From The Record · 40 stories
Liquid Network loses $320 million in Bitcoin to purported white-hat hackers
The Liquid Network, a Bitcoin sidechain, had approximately $320 million (4,000 BTC) drained from its federation wallet by individuals claiming to be white-hat hackers. These individuals state they will return the funds once a vulnerability is fixed, prompting Liquid to suspend transactions and engage with them.
Cyberattack Exposes Data of 8.7 Million Customers at Three UK Airports
Manchester Airports Group (MAG) reported a cyberattack affecting approximately 8.7 million customers across Manchester, London Stansted, and East Midlands airports. The breach compromised personal data such as email addresses, phone numbers, vehicle registrations, and postcodes, but no financial information was accessed.
US Seizes Domains Linked to Chinese Hacking Group QTFY Targeting Government Agencies
The U.S. Department of Justice and FBI seized domains associated with the Chinese state-sponsored hacking group QTFY, disrupting its operations. This group allegedly used QTRouter and QScan malware to compromise U.S. critical infrastructure and government entities, including NASA, the Federal Reserve, and the U.S. Senate, since 2018.
New Android Car Head Unit Malware Uses Built-In Updaters for Ad Fraud and Botnets
A new malware family targeting Android-based vehicle head units from DoFun has been discovered, spreading through the devices' built-in update mechanisms. This malware aims to facilitate ad fraud and create a proxy botnet, marking the first documented case of malware on car head units with a device-specific infection chain.
Polish Energy Plant Cyberattack Used Novel Private APN Vector, Shutting Down Turbine
A previously undisclosed cyberattack in December 2025 targeted a small Polish combined heat and power (CHP) plant, causing a temporary shutdown of its steam turbine and water treatment system. The attack, which threatened heat supply to 50,000 residents, utilized a private Access Point Name (APN) as an attack vector, marking the first documented real-world use of this method to access industrial control systems.
Zimbra Releases Critical Security Patches for Classic Web Client
Zimbra has released version 10.1.19 to patch a critical stored XSS vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via crafted emails. Additionally, Zimbra version 10.1.20 addresses multiple vulnerabilities, including command injection and mail forwarding bypass. The updates are crucial to maintain security for users of the Zimbra Collaboration Suite.
Coca-Cola's Fairlife Hits U.S. Production Halt Due to Anubis Ransomware Attack
A ransomware attack by the Anubis group has forced Coca-Cola's Fairlife to suspend U.S. production. Hackers claim they extracted 1 TB of data, threatening to release it unless a ransom is paid. The incident raises concerns about cybersecurity in the food and beverage sector.
Ofcom Probes TikTok's Child Safety Due to Age Verification Concerns
UK regulator Ofcom is investigating TikTok's age verification methods under the Online Safety Act 2023. Concerns revolve around TikTok's use of 'age inference' technology, which might not adequately identify minors and expose them to harmful content. TikTok claims compliance with safety obligations, while Ofcom's findings could result in significant penalties if failures are confirmed.
Microsoft Issues Record 570 Security Patches, Including Three Zero-Days
Microsoft's July 2026 Patch Tuesday included a record 570 security patches, with three zero-day vulnerabilities addressed. The increase is partly due to AI-assisted discovery, highlighting a trend in vulnerability identification and remediation.
19-Year-Old Extradited to U.S. for Role in Scattered Spider Hacks
Peter Stokes, a dual U.S. and Estonian citizen, was extradited from Finland to the U.S. to face charges related to hacking activities with Scattered Spider. Notable incidents include a 2025 cyberattack on a luxury jewelry retailer demanding an $8 million cryptocurrency ransom. The extradition underscores efforts to combat global cybercrime.
Microsoft and Partners Dismantle EvilTokens AI Cybercrime Platform, Two Arrested
Microsoft, in collaboration with partners including Health-ISAC, Cloudflare, and OpenAI, has taken down EvilTokens, an AI-powered cybercrime platform. The platform, which offered AI tools for account compromise and financial fraud, led to the arrest of two men, aged 32 and 38, in the UK by the Metropolitan Police Service.
Revolut confirms customer data breach via fraudulent government agency requests
Revolut disclosed that an unauthorized third party obtained sensitive customer data by submitting fraudulent requests from a legitimate government agency email domain. The exposed information includes identity details, contact information, and potentially verification selfies, account statements, and transaction histories for a limited number of customers. This incident highlights vulnerabilities in data access protocols, even when dealing with seemingly legitimate government communications.
PaperCut warns of active exploitation of zero-day vulnerability in NG and MF software
PaperCut issued an urgent security advisory regarding a zero-day vulnerability in all versions of its PaperCut NG and PaperCut MF print management software, which is actively being exploited in attacks. The company released emergency patches and advised organizations to restrict access to web interfaces of Internet-exposed servers, as this vulnerability poses a significant risk to affected systems.
Craneware Reports Data Breach Affecting US Hospitals and Pharmacies
Craneware, a UK-based software provider for over 2,000 US hospitals, reported a data breach involving employee and customer information. The breach resulted in the theft of significant data, impacting hospitals' billing and patient management services. The incident has been contained, with investigations ongoing.
Russian National Charged in US for Malware Campaign Targeting 80,000 Freelancers
Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, has been extradited to the US and charged with orchestrating a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware between 2016 and 2017. Aktulaev used 255 fake accounts on an unnamed freelance employment platform to distribute malicious Excel attachments, gaining remote control and stealing data from victims' systems. This case highlights international efforts to prosecute cybercriminals.
Two Berlin State Ministries Disconnected from Government Network Following Security Breach
Two Berlin state ministries, responsible for urban development and mobility, have been isolated from the city government's IT network due to a security breach. This incident has disrupted internal communications and some public services, highlighting vulnerabilities in government IT infrastructure.
Sality P2P Botnet Dismantled After 23 Years of Operation
The Sality peer-to-peer (P2P) botnet, active since 2003, has been disrupted through an international law enforcement effort involving the U.S. Department of Justice, Europol, Eurojust, and private partners like CrowdStrike and the Shadowserver Foundation. The operation, which took place on August 31, 2026, included a P2P sinkhole and domain seizures, effectively neutralizing a long-standing threat that infected over 15,000 devices and distributed various malware, including the EggJagger clipjacking tool.
Boston Scientific reports cyberattack disrupting global operations and order processing
Medical technology company Boston Scientific experienced a cyberattack on August 25 that disrupted its IT systems, causing a network outage and affecting its ability to process and ship customer orders globally. The incident impacts a major medical device manufacturer, potentially affecting the supply chain for critical medical equipment worldwide.
ATF confirms "major incident" after Qilin ransomware group claims breach
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a "major incident" involving a breach of one of its standalone systems, following claims by the Qilin ransomware group. The agency stated that its main enterprise network, eForms system, and other ATF systems were not affected, and operations remain uninterrupted.
Ransom Cartel Creator Sentenced to 16 Years for Ransomware-as-a-Service Operation
Maksim Silnikau, the 40-year-old Belarusian creator and administrator of the Ransom Cartel ransomware-as-a-service operation, was sentenced to 16 years in prison in Virginia. Silnikau developed the ransomware and recruited affiliates to attack at least 18 companies globally between 2021 and 2023, providing them with tools and infrastructure for intrusions and ransom negotiations.
SafePal data breach exposes order information for 39,798 customers
Cryptocurrency hardware wallet provider SafePal reported a data breach affecting approximately 39,798 customers, exposing names, email addresses, shipping addresses, phone numbers, and purchase information. A threat actor is now claiming to sell this stolen data on a cybercrime forum. This breach could lead to targeted phishing and social engineering attacks against affected customers.
FBI Warns of Cybercriminals Hacking Accounts to Steal Explicit Images for Extortion
The FBI has issued a public warning about cybercriminals hacking into social media and online accounts of adults and children to steal explicit images and videos. These stolen materials are then used for blackmail, sold on criminal marketplaces, or shared with other criminals to facilitate further sextortion, with student-athletes and young boys frequently targeted.
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are redirecting users to fake Microsoft 365 login pages by changing DNS settings on Wi-Fi devices in hotels and conference centers. This campaign, ongoing since June, affects organizations across various sectors by potentially compromising sensitive business information.
Origin Energy Confirms Customer Data Breach Affecting Personal and Partial Banking Details
Origin Energy confirmed a data breach affecting its 4.8 million customer accounts, compromising personal details and partial banking information. This incident exposes customers to potential identity theft and phishing, highlighting ongoing cybersecurity risks for critical service providers.
US Charges Russians for Operating 'Bulletproof' Hosting Services Linked to $62M in Cybercrime Losses
U.S. prosecutors have unsealed charges against three Russian nationals linked to bulletproof hosting providers Media Land and ML.Cloud. The Russians allegedly supported ransomware attacks through these services, causing over $62 million in damages. A $10 million reward is offered for information leading to their arrests.
Former EU Parliament Member Hacked with Pegasus While Investigating Spyware
Stelios Kouloglou, a former European Parliament member, was targeted with Pegasus spyware during his work on the PEGA Committee, which investigated commercial spyware misuse. The hack occurred as the committee prepared recommendations on regulating spyware. This incident underscores concerns about government surveillance practices in the EU.
Polish Invoicing Platform Fakturownia Suffers Data Breach, Exposing Customer Data
Fakturownia, a major Polish online invoicing platform used by over 600,000 businesses, experienced a data breach due to a vulnerability, potentially exposing user and customer data. The incident is under investigation by the company and Polish authorities, raising concerns due to Fakturownia's integration with Poland's National e-Invoicing System (KSeF).
Former US Soldier Sentenced to 70 Months for Extorting Tech and Telecom Firms
A former U.S. Army soldier received a 70-month prison sentence for hacking and extorting at least 10 U.S. technology and telecommunications companies. He and accomplices stole login credentials, extorted companies for over $1 million, and sold stolen data, impacting sensitive customer records and leading to SIM-swapping fraud.
ShinyHunters Breaches Clop Ransomware Leak Site, Claims Data and Private Key Theft
The ShinyHunters extortion group breached the Clop ransomware operation's data leak site, defacing it and claiming to have stolen server data and the private keys for its onion service. This incident highlights the ongoing conflict between different cybercriminal groups and could impact Clop's future operations if the claims of private key theft are verified.
Rydox Cybercriminal Marketplace Operator Pleads Guilty After Brother's Deportation
Ardit Kutleshi, an operator of the Rydox cybercriminal marketplace, pleaded guilty to aggravated identity theft and money laundering charges. This development follows the deportation of his brother, who was also involved in running the illicit platform that facilitated the sale of stolen personal information and fraud tools.
Ryuk Ransomware Member Sentenced to 24 Months in Prison for Hacking US Companies
Karen Serobovich Vardanyan, a member of the Ryuk ransomware group, received a 24-month prison sentence for hacking US companies and deploying ransomware. Vardanyan specialized in gaining initial access to corporate networks, contributing to attacks that extorted over $15 million in Bitcoin from victims.
Conti Ransomware Member Sentenced to Four Years in Prison for Wire Fraud Conspiracy
A Ukrainian national, Oleksii Oleksiyovych Lytvynenko, received a four-year prison sentence for his involvement in Conti ransomware attacks between 2021 and 2022. This sentencing highlights ongoing law enforcement efforts against cybercrime groups and their members.
FBI arrests alleged ringleader in $240 million Bitcoin theft and money laundering scheme
The FBI arrested Malone Lam, an alleged ringleader, and 17 others involved in a $240 million Bitcoin theft from August 2024, which was followed by a spending spree and a sophisticated money laundering operation. This case highlights an increase in cryptocurrency investment fraud complaints to the FBI, which rose by nearly 50% in 2025.
Grindr to pay £26M to settle claims of sharing user HIV status and personal data
Grindr has agreed to pay £26 million to settle a class-action lawsuit alleging it shared users' personal information, including HIV status, with third parties before 2020. This settlement addresses claims of privacy breaches and misuse of sensitive data, highlighting the ongoing legal and ethical challenges faced by tech companies regarding user data protection.
China-Linked Fire Ant Group Compromises Cisco Routers to Steal Credentials and Blind Logs
The China-nexus cyber espionage group Fire Ant has expanded its operations to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts. This allows the group to capture network traffic, steal credentials, and disable security logging, providing a vantage point into high-value networks, including critical infrastructure.
Venezuelan National Sentenced to 8 Years for ATM Jackpotting Scheme
A Venezuelan national received an 8-year federal prison sentence for his involvement in an ATM jackpotting scheme that resulted in over $3.5 million in losses. This sentence is reportedly the longest federal term for an individual's role in ATM jackpotting, highlighting ongoing efforts to combat this type of financial crime.
Large DDoS Attack Disrupts Norwegian Government Services for Over a Day
A large-scale distributed denial-of-service (DDoS) attack targeted the infrastructure of Norway's Digitalisation Agency (Digdir), disrupting multiple public services for over 24 hours. This incident highlights the vulnerability of critical government digital infrastructure to cyberattacks and the potential for widespread disruption to citizen services.
Global Cybercrime Crackdown Arrests 58, Identifies 263 Suspects in Operation Jackal IV
Law enforcement agencies from 22 countries arrested 58 individuals and identified 263 suspects linked to cybercrime networks, primarily targeting West African groups like Black Axe, during "Operation Jackal IV." This operation disrupted financial fraud schemes, including romance and investment scams, and highlighted the use of Crime-as-a-Service by these syndicates.
Senators Question TikTok Over Experiment Disabling Safety Features for 15 Million Users
Senators Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) have demanded answers from TikTok regarding an experiment that disabled an algorithmic safety feature for 15 million U.S. users, including minors. This safeguard, designed to prevent exposure to harmful content, was reportedly withheld to assess its impact on user engagement, raising concerns about user protection.
US Charges 17 Iranian Hackers, Offers $10 Million Rewards for Five Individuals
The US has charged 17 members of Iran's Mabna Institute for hacking into hundreds of organizations globally, including universities, companies, and government agencies. This action highlights ongoing cyber espionage efforts attributed to state-sponsored groups and the US government's response to intellectual property theft.