From The Record · 40 stories
French Tax Authority Investigates Data Breach After Hacker Claims 600,000 Victims
France's Directorate General of Public Finances (DGFiP) confirmed a data breach in late June where an attacker accessed and extracted data on individuals and businesses. The incident became public after a hacker claimed responsibility, stating they obtained data on over 600,000 people, including personal and tax identification information.
New Mirai Variant "Evooo1Bot" Adds Stealth and Proxy Capabilities to Botnet Code
A new Mirai botnet variant, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, according to FortiGuard Labs. This variant includes enhanced stealth features like SSH honeypot detection and a SOCKS proxy function, allowing attackers to conceal their origin and pivot into internal networks. The added capabilities make Evooo1Bot more sophisticated than previous Mirai-derived malware, posing a greater threat to network security.
Russian Sandworm Hackers Target Ukrainian IT Workers with Malicious VPNs via Fake Job Offers
Russian military intelligence hackers, identified as Sandworm (UAC-0145), are posing as recruiters on Ukrainian job sites to trick IT professionals into installing malicious software. Active since at least May, the campaign aims to compromise systems by having victims download a modified VPN application during a fake recruitment process, allowing for command execution and further payload delivery.
Kids Online Safety Act Advances in Senate, Faces House Disagreement on 'Duty of Care'
The Kids Online Safety Act (KOSA) advanced through the Senate Commerce, Science and Transportation Committee, moving it closer to a full Senate vote. The bill, which has 76 cosponsors, aims to establish protections for children online through parental controls and by requiring social media platforms to exercise a "duty of care" to prevent harm to minors. However, a key disagreement with the House version of the bill, specifically regarding the "duty of care" provision, may hinder its passage this session.
UK Police and Education Data Breached by ExfilSquad, Ransom Demanded
The UK's Police National Legal Database (PNLD) and Department for Education (DfE) experienced separate data breaches, with the ExfilSquad extortion group claiming responsibility. The PNLD breach exposed contact information for over 100,000 police officers and criminal justice professionals, while the DfE incident involved over 600,000 lines of data from two portals. ExfilSquad is demanding a ransom for the data.
Amazon Attributes Multiple npm Package Hijacks to North Korea's Sapphire Sleet
Amazon Threat Intelligence has attributed the September 2025 hijacks of the npm packages debug and chalk, along with the March 2026 axios compromise and an earlier typo-crypto incident, to North Korea's Sapphire Sleet group. This attribution connects previously separate incidents of crypto theft and package compromise under a single threat actor, highlighting a consistent pattern of social engineering and supply chain attacks affecting widely used JavaScript libraries.
DOJ Seizes Over 1,000 Domains for Illegal World Cup Streaming
The U.S. Department of Justice seized and blocked over 1,000 domains during the World Cup for illegal streaming. This action aims to protect intellectual property and consumers from potential security threats associated with unauthorized streaming sites.
U.S. Sanctions VPN and Malware Providers for Ransomware Support
The U.S. Treasury sanctioned First VPN Service and its administrator for aiding ransomware activities against American infrastructure. Ukrainian Dmytro Rashevskyi, associated with the VPN, and Belarusian Yegeniy Silayev, a cryptor seller, were named in the sanctions. The sanctions prevent U.S. entities from transacting with them, underscoring a broader crackdown on cybercriminal support networks.
UK and EU Sanction Russia's FSB and GRU for Cyberattacks Involving Critical Infrastructure
The UK and EU have imposed joint cyber sanctions targeting Russia's FSB and GRU following a cyberattack on Poland's energy grid that nearly caused a major blackout last winter. The coordinated sanctions, the first of their kind, address ongoing Russian-led cyber espionage campaigns against EU member states. These actions reflect growing international concerns regarding Russia's capacity to destabilize Europe’s critical infrastructure.
China and India-Linked Hackers Infiltrate Balochistan Police Networks
Chinese and Indian cyberespionage groups targeted the Balochistan Police from February 2024 to April 2026. The attackers accessed sensitive systems, including biometric data and criminal records. This exposes significant regional security vulnerabilities tied to geopolitical tensions.
EU Parliament Revives Chat Control 1.0 Allowing CSAM Scans Until 2028
The European Parliament has approved a procedure to revive the expired 'Chat Control 1.0' regulation, permitting tech companies to scan digital communications for child sexual abuse material (CSAM) until 2028. Despite previous rejections, the law was reinstated through a legal maneuver requiring an absolute majority to block it. The regulation raises significant privacy concerns, but excludes encrypted messaging services.
12 Million Affected in KDDI Data Breach, Exploiting Zero-Day Vulnerability
KDDI, a major Japanese telecom provider, confirmed a breach affecting 12.2 million email addresses and 7.6 million passwords via a compromised email system used by five ISPs. The breach exploited a zero-day vulnerability in third-party software. KDDI has implemented security measures and coordinated password resets to prevent future incidents.
Supreme Court Upholds Texas App Store Age Verification Law
The US Supreme Court denied requests from trade groups, including Apple and Google, to block the enforcement of Texas's App Store Accountability Act, a law requiring age verification for app users. The law mandates that app stores verify users' ages and obtain parental consent for minors, amid constitutional debates. This development impacts how app companies handle user compliance in Texas.
Medtronic Hack Exposes Data of Nearly 4 Million People in ShinyHunters Breach
Medtronic suffered a data breach in April 2026, compromising the personal and medical information of over 3.8 million individuals, with some sources claiming 9 million records affected. The ShinyHunters group accessed Medtronic's corporate IT systems, despite the company's reassurance about device safety. Medtronic is offering credit monitoring and support services to those impacted, highlighting security vulnerabilities in healthcare technology.
Former US Air Force Members Sentenced for Multi-Year BEC and Phishing Scams
Two former US Air Force members, Chijioke Timothy Odimegwu and Harafat Mogaji, received federal prison sentences totaling 189 months for their involvement in business email compromise (BEC) and phishing campaigns. They stole over $2.4 million by redirecting legitimate wire transfers and making unauthorized financial transactions, highlighting the ongoing threat of BEC attacks to businesses.
Microsoft releases 419 security fixes, including 3 zero-days, amid AI-driven bug surge
Microsoft released patches for 419 security vulnerabilities, including three zero-days, marking one of its largest monthly counts. This surge in discovered flaws is attributed to the increasing use of AI in vulnerability discovery, leading to a significant increase in the number of issues security teams must address.
North Korean Kimsuky Group Compromises South Korean Software Vendors and Customers
The North Korean Kimsuky group (APT43) compromised South Korean collaborative-work software vendors and subsequently breached their customers in a campaign spanning 2025 and early 2026. The attacks involved remote code execution, social engineering, and malware deployment to steal customer server information and employee credentials, highlighting persistent state-sponsored supply chain threats.
Finland issues wanted notice for hacker behind Vastaamo psychotherapy data breach
Finnish police have issued a wanted notice for Aleksanteri Kivimäki after his appeal was denied. Kivimäki was convicted for hacking psychotherapy provider Vastaamo and extorting patients, with implications for cybercrime accountability.
EU files court cases against four countries over cybersecurity law delays
The European Commission has initiated legal action against Ireland, Spain, France, and the Netherlands for not implementing the NIS2 Directive, which sets standards for cybersecurity across critical sectors. The action signals the EU's commitment to bolster cybersecurity, particularly as threats to infrastructure grow.
Greek victims sue Intellexa over Predator spyware allegations
Eight Greek victims of Predator spyware have filed a lawsuit against Intellexa and 13 affiliated individuals, seeking approximately €7.6 million in damages. This case aims to address the violations of privacy and data confidentiality resulting from the unauthorized surveillance activities tied to the spyware, which have already led to significant political repercussions in Greece.
Taiwan charges two businessmen in Chinese espionage scheme
Taiwan has charged two businessmen for aiding Chinese hackers in an espionage campaign targeting political and journalistic figures. The duo reportedly provided accounts used to impersonate journalists, facilitating malware deployment against Taiwanese individuals.
$20 million drained from BONK cryptocurrency in governance attack
Attackers exploited a governance proposal to drain $20 million from the BONK cryptocurrency. BonkDAO is collaborating with law enforcement to recover the funds and has temporarily suspended activities with the coin on South Korean exchange Upbit.
Ukrainian media outlets targeted by Russian hackers amid military pressures
Ukrainian media organizations are increasingly becoming priority targets for Russian hackers, according to the SBU. This escalation in cyber warfare aims to disrupt media operations and spread disinformation, impacting public trust during the ongoing conflict.
Supreme Court ruling jeopardizes EU-US data transfer framework
A Supreme Court ruling allowing the president to dismiss independent agency heads jeopardizes the EU-U.S. Data Privacy Framework. Max Schrems plans to sue to invalidate the framework, which governs data transfers crucial for €1.7 trillion in transatlantic trade.
ShinyHunters Launches New Oracle PeopleSoft Exploitation Campaign Bypassing WAFs
Mandiant and Google Threat Intelligence Group reported that the ShinyHunters group initiated a new mass-exploitation campaign targeting Oracle PeopleSoft customers. This campaign uses a modified exploit for CVE-2026-35273 to bypass web application firewalls (WAFs), expanding its targets beyond the education sector to various industries.
Astrana Health Reports Data Breach After Social Engineering Attack
Astrana Health, a healthcare management company, disclosed a data breach where private and confidential information was exfiltrated from its servers following a social engineering attack on employees. The company is assessing the extent to which patient, employee, and business data may have been accessed.
Ofcom investigates Pornhub owner Aylo over age verification effectiveness
Ofcom has launched an investigation into Aylo, owner of Pornhub, to determine if its new age verification system effectively prevents minors from accessing adult content. The regulator is concerned Aylo may not have conducted sufficient due diligence before implementing the third-party age checks, which could leave children at risk under the UK's Online Safety Act.
UK to establish new agency to counter disinformation and deepfakes from hostile states
The UK will create a National Centre for Information Defence to combat disinformation and deepfakes from hostile states like Russia, as announced by Andy Burnham. This initiative aims to detect, attribute, and disrupt information attacks, many of which are AI-enabled, by integrating intelligence agencies, law enforcement, and social media companies.
LinkedIn wins dismissal of "BrowserGate" lawsuits over scanning user browser extensions
A US District Court judge dismissed two class-action lawsuits against LinkedIn regarding its practice of scanning users' browser extensions. The judge ruled that the plaintiffs lacked standing as they did not adequately allege that private information was conveyed to LinkedIn, indicating that a privacy violation is unlikely to be proven.
China-Aligned FamousSparrow Group Deploys New SparroWocky Backdoor in Latin America
The China-aligned threat actor FamousSparrow has been deploying a new C++ backdoor named SparroWocky in attacks targeting government agencies across Latin American countries since at least August 2025. This new modular backdoor, which replaces SparrowDoor as the group's primary implant, is capable of executing arbitrary files, acting as a TCP proxy, running commands, and collecting system information. Researchers theorize the campaign aims to monitor local government reactions to U.S. pressures in the region.
Microsoft Reports AI-Enhanced Invoice Scam Emails Targeting Businesses
Microsoft security researchers identified a new wave of business email compromise (BEC) invoice scams using AI to create more convincing and tailored fraudulent emails. Attackers are combining executive impersonation, vendor branding, and fabricated email chains to increase legitimacy, with a campaign in early August targeting over a million users, primarily in the US.
ShinyHunters claims breach of Florida DMV database, stole 200,000 driver records
The ShinyHunters hacking group claims to have breached Florida's Driver and Vehicle Information Database (DAVID) and stolen over 200,000 driver records. The group stated they exploited a password-reset flaw to gain access and are threatening to leak the data if the Florida Highway Safety and Motor Vehicles (FLHSMV) agency does not negotiate. This incident highlights vulnerabilities in government systems holding sensitive personal data.
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Seizes $52.8 Million in Crypto
The U.S. Department of Justice (DoJ) and Treasury Department took coordinated actions against Xinbi Guarantee, an illicit online marketplace, seizing $52.8 million from 52 cryptocurrency wallets and sanctioning the platform. Xinbi Guarantee, created in 2022, facilitated cyber scams, money laundering, and human trafficking, processing at least $24 billion in transactions.
US Government Designates Privacy-Oriented Host Autistici/Inventati as "Global Terrorist"
The US government classified the Italian collective Autistici/Inventati as a "Specially Designated Global Terrorist" on August 26, 2026, citing its "far-left" politics and alleged provision of tools to extremist groups. This designation impacts a volunteer-run service that offers privacy-oriented communication tools to approximately 16,000 mailboxes, 1,500 websites, 5,500 mailing lists, and 10,000 blogs.
Thomson Reuters C-Track Platform Breach Exposes US and Canadian Court Data
Thomson Reuters disclosed a data breach affecting its C-Track court case management platform, exposing sealed court information and sensitive personal data from courts in at least 12 U.S. states, the U.S. Virgin Islands, and Canada. The breach, discovered on June 30, involved unauthorized access to files from March through June, potentially compromising names, Social Security numbers, and medical information, though no misuse has been reported.
Tectonic Crypto Platform Suffers $6 Million Exploit, Cronos Blockchain Halted
The Tectonic decentralized lending platform experienced a security incident where fraudsters manipulated the price of its TONIC token, inflating it over 100 times to borrow assets. Approximately $6 million in Ethereum was stolen, leading the Cronos blockchain to halt activity and then restart, with an additional $68 million prevented from leaving the platform.
Trump Order Declares National Emergency to Block Foreign Backdoors in US Power Grid
President Trump issued Executive Order 14420, declaring a national emergency to address vulnerabilities in the US bulk power system from foreign-supplied electrical equipment. The order prohibits the acquisition, import, transfer, or installation of certain foreign-produced bulk-power equipment after August 26, 2026, if deemed to pose security risks. This aims to mitigate supply chain risks and potential embedded hardware backdoors in critical infrastructure.
UK to use Ukraine battlefield data to train AI for critical infrastructure protection
The UK has partnered with Ukraine to use battlefield data from Ukraine's Avengers AI lab to train AI models for protecting UK defense sites, railways, and energy plants. This initiative aims to identify threats like protesters or hostile state attacks using AI-optimized sensors in fiber-optic cables, with private companies also gaining access to the data.
Heights Finance Data Breach Exposes Financial and Personal Information of Nearly 750,000 Customers
Heights Finance, a debt consolidation loan company, experienced a data breach in May that exposed sensitive financial and personal information, including Social Security numbers, for approximately 734,828 customers. The breach occurred on a third-party cloud platform and did not affect the company's internal loan management systems. This incident highlights the ongoing risks associated with third-party cloud service providers and the potential for widespread data compromise in the financial sector.
Seven Arrested in €30M Commerzbank Fraud Exploiting Service Provider Flaw
Seven individuals have been arrested in Brazil and Europe in connection with a €30 million bank fraud that impacted Commerzbank customers in November 2023. The fraud exploited a vulnerability in a service provider's system, leading to unauthorized withdrawals, though Commerzbank states customers suffered no financial losses.