From The Record · 40 stories
Brazil Orders Discord to Suspend Livestreaming Feature After Teen's Death
Brazil's National Data Protection Authority (ANPD) has ordered Discord to suspend its "Go Live" livestreaming feature. This action follows an investigation into the death of a 13-year-old girl who was allegedly encouraged to take her own life during a Discord livestream. The suspension will remain until Discord implements adequate protective measures for minors, as the ANPD found the platform lacked real-time access to livestream content for automated violation detection.
New York Funds Water System Cybersecurity; Senate Bill Proposes $300M Annual Federal Aid
New York State has allocated over $9 million to 153 drinking water and wastewater systems to enhance cybersecurity defenses and comply with new state standards. Concurrently, Senate Democrats introduced the Water Cyber Shield Act, proposing $300 million annually for national water infrastructure cybersecurity improvements and expanded EPA authority, following recent cyberattacks on water systems.
UK Man Sentenced for Blackmail and Sextortion of 117 Victims as Part of 'The Com'
Justin Swaddle, a 20-year-old from Leeds, was sentenced to two years in prison for blackmail and sextortion offenses against 117 victims aged 13 to 17. Operating under aliases like 'Epstein' and 'Moscow' on platforms including Snapchat, Telegram, and Discord, Swaddle was a member of 'The Com,' an online collective whose members coerce victims into self-harm and sexual activity for peer status.
North Carolina Ports Hit by Cyberattack, Forcing Manual Operations
North Carolina Ports experienced a cyberattack that disrupted IT systems and forced a shift to manual operations across its three locations: Wilmington, Morehead City, and Charlotte. The incident, detected on August 4, led to system-wide outages and delays, though operations are gradually returning to normal with manual processing still in effect. This event highlights the ongoing vulnerability of critical infrastructure to cyber threats.
Russia Charges Telegram Founder Pavel Durov with Aiding Terrorism, Seeks Arrest
Russia's Federal Security Service (FSB) has charged Telegram founder Pavel Durov with aiding terrorist activity and placed him on an international wanted list. The FSB alleges Telegram failed to remove channels and bots used by Ukrainian special services and extremist organizations to coordinate sabotage and terrorism within Russia, resulting in casualties and financial damage. Durov has rejected the allegations, stating Russia is retaliating for his refusal to comply with demands for mass surveillance and censorship.
Liechtenstein's Register of Beneficial Owners Breached, 31,000 Records Exfiltrated
A cyberattack on Liechtenstein's Register of Beneficial Owners resulted in the exfiltration of data belonging to approximately 31,000 individuals. The breach, which occurred from Wednesday night into Thursday last week, compromised a critical financial transparency tool used to combat money laundering and terror financing in the principality.
Amgen Discloses Data Breach Affecting Patient Health and Proprietary Information
Biotechnology company Amgen reported a data breach where threat actors stole corporate data and patient information from third-party cloud systems. The unauthorized activity was detected in July 2026, leading to an ongoing investigation into the scope of the exfiltrated data, which includes proprietary information and protected health information.
FTC Sues Hims & Hers Over Alleged Patient Data Sharing with Advertisers
The Federal Trade Commission (FTC) has filed a lawsuit against telehealth provider Hims & Hers, alleging the company shared sensitive patient health information with advertising platforms such as Meta, Snap, Microsoft, Pinterest, Reddit, and X. The FTC claims Hims & Hers engaged in deceptive practices by promising privacy while sharing customer data, violating the FTC Act. This action highlights ongoing regulatory scrutiny of data privacy in the telehealth sector.
White House Launches AI-Driven Gold Eagle Initiative for Cybersecurity Coordination
The White House has launched the Gold Eagle initiative, an AI-supported federal clearinghouse for cybersecurity vulnerabilities. This program aims to enhance vulnerability detection and remediation across government and private sectors by facilitating collaboration between software maintainers and infrastructure operators. Gold Eagle is backed by multiple federal agencies and uses AI to manage cybersecurity risks efficiently.
Swiss rail manufacturer Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail rejected a $12.3 million ransom demand from the Everest ransomware gang following a data breach on a platform shared with a supplier. The company reported no impact on its IT systems or production operations, and stated only non-security-relevant technical information was stolen, demonstrating a firm stance against cyber extortion.
South Korea's diplomat training system breached by hackers for 9 months
Hackers compromised South Korea's diplomatic academy's e-learning platform for nine months, exposing employee data. This breach raises serious cybersecurity concerns, especially given the country's past experiences with North Korean cyberattacks.
Cyberattack Halts Operations of Japanese Cold-Chain Operator Nichirei, Impacts Food Supply
A cyberattack on Nichirei Logistics Group disrupted frozen food shipments in Japan, affecting major chains like KFC. Operations began partial restoration post-attack, with a focus on data safety due to potential personal data compromise.
23andMe Settles $18 Million Data Breach Case Across 42 States
23andMe will pay $18 million to settle claims from 42 states over a data breach affecting 6.9 million users, including genetic data. The settlement requires enhanced cybersecurity measures and accountability going forward. This settlement follows issues of inadequate data protection and significant delays in breach notifications.
Hacker Attack Disrupts Romania's Land Registry Operations
Romania's land registry agency suffered a cyberattack, resulting in the wiping of its database and a halt in real estate transactions. The agency is migrating its systems to the government cloud to restore operations while ensuring data integrity.
Russian Hackers Use Security Cameras to Monitor NATO and Ukrainian Military Movements
Russian intelligence services are using internet-connected security cameras across Ukraine and NATO states to gather military intelligence. This operation involves exploiting cameras with default settings or security flaws, collecting data on military logistics and weapon shipments, and targeting Ukrainian troops. The breaches pose serious security risks across Europe and Ukraine.
Dutch Police Uncover Global Crypto Scam, Arrest Alleged Leader
Dutch police dismantled a large-scale international crypto scam, arresting the alleged mastermind and several associates. The scheme, operating through 20 call centers, swindled tens of thousands, making over €100 million monthly. The main suspect is a 46-year-old Israeli-Polish known in the cyberworld, caught in Poland and extradited to the Netherlands.
Lidl Data Breach Affects Customers in Germany, Belgium, and Netherlands
Lidl, a European supermarket chain, suffered a data breach affecting online customers in Germany, Belgium, and the Netherlands. Attackers accessed customer data stored by a third-party service provider. Although no payment information was compromised, affected customers have been advised to be cautious of potential phishing scams.
Supreme Court Ruling on Location Data May Impact Automated License Plate Cameras
The Supreme Court's decision in Chatrie v. United States mandates warrants for cellphone location data, potentially affecting the use of automated license plate readers (ALPRs) like those used by Flock Safety. This could impose legal constraints on current law enforcement practices utilizing widespread ALPR networks without warrants. The case reflects broader privacy concerns about surveillance technologies and Fourth Amendment rights.
Dutch Police Probe Local Hackers in Odido Telecom Data Breach
The Dutch police are investigating local hackers in the February Odido data breach affecting 6.2 million customers. A suspect impersonated an Odido IT employee, facilitating unauthorized access through a customer contact system. Authorities are requesting public assistance to identify the caller.
Block Inc. Settles for $45M Over Cash App Security Allegations with 46 States
Block, Inc., the parent company of Cash App, agreed to pay $45 million to settle claims from 46 U.S. states over allegations of misleading users about security protections. State attorneys general accused Block of inadequate fraud protection measures which left users exposed. This settlement addresses prior consumer protection failures and requires around-the-clock customer support.
UK Unveils AI-Driven 'Cyber Shield' for Enhanced National Cybersecurity
The UK announced the Cyber Shield initiative to improve national cybersecurity through agentic AI systems. The initiative, led by the National Cyber Security Centre, focuses on countering advanced threats that exploit AI to rapidly identify vulnerabilities. This collaboration with academia and industry aims to hardwire AI advancements into national security defenses against increasingly sophisticated cyber threats.
Spanish Police Arrest Suspected Member of Pro-Russian Hacktivist Groups
Spanish authorities arrested a man in Palencia linked to pro-Russian hacktivist groups CARR and Z-Pentest following an FBI tip. The suspect is accused of aiding a hacker's escape and supporting cyber activities against Ukraine. The arrest could impact international investigations into cyber threats.
Canadian Spy Agency Conducted Cyber Operations Against Criminal Groups
In 2022, Canada's Communications Security Establishment executed cyber operations against drug traffickers, violent extremists, and a ransomware gang. These state-authorized interventions aimed to thwart groups threatening Canada's national security and public safety. The operations utilized signals intelligence to disrupt criminal activities abroad, significantly impacting the targeted groups.
Congress Considers Increased Mental Health Support for Cyber Command Personnel After Suicides
Congress is exploring new support mechanisms for U.S. Cyber Command personnel following a series of suicide deaths, aiming to address mental and emotional well-being amidst increased operational demands. This initiative highlights growing concerns about the psychological toll on military cyber operators as their missions expand in scope and intensity.
Ukrainian report details Russian mobile attacks, including iPhone exploit kit DarkSword
Ukrainian researchers reported increased targeting of military and government smartphones by Russian hackers using malicious apps and sophisticated exploits for both Android and iOS devices. The report highlights the use of DarkSword, an iPhone exploit kit, in watering-hole attacks to steal sensitive information.
Spyware Firm Paragon to Go Public via SPAC Merger with Bold Eagle Acquisition Corp.
Paragon Solutions, a spyware manufacturer, will become publicly traded on Nasdaq by the end of the year through a merger with Bold Eagle Acquisition Corp. and its parent company REDLattice. This move provides capital for growth and increases transparency through public SEC filings, despite past controversies regarding its spyware use.
Dodo Pizza confirms cyberattack, customer data potentially compromised
Russian fast-food chain Dodo Pizza confirmed a cyberattack that potentially exposed customer names, addresses, email addresses, phone numbers, dates of birth, and order details. The hacking group DataSuckers claimed responsibility, stating they accessed databases for 68 million customers and 15 years of order history, though Dodo Pizza did not confirm the number of affected customers.
Arizona Supreme Court reports data breach, personal information of residents stolen
The Arizona Supreme Court announced that its court system was attacked by hackers who stole the personal information of "many Arizonans." The incident did not involve ransomware, and no ransom demands have been made.
Polish medical software provider Qbusoft suffers data breach via SQL injection
Qbusoft, a Polish medical software provider, experienced a data breach in August due to an SQL injection vulnerability in its Medyc platform. The attack exposed patient names, national identification numbers, addresses, phone numbers, and email addresses, with a high likelihood of medical records also being compromised.
Labcorp fined $2.3M and mandated to overhaul data security after 2019 breach
Labcorp will pay a $2.3 million fine and implement extensive data security reforms following a 2019 data breach that affected 10.2 million customers. A coalition of 44 state attorneys general settled a lawsuit, requiring Labcorp to improve vendor oversight and data protection practices.
Welsh Police Force Suffers Cyberattack, Staff Data Potentially Compromised
Dyfed-Powys Police in Wales experienced a cyberattack that disrupted non-emergency systems and may have compromised staff information. The incident, identified earlier this month, is under investigation to determine the extent of employee data access, though no public data appears affected.
Digital Forensics Firm Oxygen Forensics Accused of Hiding Russian Ownership from US Agencies
The Department of Justice arrested two principals of Oxygen Forensics, alleging the company concealed its Russian ownership and software origin while securing contracts with US federal agencies. The firm sold digital forensics software to the Departments of Defense and Homeland Security, falsely claiming US development. This raises concerns about supply chain integrity for sensitive government tools.
Senators introduce bill for voluntary telecom cybersecurity rules after Salt Typhoon hacks
Senators Mark Warner and Ted Cruz introduced the Telecommunications Cybersecurity and Resilience Act, which proposes voluntary cybersecurity best practices and an optional certification for the telecommunications industry. This initiative responds to the Salt Typhoon attacks, where Chinese hackers breached major U.S. telecom companies over several years, accessing sensitive call data.
Kyiv Internet Providers Report Major Outages After Russian Attacks Damage Data Centers
Russian drone strikes damaged data centers and telecommunications infrastructure in Kyiv, causing internet outages for thousands of households. Several internet providers, including Kyiv Link, Pautina, Utels, and Crazy Network, experienced partial connectivity losses. The attacks disrupted critical civilian infrastructure, impacting access to information for residents.
US Intelligence Finds No Successful Foreign Meddling in 2024 Election
US intelligence agencies found no evidence of successful foreign interference in the 2024 presidential election, according to a classified assessment. The report, however, noted that Russia, Iran, and China conducted influence campaigns, with Russia's efforts being the most significant.
Russian Internet Shutdowns Disrupt Drone Attack Warnings, Endangering Civilians
Russia's increasing restrictions on mobile internet and cellular service are hindering citizens' ability to receive timely warnings about incoming Ukrainian drone and missile attacks. These shutdowns, intended to prevent drones from using cellular networks, also disrupt digital alert systems like Telegram, leading to delayed or absent warnings for residents.
Belgian Table Tennis and Gymnastics Federations Hit by Cyberattacks
The Royal Belgian Table Tennis Federation (FRBTT) and its French-speaking branch (AFTT) are investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members and users. A separate cyberattack also affected Belgium's French-speaking Gymnastics Federation (FfG), with a hacker claiming responsibility for both incidents. This highlights ongoing cybersecurity vulnerabilities within sports organizations.
University of Munich Investigates Cyberattack Exposing Student Financial Data
Ludwig Maximilian University of Munich is investigating a cyberattack that accessed student enrollment data, potentially exposing financial aid and health insurance information. The incident affects personal and financial details of students, prompting an ongoing investigation with law enforcement and cybersecurity specialists.
Hackers Claim Breach of Russian Election Systems Ahead of Parliamentary Vote
An anonymous hacking group, CikLeak, claims to have breached systems connected to Russia's election infrastructure, including the Central Election Commission and its contractors, days before parliamentary elections. The group states it stole internal documents, server configurations, passwords, and employee communications, providing them to an independent investigative outlet. This incident raises concerns about the security of the Vybory 2.0 platform, which is being used for the first time in a federal election.
Nations Act on North Korean IT Worker Scheme After UN Report
Multiple countries have initiated legal actions against North Korean IT workers or their facilitators following a UN report detailing Pyongyang's illicit IT worker scheme. These actions include investigations, asset freezes, and detentions in response to North Koreans using stolen or purchased IDs to secure high-paying IT roles and funnel earnings back to North Korea.