Cyber Security Blog

Major Cyber Attacks, Data Breaches, Ransomware Attacks in August 2026

Written by Aditi Uberoi | 1 September 2026

August 2026 saw cyber threats cut across an unusually diverse range of sectors, from logistics and financial services to healthcare, government and critical infrastructure. Major incidents involving CEVA Logistics, the French Tax Authority, Sakura Internet, RingCentral, SafePal, CareCloud and Apollo Global Management demonstrated that both large enterprises and public-sector organisations remain attractive targets for cybercriminals. 

  1. Ransomware Attacks in August 2026
  2. Data Breaches in August 2026 
  3. Cyber Attacks in August 2026
  4. New Malware and Ransomware Discovered
  5. Vulnerabilities Discovered and Patches Released 
  6. Advisories issued, reports, analysis etc. in August 2026


Particularly concerning were attacks affecting UK power infrastructure and Minnesota municipal water systems, once again bringing the cybersecurity of essential services into focus. Meanwhile, incidents targeting US hedge funds highlighted the persistent risks facing organisations entrusted with high-value financial data and transactions.

The biggest cyber attacks and data breaches of August 2026 offer important lessons in third-party risk management, identity and access security, ransomware resilience, data protection and critical infrastructure defence.

In this monthly roundup, we examine the incidents that made headlines, what is known about their impact, and the practical cybersecurity lessons organisations can take from them to strengthen their own cyber resilience.

Ransomware Attacks in August 2026

Date

Victim

Summary

Threat Actor

Business Impact

Source Link

August 7, 2026

Fidelity Services Group

South Africa’s largest private security company suffers data breach

Ransomhouse

Ransomhouse compromised Fidelity Services Group’s systems and leaked stolen company data after an extortion attempt failed. Fidelity isolated affected systems and investigated the incident but said customer and third-party information had not been breached.

Fidelity Services Group Ransomware Attack

August 11, 2026

Organisations across multiple sectors, with the DeadLock leak site listing around 80 victims mainly in Europe.

DeadLock ransomware uses blockchain to resist infrastructure takedown

DeadLock ransomware operators and affiliates

DeadLock ransomware operators used double-extortion tactics to steal and encrypt victims’ data, while adopting blockchain-based infrastructure on the Polygon network and the decentralized Session network to make their communications and leak operations harder for law enforcement to disrupt or take down.

DeadLock ransomware uses blockchain to resist infrastructure takedown

August 13, 2026

An unnamed organisation

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

Akira ransomware affiliate

The Akira affiliate had gained access through a SonicWall SSL VPN account that lacked MFA, stolen credentials and data from file shares, and then rebooted the victim’s computer into Safe Mode to disable security tools; however, the restricted environment caused Akira’s encryptor to fail before it could encrypt the endpoint.

Akira ransomware scum blocked victim's security tools

August 17, 2026

Shell

Shell investigates data breach: Cl0p ransomware group

Cl0p (Cl0p ransomware group)

Shell investigated a potential breach after Cl0p claimed it had stolen about 89 GB of sensitive company data, including engineering drawings, facility reports, photos and project plans, although Shell had not confirmed that its systems were compromised.

Shell investigates data breach

August 17, 2026

General Electric (GE) and Philips

Philips and GE investigating Clop ransomware data theft claims

Clop ransomware group

Clop claimed it had breached GE and Philips and stolen sensitive data, while Philips confirmed that an attempted compromise of an internal enterprise server had been contained without affecting customer environments, and GE said it was assessing the potential incident.

Source: Bleeping Computer

August 17, 2026

Multiple major companies, including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Wyndham Hotels, Hexaware and Kyndryl

Hacker claims 3.6 million Azure account records stolen from major companies

TheHatman

TheHatman claimed to have stolen about 3.64 million employee and tenant records from the Azure environments of several major companies using compromised credentials, exposing names, employee IDs, email addresses, job titles, phone numbers, addresses and service-account information, although some affected companies said they found no evidence their systems had been breached.

Source: Bleeping Computer

August 18, 2026

Brighton East Dental Clinic

Patient data potentially compromised in alleged dental clinic data breach

INC Ransom

INC Ransom claimed it had breached Brighton East Dental Clinic and published about 37 GB of data, including patient dental X-rays, referral and treatment details, medical correspondence, diagnosis recordings, consent forms and other sensitive internal documents dating from 2003 to 2025.

Inc Ransom allegedly Breached Brighton East Dental Clinic

August 19, 2026

More than 500 U.S. critical infrastructure organisations across healthcare, defence, critical manufacturing, government services, IT and financial services, as well as medical, education, legal, insurance and technology organisations.

Medusa ransomware hit over 500 critical infrastructure organisations

Medusa ransomware gang

Medusa ransomware had breached more than 500 critical infrastructure organisations since June 2021, disrupting and compromising organisations across multiple sectors and increasing the risk of data theft, operational disruption and ransom-driven extortion.

Source: Bleeping Computer

August 21, 2026

U.S. Bank, formally known as U.S. Bancorp.

LockBit Claims US Bank Data Breach

LockBit

LockBit claimed it had breached U.S. Bank and threatened to leak the stolen data by September 4. But no data sample has been released, so the extent and type of information allegedly compromised remains unconfirmed while the bank investigated the claim.

Source: cybernews.com

 
 
 


 Back to Top 

 

Data Breaches in August 2026

Date

Victim

Summary

Threat Actor

Business Impact

Source Link

August 2, 2026

UK Government Investments (UKGI)

UK's State Investments Agency Hit by Data Breach

Unknown

A data breach exposed sensitive internal information and the personal details of 51 UK government officials after data was left publicly accessible for around 40 hours due to a failure to follow security procedures.

Source: www.theguardian.com

August 2, 19, 2026

CareCloud

CareCloud Breach Exposed Medical and Financial Data of 345,000 People

Unknown

Hackers stole sensitive information belonging to more than 3.75 million CareCloud patients, including names, addresses, Social Security numbers, medical and health records, government IDs, and banking and financial information.

CareCloud Breach

August 3, 2026

Allstate

Allstate Breach Claim Raises Questions About Scope of Exposure

Unknown

Claims of a potential data breach at Allstate raised concerns that customer information may have been exposed, prompting scrutiny over the scope of the incident and the potential risk to affected individuals.

Source: www.insurancebusinessmag.com

August 3, 2026

Police National Legal Database (PNLD)

PNLD Breach Exposes UK Police and Intelligence Data in Major Security Incident

Unknown

A data breach exposed sensitive information from the Police National Legal Database, including data related to UK police and intelligence personnel, raising concerns over national security and the potential misuse of confidential law enforcement information.

Source: thehackernews.com

August 4, 2026

Madera Community Hospital

150,000 Impacted by Madera Community Hospital Data Breach

Unknown

A data breach exposed the personal and protected health information of approximately 150,000 Madera Community Hospital patients, increasing the risk of identity theft, medical fraud, and phishing attacks.

Source: securityweek.com

August 4, 2026

Paidwork

Paidwork Data Breach

Unknown

A data breach exposed Paidwork users' personal information, prompting a legal investigation and increasing the risk of identity theft, phishing, and other fraudulent activity for affected individuals.

Source: prnewswire.com

August 5, 2026

MCBS

MCBS Data Breach Affects 1.2 Million Individuals

Unknown

A data breach exposed the personal information of approximately 1.2 million individuals associated with MCBS, increasing the risk of identity theft, phishing, and other forms of fraud for those affected.

Source: securityweek.com

August 5, 2026

Everside Health

Everside Health Data Breach Exposes Personal Information, Murphy Law Firm Investigates Legal Claims

Unknown

A data breach exposed the personal information of Everside Health patients and other affected individuals, increasing the risk of identity theft, healthcare fraud, and phishing attacks while prompting a legal investigation.

Source:globenewswire.com

August 5, 2026

CTS Journey Holdings LLC

CTS Journey Holdings LLC Data Breach: Edelson Lechtzin LLP Launches Investigation into Exposure of Personal Information

Unknown

A data breach exposed the personal information of individuals associated with CTS Journey Holdings LLC, increasing the risk of identity theft, phishing, and financial fraud while prompting a legal investigation.

Source:globenewswire.com

August 5, 2026

Brown Health Medical Group-MA

Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals

Unknown

Hackers accessed a legacy file server at Brown Health Medical Group-MA and potentially exposed the personal, medical, employment, government ID, payment-card, and financial information of 311,760 individuals, although its electronic health record system was not affected.

Source: securityaffairs.com

August 5, 2026

Snowflake customer organisations, including AT&T, Ticketmaster, Santander, Advance Auto Parts, and others

Canadian pleads guilty to Snowflake cloud data-theft attacks

Connor Riley Moucka (also known as Alexander Moucka and Waifu), along with John Erin Binns.

Attackers accessed Snowflake accounts that lacked MFA and stole terabytes of sensitive data from at least 165 organisations, affecting more than 100 million people and causing victims over $9.5 million in losses while the attackers also obtained cryptocurrency through extortion.

Source: Bleeping Computer

August 6, 2026

Brazil’s Health Surveillance Information System (SISVISA)

Exposed SISVISA database leaks 102,000 Brazilian health surveillance records

Unknown

An unsecured SISVISA database exposed 102,215 files totaling about 79 GB, including names, addresses, tax IDs, identity documents, photographs, fingerprints, inspection reports and other health-surveillance records, creating significant risks of identity theft, fraud and impersonation.

Source: securityaffairs.com

August 6, 2026

Moody Bible Institute of Chicago

Moody Bible Institute of Chicago Data Breach

Unknown

A data breach exposed personal information belonging to individuals connected with Moody Bible Institute of Chicago, prompting a legal investigation and raising concerns about potential identity theft, fraud, and phishing risks.

Source: prnewswire.com

August 7, 2026

Ace & Tate customers

Ace & Tate reports data breach at logistics company

 

A security incident at Ace & Tate's logistics partner exposed customers' names, addresses, email addresses, phone numbers, order details and tracking information, while financial data, usernames and passwords remained unaffected.

Source: retaildetail.eu

August 7, 2026

Framework

Computer maker Framework notifies ‘all customers’ of a data breach

Unknown

Hackers accessed Framework’s cloud instance through an upstream Metabase breach and stole customers’ names, email addresses, phone numbers and physical addresses, while payment information was not exposed.

Source: Tech Crunch

August 7, 2026

Unlimited Technology Systems and patients of the healthcare providers it served

Unlimited Technology Systems breach impacts 3.8 million people

Unknown

Hackers accessed files at Unlimited Technology Systems' commercial data center for five days in October 2025, potentially exposing the sensitive personal and medical information of 3,803,750 people, including Social Security numbers, government IDs, insurance details and diagnosis information.

Source: Bleeping Computer

August 7, 2026

Levi Strauss & Co. (Levi’s)

Levi Strauss & Co. says hackers stole corporate data in cyber attack

Unknown

Hackers socially engineered three Levi’s employees to access their company-issued computers and steal corporate data, but the company contained the intrusion quickly and said customer data and business operations were not affected.

Source: Bleeping Computer

August 11, 2026

CEVA Logistics and multiple customers that relied on its logistics services, including Valve/Steam, Bol, De Bijenkorf, Ace & Tate and Ajax.

A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers and beyond

Unknown

Attackers gained access to CEVA Logistics systems between July 29 and August 1, 2026, disrupting operations at eight European warehouses and potentially exposing customer and shipment information; the incident caused shipping delays and affected several businesses, while Valve said European Steam hardware customers’ names, addresses, phone numbers, email addresses and order details may have been compromised.

Source: The Record

August 11, 2026

The Shrewsbury and Telford Hospital Charity

Data breach hits hospital charity supporters

Unknown

The Shrewsbury and Telford Hospital Charity was affected by a third-party Beacon CRM breach that exposed sensitive donor and supporter information, including names, addresses, email addresses, phone numbers and membership or donation details, although payment-card information was not involved and no misuse had been identified.

Source: The BBC

August 12, 2026

Yorkshire’s Brain Tumour Charity

Brain tumour charity latest victim of cyber breach

Unknown

Yorkshire’s Brain Tumour Charity became the latest organisation affected by a cyber breach, with the incident raising concerns over the security of information held by the charity and prompting it to investigate the compromise.

Source: The BBC

August 12, 2026

Multiple organisations worldwide

City-Forum data-theft attacks target Salesforce, ServiceNow portals

Unknown

The City-Forum campaign had exploited overly permissive guest-user settings in Salesforce and ServiceNow portals to enumerate and steal data that organisations had unintentionally exposed to unauthenticated users, with the activity affecting organisations globally and continuing to increase.

Source: Bleeping Computer

August 12, 2026

Kovack Financial, LLC

Kovack Financial Data Breach Allegedly Exposed Social Security Numbers and Financial Account Information

Unknown

An unauthorised actor had accessed files within Kovack Financial’s network between August 8 and August 27, 2025, and the company later determined that the files contained sensitive information, including Social Security numbers, financial account information and driver’s license numbers; Kovack began notifying affected individuals on August 10, 2026.

Source: prnewswire.com

August 12, 2026

Uber Freight, the logistics subsidiary of Uber

Uber Freight is reportedly investigating a data breach over hacker group claims

Helix

Helix claimed that it had breached Uber Freight and stolen data from its cloud environment, including mailboxes, cloud storage, accounts-payable files and dispatch documents, while Uber Freight investigated the claims and said its business operations had remained unaffected.

Source: Tech Crunch

August 13, 2026

MyDr, a healthcare system used by doctors and medical institutions across Poland

A massive data breach in Poland affected nearly 19 million people

Unknown

A massive breach of the MyDr healthcare system exposed data potentially affecting nearly 19 million people, with more than 2 terabytes of information reportedly stolen, including prescription details, medical appointments, medications and documents; around 12,000 medical facilities were connected to the affected system while Polish authorities investigated the incident.

MyDr Data Breach

August 13, 2026

Trezor customers

Nearly 14,000 Trezor customers exposed in ShipMonk data breach

Unknown

An unauthorised party had breached ShipMonk, Trezor’s shipping partner, exposing the names, email addresses, phone numbers and shipping addresses of thousands of Trezor customers, while Trezor said its own systems, wallet devices and customer funds had remained secure; the exposed information could have increased the risk of targeted phishing and social-engineering attacks.

Source: newsbytesapp.com

August 14, 2026

French individual and professional taxpayers

French taxpayers' data stolen in cyber attack, French Finance Ministry say

Unknown

French taxpayers’ personal and professional data were stolen in a cyber attack, exposing sensitive information and creating potential risks of fraud, identity theft and misuse of financial data while authorities investigated the scope of the breach.

Source: Reuters

August 14, 2026

RingCentral

RingCentral data breach exposed information of 1.6 million accounts

ShinyHunters

RingCentral suffered a breach after a sophisticated social-engineering attack compromised its systems and exposed personal information linked to about 1.6 million accounts, including names, email addresses, phone numbers and physical addresses, although its core platform continued operating without disruption.

Source: Bleeping Computer

August 14, 2026

Beacon CRM and more than 1,000 charity and nonprofit organisations using its platform

Over 1,000 Charities Hit by Beacon CRM Data Breach

Unknown

Beacon’s CRM breach exposed customer database backups after attackers used a compromised AWS access key, potentially affecting personal information such as names, phone numbers, email addresses and postal addresses across more than 1,000 charities, while no known cybercrime group had claimed responsibility.

Source: Security Week

August 15, 2026

Sogang University

Sogang University data breach exposes 180,000 student, staff accounts

Unknown

Sogang University suffered a cyber attack that exposed names, student/staff ID numbers, affiliations, email addresses, mobile numbers and encrypted login passwords of about 180,000 people, prompting the university to block the attacker’s IP address, restrict the affected service and strengthen its security monitoring.

Source: koreajoongangdaily.com

August 17, 2026

SafePal customers

40,000 impacted by SafePal data breach

Unknown

SafePal disclosed that attackers exploited a vulnerability in its order-tracking plugin and stole personal information of about 39,798 customers, including names, addresses, email addresses, phone numbers and order details, while wallet credentials and financial information were not affected.

SafePal Data Breach

August 18, 2026

Heights Finance

Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach

Unknown

The breach exposed sensitive financial and personal information of 734,828 people, including bank account and routing details, Social Security numbers, tax IDs, driver’s license/state ID numbers and other customer information, although the company said its core loan systems and networks were not affected.

Source: The Record

August 18, 2026

Bits of Gold and approximately 200,000 customers

Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers

Unknown

Bits of Gold suffered a third-party data breach that exposed customer names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details and public wallet addresses, while customer funds, passwords and private keys remained unaffected.

Source: coindesk.com

August 19, 2026

Latvia’s Road Traffic Safety Directorate (CSDD), affecting more than 1.2 million people and about 200,000 businesses and other legal entities.

Latvian officials resign after cyber attack exposes data on 1.2 million people

Unknown

Hackers accessed historical CSDD payment records and stole personal and vehicle-related information, including identification numbers, license plates, payment details and registered addresses, potentially exposing more than 1.2 million people and 200,000 entities to fraud and social-engineering attacks, although CSDD’s daily services remained operational.

Source: The Record

August 19, 2026

Paylogix, LLC

Paylogix Data Breach Exposes Personal Information

Unknown

Cybercriminals infiltrated Paylogix’s network between November 13 and November 18, 2025, and potentially accessed files containing sensitive information of thousands of individuals, including names, Social Security numbers, financial account details, payment card information and driver’s license numbers, creating risks of identity theft and fraud.

Source:globenewswire.coml

August 19, 2026

Sakura Internet

Sakura Internet hack exposes data of up to 1.36 million accounts

Unknown

Sakura Internet’s sales management system was accessed by hackers, potentially exposing data from up to 1,360,563 customer accounts, although the company said no data exfiltration had been confirmed and there were no reported service disruptions.

Source: Bleeping Computer

August 21, 2026

Apollo Global Management

Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants

Falcon, Helix, Pink and Redact — the groups associated with the broader financial-sector hacking campaign

Hackers used social engineering to access Apollo’s cloud environment between July 6 and July 10, 2026, and stole names, birth dates, home addresses, contact details and Social Security numbers, exposing sensitive personal information while the company investigated the breach.

Source: Tech Crunch

August 20,2026

Alphanumeric Systems

Alphanumeric Systems Data Breach Reportedly Led to Exposure of Personal Information

Settra

Alphanumeric Systems was reportedly targeted by Settra, which allegedly exfiltrated about 161 GB of data, potentially putting sensitive personal and health-related information belonging to employees, affiliated providers and others at risk, although the company had not confirmed the breach.

Source: globenewswire.com

August 21, 2026

The Hospital for Sick Children (SickKids), including employees of SickKids, Boomerang pediatric clinic, SickKids Foundation, and job applicants

SickKids data breach exposes employee and job applicant info

Unknown

SickKids suffered a cybersecurity incident through a flaw in third-party software that exposed personal information belonging to current and former employees and job applicants, while its Careers website was temporarily affected but clinical systems and patient records remained untouched and patient care continued normally.

Source: Bleeping Computer

August 21, 2026

Turner Construction Company

Turner Construction Company Data Breach Exposed Sensitive Personal Information of Affected Individuals

Akira Ransomware Group

Turner Construction Company experienced a data breach after an unauthorised party gained access to its network, potentially exposing sensitive personal information such as Social Security numbers and other identifying details, which could have left affected individuals vulnerable to identity theft and fraud.

Source: ClassAction.org

August 24, 2026

Surgeons Choice Medical Center

Surgeons Choice Medical Center Data Breach Exposed Patients’ Sensitive Health and Personal Information

Unknown

Surgeons Choice Medical Center suffered a data breach after an unauthorised party accessed its network, potentially exposing sensitive information including Social Security numbers and health information, which could have increased affected individuals’ risk of identity theft and fraud.

Source: prnewswire.com

August 26, 2026

Carhartt

Carhartt data breach affects 12.9M, half of what ShinyHunters claimed

ShinyHunters

ShinyHunters claimed to have stolen 50 GB of Carhartt data following a $3.3 million extortion demand. Analysis by Troy Hunt and Have I Been Pwned found that the dataset contained substantial synthetic and duplicate data, reducing the credible number of affected individuals to 12,933,413. The exposed data includes names, email addresses, phone numbers and physical addresses.

Source: The Register

August 26, 2026

Nutex Health

Sensitive Information Exposed in Nutex Health Data Breach

Unknown

Nutex Health detected unauthorised access to its network, with attackers accessing and exfiltrating files from some servers. The potentially stolen information may include patient, employee, provider, business, financial and intellectual-property data.

Source: Security Week

August 26, 2026

Baylor Genetics

2.8M affected in Baylor Genetics breach involving medical data

Unknown

Baylor Genetics suffered a major data breach affecting approximately 2.8 million people. Exposed information may include genetic and laboratory test results, medical conditions, Social Security numbers and other sensitive personal and health information.

Baylor Genetics Data Breach

August 27, 2026 

Manchester Airports Group (MAG), which operated Manchester Airport, London Stansted Airport and East Midlands Airport. 

Three UK airports hit by cyber-attack with data of 8.7m customers accessed 

Unknown 

A cyber attack compromised data belonging to about 8.7 million customers, including email addresses, phone numbers, vehicle registration numbers and postcodes linked to car park, lounge, fast-track and airport Wi-Fi services; airport operations, aviation security and passenger safety were not affected, and bank or payment details were not stored in the compromised system.  

Source: The Guardian 

August 28, 2026

 McKesson 

McKesson discloses breach after ShinyHunters claims patient data theft 

 ShinyHunters 

McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. ShinyHunters claimed it had stolen approximately 284 million patient records, although the full scope and authenticity of the stolen data had not yet been independently confirmed. 

Source: Bleeping Computer

 
 

Back to Top 

Cyber Attacks in August 2026

Date

Victim

Summary

Threat Actor

Business Impact

Source Link

August 3, 2026

Hungarian State Treasury

Cyber attack on Hungary's State Treasury Routed Through Russian Servers

Unknown

A cyber attack targeted the Hungarian State Treasury, disrupting online services and raising concerns over the security of government systems after investigators found the attack had been routed through Russian servers.

Attack on Hungarian State Treasury

August 3, 2026

Users targeted by the DoubleCup ClickFix malware campaign

New DoubleCup ClickFix Service Hides Malware in Browser Cache Images

DoubleCup operators

The DoubleCup ClickFix service tricked users into executing malware that was hidden inside browser cache images, enabling attackers to compromise systems while evading traditional security detection.

Source: Bleeping Computer

August 3, 2026

Roblox users who downloaded the fake Xeno Script Launcher

Fake Roblox Xeno Script Launcher Pushes Infostealer, RAT Malware

Unknown

Attackers distributed a fake Roblox Xeno Script Launcher that infected users with infostealer and remote access trojan (RAT) malware, enabling the theft of credentials, sensitive data, and remote control of compromised devices.

Source: Bleeping Computer

August 4, 2026

English National Ballet

English National Ballet data at risk from cyber attack

Unknown

English National Ballet was among several cultural organisations affected by a cyber attack on their customer-relations software, putting customer data at risk of exposure.

Source: thestage.co.uk

August 4, 2026

Columbus Water Works, Columbus, Georgia

Columbus Water Works hit by cybersecurity attack, Homeland Security director says water was never at risk

Unknown

Columbus Water Works had suffered a cyber attack on its computer systems on July 27, 2026, forcing staff to switch to manual operations and conduct on-site checks, but the emergency plan prevented any interruption to water service and officials confirmed that the public water supply and water quality had remained safe.

Source:wtvm.com

August 5, 2026

Android users targeted by BtMob RAT

Inside the Underground Business of BtMob RAT

BtMob RAT operators

The BtMob remote access trojan was used to secretly compromise Android devices, enabling attackers to steal sensitive data, monitor victims' activities, intercept communications, and remotely control infected phones.

Source: Bleeping Computer

August 6, 2026

Swiss Federal Office for Information Technology and Telecommunication (BIT)

Swiss government SharePoint breach compromised 200 accounts

Unknown

Hackers exploited vulnerabilities in the Swiss government's Microsoft SharePoint servers and compromised about 200 accounts, prompting authorities to block external access, reset affected passwords, patch the systems, and investigate whether any data had been stolen.

Source: Bleeping Computer

August 6, 2026

Point72, Citadel, and Millennium Management

Big US hedge funds targeted by wave of cyber attacks

Unknown

Several major U.S. hedge funds were targeted by a wave of voice-phishing attacks in which criminals impersonated trusted employees or IT help desks to obtain login credentials, although no client information was believed to have been stolen from Point72 and Citadel did not appear to have been breached.

Source: Financial Times

August 6, 2026

North Carolina Ports

Cyber attack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate

Unknown

An outside actor hacked North Carolina Ports’ IT systems, forcing all three facilities to switch to manual operations, causing expected delays while officials worked with the U.S. Coast Guard and forensic specialists to contain and restore the affected systems.

Source: The Record

August 7, 2026

Canterbury Cathedral

Cathedral affected by cyber attack

Unknown

Canterbury Cathedral was affected by a cyber attack that disrupted parts of its computer systems, while officials investigated the incident and worked to restore normal services.

Source: The BBC

August 8, 2026

TrueConf and organisations using compromised TrueConf servers

Hackers breach TrueConf to trojanize client installers with backdoors

Head Mare hacktivist group.

Head Mare exploited vulnerable TrueConf servers to gain privileged access, replace legitimate client installers with backdoored versions, and potentially compromise organisations that downloaded the malicious updates, including through trusted counterparties.

Source: Bleeping Computer

August 8, 2026

City of Suisun City, California

Cyber Attack Shuts Down Suisun City Network as Officials Investigate Data Breach

Unknown

A cyber attack disrupted Suisun City’s computer network and forced officials to take systems offline while they investigated whether sensitive city data had been accessed or stolen; the incident also affected the availability of municipal services.

Source: abc10.com

August 10, 2026

A small combined heat-and-power (CHP) plant in Poland

Hackers breached a small Polish energy plant via private APN last year

Russian-linked Electrum

The attackers moved from a compromised wind-farm network into the CHP plant through a misconfigured private APN, accessed its operational technology network and switched Siemens PLCs into STOP mode, shutting down the steam turbine and water-treatment system; staff restored the systems quickly, so the outage remained short-lived and did not affect residents

Source: Bleeping Computer

August 11, 2026

System administrators and IT professionals

Sandworm hackers target IT pros with trojanized WireGuard VPN client

UAC-0145 (Sandworm/APT44)

UAC-0145 targeted IT professionals through fake job offers and technical interviews, then tricked victims into downloading a trojanized WireGuard VPN client that executed malicious PowerShell code on Windows and additional malware on Linux, potentially giving the attackers a foothold in corporate environments.

Source: Bleeping Computer

August 12, 2026

Android users in Czechia, Slovakia, and Slovenia, particularly banking customers targeted through impersonated bank-support calls

Android malware combo takes out loans and relays victims' credit cards

Unknown

Attackers had tricked victims into installing the SpyNote RAT, gained remote access to their Android devices, installed WindRelay, took out loans in victims’ names, and relayed live NFC payment-card data to their own devices so they could make fraudulent purchases.

Source: Bleeping Computer

August 13, 2026

Taiwanese government agencies including the Justice Ministry and the nuclear safety agency

Taiwan says it was hit by ‘abnormal’ AI-assisted cyber-attack

Unknown

Attackers had used a hybrid approach combining human operators with AI agents to target Taiwanese government networks from overseas, reportedly compromising at least 85 government accounts and extracting more than 2,500 personnel records, while the affected agencies investigated the activity and strengthened their cybersecurity monitoring and protections.

Source: The Guardian

August 16, 2026

macOS users

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

Unknown

AmnesiaStealer infected macOS users through ClickFix campaigns and allowed attackers to remotely control authenticated browser sessions, steal passwords, cookies, cryptocurrency wallets, keychain data, documents, and other sensitive information.

Source: Bleeping Computer

August 18, 2026

University of Texas at San Antonio (UTSA)

University of Texas forced to take systems offline in San Antonio after cyber attack

Unknown

UTSA took several systems, including phones, offline after detecting malicious activity on its network, disrupting access to university services just before classes began and forcing the university to extend payment deadlines and adjust course waitlists, although it found no evidence that university data had been accessed or stolen.

Source: The Record

August 20, 2026

Alation

AI data giant Alation confirms cyber attack

Unknown

Alation confirmed that unauthorised activity had affected one of its systems and caused degraded availability for some customers for about an hour, while the company investigated the incident and had not determined whether any customer data was stolen or exfiltrated.

Source: Tech Crunch

August 20, 2026

Government bodies and economic institutions across Central Asia, including organisations in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia and Kazakhstan

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

SilkParasite — suspected China-based, military-grade espionage hackers.

The SilkParasite campaign targeted Central Asian government organisations through spearphishing emails and malicious Office documents, infecting systems with multiple malware families and enabling the attackers to conduct long-term cyber espionage while using AI-assisted malware development to make the campaign harder to detect.

Source: The Record

August 20, 2026

Android users, primarily in Ukraine and other European countries.

New Manic Android malware can exfiltrate data through nearby devices

Unknown

Manic Android malware had targeted users across Europe by combining spyware, banking fraud and remote-control capabilities, stealing sensitive information from banking, payment, cryptocurrency, messaging and authentication apps and using nearby infected devices over Wi-Fi Direct or Bluetooth to exfiltrate stolen data when its command-and-control server was unreachable.

Source: Bleeping Computer

August 23, 2026

Android users, particularly those using banking, financial, cryptocurrency and e-wallet applications.

ToxicPanda Android malware uses VPN permissions to block Google Play

Unknown

ToxicPanda 2.0 expanded its capabilities by using VPN permissions to block Google Play and Play Protect communications, while its operators could steal banking credentials, PINs, passwords and other sensitive information through phishing overlays and abuse Wireless ADB to gain deeper control of infected Android devices.

Source: Bleeping Computer

August 23, 2026

A small-scale UK power generator; the specific facility was not publicly identified.

UK Power Plant Forced To Shut Down for Four Days in Cyber Attack Carried Out by Iran-Backed Hackers

Iran-linked hackers

An Iran-linked cyber attack forced a small UK power generator offline for four days, disrupting its operations, although the incident remained contained and did not threaten the wider UK electricity supply.

Source: ibtimes.co.uk

August 25, 2026

Organisations using vulnerable Zimbra Collaboration Suite servers

Hackers breached over 270 Zimbra servers in ongoing attacks

Unknown

Attackers actively exploit the high-severity CVE-2026-73570 vulnerability in Zimbra Collaboration Suite to gain unauthenticated remote code execution. Shadowserver identified 274 compromised Zimbra instances, with more than 8,200 potentially vulnerable systems still unpatched. The flaw can allow attackers to execute commands on affected servers and potentially access sensitive emails and other data.

Source: Bleeping Computer

August 27, 2026

U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)

ATF confirms major incident after recent Qilin breach claims

Qilin Ransomware Group

ATF confirmed that a standalone system was compromised after Qilin listed the agency on its dark-web leak site. ATF described the incident as a “major incident” and is investigating it in coordination with the U.S. Department of Justice. Qilin has not publicly stated whether it stole data or demanded a ransom.

Source: Bleeping Computer

August 27, 2026

 Boston Scientific 

Cyber Attack Causes Global Disruption at Boston Scientific 

Unknown 

Boston Scientific suffered a cyber attack on August 25, 2026, that caused a network outage and disrupted access to key IT systems and business applications, affecting the company’s ability to manufacture products and process and ship customer orders; the company had not confirmed whether any data was stolen. 

Source: Security Week 

 
 


Back to Top 

New Ransomware/Malware Discovered in August 2026

New Ransomware

Summary

TWINLOOT

A newly uncovered Python-based malware framework used Microsoft services such as SharePoint, Teams, Azure and the victim's own Edge browser to hide command-and-control communications inside trusted Microsoft infrastructure.

iAuthFlow

A newly identified phishing toolkit that could allow attackers to create their own passkeys on compromised accounts during a brief authenticated session, potentially retaining access even after the victim changed their password.

MacSync Stealer

A macOS infostealer that targeted passwords, browser cookies, Keychain secrets, cryptocurrency wallets, Telegram sessions and SSH/cloud credentials. It was distributed through ClickFix campaigns that tricked victims into executing commands in Terminal.

Abyssos

A newly identified modular remote-access trojan that researchers discovered in attacks during 2026. It was notable for its modular design and remote-control capabilities.

PhantomCore

A backdoor used by the Head Mare threat group in attacks against organisations through vulnerable TrueConf videoconferencing servers. It was part of a newly documented multi-stage attack chain.

PhantomGraph

A backdoor used by the Head Mare threat group in attacks against organisations through vulnerable TrueConf videoconferencing servers. It was part of a newly documented multi-stage attack chain

 
 
 Source for the above table: Bleeping Computer, Recorded Future News

 Back to Top  

 

Vulnerabilities/Patches Discovered in August 2026

Date

New Flaws/Fixes

Summary

August 1, 2026

CVE-2026-8360

Ruby on Rails released security updates to fix a critical Active Storage vulnerability that could have allowed attackers to achieve remote code execution on vulnerable applications.

August 2, 2026

CVE-2026-10585

Researchers found that a weakness in the Coldcard hardware wallet's random number generator was likely exploited to steal approximately $88 million worth of Bitcoin, prompting users to update affected devices immediately.

August 3, 2026

CVE-2026-10867

N-able warned that attackers had actively exploited an authentication bypass vulnerability in N-central, urging customers to apply the available security updates immediately to prevent unauthorized access.

August 10, 2026

CVE-2026-15409 and CVE-2026-15410

CISA confirmed that ransomware gangs had begun exploiting two recently patched SonicWall SMA1000 flaws to gain access to vulnerable VPN appliances, prompting organizations to urgently apply the available security updates.

August 10, 2026

CVE-2026-18577

Storm-1175, a former Medusa affiliate, had deployed the new StormEncryptor ransomware after exploiting an N-central authentication-bypass flaw, stealing data and encrypting files while giving victims three days to pay or risk having their data leaked.

August 12, 2026

CVE-2026-68820

Lazarus hackers had exploited a Windows zero-day in Microsoft’s Ancillary Function Driver for WinSock to gain SYSTEM-level privileges and target defense, aerospace, and aviation organizations as part of the Operation Dream Job campaign

August 12, 2026

CVE-2026-71362

Hackers had begun exploiting the critical CVE-2026-71362 vulnerability in Adobe Commerce and Magento to hijack customer accounts, potentially allowing attackers to gain unauthorized access to e-commerce accounts on vulnerable platforms.

August 14, 2026

CVE-2026-44761

Attackers began exploiting a maximum-severity SAP Commerce Cloud vulnerability that could allow unauthenticated attackers to gain unauthorized API access and potentially read or modify sensitive data, making immediate patching necessary.

August 14, 2026

CVE-2026-65400

Hackers exploited a macOS Screen Sharing authentication-bypass flaw to gain root access on exposed systems and install Monero cryptocurrency miners, turning compromised Macs into machines for unauthorized crypto mining.

August 18, 2026

CVE-2025-60710

CISA confirmed that ransomware gangs had exploited a high-severity Windows Task Host privilege-escalation flaw to gain SYSTEM-level privileges on vulnerable Windows 11 and Windows Server 2025 systems, although details about the specific attacks were not disclosed.

August 16, 2026

CVE-2026-33824

Hackers actively exploited a critical Windows IKE Extension flaw that allowed unauthenticated attackers to remotely execute code on unpatched Windows systems by sending specially crafted packets.

August 20, 2026

CVE-2026-73570

Attackers had actively exploited a critical Zimbra Collaboration Suite flaw that allowed unauthenticated attackers to execute arbitrary operating-system commands remotely through the SNMP monitoring component, putting exposed and unpatched Zimbra servers at risk.

August 20, 2026

CVE-2026-64849

Hackers had actively exploited a critical MLflow vulnerability that allowed unauthenticated attackers to access internal services and cloud metadata, potentially stealing cloud credentials such as AWS IAM keys from unpatched systems.

August 20, 2026

CVE-2026-19490 and CVE-2026-19489

Citrix warned administrators to urgently patch two newly disclosed NetScaler vulnerabilities, including a critical flaw that could have allowed unauthenticated remote attackers to bypass authentication and gain access to protected systems.

August 28, 2026

CVE-2026-81578 and CVE-2026-82078 

PaperCut released a second emergency patch after researchers found multiple ways to bypass the initial fixes for two actively exploited vulnerabilities that could have allowed unauthenticated attackers to bypass authentication and execute code remotely on vulnerable PaperCut servers.  

 
 
 Source for the above table: Bleeping Computer, Recorded Future  

 Back to Top

Warnings/Advisories/Reports/Analysis

News Type

Summary

Warning

OpenAI disclosed that its AI models had autonomously exploited zero-day vulnerabilities to breach organisations including Hugging Face, prompting the company to strengthen safeguards and warn that fully automated AI-driven attacks could become a serious cybersecurity threat.

Warning

CISA warned that hackers had actively exploited critical Langflow, N-central, and Apache Tomcat vulnerabilities to gain unauthorised access and potentially take control of affected systems, urging organizations to patch the flaws promptly.

Report

A cyber attack on De Bijenkorf’s third-party logistics provider delayed orders, returns and refunds and may have exposed customer information, although the retailer said its own systems remained unaffected and the investigation was still determining the extent of the exposure.

Report

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after suspicious activity was detected on servers managed by a third-party vendor, while the company investigated the incident with cybersecurity forensic specialists.

Warning

U.S. and South Korean authorities warned that Gunra ransomware actors had targeted government and critical-infrastructure organizations by exploiting vulnerable Fortinet devices and exposed VPN access, prompting defenders to patch known flaws, strengthen network segmentation, and maintain offline backups.

Report

Security researcher Nightmare Eclipse publicly disclosed a new Windows Defender zero-day called ShieldBreak, which could let an attacker escalate from low-level access to full control of a Windows device and its data

Warning

Cisco warned that two high-severity ClamAV vulnerabilities had publicly available exploit code that could be abused to crash the ClamAV scanning process and cause denial-of-service conditions on affected systems.

Warning

Cisco warned that attackers had actively exploited a high-severity flaw in ASA and FTD VPN services to remotely crash vulnerable firewalls and cause denial-of-service conditions, prompting customers to apply the available security updates.

Report

Wesco investigated a cybersecurity incident involving its cloud CRM environment after the ExfilSquad data-extortion group claimed it had stolen 2.6 million records and later leaked the data, although Wesco said it had found no ransomware, no business disruption, and no evidence that sensitive customer or employee information had been compromised.

Report

EclipseSupport had launched a new ransomware-as-a-service platform called Eclipse, which targeted Windows, Linux, NAS, VMware ESXi and Nutanix environments and recruited affiliates to carry out multi-platform ransomware attacks.

Report

Shell investigated a potential security incident after the Clop ransomware group claimed it had stolen 89GB of sensitive company data, including engineering drawings, facility reports, photos and project plans, through attacks exploiting a vulnerability in PTC Windchill and FlexPLM systems.

Warning

OpenAI warned that increasingly capable AI models had made it possible for attackers to automate major stages of cyberattacks, rapidly identify vulnerabilities and chain weaknesses such as exposed credentials and misconfigurations into sophisticated attacks.

Warning

U.S. cybersecurity agencies warned that threat actors had used AI-generated scripts to target internet-exposed Siemens S7 Series PLCs in critical infrastructure, potentially allowing them to gain access to industrial systems and disrupt physical operations.

Report

ReliaQuest confirmed that ShinyHunters had targeted its employees through impersonation and a fake SSO page, but the attempted intrusion was contained before the attackers could access company applications or steal customer data.

Report

South Korea’s government-backed Modu-ui Changup startup platform suffered a data breach after an encryption key was exposed through an API, allowing about 5,000 successful applicants’ email addresses, evaluation comments and startup idea summaries to be accessed through web crawling.

 
 
 Sources: Bleeping Computer and Infosecurity Magazine

Back to Top