Visualização de leitura

The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks

weekly round

This week’s cybersecurity roundup highlights growing concerns around online child safety, healthcare data protection, supply chain risks, and cyber threats affecting organizations worldwide. From regulatory scrutiny of digital platforms to large-scale vulnerabilities and operational disruptions, recent incidents show how cyber risks continue expanding across industries.  The key theme in this weekly roundup is the increasing pressure on organizations to strengthen security, improve data protection measures, and adapt to rapidly changing threat environments. Regulators, businesses, and cybersecurity teams are facing challenges ranging from social engineering attacks and malware incidents to vulnerabilities affecting widely used enterprise technologies. 

The Cyber Express Weekly Roundup 

UK Investigates TikTok Age Verification Compliance 

The UK communications regulator Ofcom has launched an investigation into TikTok’s age verification system, examining whether the platform is meeting its child safety obligations under the Online Safety Act. The probe comes as the UK government prepares stricter social media restrictions for users under 16, with enhanced age assurance requirements expected to take effect by Spring 2027. Read more… 

Partnered Health Cyberattack Exposes Australian Patient Data 

Healthcare provider Partnered Health has suffered a cyberattack that exposed sensitive patient information from 21 clinics across Australia. The compromised data reportedly includes personal details, Medicare information, health insurance records, and medical documents. Authorities and the company continue investigating the incident to determine the full scope of the breach and whether additional information was affected. Read more… 

Qantas Data Breach Cleared After Privacy Review 

Australia’s privacy regulator has concluded its review of the 2025 Qantas data breach, finding no evidence that the airline failed to take reasonable measures to protect customer information. The incident affected approximately 5.67 million records after attackers used social engineering techniques to compromise a contact center employee. Read more… 

Nichirei Cyberattack Disrupts KFC Japan Supply Chain 

Japanese frozen food and logistics company Nichirei experienced a cyberattack that disrupted deliveries to KFC Japan after unauthorized access impacted its systems. The company isolated affected infrastructure, suspended certain logistics operations, and began recovery efforts with external cybersecurity specialists while investigating the incident. Read more… 

Microsoft Patch Tuesday Addresses 622 Security Flaws 

Microsoft’s July 2026 Patch Tuesday update fixed 622 vulnerabilities across its product ecosystem, making it the company’s largest security release to date. The update included patches for two actively exploited zero-day vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting Microsoft SharePoint Server and Active Directory Federation Services. Read more… 

Nihon Kotsu Cyberattack Disrupts Japan Taxi Operations 

Japan’s largest taxi operator, Nihon Kotsu, suffered a malware-related cyberattack that forced the company to shut down parts of its IT infrastructure. The incident, detected on July 11, 2026, affected taxi dispatch services and internal systems as the company worked to contain the attack and investigate potential data exposure. Read more… 

Weekly Cybersecurity Takeaway 

This week’s cybersecurity developments highlight the growing complexity of modern cyber threats, with attacks and security challenges affecting technology platforms, healthcare providers, logistics companies, transportation services, and enterprise software environments. From regulatory action on digital safety to actively exploited vulnerabilities and supply chain disruptions, organizations are facing increased pressure to strengthen resilience and respond faster to emerging risks. 

EMEA Emerges as Global Hotspot for Financial Services DDoS Attacks

Financial Services DDoS Attacks

The global financial sector is facing a sharp rise in Financial Services DDoS Attacks, with cybercriminals increasingly targeting banks, payment systems, and online financial platforms through larger, longer, and more attacks, according to new research from Akamai. In its latest State of the Internet (SOTI) Security report titled AI-Empowered Botnets and API Visibility Gaps: Attack Trends in Financial Services, research warned that AI-powered botnets and politically motivated hacktivist groups are intensifying the cyber threat landscape for the banking and financial services industry. Researchers found that Financial Services DDoS Attacks have become more persistent and operationally disruptive, particularly across Layers 3 and 4 web and API infrastructure.

Financial Services DDoS Attacks Top the Chart

According to the report, financial services organizations are now the most targeted industry for web and API distributed denial-of-service attacks. Akamai revealed that the median duration of global Layers 3 and 4 Financial Services DDoS Attacks has increased by 738% since 2024. The company attributed the surge to AI-powered attack infrastructure and growing hacktivist activity, including campaigns linked to pro-Iran cyber groups. Security researchers said attackers are increasingly focusing on:
  • Online banking systems
  • Real-time payment platforms
  • API infrastructure
  • Customer-facing financial applications
The report noted that while financial institutions continue expanding digital banking and payment services, the growing reliance on APIs and cloud-connected infrastructure has also expanded the attack surface available to threat actors.

API-Related Cyber Risks Emerging as Major Security Weakness

One of the strongest findings in the report involved API-related cyber risks. According to reserach’s 2026 API Security Impact Study, 96% of financial service leaders surveyed reported at least one API security incident within the past year. That figure was the highest recorded among all industries included in the research. The report also found that:
  • 60% of all web attacks in 2025 targeted banking institutions
  • 83% of attacks against API endpoints focused on financial organizations
Researchers warned that APIs are increasingly becoming high-value targets because they support critical services such as digital payments, account management, authentication systems, and mobile banking applications. Steve Winterfeld, Advisory Chief Information Security Officer at Akamai, said APIs are now central to modern cyberattacks against financial institutions. “Cybercriminals and hacktivists continue to escalate DDoS from nuisance attacks to a sustained siege encompassing both hacktivism and cybercrime, and financial services are in the crosshairs,” Winterfeld said. He added that artificial intelligence is accelerating existing cybersecurity threats rather than replacing them.

AI Botnets Driving DDoS Campaigns

The report highlighted how AI-driven infrastructure is helping attackers automate and scale malicious operations more effectively. Researchers observed a 147% surge in advanced bot activity during late 2025. In one case study referenced by Akamai, nearly 96% of all traffic reaching a targeted website was identified as malicious scraping bot activity. The company warned that AI-powered botnets are making Financial Services DDoS Attacks more difficult to detect and mitigate because attackers can dynamically adapt attack patterns and traffic behavior. These botnets are also being used to:
  • Overwhelm infrastructure
  • Disrupt payment systems
  • Target APIs
  • Scrape sensitive data
  • Launch credential abuse campaigns
Cybersecurity experts have increasingly warned that AI-enabled automation allows threat actors to launch large-scale attacks with fewer technical resources.

Attack Patterns Differ Across Global Regions

Research also identified major regional differences in cyberattack patterns targeting financial institutions. The report found:
  • Europe, the Middle East, and Africa accounted for 62% of Layers 3 and 4 DDoS attacks
  • Asia-Pacific experienced 52% of Layer 7 DDoS attacks
  • North America recorded the highest volume of web attacks at 44%
Researchers said these differences reflect varying attacker strategies, infrastructure deployment patterns, and regional cybersecurity maturity levels. The report also revealed that nearly 80% of financial institutions experienced ransomware attacks during the past two years. However, fewer than half of surveyed organizations reported adopting advanced cybersecurity technologies capable of handling modern attack methods.

Growing Pressure on Financial Sector Cybersecurity

The latest findings add to growing concerns around operational resilience within the global financial industry. As banks and financial institutions continue accelerating digital transformation initiatives, cybersecurity teams are being forced to defend increasingly complex environments that rely heavily on APIs, cloud platforms, automated infrastructure, and third-party integrations. Research said organizations must improve visibility into APIs, strengthen DDoS mitigation strategies, and modernize threat detection capabilities to address the evolving threat landscape. The SOTI report also includes guidance on DNS security, DDoS mitigation practices, AI architecture security considerations, and insights from financial sector cybersecurity experts, including contributions from the FS-ISAC.

Global Banks Scramble After AI Tool Exposes Cyber Weaknesses

AI-driven cyber risks

Banks across the United States, Europe, and Japan are accelerating efforts to strengthen cybersecurity defenses after the emergence of a new artificial intelligence-powered vulnerability discovery tool raised concerns across the financial sector. The growing discussion around AI-driven cyber risks comes after Anthropic’s Mythos AI tool reportedly exposed previously unknown vulnerabilities within banking systems, prompting financial institutions and regulators to reassess their cyber resilience strategies. While access to the vulnerability-hunting AI model remains limited to select organizations, cybersecurity experts warn that the technology demonstrates how rapidly evolving AI capabilities could reshape cyber threats targeting critical financial infrastructure. According to recent cybersecurity updates highlighted by the World Economic Forum, banks with ageing legacy systems are facing increased pressure to identify and patch weaknesses before malicious actors begin exploiting similar AI-powered capabilities.

AI-Driven Cyber Risks Push Banks to Strengthen Defenses

The rise of AI-driven cyber risks has triggered warnings from financial regulators and international organizations concerned about the potential impact on global financial stability. The European Central Bank has urged banks across the eurozone to prepare urgently for future cyberattacks. Frank Elderson, a member of the ECB Executive Board, warned that institutions cannot afford to delay cybersecurity improvements simply because they lack direct access to tools like Mythos. Smaller banks are also receiving shared intelligence and vulnerability findings from larger financial institutions to improve sector-wide preparedness. The International Monetary Fund has similarly cautioned that rapidly evolving AI-enabled cyber threats could destabilize financial systems if not properly managed. A recent World Economic Forum report developed in collaboration with KPMG examined how organizations can deploy AI securely in cybersecurity operations. The report, titled Empowering Defenders: AI for Cybersecurity, outlined four levels of AI autonomy and warned that while machine-speed responses improve defense capabilities, reduced human oversight may increase operational risks if errors go undetected.

Canvas Breach Raises Questions About Ransom Payments

Another major cybersecurity development involved the company behind the widely used education platform Canvas. Instructure confirmed it had reached an agreement with hackers responsible for stealing approximately 3.5 terabytes of student and university data during a cyberattack that disrupted institutions across the US, Canada, Australia, and the UK earlier this month. The company said the agreement prevented the publication of the stolen information and included what it described as “digital confirmation” that the data had been destroyed. However, the organization did not clarify whether a ransom payment was involved. The incident has reignited debate around ransomware negotiations and cyber extortion tactics. Many cybersecurity experts warn that paying attackers does not guarantee stolen data will actually be deleted and could encourage future attacks. Research cited in the report showed that 58% of Chief Information Security Officers surveyed by a US cybersecurity company said they would consider paying hackers to minimize operational disruption. Cybersecurity analysts also warned that modern ransomware attacks increasingly involve “double extortion” tactics, where attackers steal sensitive data before encrypting systems and demanding payment.

Growing Cybersecurity Concerns Around Global Events and AI Threats

Cybersecurity experts are also warning about threats connected to major international events, including the upcoming 2026 FIFA World Cup hosted across the United States, Canada, and Mexico. Researchers believe the tournament could become a high-profile target for cybercriminals because of its global visibility and heavy reliance on digital infrastructure. Security experts have already reported increased phishing campaigns, fake ticket scams, and fraudulent websites targeting football fans. Meanwhile, new cyberattacks linked to the threat group Ghostwriter have reportedly targeted government organizations in Ukraine using phishing emails disguised as communications from a local telecommunications company. Google also disclosed what researchers described as the first AI-generated zero-day exploit designed to bypass two-factor authentication systems. Security experts believe the discovery prevented what could have become a large-scale exploitation campaign. Separately, OpenAI confirmed that two employee devices were affected during the recent TanStack supply chain attack. The company stated there was no evidence that customer data, production systems, or intellectual property had been compromised. German authorities also dismantled a revived version of Crimenetwork, a cybercriminal marketplace linked to illegal trade involving stolen data, drugs, and forged documents. Law enforcement agencies estimate the platform generated more than $4.2 million in revenue. The latest developments reflect growing concern among governments, regulators, and cybersecurity leaders that AI-powered cyber threats, ransomware operations, and increasingly sophisticated criminal ecosystems are reshaping the global cybersecurity landscape.

U.S. Treasury Rolls Out Cybersecurity Information Sharing Initiative as Crypto Attacks Rise

digital asset cybersecurity initiative

The U.S. Department of the Treasury has unveiled a new digital asset cybersecurity initiative, aimed at strengthening defenses across the rapidly growing digital asset ecosystem. The initiative, announced by the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP), seeks to provide timely and actionable cyber threat intelligence to eligible U.S.-based digital asset firms. The move comes amid escalating cyberattacks targeting cryptocurrency platforms and follows recommendations outlined in the federal report “Strengthening American Leadership in Digital Financial Technology.”

Understanding About Digital Asset Cybersecurity Initiative 

At its core, the digital asset cybersecurity initiative will extend high-quality threat intelligence, previously reserved for traditional financial institutions—to digital asset companies and industry organizations. This includes insights that help firms detect, prevent, and respond to cyber threats affecting their platforms, customers, and infrastructure. “Digital asset firms are an increasingly important part of the U.S. financial sector, and their resilience is critical to the health of the broader system,” said Luke Pettit, Assistant Secretary for Financial Institutions. “By extending access to the same high-quality cybersecurity information used by traditional financial institutions, Treasury is helping promote a more secure and responsible digital asset ecosystem,” he added further. Eligible firms that meet Treasury criteria will receive this information at no cost, signaling a broader push to align cybersecurity standards across financial sectors.

Rising Threats Drive Urgency for Digital Asset Cybersecurity

The digital asset cybersecurity initiative comes at a time when cyber threats against cryptocurrency platforms are intensifying in both scale and complexity. Treasury officials emphasized that the initiative directly responds to this evolving threat landscape. “Cyber threats targeting digital asset platforms are growing in frequency and sophistication,” said Cory Wilson, Deputy Assistant Secretary for Cybersecurity. “This initiative expands access to actionable threat information that helps firms strengthen defenses, reduce risk, and respond more effectively to incidents.” Recent incidents emphasize the urgency. Alleged North Korean hackers reportedly stole $280 million from crypto platform Drift using a complex attack. Industry-wide losses exceeded $3.4 billion last year, with billions more lost annually over the past five years. In another case, Bitcoin ATM operator Bitcoin Depot disclosed a cyberattack on March 23 that resulted in losses exceeding $3.6 million. Additional breaches this year have reported losses of $26 million and $40 million, highlighting persistent vulnerabilities across the sector.

Government Push Amid Ongoing Crypto Crime

Despite increased enforcement efforts, cybercriminals and nation-state actors continue to exploit weaknesses in the digital asset ecosystem. U.S. authorities, including the Justice Department, have ramped up prosecutions and issued repeated warnings about infiltration attempts, particularly by North Korean threat groups. However, these measures have had limited success in curbing attacks. Threat actors continue to exploit coding flaws, social engineering tactics, and employee vulnerabilities to gain access to crypto platforms. The digital asset cybersecurity initiative is designed to complement these efforts by shifting focus toward proactive defense and real-time intelligence sharing rather than reactive enforcement alone.

Strengthening the Future of Digital Finance

Treasury officials also framed the digital asset cybersecurity initiative as a foundational step for the future of digital finance. As digital assets become more integrated into mainstream financial systems, cybersecurity is emerging as a critical pillar for sustainable growth. “This initiative reflects the principles of the GENIUS Act by promoting responsible innovation grounded in strong cybersecurity and operational resilience,” said Tyler Williams, Counselor to the Secretary for Digital Assets. “As digital assets become more integrated into the financial system, access to timely and actionable cyber threat information is essential to protecting consumers and safeguarding the stability of U.S. financial markets,” Williams added. The broader federal strategy emphasizes balancing innovation with security. The Treasury’s report highlights the need for regulatory clarity, risk mitigation, and public-private collaboration to support the long-term growth of digital assets while addressing illicit finance and cyber risks.

A Step Toward Industry-Wide Cyber Resilience

With cyberattacks continuing to disrupt the crypto ecosystem, the digital asset cybersecurity initiative represents a significant step toward improving industry-wide resilience. By bridging the gap between traditional financial cybersecurity frameworks and emerging digital asset platforms, the initiative aims to create a more secure and stable environment for innovation. As digital assets evolve from niche technology to a core component of global finance, initiatives like this may play a key role in shaping how the industry manages risk, and whether it can keep pace with increasing cyber threats.
❌