Ransomware/nation-state & data breaches
Key Questions
How many ransomware victims were reported in 2026?
A 2026 report documented 7,551 victims, representing a 24.9% increase, with Qilin and The Gentlemen groups leading in activity.
What new extortion techniques are ransomware groups using?
Groups are leveraging BitLocker and printer-based extortion alongside traditional encryption, as seen in campaigns targeting OT environments.
Which major companies suffered recent data breaches?
Under Armour/MyFitnessPal (150M users), DentaQuest (23M+), Paidwork (23M), and Origin Energy (2M records) were among those impacted.
What breach affected an Israeli military supplier?
IMCO was hit by the hacktivist group 'Cyber Support Front', resulting in 30 TB of stolen data including blueprints and camera footage.
How is Cl0p exploiting PTC software?
Cl0p affiliates are targeting CVE-2026-12569 in PTC Windchill/FlexPLM for pre-auth RCE, with the flaw added to CISA KEV.
What was the scale of the DC housing authority incident?
The breach disrupted operations for weeks and exposed PII, highlighting ongoing challenges for government agencies.
Which malware targets crypto wallet seed phrases from photos?
SparkKitty malware found in app stores scans photo libraries for crypto seed phrases and other sensitive information.
How are data leaks fueling sextortion scams?
ShinyHunters leaks are being used in $2000 sextortion email campaigns, with attackers leveraging exposed personal data for credibility.
Ransomware and nation-state activity escalating. Coldcard hack now $130M+ with fourth wave, traced to 2021 firmware bug; Ledger pushes certified hardware RNG. Qilin dominated H1 2026 with 370 attacks. INC ransomware exploiting SonicWall. Water utilities coordinated attack (30+ sites, Iran-linked) now confirmed in 12 states including wastewater infrastructure; Handala claims credit. Darktrace: cloud/SaaS top targets. Healthcare breaches: CareCloud, Aesto, Cameron Regional, Radia Inc. (CHAOS ransomware), PAMCAH (PHI/PII exposed). UK police data leak. Crypto hacks $1.1B H1 2026. ExfilSquad exploits misconfigured Power Pages portals exposing Dataverse data. RTX Corp data breach under investigation. New: Water sector attacks expanded to 12 states with FBI technical details on PLC exploitation. OT exposure: 4,407 Rockwell controllers exposed, exploited by Iranian actors. Qilin ransomware hits UK and Intertrust, with Synnovis downstream breach exposing 32K patient records. Ransomware groups now use AI to generate legal documents for extortion pressure.