructure. Read more... 

New Zealand Proposes Social Media Ban for Under-16s 

New Zealand has introduced legislation that would require high-risk social media platforms to prevent users under the age of 16 from accessing their services. Proposed age-verification methods could include digital identification, facial age estimation, or official identification documents. Read more... 

Cyble and DRONA Launch AI Cyber Defense Initiative in India 

Cyble and DRONA Cyber Solutions have launched an AI-powered cybersecurity initiative in Ahmedabad aimed at helping mid-sized businesses detect, investigate, and contain cyber threats. The initiative combines threat intelligence, AI-driven investigations, and endpoint enforcement to provide organizations with faster and more coordinated responses to security incidents. Read more... 

AI Agents Could Create New Cybersecurity Risks 

Adarsh Kant Sinha, CEO of ANVE.AI, warned that autonomous AI agents could introduce significant new cybersecurity risks as organizations increasingly allow them to interact with business-critical systems. AI agents may gain access to email, customer relationship management platforms, cloud infrastructure, and financial systems, potentially creating new avenues for misuse or compromise. Read more... 

Ledger Fixes Ethereum App Flaw Amid Disclosure Dispute 

Ledger said it fixed a clear-signing vulnerability in its Ethereum application approximately two weeks before security firm TestMachine publicly disclosed the issue. The vulnerability could potentially allow a malicious application to display one transaction to a user while preparing a different transaction for signing. Read more... 

Global Crackdown Nets 58 Arrests in West African Crime Networks 

An eight-month international law enforcement operation led by INTERPOL has resulted in 58 arrests and the identification of 263 suspects across 22 countries. Operation Jackal IV targeted West African criminal networks involved in cyber-enabled fraud, money laundering, romance scams, and investment scams. Read more... 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are crossing organizational, technological, and geographical boundaries, affecting cloud identity systems, artificial intelligence, digital platforms, cryptocurrency applications, and international financial crime.  Organizations should prioritize strong identity and access controls, rapid vulnerability remediation, careful management of AI-agent permissions, secure integrations, human oversight, and continuous threat monitoring.   As autonomous technologies become more deeply integrated into business operations and cybercriminal networks continue to operate across borders, security teams must adapt to a threat landscape that is becoming broader, more interconnected, and increasingly difficult to contain. 

Gunra Ransomware Builds a New Attack Network Through RaaS

Gunra ransomware

Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met. The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.

Gunra Ransomware Shifts to Affiliate Model

By early 2026, the group had expanded through a formal ransomware-as-a-service affiliate program advertised on dark web forums. The program provides affiliates with a management panel, configurable ransomware builder, cross-platform locker payloads and affiliate documentation. The FBI also observed Gunra operating under new branding aliases, including Golden Community, while recruiting penetration testers and ethical hackers as initial access brokers. Gunra initially focused on Windows environments before introducing a Linux variant and moving toward broader cross-platform targeting. Victims observed on the group’s dedicated leak site include organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific. Targeted sectors include healthcare and public health, financial services and insurance, critical manufacturing, transportation, government services, utilities, academia, media and communications, retail, and professional and nonprofit services. Gunra ransomware

VPN Vulnerabilities Used for Initial Access

According to the advisory, Gunra actors primarily gained initial access by exploiting known vulnerabilities in internet-facing devices, including firewall and VPN gateways. The FBI observed exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities affecting specific FortiOS and FortiProxy versions. The Republic of Korea’s National Police Agency also observed Gunra actors exploiting credential exposure and SSH access control weaknesses in internet-facing VPN gateways to obtain unauthorized remote access. After gaining access, attackers used tools including Impacket utilities to move laterally through victim networks using SMB. In one case, actors compromised an SSL-VPN appliance using default credentials where account lockout controls were absent. They later used stolen session information to access internal virtual desktop infrastructure and move through systems including Active Directory servers and IT personnel workstations.

Data Theft Precedes Encryption

The double-extortion ransomware operation involves stealing sensitive information before encrypting systems. The FBI observed Gunra actors collecting business-critical documents, databases, personally identifiable information, and internal email communications. In at least one case, the actors used a malicious executable called main.exe to exfiltrate data from Microsoft OneDrive and SharePoint. Compressed archives containing sensitive information were also transferred to the Mega file-sharing service, with the volume of exfiltrated data reaching tens of terabytes. For encryption, Gunra uses ChaCha20 and RSA-4096 algorithms and has been observed using the .ENCRT extension for encrypted files. A documented sample from July 2025 used the .CRYPT extension. The ransomware also uses Windows Management Instrumentation to delete volume shadow copies before encryption, while one victim had backup and archived data deleted from both primary and disaster recovery infrastructure.

Agencies Urge Patching and Network Segmentation

The authoring agencies recommend that organizations prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. They also advise implementing and testing offline, immutable backups stored in physically separate and segmented locations. Network segmentation is another key recommendation, intended to restrict lateral movement and limit the spread of ransomware between systems. The agencies also recommend reviewing domain controllers, servers, workstations and Active Directory environments for unrecognized accounts, auditing administrative privileges, requiring MFA where possible and testing security controls against the Gunra techniques mapped to the MITRE ATT&CK framework. The joint advisory was published August 10, 2026, as part of the ongoing #StopRansomware initiative.

Ransomware Kingpin Gets 16 Years for Global Cyberattacks

Ransom Cartel ransomware

A Ransom Cartel ransomware leader has been sentenced to 16 years in prison after being convicted of conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft, according to the U.S. Department of Justice. Maksim Silnikau, a 40-year-old Belarusian national, was identified in court documents as the creator and administrator of the Ransom Cartel ransomware strain, which was developed in 2021. Silnikau had been active on Russian-speaking cybercrime forums since at least 2005 and was also a member of the cybercrime website Direct Connection between 2011 and 2016.

Ransom Cartel Ransomware Operation

Beginning in May 2021, Silnikau developed the ransomware scheme and recruited participants through cybercrime forums. He distributed information and tools to participants, including stolen credentials linked to compromised computers and tools designed to encrypt or lock those systems. Silnikau also maintained a hidden website used by himself and his co-conspirators to monitor and control ransomware operations. According to the court documents, the website provided a platform for the group to communicate with one another, interact with victims, send and negotiate ransom demands, and manage the distribution of funds among the conspirators. The operation targeted companies between 2021 and 2023. During that period, Ransom Cartel ransomware conspirators carried out attacks against at least 18 companies around the world, including organizations based in California, New York, Nebraska, and other countries outside the United States.

Ransomware Attacks Targeted Companies Worldwide

The ransomware attacks involved data theft and monetary demands. The attackers sought payment in exchange for providing keys to unlock stolen data or for promises not to publish the information taken from victims. The operation’s growth was disrupted following Silnikau’s arrest in July 2023. He was later extradited from Poland to face prosecution in the Eastern District of Virginia and the District of New Jersey. The sentencing announcement was made by Theophani K. Stamos, First Assistant U.S. Attorney for the Eastern District of Virginia; Acting Special Agent in Charge Andrew Forrest of the U.S. Secret Service Criminal Investigative Division; Chris Ormerod, Special Agent in Charge of the FBI Kansas City Field Office; and Craig L. Tremaroli, Special Agent in Charge of the FBI Albany Field Office.

Maksim Silnikau Sentenced to 16 Years

The Justice Department’s Office of International Affairs provided substantial assistance with Silnikau’s extradition and the collection of evidence. The U.S. Attorney’s Office for the District of New Jersey and the Computer Crime and Intellectual Property section also assisted with the case. Assistant U.S. Attorney Jonathan S. Keim and former Assistant U.S. Attorney Zoe Bedell prosecuted the case. The 16 years in prison sentence follows the disruption of an international ransomware operation that targeted at least 18 companies during its active period. Silnikau’s role, according to court documents, extended across the development and administration of the ransomware strain, recruitment of participants, provision of attack tools, victim communications, and management of funds generated through the operation.

The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks

The Cyber Express weekly roundup H1

This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure.  The latest developments reinforce that cyber threats are no longer limited to direct attacks on organizations. Threat actors are exploiting ransomware-as-a-service ecosystems, compromising government registries, targeting law enforcement databases, and abusing third-party platforms that support retail and healthcare operations.   Organizations must strengthen third-party risk management, improve data protection measures, and enhance incident response capabilities to reduce the impact of evolving cyber threats. 

The Cyber Express Weekly Roundup 

Qilin Dominated Ransomware Attacks in H1 2026 

Qilin emerged as the most active ransomware group during the first half of 2026, targeting organizations worldwide through its ransomware-as-a-service (RaaS) operation. Manufacturing, healthcare, construction, and professional services were among the sectors most affected as the group continued expanding its global reach. Read more… 

Hackers Breach Beneficial Owners Registry, Expose Data of 31,000 Firms 

Hackers breached the Register of Beneficial Owners (VwbP), gaining unauthorized access to data associated with approximately 31,000 legal entities. Authorities temporarily took the registry offline, launched an investigation, and established a crisis response team, stating there is currently no evidence that records were altered or deleted. Read more… 

PNLD Data Breach Leaks Police and Government Contact Details 

A data breach involving the Police National Legal Database (PNLD) exposed names, organizations, and work email addresses belonging to police officers, government partners, criminal justice professionals, and some Ask the Police users after the information appeared on the dark web. Authorities are investigating the incident and assessing its potential impact. Read more… 

De Bijenkorf Logistics Cyberattack Delays Orders and Raises Data Exposure Concerns 

A cyberattack targeting a third-party logistics provider disrupted deliveries, returns, and refunds for Dutch retailer De Bijenkorf. While the retailer confirmed its internal systems were not compromised, investigators are assessing whether customer contact details and order information were exposed. Payment information, passwords, and financial data were not affected, and customers have been advised to remain vigilant against phishing attempts. Read more… 

Updoc Data Breach Exposes Customer Contact Information 

Australian telehealth provider Updoc disclosed a data breach after unauthorized access to a third-party operational platform exposed some customers' names, email addresses, and postal addresses. The company confirmed that its internal systems remained secure and that no medical records, payment information, or financial data were compromised. Read more… 

Weekly Cybersecurity Takeaway 

This week's incidents highlight the continued evolution of cyber threats across ransomware operations, government data breaches, and third-party supply chain compromises.  A common theme across these events is the growing risk posed by trusted third-party platforms and shared digital ecosystems. Attackers are targeting external service providers, government databases, and ransomware affiliate networks to expand their reach and maximize operational disruption.  Organizations should prioritize stronger third-party risk management, continuous monitoring, robust access controls, and timely incident response to reduce the impact of supply chain attacks and data breaches. As businesses become more interconnected, strengthening the security of partner ecosystems is becoming just as important as protecting internal infrastructure. 

How the World’s Most Active Ransomware Operation Expanded in H1 2026

Qilin ransomware

The first half of 2026 reinforced a familiar reality in ransomware: a small number of highly capable operators continue to drive a disproportionate share of global attacks. Among them, Qilin ransomware emerged as the most active threat group tracked by Cyble Research and Intelligence Labs (CRIL), demonstrating the scale and reach of today’s ransomware-as-a-service (RaaS) ecosystem. CRIL observed Qilin targeting organizations across multiple regions and industries, with activity spanning North America, Europe, Asia-Pacific, South America, and other global markets. Its widespread campaigns highlight how modern ransomware groups leverage affiliate networks, purchased access, and proven extortion techniques to maintain sustained operational momentum.

Download the Cyble H1 2026 Cyber Threat Landscape Report for the full analysis.

Breaking Down the Qilin Ransomware Operation 

Qilin’s activity was particularly significant in North America, where the group accounted for 370 ransomware attacks during H1 2026. This represented nearly one-fifth of all ransomware incidents recorded in the region. Qilin ransomware The group also maintained a strong presence in Europe and the UK, claiming 158 attacks, while Asia-Pacific recorded 64 incidents linked to Qilin. In South America, the group was responsible for 40 attacks, further demonstrating its ability to operate across diverse geographic environments. Rather than concentrating on a single market, Qilin followed a broad targeting strategy designed to maximize opportunities across industries. 

Targeting Sectors Where Downtime Hurts Most 

Qilin’s victim profile reflected a common ransomware strategy: focusing on organizations where operational disruption creates immediate pressure.  Manufacturing organizations remain especially attractive because ransomware incidents can interrupt production lines and affect supply chains. Healthcare organizations face additional pressure due to the critical nature. Construction, Healthcare, and Professional Services were among the sectors most frequently targeted. These industries often depend on continuous availability, hold sensitive information, and face significant financial or regulatory consequences when systems are disrupted.  Manufacturing organizations remain especially attractive because ransomware incidents can interrupt production lines and affect supply chains. Healthcare organizations face additional pressure due to the critical nature of their services and the sensitivity of patient information.  Professional Services firms, including legal and consulting organizations, also represent valuable targets because they manage confidential client data that can increase the impact of double-extortion campaigns. 

The RaaS Model Behind Qilin’s Growth 

Qilin’s success reflects the maturity of the ransomware-as-a-service model. Instead of relying on a single internal team to handle every stage of an attack, RaaS groups operate through specialized ecosystems that include affiliates, initial access brokers, and other underground service providers.  This structure allows ransomware brands to expand quickly, launch simultaneous campaigns, and maintain activity even as individual operators face disruption. The continued success of groups like Qilin shows why ransomware remains difficult to contain. Law enforcement actions and infrastructure takedowns can affect individual operations, but decentralized affiliate models allow new campaigns to continue.

Defending Against the Qilin Threat 

The group’s activity reinforces several priorities for organizations: reducing exposed attack surfaces, strengthening identity controls, monitoring suspicious access activity, and preparing for data theft alongside encryption.  Since ransomware operators increasingly rely on stolen credentials and compromised infrastructure, security programs must focus on preventing initial access as much as responding to active attacks. 

To explore Qilin’s attack patterns, global ransomware trends, targeted industries, and the broader threat landscape observed in H1 2026, download the complete Cyble H1 2026 Cyber Threat Landscape Report

How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026

Gentlemen ransomware group

Ransomware’s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas.  According to research from Cyble Research and Intelligence Labs (CRIL), The Gentlemen became one of the top ransomware actors globally, demonstrating how quickly emerging ransomware-as-a-service (RaaS) groups can scale through affiliate-driven operations.  Unlike older ransomware brands that rely on a narrow set of preferred targets, The Gentlemen displayed a broad targeting strategy. The group impacted organizations across Manufacturing, Construction, Healthcare, Government, and IT sectors — industries where operational disruption, sensitive information, and regulatory pressure create strong incentives for victims to respond quickly. 

The Gentlemen Ransomware Group Becomes a Regional Threat 

The group’s strongest activity was observed in Europe and the UK, where it was responsible for 144 ransomware attacks during H1 2026. The region’s Manufacturing, Construction, Healthcare, and Professional Services sectors were among the most affected, highlighting the group’s preference for organizations with valuable data and limited tolerance for downtime.  In Asia-Pacific, The Gentlemen became the leading ransomware threat, accounting for 114 attacks — nearly one-quarter of the region’s ransomware activity. Manufacturing was among the primary targets, with additional campaigns affecting IT services, Professional Services, Healthcare, and government entities.  The group also gained significant attention in the Middle East & Africa, where it accounted for 56 attacks, representing more than 26% of ransomware incidents in the region. Construction, BFSI, and Government organizations were frequent targets, demonstrating the group’s interest in sectors linked to critical services and economic activity.  South America also saw notable activity, with The Gentlemen responsible for 46 attacks, making it one of the region’s leading ransomware operators.  Also Read: One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States

Double Extortion Remains the Core Strategy 

The rise of The Gentlemen reflects a broader ransomware trend: encryption alone is no longer the primary weapon. Like most modern ransomware operations, the group relies on double extortion — stealing sensitive information before encrypting systems and using the threat of public exposure as additional pressure.  This approach allows ransomware groups to target organizations even when companies maintain effective backup and recovery capabilities. Stolen data can be leveraged for financial gain, reputational damage, regulatory pressure, or further attacks. 

What Makes The Gentlemen a Growing Concern? 

The group’s rapid expansion highlights the resilience of the RaaS ecosystem. Modern ransomware operations no longer depend solely on a single team’s technical capabilities. Instead, affiliates, access brokers, and specialized cybercrime services allow operators to expand quickly across industries and regions.  The Gentlemen’s activity also reinforces a key security challenge: organizations cannot rely only on historical threat rankings. New ransomware groups can rapidly become major players by exploiting exposed systems, purchasing initial access, and adopting proven extortion tactics.  For security teams, monitoring emerging ransomware operators and tracking changes in attacker behavior is becoming as important as defending against established groups.  To explore the complete ransomware landscape, including regional attack trends, targeted industries, and the activity of leading ransomware groups, download the full Cyble H1 2026 Cyber Threat Landscape Report. 

The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threats

The Cyber Express weekly roundup July 2026

This week’s cybersecurity landscape highlights the continued expansion of cyber risks across governments, businesses, and consumers. From ransomware campaigns targeting organizations worldwide to credential-based attacks, data breaches, online fraud, and digital piracy crackdowns, recent incidents show how threat actors are exploiting both technical vulnerabilities and human behavior.  The latest developments underline the need for stronger security practices, including improved identity protection, faster incident response, and greater awareness of evolving cyber threats. Organizations are increasingly dealing with attacks that go beyond data theft, affecting operations, customer trust, and critical services. 

The Cyber Express Weekly Roundup 

U.S. Accounts for Nearly Half of Global Ransomware Attacks in H1 2026 

The United States experienced 1,721 ransomware attacks during the first half of 2026, representing nearly 45% of all incidents tracked globally, according to research from Cyble Research and Intelligence Labs (CRIL). The report identified ransomware groups Qilin and Akira as among the most active threat actors during the period. Read more... 

Dubai Police Warns Against Online Visa Fraud Schemes 

Dubai Police has issued a warning about fraudulent online advertisements offering work, residency, and visit visas in exchange for payment. Scammers have reportedly used social media platforms and messaging applications to impersonate government entities or unauthorized service providers to trick victims. Read more... 

Craneware Data Breach Exposes Employee and Customer Information 

Healthcare technology company Craneware confirmed that unauthorized individuals accessed part of its data environment, resulting in the exposure of employee information as well as some customer and partner records. The company stated that the incident has been contained and has not disrupted business operations or customer services. Read more...  

U.S. Targets Illegal FIFA World Cup Streaming Networks 

The U.S. Department of Justice seized more than 1,000 domains allegedly involved in illegally streaming FIFA World Cup 2026 matches. The action was carried out under Operation Offsides, an initiative focused on combating online piracy and protecting intellectual property rights. Read more... 

Chick-fil-A Customer Accounts Targeted in Credential Attack 

Chick-fil-A confirmed that certain customer accounts were accessed during an automated credential-stuffing attack between June 17 and June 19, 2026. The attackers used account credentials obtained from an external source to gain unauthorized access. The company said affected information may have included customer names, email addresses, membership details, and limited payment-related data. Read more... 

South Korea Diplomatic System Breach Lasted Nearly 10 Months 

South Korea’s Ministry of Foreign Affairs revealed that attackers maintained access to the National Diplomatic Academy’s online education system for almost 10 months. The breach, which began in April 2025, exposed information linked to thousands of current and former ministry employees. Compromised data included user IDs, names, email addresses, and encrypted passwords. Read more... 

Weekly Cybersecurity Takeaway 

The week’s incidents demonstrate how cyber threats continue to evolve across multiple areas, from ransomware and account compromise to online scams and government-related breaches. Attackers are increasingly targeting weaknesses in identity management, user behavior, and digital infrastructure.  Organizations and individuals must focus on proactive security measures, including stronger authentication controls, regular monitoring, timely updates, and greater awareness of social engineering tactics. As cyber threats become more widespread and interconnected, improving resilience remains essential for protecting data, services, and public trust. 

One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States

Ransomware Attacks, Qilin, US, Ransomware Attacks on US

Strip away the geopolitics, the hacktivist noise, and the espionage headlines, and one number from the first half of 2026 stands out above everything else: 1,721. That's how many ransomware attacks hit organizations in the United States between January and June, according to new research from Cyble Research and Intelligence Labs (CRIL). It's not just the highest total of any country tracked in the report — it's more than the next nine most-targeted countries combined.

Canada, in second place worldwide, recorded 179 attacks. Germany logged 155. The United Kingdom, 138. Add up the rest of the global top 10 — France, Italy, Spain, Thailand, India and Brazil — and the total still falls more than 600 attacks short of the U.S. figure alone. Out of 3,836 ransomware attacks CRIL tracked worldwide this half, roughly 45% landed on American soil.

Also read: Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

A Single Region, an Outsized Share

Widen the lens slightly and the picture holds. North America as a whole recorded 1,981 ransomware attacks in H1 2026 — more than half of every ransomware incident Cyble observed globally — alongside 35 data breach and leak incidents and 9 initial access sale listings. The report describes the region as home to "a mature, persistently active RaaS ecosystem operating at high volume across a wide range of industries and geographies."

Two ransomware-as-a-service operators did much of the damage. Qilin, the single most prolific gang worldwide, claimed 370 of those North American attacks on its own — nearly 19% of the regional total. Akira followed with 268, and INC Ransom added another 164. Together, Qilin and Akira alone accounted for more than half of all recorded ransomware activity across the region, a level of concentration that points to a small number of highly organized affiliate networks doing the bulk of the damage rather than a diffuse swarm of opportunists.

Also read: Qilin Ransomware Group’s TTPs Examined by Researchers

Where the Pressure Lands

Professional Services bore the brunt of North American ransomware activity, with INC Ransom showing a marked preference for law firms and other high-value services with sensitive client data. Construction, Manufacturing and Healthcare followed close behind.

One operator, AiLock, stood out for a coordinated wave of victim disclosures that all landed on the same day — March 3 — a pattern consistent with a mass-exploitation campaign rather than isolated intrusions. LockBit, despite years of law enforcement pressure and takedown attempts, kept up a steady tempo against public-sector and educational targets throughout the period, showcasing how difficult the group has been to fully dismantle.

On the data breach side, Technology and financial services (BFSI) were the most frequently targeted sectors in North America, together accounting for roughly 43% of incidents — a reflection of how much intellectual property and monetizable personal data those industries hold.

Notably, Agriculture & Livestock emerged as a significant target for initial access brokers, accounting for a third of all access listings tied to the region. Cyble flags this as a sign of "growing risk in the food supply chain," an area that has historically drawn less attention from ransomware operators than finance or healthcare.

The initial access market itself was strikingly concentrated: two sellers, tracked under the handles "redpin" and "xpl0itrs," accounted for nearly all listings targeting North American organizations. Threat actors also continued to lean on known and zero-day vulnerabilities in widely deployed enterprise platforms — including products from Ivanti and Palo Alto Networks — as their preferred way into corporate networks.

Hacktivism Blurs into Cybercrime

North America wasn't spared the hacktivism wave sweeping the rest of the world either. Collectives including SOLDADOS DIGITALES – UNIÓN AMERICANA and LYSTIC TEAM #ID drove roughly 56 data leak or dump posts and touched about 360 unique domains across the region, with Government, Technology, financial services and telecommunications entities most frequently in the crosshairs.

Cyble's broader findings suggest many groups marketing themselves as ideologically driven hacktivists are, in practice, running side businesses in stolen data brokerage and DDoS-for-hire services — a blurring of motive that complicates how defenders triage the threat.

The scale of the U.S. numbers doesn't necessarily mean American companies have weaker defenses than their global peers — the concentration also reflects the sheer size and digital density of the U.S. economy, and its outsized share of the high-value targets ransomware affiliates chase. But the data does argue for a shift in posture.

Cyble's broader recommendations — treating data exfiltration, not just encryption, as the primary risk; prioritizing patches for the recurring vendor list; and monitoring initial access markets as a leading indicator rather than an afterthought — apply nowhere more urgently than in a country absorbing this much of the world's ransomware volume on its own.

Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

Fairlife ransomware attack

The Fairlife ransomware attack has temporarily halted production operations at Coca-Cola-owned dairy company fairlife in the United States after unauthorized access was detected in a portion of its systems, including production-related systems. According to The Coca-Cola Company, fairlife identified unauthorized access by a third party in connection with a ransomware event. Following the discovery, the company activated its incident response and business continuity protocols while launching an investigation with the support of external advisors and cybersecurity experts. Law enforcement has also been notified. The company said the investigation is ongoing and that the full scope, nature, and impact of the incident are not yet known.

Fairlife Ransomware Attack Suspends U.S. Production

The Fairlife ransomware attack has resulted in the temporary suspension of production operations at fairlife facilities across the United States. However, the company stated that product quality and safety have not been affected by the incident. According to the company's statement, fairlife's production operations in Canada remain operational and have not been impacted by the ransomware event. The Coca-Cola Company also confirmed in a Form 8-K filing dated July 16, 2026, that fairlife detected the unauthorized access on Thursday. The filing reiterated that the company immediately activated its incident response procedures and business continuity protocols after identifying the intrusion. While the company continues to assess the incident, it said it has not yet determined whether the ransomware attack is reasonably likely to materially affect its business because the full impact remains unknown. The company added that it is working to complete its investigation and restore affected systems and production operations as quickly as possible.

Investigation Into Unauthorized Access Continues

The ongoing investigation is being conducted with assistance from outside cybersecurity experts. According to the company, the incident involved unauthorized access to a portion of fairlife's systems, including systems related to production. At this stage, The Coca-Cola Company has not disclosed how the attackers gained access, whether any data was compromised, or if a ransomware group has claimed responsibility for the attack. The company emphasized that its assessment is still underway and that additional details will be shared as more information becomes available.

Food and Beverage Sector Faces Growing Cybersecurity Risks

The food and beverage cyberattack trend has continued to affect manufacturers and logistics providers worldwide in recent months. On July 16, a cyberattack targeting Nichirei disrupted food deliveries across Japan after the frozen food and logistics provider confirmed unauthorized access to its servers. The incident affected logistics operations supporting KFC Japan, leading to temporary service disruptions while systems were being restored. Earlier this year, in February 2026, Australian poultry processor Hazeldenes also experienced a cybersecurity incident that disrupted production across its network. The Victoria-based company later announced it had begun a phased return to production to restore operations safely and securely while investigations continued. The latest incident involving fairlife adds another major food producer to the list of companies dealing with operational disruptions linked to cyber incidents. While production has been paused at fairlife's U.S. facilities, the company has maintained that product quality and safety remain unaffected and that its Canadian production continues without disruption. As the investigation progresses, The Coca-Cola Company said it remains focused on restoring impacted systems and resuming normal production operations. The company also noted that the complete scope and potential business impact of the incident have not yet been determined.

Nichirei Cyberattack Hits KFC Japan, Disrupts Frozen Food Supply

Nichirei Cyberattack

The Nichirei cyberattack has disrupted food deliveries across Japan after the frozen food and logistics provider confirmed its servers were compromised in a cybersecurity incident involving unauthorized access. The attack affected logistics operations supporting KFC Japan, forcing temporary service disruptions while the company investigates the incident and works to restore systems. Nichirei Corporation said it detected system failures on July 13 and established an emergency response headquarters the same day. "Nichirei Corporation (the "Company") experienced system failures on July 13, 2026, and has since been investigating its cause. The Company hereby announces the facts identified through the investigation to date and the measures it plans to take going forward," reads notice issued by Nichirei. An investigation later confirmed that company servers had been targeted in a cyberattack. While the company has not disclosed technical details to prevent further damage, it said recovery efforts are underway with the support of an external cybersecurity specialist.

Nichirei Cyberattack Disrupts Logistics and Food Shipments

Following the attack, Nichirei disconnected systems across the Nichirei Group to protect customer and business partner data. The decision disrupted inbound and outbound operations at Nichirei Logistics refrigerated warehouses and halted frozen food shipments handled by Nichirei Foods. The company said it plans to gradually resume affected operations from July 17 after implementing additional security measures. Nichirei also confirmed that some affected servers contained personal information. As a precaution, it submitted an initial report to Japan's Personal Information Protection Commission regarding the possibility of a personal information leak. The company emphasized that, as of its latest update, there is no confirmed evidence that personal information or customer data has been exposed externally. Investigations remain ongoing, and Nichirei said it will notify relevant parties if any data leakage is confirmed.

Nichirei Cyberattack Impacts KFC Japan Store Operations

The incident quickly spread beyond Nichirei's own operations, affecting KFC Japan, which relies on Nichirei Logistics to deliver ingredients to stores nationwide. According to KFC Japan, deliveries have been disrupted since July 14 following the unauthorized access at its logistics partner. As inventory levels fluctuate, customers may experience product shortages, limited menu availability, shortened operating hours, or temporary store closures. The restaurant chain also temporarily suspended mobile orders, delivery services, coupons, and online ordering through its official website and mobile application. KFC Japan said it is working closely with Nichirei Logistics and other partners to restore normal operations as quickly as possible. However, it has not provided an estimated timeline for full recovery.

Investigation Continues Into Japan Cyberattack

Nichirei said the financial impact of the incident is still being assessed. The company expects to release its first-quarter financial results for the fiscal year ending December 31, 2026, on August 7 as scheduled unless further developments require additional disclosure. The company added that it will continue investigating the cyberattack on Nichirei and release additional information if material findings emerge. The incident follows a series of recent Japan cyberattack disclosures involving major organizations. Earlier this week, The Cyber Express reported that Nihon Kotsu experienced a malware-related security incident that disrupted taxi dispatch services after portions of its IT infrastructure were taken offline. Earlier this month, The Cyber Express also reported cyber incidents involving Aflac Japan, KDDI, Sapporo Holdings, and Nidec. While those cases affected different industries, attackers frequently gained access through subsidiaries, overseas operations, or third-party infrastructure rather than directly compromising corporate headquarters. Separately, Asahi Group Holdings continues recovering from a ransomware attack that significantly disrupted online ordering and shipment operations, forcing the company to rely on manual processes.

Supply Chain Risks Remain in Focus

The Nichirei cyberattack highlights how attacks on logistics providers can quickly evolve into broader supply chain disruption affecting downstream businesses and consumers. Although Nichirei has begun restoring operations, investigations into the incident remain active. Authorities are also continuing to examine whether any personal information was compromised while the company works to return logistics services and KFC Japan operations to normal. With multiple high-profile cyber incidents affecting Japanese organizations in recent weeks, the latest disruption highlight he growing operational impact of attacks targeting critical logistics and supply chain infrastructure.

Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure

Three Russian cybercrime indictment

Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled ransomware, malware, phishing, and other cybercriminal activities, resulting in more than $62 million in losses to victims across the United States and several other countries.

The U.S. Attorney's Office for the Northern District of Ohio announced the unsealing of the indictment following a seven-year investigation. Alongside the criminal charges, the U.S. Department of State is offering a reward of up to $10 million for information on foreign government-linked associates connected to the operation.

Three Russian Nationals and Two Companies Indicted

A federal grand jury returned the indictment in December 2024 against:

  • Alexander Alexandrovich Volosovik, 43, of St. Petersburg, Russia
  • Kirill Andreevich Zatolokin, 34, of St. Petersburg, Russia
  • Yulia Vladimirovna Pankova, 29, of St. Petersburg, Russia
  • Media Land LLC
  • ML.Cloud LLC

The defendants face charges including conspiracy to commit computer fraud, wire fraud, money laundering, and aiding cybercriminal activities.

Russian cybercrime indictment

Assistant Attorney General A. Tysen Duva said the defendants allegedly operated criminal infrastructure from overseas that supported attacks against U.S. critical institutions and placed the public at risk.

Bulletproof Hosting Allegedly Enabled Cybercrime Operations

According to court documents, Media Land, owned by Volosovik, and ML.Cloud, owned by Pankova, provided internet infrastructure and server hosting services designed to help cybercriminals evade law enforcement.

Authorities allege the companies operated from St. Petersburg while maintaining infrastructure in multiple countries, including China, Finland, the Netherlands, and the United States.

The businesses allegedly offered bulletproof hosting services that enabled criminal clients to deploy malware and ransomware, extort victims for money and cryptocurrency, register fraudulent domains, operate criminal marketplaces, and launch phishing and brute-force attacks.

Investigators said the companies also provided technical support to cybercriminal customers, allowing malicious campaigns to continue while avoiding detection.

Victims Spanned Critical Sectors Across 21 States

Officials said the operation targeted dozens of organizations across 21 U.S. states as well as multiple countries.

Victims included:

  • Banks
  • Schools
  • Government entities
  • Hospitals
  • Media companies

Communities affected in Ohio included Akron, Brookfield, Canton, Cleveland, Elyria, Medina, Findlay, Solon, and Valley View.

Russian cybercrime indictment

Additional affected states included California, Florida, Georgia, Illinois, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, New Hampshire, New York, North Carolina, Pennsylvania, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin, and Delaware.

International victims were identified in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom.

FBI Cyber Division Assistant Director Brett Leatherman said Media Land enabled malicious activity that caused tens of millions of dollars in losses while impacting victims across multiple countries.

Russian Cybercrime Indictment Prompts $10 Million Reward Offer

The U.S. Department of State's Rewards for Justice program announced a reward of up to $10 million for actionable information regarding foreign government-linked associates of the indicted individuals, their malicious cyber activities, or foreign government-linked use of Media Land or ML.Cloud.

The program also noted that relocation assistance may be available for qualifying information.

International Sanctions Expand Pressure

The indictment follows coordinated international action against the alleged operators. In November 2025, the U.S. Department of the Treasury's Office of Foreign Assets Control, together with authorities from the United Kingdom and Australia, sanctioned Media Land for facilitating global ransomware operations, distributed denial-of-service attacks, and other malicious cyber activities.

The sanctions also targeted Volosovik, Zatolokin, and Pankova individually, along with Media Land subsidiaries Media Land Technology (MLT), Data Center Kirishi (DC Kirishi), and sister company ML Cloud.

On July 13, the European Union also announced sanctions against the companies and key individuals as part of broader efforts to disrupt cybercrime infrastructure.

International Agencies Back the Investigation

The investigation was led by the FBI Cleveland Division with support from the Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Foreign Assets Control.

Authorities also received assistance from the National Police of the Netherlands, the Public Prosecutor's Office of the Netherlands, the United Kingdom's National Crime Agency, the United Kingdom Foreign Commonwealth and Development Office, the Australian Department of Foreign Affairs and Trade, and the Australian Federal Police.

Officials from CISA and partner agencies said disrupting bulletproof hosting providers remains essential because these services form a critical part of the cybercriminal ecosystem by enabling ransomware, phishing, malware, and other malicious operations while helping threat actors remain anonymous.

Vishing Call Becomes Key Lead in Massive Odido Cyberattack

Odido cyberattack

The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the ShinyHunters ransomware-linked attack that exposed the personal data of approximately 6.39 million customers. Law enforcement has urged the public to come forward with information as investigators work to identify those responsible for one of the country's largest telecom data breaches.

The cyberattack took place on February 5 and 6 after attackers allegedly used voice phishing (vishing) to deceive Odido's customer service team.

According to the company, the attackers posed as members of its internal IT staff, gaining unauthorized access before exfiltrating customer data. Odido said its teams detected the unauthorized access immediately on both occasions and revoked the attackers' access, but the incident still resulted in a large-scale data breach.

Odido Cyberattack Investigation Finds Possible Dutch Link

Under the direction of the National Public Prosecution Service, the High Tech Crime Team (THTC) of the National Investigation and Intervention Unit launched an extensive investigation into the breach.

Authorities said investigators have found strong indications that Dutch criminals may have been involved. One key lead centers on a phone call made shortly before the breach in which a Dutch-speaking man allegedly impersonated an Odido IT employee while speaking with customer service representatives. Police are continuing efforts to identify the caller and have indicated that his voice could be made public if necessary.

Investigators believe people within cybercrime circles may have information about those responsible and are encouraging anyone with relevant details to contact law enforcement.

ShinyHunters Named as Threat Actor

Odido attributed the attack to the cybercriminal group ShinyHunters, which the company said carried out the social engineering campaign.

Chief Executive Officer Søren Abildgaard acknowledged the incident in a public statement, apologizing to customers and outlining the company's commitment to strengthening its cybersecurity capabilities. He said Odido would continue investing in security, improve data protection practices, expand customer support, and share lessons learned from the incident.

The CEO also explained why the company refused to pay the ransom demand. According to Odido, paying cybercriminals would reward illegal activity and could encourage future attacks against other Dutch organizations. The company said the decision was made following guidance from authorities, despite knowing that stolen data could eventually be published.

Millions of Customers Impacted

Odido confirmed that approximately 6.39 million active and former customers of Odido and its Ben brand were affected by the breach. Customers of Simpel were not impacted.

The exposed information varied by individual and included names, addresses, mobile phone numbers, customer numbers, email addresses, IBAN numbers, dates of birth, identification details, nationality, and gender.

The company clarified that My Odido account passwords, call records, location data, billing information, and scans of identity documents were not compromised.

Odido also addressed reports claiming customer passwords had been leaked, stating that login passwords remain securely encrypted and were never accessible during the attack. Instead, a separate telephone verification field known as "password_c," used as a customer challenge code, was included for a limited number of customers. The company has since discontinued using that verification method.

Customer Support and Security Measures Expanded

Following the breach, Odido increased customer support by adding more than 140 service agents and introduced additional security measures. These include its "Check je Gesprek" verification service, allowing customers to confirm whether communications claiming to be from Odido are legitimate, along with access to the F-Secure digital security service.

The telecom provider said all customers identified as affected have been notified by email or SMS, while customer service teams continue assisting users with questions related to their specific data exposure.

Meanwhile, Dutch authorities expect investigations into the Odido cyberattack to continue for several months. Police have also warned that cyberattacks targeting businesses and institutions are becoming increasingly common, urging organizations to strengthen cybersecurity defenses and encouraging citizens to remain vigilant against follow-on fraud and phishing attempts.

Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S.

Scattered Spider

An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group.

Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago after being extradited from Finland.

According to the U.S. Department of Justice, Stokes was arrested by Finnish authorities in April following an Interpol Red Notice and was transferred to the United States last week. A criminal complaint filed in the Northern District of Illinois accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.

Scattered Spider Linked to More Than 100 Network Intrusions

According to the complaint, Scattered Spider, also known as Octo Tempest, UNC3944, and 0ktapus, has been associated with more than 100 network intrusions. Authorities allege the group's activities have resulted in over $100 million in ransom payments and millions of dollars in additional damages suffered by victims.

Investigators said the group targeted companies across the United States by obtaining access to employee accounts through fraudulent methods.

Once inside corporate networks, the attackers allegedly encrypted data or exfiltrated sensitive information to remote servers before demanding cryptocurrency payments to restore access or prevent the public release of stolen data.

Complaint Details Alleged Luxury Retailer Cyberattack

The criminal complaint describes an alleged cyber intrusion that occurred in May 2025 involving a luxury jewelry retailer.

Federal prosecutors allege that Stokes and other co-conspirators breached the retailer's computer systems, exfiltrated company data, and demanded approximately $8 million in cryptocurrency as ransom. According to court documents, the retailer's security team successfully removed the threat actors from its network before any ransom payment was made.

Although the company did not pay the ransom, authorities said it still incurred losses of at least $2 million due to business disruption, investigation costs, and mitigation efforts following the incident.

Operation Riptide Targets Cybercrime Networks

The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois, and the FBI. The investigation also involved the FBI's Copenhagen Law Enforcement Attaché Office, the FBI Las Vegas Field Office, the Justice Department's Office of International Affairs, and Finland's National Bureau of Investigation.

Officials said the case forms part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal actors, infrastructure, financial networks, and fraud schemes targeting Americans.

According to the FBI, Americans reported more than $20 billion in cybercrime losses last year, representing a 26% increase compared with the previous year.

Authorities Cite International Cooperation

Assistant Attorney General A. Tysen Duva said the charges stem from years of investigative work by the Justice Department, the U.S. Attorney's Office, and the FBI, adding that authorities would continue working together to pursue cybercriminals operating across international borders.

U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and emphasized the government's commitment to prosecuting individuals involved in cyber intrusions.

FBI Special Agent-in-Charge Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the hacking group and pursuing cross-border cybercrime investigations.

Recent Guidance on Scattered Spider Threat

The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the FBI and CISA released updated guidance describing the group's latest attack techniques, including the use of DragonForce ransomware to encrypt VMware ESXi servers.

The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant multifactor authentication (MFA), and apply application controls to manage software execution.

Separately, in November 2025, two alleged Scattered Spider members appeared before Southwark Crown Court in the United Kingdom and pleaded not guilty to charges related to the August 2024 cyberattack on Transport for London (TfL).

The Department of Justice emphasized that the complaint against Stokes contains allegations only. As with all criminal cases, he is presumed innocent unless and until proven guilty in court.

Operation Endgame Disrupts SocGholish, StealC Malware Networks

Operation Endgame Disrupts SocGholish

Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware.

Led by Europol and Eurojust, the operation brought together authorities from Canada, Denmark, Germany, the Netherlands, the United Kingdom, the United States, Microsoft, and several cybersecurity organizations. Officials said the objective was to disrupt the infrastructure cybercriminals rely on to launch ransomware attacks, financial fraud, and attacks against critical infrastructure.

Operation Endgame Targets Cybercrime Infrastructure

During the coordinated action, authorities targeted the infrastructure supporting malware delivery rather than focusing on a single malware family.

Law enforcement and industry partners took action against 326 servers and 142 domains, significantly disrupting malware distribution channels. Investigators also identified and restricted criminal cryptocurrency assets currently valued at more than EUR 41 million (USD 47 million) while recovering approximately 27 million stolen login credentials.

According to Europol, the operation aimed to disrupt the "assembly line" used by cybercriminals to gain initial access to victim systems before deploying ransomware or stealing sensitive information.

[caption id="attachment_112936" align="aligncenter" width="600"]Operation Endgame Image Soure: Europol[/caption] [caption id="attachment_112937" align="aligncenter" width="600"]Operation Endgame Strikes Malware Image Source: Europol[/caption]

SocGholish, Amadey and StealC Malware Played Different Roles

The operation focused on three malware families that are commonly offered under the cybercrime-as-a-service model.

  • SocGholish functioned as a malware loader that distributed fake browser updates through compromised WordPress websites. Users who installed these fake updates unknowingly infected their systems, allowing attackers to gain initial access and later deploy ransomware or other malicious tools.
  • StealC malware primarily targeted sensitive information stored on infected devices, including passwords, authentication data, and digital identities. The stolen information was later used for fraud or traded within cybercriminal marketplaces.
  • Amadey was mainly distributed through phishing campaigns. It provided attackers with initial access to compromised systems while also offering information-stealing capabilities that enabled the theft of sensitive user data.

Microsoft reported that during the first two weeks of May 2026 alone, Amadey and StealC malware were linked to more than 140,000 infected computers worldwide.

Thousands of Infected WordPress Sites Cleaned

One of the largest actions under Operation Endgame targeted SocGholish, also known as FakeUpdates.

Authorities remediated 14,971 infected WordPress websites, including websites belonging to restaurants, automotive repair businesses, and other organizations. Investigators also disabled the SocGholish botnet by taking control of domains and shutting down supporting servers.

Website owners whose credentials had been exposed were notified through platforms including Have I Been Pwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and NL-NCSC.

The Dutch Police urged WordPress administrators to change passwords, enable multi-factor authentication, remove unknown administrator accounts, and keep their websites updated to reduce future compromise risks.

SocGholish Linked to Evil Corp

Authorities said SocGholish has been linked to Evil Corp, a Russian cybercriminal group previously associated with the Zeus and Dridex malware families, as well as multiple ransomware and money laundering operations.

Rather than targeting only malware operators, investigators focused on disrupting the broader infrastructure supporting cybercriminal activity. Europol said this strategy increases operational costs for threat actors and makes large-scale cyberattacks more difficult to execute.

Europol Coordinates Global Cyber Operation

Europol's European Cybercrime Centre (EC3) coordinated operational intelligence sharing through SIENA while providing analytical, technical, and cryptocurrency tracing support throughout the investigation.

The operation forms part of Operation Endgame, described by Europol as the largest international initiative to disrupt ransomware enablers worldwide.

Officials said the latest disruption reflects a growing international strategy of targeting the infrastructure that enables cybercrime operations, rather than responding only after attacks have occurred.

TfL Hackers Plead Guilty After Breach Exposed Customer Data and Cost £29 Million

Transport for London cyberattack

Two alleged members of the cybercrime collective Scattered Spider have pleaded guilty to their roles in the Transport for London cyberattack, an incident that disrupted services, exposed customer data, and resulted in approximately £29 million in losses and recovery costs for London's transport authority. The guilty pleas were entered by Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, on the opening day of proceedings at Woolwich Crown Court. The pair had been due to stand trial on June 22 but changed their pleas to guilty.

Transport for London Cyberattack Led to Major Disruption

According to the National Crime Agency (NCA) and City of London Police, TfL's network was infiltrated between August 31 and September 3, 2024. The breach forced all 28,000 employees to attend TfL offices for password resets and caused significant operational disruption across the organization. The TfL cyberattack also resulted in unauthorized access to data held within TfL's Oyster refunds system. The incident affected the authority's customer refund process, delaying reimbursements for some customers. In addition, the application system for Oyster photocards used by children and young people was temporarily shut down. Authorities said the attack caused substantial financial damage, with TfL reporting losses and recovery costs totaling approximately £29 million.

Investigation Linked Attackers to Scattered Spider

Jubair and Flowers were arrested at their homes on September 16, 2024, following a joint investigation conducted by the NCA and City of London Police. Investigators identified both individuals as members of Scattered Spider, a cybercriminal collective that has been linked to a number of high-profile intrusions. During searches of Flowers' residence, officers recovered laptops, desktop computers, hard drives, and USB storage devices. Evidence recovered from one Acer laptop included a screenshot showing connectivity to TfL infrastructure. [caption id="attachment_112868" align="aligncenter" width="600"]Transport for London cyberattack Source: NCA[/caption] Authorities also found evidence indicating Flowers had accessed an online marketplace that sold breached credentials. Investigators further discovered videos recorded by Flowers that allegedly showed Jubair accessing TfL systems during the attack. The investigation revealed that the two communicated through Telegram and collaborated using an online workspace platform that allowed multiple participants to work remotely on shared systems.

Additional Allegations Involving US Healthcare Networks

The investigation extended beyond the Transport for London cyberattack. When Flowers was first arrested on September 6, 2024, NCA officers identified evidence suggesting unauthorized activity targeting the networks of SSM Health Care Corporation and Sutter Health in the United States. Court records show Flowers pleaded guilty to charges related to a conspiracy to conduct unauthorized acts against SSM Health Care Corporation's computer systems with intent to impair operations. He also admitted attempting unauthorized acts against Sutter Health's systems with the same intent. Jubair additionally faced a charge for failing to disclose PINs or passwords associated with devices seized during the investigation. Authorities noted that Flowers breached bail conditions on two occasions in March and May 2025.

Law Enforcement Highlights Impact of Cybercrime

Paul Foster, Deputy Director and head of the NCA's National Cyber Crime Unit, described the case as a lengthy and highly complex investigation. He said the attack demonstrated that cybercrime has significant real-world consequences, affecting public services and causing millions of pounds in losses to critical national infrastructure. Foster also highlighted the growing threat posed by cybercriminal groups operating from the UK and other English-speaking countries, citing Scattered Spider as a notable example. Deputy Commissioner Nik Adams of the City of London Police said the cyberattack had a significant impact on essential public services and daily operations. He emphasized that individuals responsible for targeting critical organizations and causing financial harm would be pursued through coordinated law enforcement efforts. The investigation received support from the West Midlands Regional Organised Crime Unit and British Transport Police. Jubair and Flowers are scheduled to be sentenced at Woolwich Crown Court on July 16.

Operation Endgame Hits SocGholish Malware Network, 14,971 Websites Cleaned

SocGholish Malware

Operation Endgame Hits SocGholish Malware Network after international law enforcement agencies carried out a coordinated operation targeting one of the most significant malware distribution chains linked to cybercrime. Authorities announced the remediation of 14,971 websites infected with SocGholish Malware, a threat used by the cybercriminal group Evil Corp to gain unauthorized access to victim systems and facilitate further attacks. The operation involved law enforcement agencies from the Netherlands, Canada, the United States, and Germany, with support from Europol and Eurojust. Officials described the action as a major disruption of the infrastructure used to distribute malware through compromised WordPress websites.

Operation Endgame Hits SocGholish Malware Network Across Multiple Countries

During the coordinated action week, authorities took down 106 servers and domains associated with the criminal infrastructure supporting SocGholish operations. According to investigators, SocGholish Malware spreads primarily through compromised WordPress websites. Visitors to infected websites are presented with fake software update prompts, often disguised as browser updates. Once downloaded and installed, the malware establishes access to the victim's system, allowing attackers to deploy additional malicious software. Law enforcement agencies also disabled the SocGholish Botnet by seizing domains and taking servers offline. In addition to infrastructure takedowns, authorities cleaned infected WordPress sites and launched a large-scale victim notification campaign to warn affected website owners and encourage stronger security measures.

WordPress Websites at the Center of the Campaign

Authorities highlighted the widespread use of WordPress as a factor contributing to the scale of the threat. According to WordPress, more than 43% of websites worldwide are built on the platform. Investigators reported that login credentials for approximately 1.4 million websites have been leaked, increasing the risk of unauthorized access and malware infections. Cybercriminals behind SocGholish typically compromise websites by exploiting weak passwords, stolen credentials, or vulnerable website configurations. Once access is obtained, malicious code is inserted into websites, allowing attackers to distribute fake updates to visitors. The infected websites included platforms providing everyday services, such as restaurants and automotive repair businesses.

Authorities Urge Website Owners to Strengthen Security

The Dutch National High Tech Crime Unit stated that malware and backdoors have been removed from affected websites and that site owners have been notified. Website owners have been urged to: Authorities emphasized that these measures can significantly reduce the likelihood of future compromise.

Fake Updates Continue to Drive Infections

Also known as FakeUpdates, SocGholish has remained active since 2017 and continues to be used as an initial access tool for broader cybercriminal operations. The malware is distributed through fraudulent software update messages that appear while users browse compromised websites. Once installed, the malware creates a connection to attackers, enabling them to gain access to victim systems. Officials warned users not to trust browser pop-ups requesting immediate software updates and advised obtaining updates only through official application stores, system settings, or verified vendors. Additional recommendations include maintaining updated antivirus software and exercising caution when encountering urgent update notifications. Law enforcement agencies linked Evil Corp to the SocGholish malware operation. The group has previously been associated with Zeus and Dridex malware campaigns, as well as multiple ransomware and money laundering operations. Authorities noted that SocGholish has been used to deploy various ransomware strains that have impacted organizations and critical infrastructure targets worldwide.

Operation Endgame Expands Global Cybercrime Disruption Efforts

Launched in 2024, Operation Endgame is described by participating agencies as the largest international effort to combat ransomware and cybercrime. The initiative brings together law enforcement and judicial authorities from the Netherlands, Germany, Denmark, the United States, Australia, France, Belgium, the United Kingdom, and Canada, with support from Europol and Eurojust. Officials stated that cooperation between public agencies and private-sector cybersecurity organizations remains a critical component of the operation as efforts continue against SocGholish and other cybercriminal networks.

Ransomware Preparedness Must Be a Boardroom Priority: NCSC Chief

Ransomware Preparedness

Ransomware Preparedness must become a strategic priority for organizations as cyberattacks grow more disruptive and difficult to contain, according to Richard Horne, CEO of the UK's NCSC (National Cyber Security Centre). Speaking during the FBI's Ahead of the Threat podcast, Horne urged business leaders to assess whether their organizations could continue operating if critical IT systems were unavailable for four weeks. His remarks come amid growing concerns over ransomware, AI-driven cyber threats, and the increasing speed at which attackers exploit known vulnerabilities.

Ransomware Preparedness Requires Planning Beyond Paying a Ransom

A key message from Horne was that organizations should not view ransom payments as a recovery strategy. Instead, effective Ransomware Preparedness depends on resilience, tested recovery plans, and executive support. According to Horne, ransomware attacks typically involve two forms of extortion. Attackers steal sensitive data and threaten to publish it, while also encrypting systems and demanding payment for decryption keys. He noted that paying criminals does not guarantee data will be deleted or systems fully restored. Referencing lessons learned from Operation Cronos, the international law enforcement operation that disrupted the LockBit ransomware group, Horne said investigators found instances where victim data remained on criminal infrastructure even after ransom payments had been made. Ransomware Preparedness

NCSC Warns Organizations About the Coming Patch Wave

The discussion also highlighted concerns about a growing Patch Wave, a term used by the NCSC to describe the anticipated surge in vulnerability disclosures and exploitation attempts fueled by artificial intelligence. FBI Cyber Division Assistant Director Brett Leatherman pointed to recent industry findings showing that attackers are exploiting known vulnerabilities faster than defenders can remediate them. Internet-facing devices and VPNs have become increasingly attractive targets, while the window between disclosure and exploitation continues to shrink. Horne stressed that organizations need long-term planning rather than short-term reactions. He encouraged businesses to develop multi-year cybersecurity roadmaps and ensure security investments remain a priority across budget cycles.

CyberUK Discussions Focused on Executive Accountability

Reflecting on discussions held during CyberUK, the UK's flagship cybersecurity conference hosted by the NCSC, Horne emphasized that cybersecurity cannot remain solely the responsibility of technical teams. He noted that many Chief Information Security Officers face challenges securing organizational support despite having visibility into technology risks. According to Horne, leadership teams must actively participate in managing cyber risk rather than treating it as an isolated IT issue. The conversation also addressed burnout among cybersecurity professionals, with both Horne and FBI officials acknowledging the operational strain placed on defenders during major incidents, including ransomware attacks and large-scale vulnerability disclosures.

Public-Private Cooperation Remains Critical

Beyond technical defenses, Horne highlighted the importance of collaboration between governments, law enforcement agencies, and the private sector. He said threat intelligence sharing creates a continuous cycle in which organizations identify threats, share findings, improve defenses, and generate new intelligence that benefits the wider cybersecurity community. Horne also pointed to growing opportunities to use artificial intelligence to accelerate threat detection and response efforts. As ransomware groups continue targeting businesses worldwide, the message from both the FBI and the NCSC was clear: organizations must invest in Ransomware Preparedness, strengthen resilience plans, and prepare for a future where cyber incidents are not a possibility but an expectation.

Conti Ransomware Conspirator Pleads Guilty in $150M Scheme

Conti ransomware

A Ukrainian national has pleaded guilty to his role in the Conti ransomware operation, one of the most prolific cybercrime campaigns in recent years. The U.S. Department of Justice announced that Oleksii Oleksiyovych Lytvynenko, 44, admitted to participating in a conspiracy that deployed Conti ransomware against more than 1,000 victims worldwide, resulting in at least $150 million in ransom payments. Lytvynenko entered his guilty plea after being extradited from Ireland to the United States. He pleaded guilty to participating in a wire fraud conspiracy connected to the ransomware scheme that targeted organizations across the United States and dozens of other countries.

Conti Ransomware Targeted Victims Worldwide

According to court documents, the Conti ransomware group carried out attacks between 2020 and 2022, compromising computers and networks in 47 U.S. states, the District of Columbia, Puerto Rico, and 31 foreign countries. Investigators allege that members of the operation gained unauthorized access to victim networks, encrypted critical data, and demanded ransom payments in exchange for restoring access. Victims were also threatened with public exposure of stolen information if they refused to pay. The FBI estimates that, by January 2022, the ransomware campaign had generated at least $150 million in ransom proceeds, making Conti one of the most financially damaging ransomware operations ever investigated by U.S. authorities. Assistant Attorney General A. Tysen Duva said the defendants used the ransomware variant to terrorize businesses and individuals globally, causing extensive financial losses and operational disruption.

Defendant Admitted Role in Malware Development

Court filings show that Lytvynenko joined the conspiracy no later than September 2021. He admitted to possessing stolen data belonging to eight U.S. victims and four international victims whose information had been compromised by members of the group. Authorities also stated that he worked as part of a team directed by another Conti conspirator and assisted in developing a malware "loader." Such tools are commonly used to deploy malicious software and execute additional attacks on compromised systems. The admission provides investigators with further insight into the technical infrastructure behind the Conti ransomware operation and the roles played by individual members within the criminal enterprise.

International Cooperation Led to Arrest and Extradition

The case highlights the growing collaboration between international law enforcement agencies in combating cybercrime. U.S. authorities worked alongside multiple Irish agencies, including the Irish Department of Justice, Home Affairs and Migration, the Office of the Attorney General, and the Garda National Cyber Crime Bureau to secure Lytvynenko's arrest and extradition. Assistant Director Brett Leatherman of the FBI Cyber Division described the guilty plea as an important step toward holding cybercriminals accountable for the damage caused to victims around the world. The U.S. Secret Service also emphasized that international borders would not prevent authorities from pursuing individuals involved in ransomware operations. Officials said the case demonstrates a continued commitment to identifying and prosecuting every member of organized cybercriminal networks.

Part of Broader Operation Riptide Crackdown

The prosecution forms part of Operation Riptide, an ongoing FBI initiative targeting criminal actors, infrastructure, and financial networks involved in cyber-enabled crime and fraud. According to the Department of Justice, Americans reported more than $20 billion in cybercrime-related losses last year, representing a 26% increase from the previous year. Through Operation Riptide, authorities are focusing on dismantling ransomware groups, fraud operations, and other transnational cybercriminal organizations responsible for significant financial harm. Lytvynenko faces a maximum sentence of 20 years in federal prison. He is scheduled to be sentenced on September 10, 2026. A federal judge will determine the final sentence after considering federal sentencing guidelines and other statutory factors. The investigation was led by the FBI's San Diego, Nashville, and El Paso field offices, alongside the U.S. Secret Service. Prosecutors noted that the case remains part of a broader effort to identify and prosecute additional individuals linked to the Conti ransomware conspiracy.

The Cyber Express Weekly Roundup: Cloud Extortion, Long-Term Espionage, Android Zero-Days, and Public Sector Security Reviews

weekly roundup TCE cybersecurity news

The cybersecurity landscape in this weekly roundup continues to show a clear shift toward identity-driven attacks, long-term persistence operations, and exploitation of trusted cloud environments. Threat actors are increasingly focusing on stealing credentials, abusing administrative access, and leveraging legitimate platforms to scale impact across organizations.  Rather than relying on one-off intrusions, attackers are now building sustained access paths into enterprise systems, enabling repeated exploitation, data theft, and extortion from within trusted environments. 

The Cyber Express Weekly Roundup

Pink Extortion Group Targets Microsoft 365 Users via Voice Phishing 

A newly identified cyber extortion group known as “Pink” is using voice phishing (vishing) campaigns to steal credentials for Microsoft 365 accounts. Once access is gained, the group rapidly exfiltrates data from cloud platforms such as SharePoint and OneDrive and sends extortion messages directly from compromised internal accounts to pressure victims. Read more… 

China-Linked VerdantBamboo Maintains 18-Month Network Access 

Researchers have uncovered an 18-month intrusion attributed to the China-linked threat group VerdantBamboo. The attackers maintained long-term access using compromised MSP credentials, multiple malware families, and repeated re-entry techniques after remediation attempts. Read more… 

DPDP and Cybersecurity: Why Less Data Means Better Security

India’s DPDP framework promotes data minimization as a key cybersecurity strategy. Organizations are urged to collect only necessary data, store it briefly, and delete unused information to reduce breach risk. Excess data increases attack surface and impact, making deletion as important as protection in modern security practices. Read more...

Google Patches Actively Exploited Android Zero-Day (CVE-2025-48595) 

Google’s June 2026 security update addresses 124 vulnerabilities in Android, including CVE-2025-48595, a high-severity zero-day that was actively exploited in targeted attacks. The flaw enables local privilege escalation without user interaction, underscoring the growing focus of sophisticated threat actors on mobile devices as high-value entry points. Read more… 

CBSE Launches Security Review of OSM Platform After Vulnerability Reports 

The Central Board of Secondary Education (CBSE) has engaged experts from the Indian Institute of Technology Madras and the Indian Institute of Technology Kanpur to review security concerns in its On-Screen Marking (OSM) system used for Class 12 board examinations. The audit follows reports of weak authentication controls and potential cloud storage exposure, prompting a full-scale security assessment and hardening exercise.  Read more… 

Weekly Cybersecurity Takeaway 

This week’s incidents reinforce a consistent pattern: attackers are prioritizing identity compromise and trusted cloud platforms over traditional perimeter breaches. From phishing-as-a-service extortion campaigns targeting Microsoft 365 to long-term espionage operations and mobile zero-days, the common thread is the abuse of legitimate access rather than forced intrusion.  As organizations continue to expand cloud and mobile reliance, the attack surface is increasingly defined not by infrastructure boundaries, but by identity trust and administrative privilege. 
❌