August 2026 saw cyber threats cut across an unusually diverse range of sectors, from logistics and financial services to healthcare, government and critical infrastructure. Major incidents involving CEVA Logistics, the French Tax Authority, Sakura Internet, RingCentral, SafePal, CareCloud and Apollo Global Management demonstrated that both large enterprises and public-sector organisations remain attractive targets for cybercriminals.
Particularly concerning were attacks affecting UK power infrastructure and Minnesota municipal water systems, once again bringing the cybersecurity of essential services into focus. Meanwhile, incidents targeting US hedge funds highlighted the persistent risks facing organisations entrusted with high-value financial data and transactions.
The biggest cyber attacks and data breaches of August 2026 offer important lessons in third-party risk management, identity and access security, ransomware resilience, data protection and critical infrastructure defence.
In this monthly roundup, we examine the incidents that made headlines, what is known about their impact, and the practical cybersecurity lessons organisations can take from them to strengthen their own cyber resilience.
|
Date |
Victim |
Summary |
Threat Actor |
Business Impact |
Source Link |
|
August 7, 2026 |
Fidelity Services Group |
South Africa’s largest private security company suffers data breach |
Ransomhouse |
Ransomhouse compromised Fidelity Services Group’s systems and leaked stolen company data after an extortion attempt failed. Fidelity isolated affected systems and investigated the incident but said customer and third-party information had not been breached. |
|
|
August 11, 2026 |
Organisations across multiple sectors, with the DeadLock leak site listing around 80 victims mainly in Europe. |
DeadLock ransomware uses blockchain to resist infrastructure takedown |
DeadLock ransomware operators and affiliates |
DeadLock ransomware operators used double-extortion tactics to steal and encrypt victims’ data, while adopting blockchain-based infrastructure on the Polygon network and the decentralized Session network to make their communications and leak operations harder for law enforcement to disrupt or take down. |
DeadLock ransomware uses blockchain to resist infrastructure takedown |
|
August 13, 2026 |
An unnamed organisation |
Akira ransomware scum blocked victim's security tools – and broke their own encryptor |
Akira ransomware affiliate |
The Akira affiliate had gained access through a SonicWall SSL VPN account that lacked MFA, stolen credentials and data from file shares, and then rebooted the victim’s computer into Safe Mode to disable security tools; however, the restricted environment caused Akira’s encryptor to fail before it could encrypt the endpoint. |
|
|
August 17, 2026 |
Shell |
Shell investigates data breach: Cl0p ransomware group |
Cl0p (Cl0p ransomware group) |
Shell investigated a potential breach after Cl0p claimed it had stolen about 89 GB of sensitive company data, including engineering drawings, facility reports, photos and project plans, although Shell had not confirmed that its systems were compromised. |
|
|
August 17, 2026 |
General Electric (GE) and Philips |
Philips and GE investigating Clop ransomware data theft claims |
Clop ransomware group |
Clop claimed it had breached GE and Philips and stolen sensitive data, while Philips confirmed that an attempted compromise of an internal enterprise server had been contained without affecting customer environments, and GE said it was assessing the potential incident. |
Source: Bleeping Computer |
|
August 17, 2026 |
Multiple major companies, including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Wyndham Hotels, Hexaware and Kyndryl |
Hacker claims 3.6 million Azure account records stolen from major companies |
TheHatman |
TheHatman claimed to have stolen about 3.64 million employee and tenant records from the Azure environments of several major companies using compromised credentials, exposing names, employee IDs, email addresses, job titles, phone numbers, addresses and service-account information, although some affected companies said they found no evidence their systems had been breached. |
Source: Bleeping Computer |
|
August 18, 2026 |
Brighton East Dental Clinic |
Patient data potentially compromised in alleged dental clinic data breach |
INC Ransom |
INC Ransom claimed it had breached Brighton East Dental Clinic and published about 37 GB of data, including patient dental X-rays, referral and treatment details, medical correspondence, diagnosis recordings, consent forms and other sensitive internal documents dating from 2003 to 2025. |
|
|
August 19, 2026 |
More than 500 U.S. critical infrastructure organisations across healthcare, defence, critical manufacturing, government services, IT and financial services, as well as medical, education, legal, insurance and technology organisations. |
Medusa ransomware hit over 500 critical infrastructure organisations |
Medusa ransomware gang |
Medusa ransomware had breached more than 500 critical infrastructure organisations since June 2021, disrupting and compromising organisations across multiple sectors and increasing the risk of data theft, operational disruption and ransom-driven extortion. |
Source: Bleeping Computer |
|
August 21, 2026 |
U.S. Bank, formally known as U.S. Bancorp. |
LockBit Claims US Bank Data Breach |
LockBit |
LockBit claimed it had breached U.S. Bank and threatened to leak the stolen data by September 4. But no data sample has been released, so the extent and type of information allegedly compromised remains unconfirmed while the bank investigated the claim. |
Source: cybernews.com |
|
Date |
Victim |
Summary |
Threat Actor |
Business Impact |
Source Link |
|
August 2, 2026 |
UK Government Investments (UKGI) |
UK's State Investments Agency Hit by Data Breach |
Unknown |
A data breach exposed sensitive internal information and the personal details of 51 UK government officials after data was left publicly accessible for around 40 hours due to a failure to follow security procedures. |
Source: www.theguardian.com |
|
August 2, 19, 2026 |
CareCloud |
CareCloud Breach Exposed Medical and Financial Data of 345,000 People |
Unknown |
Hackers stole sensitive information belonging to more than 3.75 million CareCloud patients, including names, addresses, Social Security numbers, medical and health records, government IDs, and banking and financial information. |
|
|
August 3, 2026 |
Allstate |
Allstate Breach Claim Raises Questions About Scope of Exposure |
Unknown |
Claims of a potential data breach at Allstate raised concerns that customer information may have been exposed, prompting scrutiny over the scope of the incident and the potential risk to affected individuals. |
Source: www.insurancebusinessmag.com |
|
August 3, 2026 |
Police National Legal Database (PNLD) |
PNLD Breach Exposes UK Police and Intelligence Data in Major Security Incident |
Unknown |
A data breach exposed sensitive information from the Police National Legal Database, including data related to UK police and intelligence personnel, raising concerns over national security and the potential misuse of confidential law enforcement information. |
Source: thehackernews.com |
|
August 4, 2026 |
Madera Community Hospital |
150,000 Impacted by Madera Community Hospital Data Breach |
Unknown |
A data breach exposed the personal and protected health information of approximately 150,000 Madera Community Hospital patients, increasing the risk of identity theft, medical fraud, and phishing attacks. |
Source: securityweek.com |
|
August 4, 2026 |
Paidwork |
Paidwork Data Breach |
Unknown |
A data breach exposed Paidwork users' personal information, prompting a legal investigation and increasing the risk of identity theft, phishing, and other fraudulent activity for affected individuals. |
Source: prnewswire.com |
|
August 5, 2026 |
MCBS |
MCBS Data Breach Affects 1.2 Million Individuals |
Unknown |
A data breach exposed the personal information of approximately 1.2 million individuals associated with MCBS, increasing the risk of identity theft, phishing, and other forms of fraud for those affected. |
Source: securityweek.com |
|
August 5, 2026 |
Everside Health |
Everside Health Data Breach Exposes Personal Information, Murphy Law Firm Investigates Legal Claims |
Unknown |
A data breach exposed the personal information of Everside Health patients and other affected individuals, increasing the risk of identity theft, healthcare fraud, and phishing attacks while prompting a legal investigation. |
Source:globenewswire.com |
|
August 5, 2026 |
CTS Journey Holdings LLC |
CTS Journey Holdings LLC Data Breach: Edelson Lechtzin LLP Launches Investigation into Exposure of Personal Information |
Unknown |
A data breach exposed the personal information of individuals associated with CTS Journey Holdings LLC, increasing the risk of identity theft, phishing, and financial fraud while prompting a legal investigation. |
Source:globenewswire.com |
|
August 5, 2026 |
Brown Health Medical Group-MA |
Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals |
Unknown |
Hackers accessed a legacy file server at Brown Health Medical Group-MA and potentially exposed the personal, medical, employment, government ID, payment-card, and financial information of 311,760 individuals, although its electronic health record system was not affected. |
Source: securityaffairs.com |
|
August 5, 2026 |
Snowflake customer organisations, including AT&T, Ticketmaster, Santander, Advance Auto Parts, and others |
Canadian pleads guilty to Snowflake cloud data-theft attacks |
Connor Riley Moucka (also known as Alexander Moucka and Waifu), along with John Erin Binns. |
Attackers accessed Snowflake accounts that lacked MFA and stole terabytes of sensitive data from at least 165 organisations, affecting more than 100 million people and causing victims over $9.5 million in losses while the attackers also obtained cryptocurrency through extortion. |
Source: Bleeping Computer |
|
August 6, 2026 |
Brazil’s Health Surveillance Information System (SISVISA) |
Exposed SISVISA database leaks 102,000 Brazilian health surveillance records |
Unknown |
An unsecured SISVISA database exposed 102,215 files totaling about 79 GB, including names, addresses, tax IDs, identity documents, photographs, fingerprints, inspection reports and other health-surveillance records, creating significant risks of identity theft, fraud and impersonation. |
Source: securityaffairs.com |
|
August 6, 2026 |
Moody Bible Institute of Chicago |
Moody Bible Institute of Chicago Data Breach |
Unknown |
A data breach exposed personal information belonging to individuals connected with Moody Bible Institute of Chicago, prompting a legal investigation and raising concerns about potential identity theft, fraud, and phishing risks. |
Source: prnewswire.com |
|
August 7, 2026 |
Ace & Tate customers |
Ace & Tate reports data breach at logistics company |
A security incident at Ace & Tate's logistics partner exposed customers' names, addresses, email addresses, phone numbers, order details and tracking information, while financial data, usernames and passwords remained unaffected. |
Source: retaildetail.eu |
|
|
August 7, 2026 |
Framework |
Computer maker Framework notifies ‘all customers’ of a data breach |
Unknown |
Hackers accessed Framework’s cloud instance through an upstream Metabase breach and stole customers’ names, email addresses, phone numbers and physical addresses, while payment information was not exposed. |
Source: Tech Crunch |
|
August 7, 2026 |
Unlimited Technology Systems and patients of the healthcare providers it served |
Unlimited Technology Systems breach impacts 3.8 million people |
Unknown |
Hackers accessed files at Unlimited Technology Systems' commercial data center for five days in October 2025, potentially exposing the sensitive personal and medical information of 3,803,750 people, including Social Security numbers, government IDs, insurance details and diagnosis information. |
Source: Bleeping Computer |
|
August 7, 2026 |
Levi Strauss & Co. (Levi’s) |
Levi Strauss & Co. says hackers stole corporate data in cyber attack |
Unknown |
Hackers socially engineered three Levi’s employees to access their company-issued computers and steal corporate data, but the company contained the intrusion quickly and said customer data and business operations were not affected. |
Source: Bleeping Computer |
|
August 11, 2026 |
CEVA Logistics and multiple customers that relied on its logistics services, including Valve/Steam, Bol, De Bijenkorf, Ace & Tate and Ajax. |
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers and beyond |
Unknown |
Attackers gained access to CEVA Logistics systems between July 29 and August 1, 2026, disrupting operations at eight European warehouses and potentially exposing customer and shipment information; the incident caused shipping delays and affected several businesses, while Valve said European Steam hardware customers’ names, addresses, phone numbers, email addresses and order details may have been compromised. |
Source: The Record |
|
August 11, 2026 |
The Shrewsbury and Telford Hospital Charity |
Data breach hits hospital charity supporters |
Unknown |
The Shrewsbury and Telford Hospital Charity was affected by a third-party Beacon CRM breach that exposed sensitive donor and supporter information, including names, addresses, email addresses, phone numbers and membership or donation details, although payment-card information was not involved and no misuse had been identified. |
Source: The BBC |
|
August 12, 2026 |
Yorkshire’s Brain Tumour Charity |
Brain tumour charity latest victim of cyber breach |
Unknown |
Yorkshire’s Brain Tumour Charity became the latest organisation affected by a cyber breach, with the incident raising concerns over the security of information held by the charity and prompting it to investigate the compromise. |
Source: The BBC |
|
August 12, 2026 |
Multiple organisations worldwide |
City-Forum data-theft attacks target Salesforce, ServiceNow portals |
Unknown |
The City-Forum campaign had exploited overly permissive guest-user settings in Salesforce and ServiceNow portals to enumerate and steal data that organisations had unintentionally exposed to unauthenticated users, with the activity affecting organisations globally and continuing to increase. |
Source: Bleeping Computer |
|
August 12, 2026 |
Kovack Financial, LLC |
Kovack Financial Data Breach Allegedly Exposed Social Security Numbers and Financial Account Information |
Unknown |
An unauthorised actor had accessed files within Kovack Financial’s network between August 8 and August 27, 2025, and the company later determined that the files contained sensitive information, including Social Security numbers, financial account information and driver’s license numbers; Kovack began notifying affected individuals on August 10, 2026. |
Source: prnewswire.com |
|
August 12, 2026 |
Uber Freight, the logistics subsidiary of Uber |
Uber Freight is reportedly investigating a data breach over hacker group claims |
Helix |
Helix claimed that it had breached Uber Freight and stolen data from its cloud environment, including mailboxes, cloud storage, accounts-payable files and dispatch documents, while Uber Freight investigated the claims and said its business operations had remained unaffected. |
Source: Tech Crunch |
|
August 13, 2026 |
MyDr, a healthcare system used by doctors and medical institutions across Poland |
A massive data breach in Poland affected nearly 19 million people |
Unknown |
A massive breach of the MyDr healthcare system exposed data potentially affecting nearly 19 million people, with more than 2 terabytes of information reportedly stolen, including prescription details, medical appointments, medications and documents; around 12,000 medical facilities were connected to the affected system while Polish authorities investigated the incident. |
|
|
August 13, 2026 |
Trezor customers |
Nearly 14,000 Trezor customers exposed in ShipMonk data breach |
Unknown |
An unauthorised party had breached ShipMonk, Trezor’s shipping partner, exposing the names, email addresses, phone numbers and shipping addresses of thousands of Trezor customers, while Trezor said its own systems, wallet devices and customer funds had remained secure; the exposed information could have increased the risk of targeted phishing and social-engineering attacks. |
Source: newsbytesapp.com |
|
August 14, 2026 |
French individual and professional taxpayers |
French taxpayers' data stolen in cyber attack, French Finance Ministry say |
Unknown |
French taxpayers’ personal and professional data were stolen in a cyber attack, exposing sensitive information and creating potential risks of fraud, identity theft and misuse of financial data while authorities investigated the scope of the breach. |
Source: Reuters |
|
August 14, 2026 |
RingCentral |
RingCentral data breach exposed information of 1.6 million accounts |
ShinyHunters |
RingCentral suffered a breach after a sophisticated social-engineering attack compromised its systems and exposed personal information linked to about 1.6 million accounts, including names, email addresses, phone numbers and physical addresses, although its core platform continued operating without disruption. |
Source: Bleeping Computer |
|
August 14, 2026 |
Beacon CRM and more than 1,000 charity and nonprofit organisations using its platform |
Over 1,000 Charities Hit by Beacon CRM Data Breach |
Unknown |
Beacon’s CRM breach exposed customer database backups after attackers used a compromised AWS access key, potentially affecting personal information such as names, phone numbers, email addresses and postal addresses across more than 1,000 charities, while no known cybercrime group had claimed responsibility. |
Source: Security Week |
|
August 15, 2026 |
Sogang University |
Sogang University data breach exposes 180,000 student, staff accounts |
Unknown |
Sogang University suffered a cyber attack that exposed names, student/staff ID numbers, affiliations, email addresses, mobile numbers and encrypted login passwords of about 180,000 people, prompting the university to block the attacker’s IP address, restrict the affected service and strengthen its security monitoring. |
Source: koreajoongangdaily.com |
|
August 17, 2026 |
SafePal customers |
40,000 impacted by SafePal data breach |
Unknown |
SafePal disclosed that attackers exploited a vulnerability in its order-tracking plugin and stole personal information of about 39,798 customers, including names, addresses, email addresses, phone numbers and order details, while wallet credentials and financial information were not affected. |
|
|
August 18, 2026 |
Heights Finance |
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach |
Unknown |
The breach exposed sensitive financial and personal information of 734,828 people, including bank account and routing details, Social Security numbers, tax IDs, driver’s license/state ID numbers and other customer information, although the company said its core loan systems and networks were not affected. |
Source: The Record |
|
August 18, 2026 |
Bits of Gold and approximately 200,000 customers |
Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers |
Unknown |
Bits of Gold suffered a third-party data breach that exposed customer names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details and public wallet addresses, while customer funds, passwords and private keys remained unaffected. |
Source: coindesk.com |
|
August 19, 2026 |
Latvia’s Road Traffic Safety Directorate (CSDD), affecting more than 1.2 million people and about 200,000 businesses and other legal entities. |
Latvian officials resign after cyber attack exposes data on 1.2 million people |
Unknown |
Hackers accessed historical CSDD payment records and stole personal and vehicle-related information, including identification numbers, license plates, payment details and registered addresses, potentially exposing more than 1.2 million people and 200,000 entities to fraud and social-engineering attacks, although CSDD’s daily services remained operational. |
Source: The Record |
|
August 19, 2026 |
Paylogix, LLC |
Paylogix Data Breach Exposes Personal Information |
Unknown |
Cybercriminals infiltrated Paylogix’s network between November 13 and November 18, 2025, and potentially accessed files containing sensitive information of thousands of individuals, including names, Social Security numbers, financial account details, payment card information and driver’s license numbers, creating risks of identity theft and fraud. |
Source:globenewswire.coml |
|
August 19, 2026 |
Sakura Internet |
Sakura Internet hack exposes data of up to 1.36 million accounts |
Unknown |
Sakura Internet’s sales management system was accessed by hackers, potentially exposing data from up to 1,360,563 customer accounts, although the company said no data exfiltration had been confirmed and there were no reported service disruptions. |
Source: Bleeping Computer |
|
August 21, 2026 |
Apollo Global Management |
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants |
Falcon, Helix, Pink and Redact — the groups associated with the broader financial-sector hacking campaign |
Hackers used social engineering to access Apollo’s cloud environment between July 6 and July 10, 2026, and stole names, birth dates, home addresses, contact details and Social Security numbers, exposing sensitive personal information while the company investigated the breach. |
Source: Tech Crunch |
|
August 20,2026 |
Alphanumeric Systems |
Alphanumeric Systems Data Breach Reportedly Led to Exposure of Personal Information |
Settra |
Alphanumeric Systems was reportedly targeted by Settra, which allegedly exfiltrated about 161 GB of data, potentially putting sensitive personal and health-related information belonging to employees, affiliated providers and others at risk, although the company had not confirmed the breach. |
Source: globenewswire.com |
|
August 21, 2026 |
The Hospital for Sick Children (SickKids), including employees of SickKids, Boomerang pediatric clinic, SickKids Foundation, and job applicants |
SickKids data breach exposes employee and job applicant info |
Unknown |
SickKids suffered a cybersecurity incident through a flaw in third-party software that exposed personal information belonging to current and former employees and job applicants, while its Careers website was temporarily affected but clinical systems and patient records remained untouched and patient care continued normally. |
Source: Bleeping Computer |
|
August 21, 2026 |
Turner Construction Company |
Turner Construction Company Data Breach Exposed Sensitive Personal Information of Affected Individuals |
Akira Ransomware Group |
Turner Construction Company experienced a data breach after an unauthorised party gained access to its network, potentially exposing sensitive personal information such as Social Security numbers and other identifying details, which could have left affected individuals vulnerable to identity theft and fraud. |
Source: ClassAction.org |
|
August 24, 2026 |
Surgeons Choice Medical Center |
Surgeons Choice Medical Center Data Breach Exposed Patients’ Sensitive Health and Personal Information |
Unknown |
Surgeons Choice Medical Center suffered a data breach after an unauthorised party accessed its network, potentially exposing sensitive information including Social Security numbers and health information, which could have increased affected individuals’ risk of identity theft and fraud. |
Source: prnewswire.com |
|
August 26, 2026 |
Carhartt |
Carhartt data breach affects 12.9M, half of what ShinyHunters claimed |
ShinyHunters |
ShinyHunters claimed to have stolen 50 GB of Carhartt data following a $3.3 million extortion demand. Analysis by Troy Hunt and Have I Been Pwned found that the dataset contained substantial synthetic and duplicate data, reducing the credible number of affected individuals to 12,933,413. The exposed data includes names, email addresses, phone numbers and physical addresses. |
Source: The Register |
|
August 26, 2026 |
Nutex Health |
Sensitive Information Exposed in Nutex Health Data Breach |
Unknown |
Nutex Health detected unauthorised access to its network, with attackers accessing and exfiltrating files from some servers. The potentially stolen information may include patient, employee, provider, business, financial and intellectual-property data. |
Source: Security Week |
|
August 26, 2026 |
Baylor Genetics |
2.8M affected in Baylor Genetics breach involving medical data |
Unknown |
Baylor Genetics suffered a major data breach affecting approximately 2.8 million people. Exposed information may include genetic and laboratory test results, medical conditions, Social Security numbers and other sensitive personal and health information. |
|
|
August 27, 2026 |
Manchester Airports Group (MAG), which operated Manchester Airport, London Stansted Airport and East Midlands Airport. |
Three UK airports hit by cyber-attack with data of 8.7m customers accessed |
Unknown |
A cyber attack compromised data belonging to about 8.7 million customers, including email addresses, phone numbers, vehicle registration numbers and postcodes linked to car park, lounge, fast-track and airport Wi-Fi services; airport operations, aviation security and passenger safety were not affected, and bank or payment details were not stored in the compromised system. |
Source: The Guardian |
|
August 28, 2026 |
McKesson |
McKesson discloses breach after ShinyHunters claims patient data theft |
ShinyHunters |
McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. ShinyHunters claimed it had stolen approximately 284 million patient records, although the full scope and authenticity of the stolen data had not yet been independently confirmed. |
Source: Bleeping Computer |
|
Date |
Victim |
Summary |
Threat Actor |
Business Impact |
Source Link |
|
August 3, 2026 |
Hungarian State Treasury |
Cyber attack on Hungary's State Treasury Routed Through Russian Servers |
Unknown |
A cyber attack targeted the Hungarian State Treasury, disrupting online services and raising concerns over the security of government systems after investigators found the attack had been routed through Russian servers. |
|
|
August 3, 2026 |
Users targeted by the DoubleCup ClickFix malware campaign |
New DoubleCup ClickFix Service Hides Malware in Browser Cache Images |
DoubleCup operators |
The DoubleCup ClickFix service tricked users into executing malware that was hidden inside browser cache images, enabling attackers to compromise systems while evading traditional security detection. |
Source: Bleeping Computer |
|
August 3, 2026 |
Roblox users who downloaded the fake Xeno Script Launcher |
Fake Roblox Xeno Script Launcher Pushes Infostealer, RAT Malware |
Unknown |
Attackers distributed a fake Roblox Xeno Script Launcher that infected users with infostealer and remote access trojan (RAT) malware, enabling the theft of credentials, sensitive data, and remote control of compromised devices. |
Source: Bleeping Computer |
|
August 4, 2026 |
English National Ballet |
English National Ballet data at risk from cyber attack |
Unknown |
English National Ballet was among several cultural organisations affected by a cyber attack on their customer-relations software, putting customer data at risk of exposure. |
Source: thestage.co.uk |
|
August 4, 2026 |
Columbus Water Works, Columbus, Georgia |
Columbus Water Works hit by cybersecurity attack, Homeland Security director says water was never at risk |
Unknown |
Columbus Water Works had suffered a cyber attack on its computer systems on July 27, 2026, forcing staff to switch to manual operations and conduct on-site checks, but the emergency plan prevented any interruption to water service and officials confirmed that the public water supply and water quality had remained safe. |
Source:wtvm.com |
|
August 5, 2026 |
Android users targeted by BtMob RAT |
Inside the Underground Business of BtMob RAT |
BtMob RAT operators |
The BtMob remote access trojan was used to secretly compromise Android devices, enabling attackers to steal sensitive data, monitor victims' activities, intercept communications, and remotely control infected phones. |
Source: Bleeping Computer |
|
August 6, 2026 |
Swiss Federal Office for Information Technology and Telecommunication (BIT) |
Swiss government SharePoint breach compromised 200 accounts |
Unknown |
Hackers exploited vulnerabilities in the Swiss government's Microsoft SharePoint servers and compromised about 200 accounts, prompting authorities to block external access, reset affected passwords, patch the systems, and investigate whether any data had been stolen. |
Source: Bleeping Computer |
|
August 6, 2026 |
Point72, Citadel, and Millennium Management |
Big US hedge funds targeted by wave of cyber attacks |
Unknown |
Several major U.S. hedge funds were targeted by a wave of voice-phishing attacks in which criminals impersonated trusted employees or IT help desks to obtain login credentials, although no client information was believed to have been stolen from Point72 and Citadel did not appear to have been breached. |
Source: Financial Times |
|
August 6, 2026 |
North Carolina Ports |
Cyber attack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate |
Unknown |
An outside actor hacked North Carolina Ports’ IT systems, forcing all three facilities to switch to manual operations, causing expected delays while officials worked with the U.S. Coast Guard and forensic specialists to contain and restore the affected systems. |
Source: The Record |
|
August 7, 2026 |
Canterbury Cathedral |
Cathedral affected by cyber attack |
Unknown |
Canterbury Cathedral was affected by a cyber attack that disrupted parts of its computer systems, while officials investigated the incident and worked to restore normal services. |
Source: The BBC |
|
August 8, 2026 |
TrueConf and organisations using compromised TrueConf servers |
Hackers breach TrueConf to trojanize client installers with backdoors |
Head Mare hacktivist group. |
Head Mare exploited vulnerable TrueConf servers to gain privileged access, replace legitimate client installers with backdoored versions, and potentially compromise organisations that downloaded the malicious updates, including through trusted counterparties. |
Source: Bleeping Computer |
|
August 8, 2026 |
City of Suisun City, California |
Cyber Attack Shuts Down Suisun City Network as Officials Investigate Data Breach |
Unknown |
A cyber attack disrupted Suisun City’s computer network and forced officials to take systems offline while they investigated whether sensitive city data had been accessed or stolen; the incident also affected the availability of municipal services. |
Source: abc10.com |
|
August 10, 2026 |
A small combined heat-and-power (CHP) plant in Poland |
Hackers breached a small Polish energy plant via private APN last year |
Russian-linked Electrum |
The attackers moved from a compromised wind-farm network into the CHP plant through a misconfigured private APN, accessed its operational technology network and switched Siemens PLCs into STOP mode, shutting down the steam turbine and water-treatment system; staff restored the systems quickly, so the outage remained short-lived and did not affect residents |
Source: Bleeping Computer |
|
August 11, 2026 |
System administrators and IT professionals |
Sandworm hackers target IT pros with trojanized WireGuard VPN client |
UAC-0145 (Sandworm/APT44) |
UAC-0145 targeted IT professionals through fake job offers and technical interviews, then tricked victims into downloading a trojanized WireGuard VPN client that executed malicious PowerShell code on Windows and additional malware on Linux, potentially giving the attackers a foothold in corporate environments. |
Source: Bleeping Computer |
|
August 12, 2026 |
Android users in Czechia, Slovakia, and Slovenia, particularly banking customers targeted through impersonated bank-support calls |
Android malware combo takes out loans and relays victims' credit cards |
Unknown |
Attackers had tricked victims into installing the SpyNote RAT, gained remote access to their Android devices, installed WindRelay, took out loans in victims’ names, and relayed live NFC payment-card data to their own devices so they could make fraudulent purchases. |
Source: Bleeping Computer |
|
August 13, 2026 |
Taiwanese government agencies including the Justice Ministry and the nuclear safety agency |
Taiwan says it was hit by ‘abnormal’ AI-assisted cyber-attack |
Unknown |
Attackers had used a hybrid approach combining human operators with AI agents to target Taiwanese government networks from overseas, reportedly compromising at least 85 government accounts and extracting more than 2,500 personnel records, while the affected agencies investigated the activity and strengthened their cybersecurity monitoring and protections. |
Source: The Guardian |
|
August 16, 2026 |
macOS users |
New AmnesiaStealer macOS malware hijacks browser sessions via remote control |
Unknown |
AmnesiaStealer infected macOS users through ClickFix campaigns and allowed attackers to remotely control authenticated browser sessions, steal passwords, cookies, cryptocurrency wallets, keychain data, documents, and other sensitive information. |
Source: Bleeping Computer |
|
August 18, 2026 |
University of Texas at San Antonio (UTSA) |
University of Texas forced to take systems offline in San Antonio after cyber attack |
Unknown |
UTSA took several systems, including phones, offline after detecting malicious activity on its network, disrupting access to university services just before classes began and forcing the university to extend payment deadlines and adjust course waitlists, although it found no evidence that university data had been accessed or stolen. |
Source: The Record |
|
August 20, 2026 |
Alation |
AI data giant Alation confirms cyber attack |
Unknown |
Alation confirmed that unauthorised activity had affected one of its systems and caused degraded availability for some customers for about an hour, while the company investigated the incident and had not determined whether any customer data was stolen or exfiltrated. |
Source: Tech Crunch |
|
August 20, 2026 |
Government bodies and economic institutions across Central Asia, including organisations in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia and Kazakhstan |
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware |
SilkParasite — suspected China-based, military-grade espionage hackers. |
The SilkParasite campaign targeted Central Asian government organisations through spearphishing emails and malicious Office documents, infecting systems with multiple malware families and enabling the attackers to conduct long-term cyber espionage while using AI-assisted malware development to make the campaign harder to detect. |
Source: The Record |
|
August 20, 2026 |
Android users, primarily in Ukraine and other European countries. |
New Manic Android malware can exfiltrate data through nearby devices |
Unknown |
Manic Android malware had targeted users across Europe by combining spyware, banking fraud and remote-control capabilities, stealing sensitive information from banking, payment, cryptocurrency, messaging and authentication apps and using nearby infected devices over Wi-Fi Direct or Bluetooth to exfiltrate stolen data when its command-and-control server was unreachable. |
Source: Bleeping Computer |
|
August 23, 2026 |
Android users, particularly those using banking, financial, cryptocurrency and e-wallet applications. |
ToxicPanda Android malware uses VPN permissions to block Google Play |
Unknown |
ToxicPanda 2.0 expanded its capabilities by using VPN permissions to block Google Play and Play Protect communications, while its operators could steal banking credentials, PINs, passwords and other sensitive information through phishing overlays and abuse Wireless ADB to gain deeper control of infected Android devices. |
Source: Bleeping Computer |
|
August 23, 2026 |
A small-scale UK power generator; the specific facility was not publicly identified. |
UK Power Plant Forced To Shut Down for Four Days in Cyber Attack Carried Out by Iran-Backed Hackers |
Iran-linked hackers |
An Iran-linked cyber attack forced a small UK power generator offline for four days, disrupting its operations, although the incident remained contained and did not threaten the wider UK electricity supply. |
Source: ibtimes.co.uk |
|
August 25, 2026 |
Organisations using vulnerable Zimbra Collaboration Suite servers |
Hackers breached over 270 Zimbra servers in ongoing attacks |
Unknown |
Attackers actively exploit the high-severity CVE-2026-73570 vulnerability in Zimbra Collaboration Suite to gain unauthenticated remote code execution. Shadowserver identified 274 compromised Zimbra instances, with more than 8,200 potentially vulnerable systems still unpatched. The flaw can allow attackers to execute commands on affected servers and potentially access sensitive emails and other data. |
Source: Bleeping Computer |
|
August 27, 2026 |
U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) |
ATF confirms major incident after recent Qilin breach claims |
Qilin Ransomware Group |
ATF confirmed that a standalone system was compromised after Qilin listed the agency on its dark-web leak site. ATF described the incident as a “major incident” and is investigating it in coordination with the U.S. Department of Justice. Qilin has not publicly stated whether it stole data or demanded a ransom. |
Source: Bleeping Computer |
|
August 27, 2026 |
Boston Scientific |
Cyber Attack Causes Global Disruption at Boston Scientific |
Unknown |
Boston Scientific suffered a cyber attack on August 25, 2026, that caused a network outage and disrupted access to key IT systems and business applications, affecting the company’s ability to manufacture products and process and ship customer orders; the company had not confirmed whether any data was stolen. |
Source: Security Week |
|
New Ransomware |
Summary |
|
TWINLOOT |
A newly uncovered Python-based malware framework used Microsoft services such as SharePoint, Teams, Azure and the victim's own Edge browser to hide command-and-control communications inside trusted Microsoft infrastructure. |
|
iAuthFlow |
A newly identified phishing toolkit that could allow attackers to create their own passkeys on compromised accounts during a brief authenticated session, potentially retaining access even after the victim changed their password. |
|
MacSync Stealer |
A macOS infostealer that targeted passwords, browser cookies, Keychain secrets, cryptocurrency wallets, Telegram sessions and SSH/cloud credentials. It was distributed through ClickFix campaigns that tricked victims into executing commands in Terminal. |
|
Abyssos |
A newly identified modular remote-access trojan that researchers discovered in attacks during 2026. It was notable for its modular design and remote-control capabilities. |
|
PhantomCore |
A backdoor used by the Head Mare threat group in attacks against organisations through vulnerable TrueConf videoconferencing servers. It was part of a newly documented multi-stage attack chain. |
|
PhantomGraph |
A backdoor used by the Head Mare threat group in attacks against organisations through vulnerable TrueConf videoconferencing servers. It was part of a newly documented multi-stage attack chain |
|
Date |
New Flaws/Fixes |
Summary |
|
August 1, 2026 |
CVE-2026-8360 |
Ruby on Rails released security updates to fix a critical Active Storage vulnerability that could have allowed attackers to achieve remote code execution on vulnerable applications. |
|
August 2, 2026 |
CVE-2026-10585 |
Researchers found that a weakness in the Coldcard hardware wallet's random number generator was likely exploited to steal approximately $88 million worth of Bitcoin, prompting users to update affected devices immediately. |
|
August 3, 2026 |
CVE-2026-10867 |
N-able warned that attackers had actively exploited an authentication bypass vulnerability in N-central, urging customers to apply the available security updates immediately to prevent unauthorized access. |
|
August 10, 2026 |
CVE-2026-15409 and CVE-2026-15410 |
CISA confirmed that ransomware gangs had begun exploiting two recently patched SonicWall SMA1000 flaws to gain access to vulnerable VPN appliances, prompting organizations to urgently apply the available security updates. |
|
August 10, 2026 |
CVE-2026-18577 |
Storm-1175, a former Medusa affiliate, had deployed the new StormEncryptor ransomware after exploiting an N-central authentication-bypass flaw, stealing data and encrypting files while giving victims three days to pay or risk having their data leaked. |
|
August 12, 2026 |
CVE-2026-68820 |
Lazarus hackers had exploited a Windows zero-day in Microsoft’s Ancillary Function Driver for WinSock to gain SYSTEM-level privileges and target defense, aerospace, and aviation organizations as part of the Operation Dream Job campaign |
|
August 12, 2026 |
CVE-2026-71362 |
Hackers had begun exploiting the critical CVE-2026-71362 vulnerability in Adobe Commerce and Magento to hijack customer accounts, potentially allowing attackers to gain unauthorized access to e-commerce accounts on vulnerable platforms. |
|
August 14, 2026 |
CVE-2026-44761 |
Attackers began exploiting a maximum-severity SAP Commerce Cloud vulnerability that could allow unauthenticated attackers to gain unauthorized API access and potentially read or modify sensitive data, making immediate patching necessary. |
|
August 14, 2026 |
CVE-2026-65400 |
Hackers exploited a macOS Screen Sharing authentication-bypass flaw to gain root access on exposed systems and install Monero cryptocurrency miners, turning compromised Macs into machines for unauthorized crypto mining. |
|
August 18, 2026 |
CVE-2025-60710 |
CISA confirmed that ransomware gangs had exploited a high-severity Windows Task Host privilege-escalation flaw to gain SYSTEM-level privileges on vulnerable Windows 11 and Windows Server 2025 systems, although details about the specific attacks were not disclosed. |
|
August 16, 2026 |
CVE-2026-33824 |
Hackers actively exploited a critical Windows IKE Extension flaw that allowed unauthenticated attackers to remotely execute code on unpatched Windows systems by sending specially crafted packets. |
|
August 20, 2026 |
CVE-2026-73570 |
Attackers had actively exploited a critical Zimbra Collaboration Suite flaw that allowed unauthenticated attackers to execute arbitrary operating-system commands remotely through the SNMP monitoring component, putting exposed and unpatched Zimbra servers at risk. |
|
August 20, 2026 |
CVE-2026-64849 |
Hackers had actively exploited a critical MLflow vulnerability that allowed unauthenticated attackers to access internal services and cloud metadata, potentially stealing cloud credentials such as AWS IAM keys from unpatched systems. |
|
August 20, 2026 |
CVE-2026-19490 and CVE-2026-19489 |
Citrix warned administrators to urgently patch two newly disclosed NetScaler vulnerabilities, including a critical flaw that could have allowed unauthenticated remote attackers to bypass authentication and gain access to protected systems. |
|
August 28, 2026 |
CVE-2026-81578 and CVE-2026-82078 |
PaperCut released a second emergency patch after researchers found multiple ways to bypass the initial fixes for two actively exploited vulnerabilities that could have allowed unauthenticated attackers to bypass authentication and execute code remotely on vulnerable PaperCut servers. |
|
News Type |
Summary |
|
Warning |
OpenAI disclosed that its AI models had autonomously exploited zero-day vulnerabilities to breach organisations including Hugging Face, prompting the company to strengthen safeguards and warn that fully automated AI-driven attacks could become a serious cybersecurity threat. |
|
Warning |
CISA warned that hackers had actively exploited critical Langflow, N-central, and Apache Tomcat vulnerabilities to gain unauthorised access and potentially take control of affected systems, urging organizations to patch the flaws promptly. |
|
Report |
A cyber attack on De Bijenkorf’s third-party logistics provider delayed orders, returns and refunds and may have exposed customer information, although the retailer said its own systems remained unaffected and the investigation was still determining the extent of the exposure. |
|
Report |
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after suspicious activity was detected on servers managed by a third-party vendor, while the company investigated the incident with cybersecurity forensic specialists. |
|
Warning |
U.S. and South Korean authorities warned that Gunra ransomware actors had targeted government and critical-infrastructure organizations by exploiting vulnerable Fortinet devices and exposed VPN access, prompting defenders to patch known flaws, strengthen network segmentation, and maintain offline backups. |
|
Report |
Security researcher Nightmare Eclipse publicly disclosed a new Windows Defender zero-day called ShieldBreak, which could let an attacker escalate from low-level access to full control of a Windows device and its data |
|
Warning |
Cisco warned that two high-severity ClamAV vulnerabilities had publicly available exploit code that could be abused to crash the ClamAV scanning process and cause denial-of-service conditions on affected systems. |
|
Warning |
Cisco warned that attackers had actively exploited a high-severity flaw in ASA and FTD VPN services to remotely crash vulnerable firewalls and cause denial-of-service conditions, prompting customers to apply the available security updates. |
|
Report |
Wesco investigated a cybersecurity incident involving its cloud CRM environment after the ExfilSquad data-extortion group claimed it had stolen 2.6 million records and later leaked the data, although Wesco said it had found no ransomware, no business disruption, and no evidence that sensitive customer or employee information had been compromised. |
|
Report |
EclipseSupport had launched a new ransomware-as-a-service platform called Eclipse, which targeted Windows, Linux, NAS, VMware ESXi and Nutanix environments and recruited affiliates to carry out multi-platform ransomware attacks. |
|
Report |
Shell investigated a potential security incident after the Clop ransomware group claimed it had stolen 89GB of sensitive company data, including engineering drawings, facility reports, photos and project plans, through attacks exploiting a vulnerability in PTC Windchill and FlexPLM systems. |
|
Warning |
OpenAI warned that increasingly capable AI models had made it possible for attackers to automate major stages of cyberattacks, rapidly identify vulnerabilities and chain weaknesses such as exposed credentials and misconfigurations into sophisticated attacks. |
|
Warning |
U.S. cybersecurity agencies warned that threat actors had used AI-generated scripts to target internet-exposed Siemens S7 Series PLCs in critical infrastructure, potentially allowing them to gain access to industrial systems and disrupt physical operations. |
|
Report |
ReliaQuest confirmed that ShinyHunters had targeted its employees through impersonation and a fake SSO page, but the attempted intrusion was contained before the attackers could access company applications or steal customer data. |
|
Report |
South Korea’s government-backed Modu-ui Changup startup platform suffered a data breach after an encryption key was exposed through an API, allowing about 5,000 successful applicants’ email addresses, evaluation comments and startup idea summaries to be accessed through web crawling. |