From The Record · 40 stories
Nations Act on North Korean IT Worker Scheme After UN Report
Multiple countries have initiated legal actions against North Korean IT workers or their facilitators following a UN report detailing Pyongyang's illicit IT worker scheme. These actions include investigations, asset freezes, and detentions in response to North Koreans using stolen or purchased IDs to secure high-paying IT roles and funnel earnings back to North Korea.
BlackCore trained Angolan officials in online influence operations, Citizen Lab reports
Israeli contractor BlackCore reportedly trained Angolan government officials in online influence operations, including creating fake social media personas and promoting government narratives. This highlights the growing use of private firms for state-sponsored online manipulation, raising concerns about information integrity and democratic processes.
NSA reorganizes into five mission centers focusing on cyber, AI, and global intelligence
The National Security Agency (NSA) is undergoing a rapid reorganization, replacing existing directorates with five new mission centers focused on China, cybersecurity, artificial intelligence, combat support, and global intelligence. This restructuring aims to accelerate the delivery of intelligence to operational environments, impacting how the agency addresses modern threats and leverages emerging technologies.
Treasury Urges Banks to Report Cyber Scams After $13 Billion in Losses Since 2023
The U.S. Treasury Department's FinCEN released an alert and study detailing nearly $13 billion in cyber scam losses between September 2023 and December 2025, urging financial institutions to increase vigilance and reporting. The report highlights the increasing rate of transnational cyber fraud, including cryptocurrency investment scams, affecting all age groups.
U.S. Cyber Command Appoints Ronzelle Green as New Chief AI Officer
U.S. Cyber Command appointed Ronzelle Green, former head of R&D at NGA, as its new Chief AI Officer, replacing Brig. Gen. Reid Novotny. This appointment is part of the military's effort to integrate AI into digital operations, with Cyber Command's AI budget request increasing significantly for fiscal 2027.
Wildberries Reports DDoS Attack Delayed Seller Payments, Ukrainian Intelligence Claims Responsibility
Russian e-commerce giant Wildberries stated a DDoS attack caused delays in payments to some sellers, with billions of rubles reportedly outstanding. Ukraine's military intelligence claimed responsibility for a cyberattack earlier in August that disrupted Wildberries' operations.
UK National Cyber Force Appoints Third Commander
The UK's National Cyber Force (NCF) has appointed its third commander since its establishment in 2020. This appointment continues the NCF's mission to consolidate offensive cyber capabilities and counter state threats, support military operations, and disrupt criminals.
CISA Acting Director Warns of Significant Cybersecurity Vulnerabilities and Need for Rapid Change
The acting director of the Cybersecurity and Infrastructure Security Agency (CISA) warned about severe cybersecurity vulnerabilities, citing past government errors, outdated technology, and AI as major threats. CISA plans to hire approximately 600 new staff to address these challenges and improve national cybersecurity defenses.
FBI Releases First Public Cybersecurity Strategy to Combat Cybercrime and Nation-State Hacking
The FBI published its first public cybersecurity strategy, outlining how the agency will counter malicious hackers and digital criminal gangs. This strategy aims to prioritize efforts against increasing cybercrime complexity and sophistication, building on previous classified approaches and recent operational successes.
CIA Official Credits Cyber Mission Center for Maduro's Capture
A CIA official stated that the agency's Cyber Mission Center provided critical intelligence for the capture of Venezuelan President Nicolás Maduro. This marks a rare public acknowledgment of the CIA's cyber operations and the center's role in a major military operation.
French Authorities Arrest Suspected ZeroBytes Hacker in Tax Authority Cyberattack
French prosecutors confirmed the arrest of an 18-year-old suspected member of the ZeroBytes hacking group in connection with cyberattacks targeting the country's tax authority and other organizations. This arrest addresses a recent data breach affecting the Directorate General of Public Finances (DGFiP) and highlights ongoing efforts to counter cybercrime groups operating in France.
US Offers $10 Million Reward for Information on Iranian Cyberattack Leader
The U.S. State Department has offered a $10 million reward for information leading to the location of Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps’ (IRGC) Cyber-Electronic Command (CEC). Yaryab allegedly directs multiple Iranian hacking groups that have targeted critical infrastructure sectors in the U.S., Europe, and the Middle East, impacting defense, energy, and telecommunications systems.
US and UK to Coordinate Efforts to Dismantle Scam Centers
The United States and United Kingdom signed a memorandum of understanding to coordinate investigations and information sharing to shut down scam centers, primarily located in Southeast Asia, that are responsible for billions in fraud. This collaboration aims to target organized crime syndicates running these centers, which often use human trafficking victims to conduct investment and romance scams.
UK account-hack losses rise 417% due to new reporting system, not necessarily more attacks
Reported financial losses from hacked online accounts in the UK increased by 417% to £6.3 million in the last financial year, with the number of victims rising 929%. This surge is primarily attributed to the introduction of the new "Report Fraud" system, which replaced the less effective "Action Fraud" system, leading to more incidents being reported rather than a direct increase in attacks.
Russian Data Centers Face New Security Requirements Amid Drone Threats
Russian data centers are increasing physical security spending due to new government requirements aimed at protecting critical infrastructure from Ukrainian drone attacks. A recent decree allows the government to take control of facilities that fail to adequately protect against such threats, impacting data centers, especially those serving government, banking, and major service providers.
VantaCore, a new pro-Ukraine hacker group, targets Russian companies with custom ransomware
A new pro-Ukrainian hacker group named VantaCore is targeting Russian organizations with custom ransomware, demanding multi-million dollar payments. This group, believed to be a rebrand of the Thor ransomware operation, uses proprietary tools for encryption, distribution, and system control, indicating an evolution in their tactics.
Hackers Expose Donor Data from Russian Fundraisers for Ukrainians and Political Prisoners
Two Russian fundraising projects, Davayte and You Are Not Alone, reported that hackers accessed their payment accounts in mid-August, exposing donor email addresses and partial payment card information. The breach occurred through an integration between Stripe and WooCommerce used for online auctions, affecting projects supporting Ukrainian civilians and Russian political prisoners.
McKesson reports 'service degradation' and data exfiltration after cyberattack
Pharmaceutical and healthcare technology company McKesson is investigating a cyberattack on a third-party application that caused service degradation and data exfiltration from its oncology and surgical business units. The ShinyHunters cybercriminal group has claimed responsibility for the attack, which could impact customer data and service availability for a major healthcare provider.
Finnish Appeals Court Revives Case Against Eagle S Officers for Subsea Cable Damage
A Finnish appeals court reinstated the prosecution of three senior officers from the oil tanker Eagle S, which severed multiple subsea cables in the Baltic Sea. The court ruled Finland has jurisdiction because the damage and its effects occurred within Finland, overturning a previous district court decision.
German Companies Report Increased Cyberattacks from Chinese and Russian Intelligence Services
A survey by Bitkom indicates that foreign intelligence services, particularly from China and Russia, are increasingly responsible for cyberattacks on German companies, with nearly 40% of affected businesses attributing incidents to state actors. This rise in state-sponsored cyber activity highlights an evolving threat landscape where the distinction between criminal groups and intelligence services is blurring, posing significant economic costs to German businesses.
NSA Hosts Reunion for Secretive Hacking Unit to Boost Recruitment
The National Security Agency (NSA) is hosting a reunion for former members of its Tailored Access Operations (TAO) unit, a secretive hacking group responsible for breaking into foreign computer systems. This event is part of an effort to recruit former employees back to the agency and revitalize the organization.
UK Government Seeks Secret Powers to Block Risky Tech Suppliers in Critical Sectors
The UK government is proposing new powers through amendments to the Cyber Security and Resilience Bill, allowing it to secretly ban technology vendors deemed national security risks from supplying critical sectors. These powers expand beyond telecommunications to include managed service providers, data centers, digital infrastructure, and essential services like energy, water, transport, and health, without public disclosure of the banned vendor.
Lawmakers Request GAO Investigation into CISA Staffing Cuts and Impact on Cybersecurity
Members of Congress have asked the Government Accountability Office (GAO) to investigate the effects of significant staffing reductions at the Cybersecurity and Infrastructure Security Agency (CISA) on its ability to protect critical infrastructure. Nearly one-third of CISA's workforce was cut since the start of the Trump administration, raising concerns about the agency's capacity to address evolving cyber threats. This investigation is important because it could reveal vulnerabilities in national cybersecurity defenses due to reduced personnel and expertise.
Russian Network Monitoring Firm Microolap Confirms Cyberattack, Denies Major Data Breach
Russian software developer Microolap confirmed that some of its non-critical systems were compromised by hackers but denied claims of access to its core network monitoring platform or theft of major company data. This incident highlights ongoing cyber warfare activities and the challenges companies face in controlling narratives around security breaches.
Latvian Officials Resign After Cyberattack Exposes Data of 1.2 Million People
Latvia's Road Traffic Safety Directorate (CSDD) confirmed a cyberattack exposed data from payment receipts for 1.2 million people and 200,000 businesses, leading to resignations of officials. This breach affects a significant portion of Latvia's population and raises concerns about potential social engineering and fraud schemes.
University of Texas at San Antonio takes systems offline after cyberattack
The University of Texas at San Antonio (UTSA) took several systems, including phones, offline after detecting cyberattack activity on its academic campus. This disruption occurred just before classes were set to begin, affecting student services like course registration and payment deadlines. UTSA's chief technology officer stated that the threat was contained at the network edge, with no evidence of data access or exfiltration found so far.
Ukrainian Agency Managing Seized Russian Assets Reports Cyberattack
Ukraine's Asset Recovery and Management Agency (ARMA) reported a cyberattack targeting its operations, which occurred amidst preparations to select a manager for seized corporate rights in IDS Ukraine. The agency is investigating whether the incident is part of a coordinated effort to disrupt its work, particularly concerning assets linked to sanctioned Russians.
Ukraine Claims Cyberattack on Russian E-commerce Giant Wildberries Amid Drone Strikes
Ukraine's military intelligence claims it disrupted operations of Wildberries, Russia's largest online marketplace, through a cyberattack. This action was intended to amplify the impact of recent drone strikes on the company's infrastructure, which Ukraine states plays a role in Russia's logistics and war financing.
Germany's Cabinet Approves Legislation Granting Spy Agencies Hacking and Sabotage Powers
Germany's cabinet approved legislation that would allow its intelligence agencies to hack foreign systems, sabotage supply chains, and disseminate false information to extremists within Germany. This overhaul of post-war spy laws is justified by a changing threat environment, including drone incidents and terrorist attacks.
UK Criminal Records Office Breached for Two Years Due to Unpatched Systems and Unread Alerts
The UK's ACRO Criminal Records Office received a reprimand from the Information Commissioner’s Office (ICO) after three intrusions over nearly two years exposed personal data, including that of domestic violence victims. The breaches occurred due to unpatched systems and ignored security alerts, highlighting significant security failures within the organization.
NSA Appoints Kerianne Tobitsch as New General Counsel
The National Security Agency (NSA) has appointed Kerianne Tobitsch, formerly a senior lawyer at the Department of Homeland Security (DHS), as its new general counsel. This appointment fills a key legal role that had been vacant for approximately a year and is critical for overseeing clandestine operations and advising on legal matters like FISA Section 702.
Cyberattacks Disrupt Government Services in California, Oklahoma, and South Dakota
Local governments in Suisun City, California, Coweta, Oklahoma, and Mitchell, South Dakota, experienced cyberattacks that disrupted public services, including 911 systems and city operations. These incidents highlight the ongoing vulnerability of municipal infrastructure to cyber threats and the immediate impact on citizen services.
New Zealand Sanctions Russian Hackers and Propaganda Groups Over Ukraine War Involvement
New Zealand imposed sanctions on 33 Russian individuals and entities, including hackers and propaganda groups, for their roles in supporting Russia's war against Ukraine. These sanctions target those involved in cyberattacks, disinformation campaigns, and alleged abductions of Ukrainian children. The action aligns New Zealand with other Western governments that have previously sanctioned some of these individuals for malicious cyber activities.
National Rural Water Association Partners with DEF CON Franklin to Launch Water Watch Center
The National Rural Water Association (NRWA) has partnered with DEF CON Franklin to create the Water Watch Center (WWC), a program providing threat intelligence and cybersecurity services to small water utilities. This initiative addresses recent cyberattacks on water systems in multiple states and aims to support the 91% of U.S. community water systems that serve fewer than 10,000 people.
Senate Confirms Adam Cassady as US Cyber Ambassador
The US Senate confirmed Adam Cassady as the next U.S. ambassador for cyber and digital policy, filling a position that has been vacant since the previous administration. This appointment is significant as Cassady will lead the Bureau of Cyberspace and Digital Policy, which recently underwent a reorganization and staff reduction.
Military Device Manufacturer IEH Corporation Discloses Cyber Incident to SEC
IEH Corporation, a manufacturer of specialized military components, disclosed a cyber incident to the SEC after an employee fell victim to a phishing attack. Intruders gained access to an email inbox containing sensitive information, including export-controlled technical data, though there is no evidence data was exfiltrated. This incident highlights ongoing cybersecurity risks for defense contractors and the potential exposure of critical military supply chain information.
House Committee Report: Chinese Telcos Maintain US Presence Despite Security Concerns
A bipartisan House Select Committee on China investigation found that China Mobile, China Unicom, and China Telecom retain significant presence in the U.S. internet ecosystem, despite previous FCC license revocations due to cybersecurity risks. The committee concluded these companies are not independent from the Chinese government and urged Congress to strengthen the FCC's authority to remove their technology from U.S. infrastructure. This matters because it highlights ongoing national security concerns regarding foreign influence in critical telecommunications networks.
De Bijenkorf warns customer data may be exposed after cyber incident at logistics partner
Dutch retailer De Bijenkorf reported a cyber incident affecting one of its logistics providers, potentially exposing customer data and causing delays in orders, returns, and refunds. The incident highlights the ongoing risk to retailers from attacks targeting third-party contractors.
Żabka convenience store chain hacked via third-party account, internal systems exposed
Polish convenience store chain Żabka experienced a cyberattack that exposed internal company systems after attackers compromised a third-party contractor's account. The breach did not affect payment systems, transaction data, the Żappka loyalty app, or day-to-day store operations, according to the company and Polish authorities. This incident highlights the supply chain risk posed by third-party vendor access to internal systems.
U.S. Cyber Command to open Silicon Valley office to foster tech sector relationships
U.S. Cyber Command plans to establish an outpost in Silicon Valley, named Cyber Command-West (CC-W), to build relationships with the tech sector and accelerate the development of cyber capabilities. This initiative is part of the "CYBERCOM 2.0" modernization effort, aiming to bridge the gap between technology demonstration and government acquisition for timely deployment in digital operations.