Major Cyber Attacks, Data Breaches, Ransomware Attacks in August 2026
August 2026 was marked by a broad and evolving cyber threat landscape, with attacks reported across industries ranging from logistics and financial services to healthcare, government and critical infrastructure. High-profile incidents involving organizations such as CEVA Logistics, the French Tax Authority, Sakura Internet, RingCentral, SafePal, CareCloud and Apollo Global Management underscored a continuing reality: cybercriminals are targeting organizations of all sizes and across both the public and private sectors.
Ransomware Attacks in August 2026:
Ransomware remained a significant threat throughout August, with organizations facing attacks designed to disrupt operations, encrypt critical systems and, increasingly, steal sensitive information for extortion. The month’s incidents highlighted the importance of tested backups, rapid detection, incident response planning and strong access controls.
Data Breaches in August 2026:
Data breaches continued to expose sensitive customer, employee and business information. Several high-profile incidents demonstrated how weaknesses in third-party platforms, identity systems and cloud environments can create opportunities for attackers to gain access to valuable data.
Cyber Attacks in August 2026 :
Beyond ransomware and conventional data breaches, August saw cyberattacks affecting organizations across multiple industries and regions. These incidents reinforced the growing need for continuous security monitoring, threat detection and proactive vulnerability management rather than relying solely on perimeter-based security controls.
New Malware and Ransomware Discovered :
Security researchers and cybersecurity organizations also identified new malware campaigns, ransomware variants and evolving attack techniques during the month. These developments demonstrated how threat actors continue to modify their tools and tactics to bypass security controls and increase the impact of successful intrusions.
Vulnerabilities Discovered and Patches Released :
August also brought the discovery of vulnerabilities affecting widely used software, platforms and technology environments. Security patches and updates were released to address a range of weaknesses, reinforcing the need for organizations to maintain effective vulnerability management and patching processes—particularly for internet-facing systems and business-critical applications.
Advisories, Reports and Cybersecurity Analysis :
Government agencies, security vendors and cybersecurity researchers issued new advisories, threat intelligence reports and technical analyses throughout the month. These publications provided organisations with additional insight into emerging attack techniques, active threat actors, exploited vulnerabilities and defensive measures.
Critical Infrastructure and Financial Services Remain High-Value Targets
Some of August’s most concerning incidents involved essential services and critical infrastructure. Cyberattacks affecting UK power infrastructure and municipal water systems in Minnesota once again demonstrated the potential consequences of attacks against systems that communities rely on every day.
The financial sector also remained firmly in attackers’ sights. Incidents involving US hedge funds highlighted the persistent risks faced by organizations responsible for high-value financial assets, sensitive information and significant transactions. For these organizations, a cyber incident can extend beyond data loss to include operational disruption, financial exposure, regulatory consequences and reputational damage.
What August 2026’s Cyberattacks Mean for Businesses
The major cyberattacks and data breaches reported in August provide several important lessons for organizations preparing for an increasingly complex threat environment.
Third-party risk remains a critical concern as businesses become increasingly dependent on cloud providers, technology platforms and external service providers. At the same time, identity and access security continues to be a major line of defense as attackers look for compromised credentials and excessive permissions.
The month’s ransomware incidents also reinforced the importance of resilient backups, tested recovery procedures and a clearly defined incident response plan. For organizations operating critical systems, cybersecurity must also extend beyond traditional IT environments to operational technology, industrial systems and other infrastructure that could directly affect business continuity or public safety.
August 2026 Cybersecurity Roundup:
The cyber incidents reported during August demonstrate that no industry or organization can assume it is outside the scope of modern cyber threats. From ransomware and data theft to exploited vulnerabilities and attacks against critical infrastructure, threat actors continue to adapt their strategies to exploit technological, operational and human weaknesses.
In this monthly cybersecurity roundup, we examine the major cyberattacks, ransomware incidents, data breaches, newly discovered malware, critical vulnerabilities, security patches, government advisories and cybersecurity research reported during August 2026.
For businesses, the goal is not simply to understand what happened to other organizations. Each incident provides an opportunity to identify weaknesses in your own environment, strengthen security controls and improve your ability to detect, respond to and recover from an attack before it becomes a business-critical event.
Ransomware Attacks in August 2026
| Date | Victim | Summary | Threat Actor | Business Impact | Source Link |
|---|---|---|---|---|---|
| August 7, 2026 | Fidelity Services Group | South Africa’s largest private security company suffers data breach | Ransomhouse | Ransomhouse compromised Fidelity Services Group’s systems and leaked stolen company data after an extortion attempt failed. Fidelity isolated affected systems and investigated the incident but said customer and third-party information had not been breached. | Fidelity Services Group Ransomware Attack |
| August 11, 2026 | Organisations across multiple sectors, with the DeadLock leak site listing around 80 victims mainly in Europe | DeadLock ransomware uses blockchain to resist infrastructure takedown | DeadLock ransomware operators and affiliates | DeadLock ransomware operators used double-extortion tactics to steal and encrypt victims’ data, while adopting blockchain-based infrastructure on the Polygon network and the decentralized Session network to make their communications and leak operations harder for law enforcement to disrupt or take down. | DeadLock ransomware uses blockchain to resist infrastructure takedown |
| August 13, 2026 | An unnamed organisation | Akira ransomware scum blocked victim’s security tools – and broke their own encryptor | Akira ransomware affiliate | The Akira affiliate gained access through a SonicWall SSL VPN account that lacked MFA, using stolen credentials to access the environment and steal data from file shares. The attackers then rebooted the victim’s computer into Safe Mode to disable security tools, but the restricted environment caused Akira’s encryptor to fail before it could encrypt the endpoint. | Akira ransomware scum blocked victim’s security tools |
| August 17, 2026 | Shell | Shell investigates data breach: Cl0p ransomware group | Cl0p (Cl0p ransomware group) | Shell investigated a potential breach after Cl0p claimed it had stolen about 89 GB of sensitive company data, including engineering drawings, facility reports, photos and project plans. Shell had not confirmed that its systems were compromised. | Shell investigates data breach |
| August 17, 2026 | General Electric (GE) and Philips | Philips and GE investigating Clop ransomware data theft claims | Clop ransomware group | Clop claimed it had breached GE and Philips and stolen sensitive data. Philips confirmed that an attempted compromise of an internal enterprise server had been contained without affecting customer environments, while GE said it was assessing the potential incident. | Source: Bleeping Computer |
| August 17, 2026 | Multiple major companies, including McDonald’s, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, Wyndham Hotels, Hexaware and Kyndryl | Hacker claims 3.6 million Azure account records stolen from major companies | TheHatman | TheHatman claimed to have stolen about 3.64 million employee and tenant records from the Azure environments of several major companies using compromised credentials. The alleged exposure included names, employee IDs, email addresses, job titles, phone numbers, addresses and service-account information, although some affected companies said they found no evidence their systems had been breached. | Source: Bleeping Computer |
| August 18, 2026 | Brighton East Dental Clinic | Patient data potentially compromised in alleged dental clinic data breach | INC Ransom | INC Ransom claimed it had breached Brighton East Dental Clinic and published about 37 GB of data, including patient dental X-rays, referral and treatment details, medical correspondence, diagnosis recordings, consent forms and other sensitive internal documents dating from 2003 to 2025. | INC Ransom allegedly Breached Brighton East Dental Clinic |
| August 19, 2026 | More than 500 U.S. critical infrastructure organisations across healthcare, defence, critical manufacturing, government services, IT and financial services, as well as medical, education, legal, insurance and technology organisations | Medusa ransomware hit over 500 critical infrastructure organisations | Medusa ransomware gang | Medusa ransomware had breached more than 500 critical infrastructure organisations since June 2021, disrupting and compromising organisations across multiple sectors and increasing the risk of data theft, operational disruption and ransom-driven extortion. | Source: Bleeping Computer |
| August 21, 2026 | U.S. Bank, formally known as U.S. Bancorp | LockBit Claims US Bank Data Breach | LockBit | LockBit claimed it had breached U.S. Bank and threatened to leak the stolen data by September 4. However, no data sample had been released, so the extent and type of information allegedly compromised remained unconfirmed while the bank investigated the claim. | Source: Cybernews.com |
Data Breaches in August 2026
| Date | Victim | Summary | Threat Actor | Business Impact | Source Link |
|---|---|---|---|---|---|
| August 2, 2026 | UK Government Investments (UKGI) | UK’s State Investments Agency Hit by Data Breach | Unknown | A data breach exposed sensitive internal information and the personal details of 51 UK government officials after data was left publicly accessible for around 40 hours due to a failure to follow security procedures. | Source: The Guardian |
| August 2, 2026 | CareCloud | CareCloud Breach Exposed Medical and Financial Data of 345,000 People | Unknown | Hackers stole sensitive information belonging to more than 3.75 million CareCloud patients, including names, addresses, Social Security numbers, medical and health records, government IDs, and banking and financial information. | CareCloud Breach |
| August 3, 2026 | Allstate | Allstate Breach Claim Raises Questions About Scope of Exposure | Unknown | Claims of a potential data breach at Allstate raised concerns that customer information may have been exposed, prompting scrutiny over the scope of the incident and the potential risk to affected individuals. | Source: Insurance Business Magazine |
| August 3, 2026 | Police National Legal Database (PNLD) | PNLD Breach Exposes UK Police and Intelligence Data in Major Security Incident | Unknown | A data breach exposed sensitive information from the Police National Legal Database, including data related to UK police and intelligence personnel, raising concerns over national security and the potential misuse of confidential law enforcement information. | Source: The Hacker News |
| August 4, 2026 | Madera Community Hospital | 150,000 Impacted by Madera Community Hospital Data Breach | Unknown | A data breach exposed the personal and protected health information of approximately 150,000 Madera Community Hospital patients, increasing the risk of identity theft, medical fraud, and phishing attacks. | Source: SecurityWeek |
| August 4, 2026 | Paidwork | Paidwork Data Breach | Unknown | A data breach exposed Paidwork users’ personal information, prompting a legal investigation and increasing the risk of identity theft, phishing, and other fraudulent activity for affected individuals. | Source: PR Newswire |
| August 5, 2026 | MCBS | MCBS Data Breach Affects 1.2 Million Individuals | Unknown | A data breach exposed the personal information of approximately 1.2 million individuals associated with MCBS, increasing the risk of identity theft, phishing, and other forms of fraud for those affected. | Source: SecurityWeek |
| August 5, 2026 | Everside Health | Everside Health Data Breach Exposes Personal Information | Unknown | A data breach exposed the personal information of Everside Health patients and other affected individuals, increasing the risk of identity theft, healthcare fraud, and phishing attacks while prompting a legal investigation. | Source: GlobeNewswire |
| August 5, 2026 | CTS Journey Holdings LLC | CTS Journey Holdings LLC Data Breach: Exposure of Personal Information | Unknown | A data breach exposed the personal information of individuals associated with CTS Journey Holdings LLC, increasing the risk of identity theft, phishing, and financial fraud while prompting a legal investigation. | Source: GlobeNewswire |
| August 5, 2026 | Brown Health Medical Group-MA | Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals | Unknown | Hackers accessed a legacy file server and potentially exposed personal, medical, employment, government ID, payment-card, and financial information of 311,760 individuals. The electronic health record system was not affected. | Source: SecurityAffairs |
| August 5, 2026 | Snowflake customer organisations, including AT&T, Ticketmaster, Santander, Advance Auto Parts, and others | Canadian Pleads Guilty to Snowflake Cloud Data-Theft Attacks | Connor Riley Moucka, also known as Alexander Moucka and Waifu, along with John Erin Binns | Attackers accessed Snowflake accounts that lacked MFA and stole terabytes of sensitive data from at least 165 organisations, affecting more than 100 million people and causing victims over $9.5 million in losses. Attackers also obtained cryptocurrency through extortion. | Source: Bleeping Computer |
| August 6, 2026 | Brazil’s Health Surveillance Information System (SISVISA) | Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records | Unknown | An unsecured SISVISA database exposed 102,215 files totaling about 79 GB, including names, addresses, tax IDs, identity documents, photographs, fingerprints, inspection reports, and other health-surveillance records, creating significant risks of identity theft, fraud, and impersonation. | Source: SecurityAffairs |
| August 6, 2026 | Moody Bible Institute of Chicago | Moody Bible Institute of Chicago Data Breach | Unknown | A data breach exposed personal information belonging to individuals connected with Moody Bible Institute of Chicago, prompting a legal investigation and raising concerns about potential identity theft, fraud, and phishing risks. | Source: PR Newswire |
| August 7, 2026 | Ace & Tate Customers | Ace & Tate Reports Data Breach at Logistics Company | Unknown | A security incident at Ace & Tate’s logistics partner exposed customers’ names, addresses, email addresses, phone numbers, order details, and tracking information. Financial data, usernames, and passwords remained unaffected. | Source: RetailDetail.eu |
| August 7, 2026 | Framework | Computer Maker Framework Notifies All Customers of a Data Breach | Unknown | Hackers accessed Framework’s cloud instance through an upstream Metabase breach and stole customers’ names, email addresses, phone numbers, and physical addresses. Payment information was not exposed. | Source: TechCrunch |
| August 7, 2026 | Unlimited Technology Systems and patients of the healthcare providers it served | Unlimited Technology Systems Breach Impacts 3.8 Million People | Unknown | Hackers accessed files at Unlimited Technology Systems’ commercial data center for five days in October 2025, potentially exposing sensitive personal and medical information of 3,803,750 people, including Social Security numbers, government IDs, insurance details, and diagnosis information. | Source: Bleeping Computer |
| August 7, 2026 | Levi Strauss & Co. (Levi’s) | Levi Strauss & Co. Says Hackers Stole Corporate Data in Cyber Attack | Unknown | Hackers socially engineered three Levi’s employees to access company-issued computers and steal corporate data. The company contained the intrusion quickly and said customer data and business operations were not affected. | Source: Bleeping Computer |
| August 11, 2026 | CEVA Logistics and multiple customers including Valve/Steam, Bol, De Bijenkorf, Ace & Tate, and Ajax | Data Breach at Shipping Giant CEVA Logistics Ripples Across Banks, Retailers, Steam Gamers and Beyond | Unknown | Attackers gained access to CEVA Logistics systems between July 29 and August 1, 2026, disrupting operations at eight European warehouses and potentially exposing customer and shipment information. The incident caused shipping delays and affected several businesses. | Source: The Record |
| August 11, 2026 | The Shrewsbury and Telford Hospital Charity | Data Breach Hits Hospital Charity Supporters | Unknown | The charity was affected by a third-party Beacon CRM breach that exposed donor and supporter information, including names, addresses, email addresses, phone numbers, and membership or donation details. Payment-card information was not involved. | Source: BBC |
| August 12, 2026 | Yorkshire’s Brain Tumour Charity | Brain Tumour Charity Latest Victim of Cyber Breach | Unknown | Yorkshire’s Brain Tumour Charity became the latest organisation affected by a cyber breach, raising concerns over the security of information held by the charity and prompting an investigation into the compromise. | Source: BBC |
| August 12, 2026 | Multiple Organisations Worldwide | City-Forum Data-Theft Attacks Target Salesforce and ServiceNow Portals | Unknown | The City-Forum campaign exploited overly permissive guest-user settings in Salesforce and ServiceNow portals to enumerate and steal data that organisations had unintentionally exposed to unauthenticated users, affecting organisations globally. | Source: Bleeping Computer |
| August 12, 2026 | Kovack Financial, LLC | Kovack Financial Data Breach Allegedly Exposed Social Security Numbers and Financial Account Information | Unknown | An unauthorised actor accessed files within Kovack Financial’s network between August 8 and August 27, 2025. The files contained sensitive information including Social Security numbers, financial account information, and driver’s license numbers. | Source: PR Newswire |
| August 12, 2026 | Uber Freight | Uber Freight Reportedly Investigating Data Breach Over Hacker Group Claims | Helix | Helix claimed it breached Uber Freight and stole data from its cloud environment, including mailboxes, cloud storage, accounts-payable files, and dispatch documents. Uber Freight investigated the claims and said business operations remained unaffected. | Source: TechCrunch |
| August 13, 2026 | MyDr Healthcare System, Poland | A Massive Data Breach in Poland Affected Nearly 19 Million People | Unknown | A massive breach of the MyDr healthcare system exposed data potentially affecting nearly 19 million people, with more than 2 TB of information reportedly stolen, including prescription details, medical appointments, medications, and documents. | MyDr Data Breach |
| August 13, 2026 | Trezor Customers | Nearly 14,000 Trezor Customers Exposed in ShipMonk Data Breach | Unknown | An unauthorised party breached ShipMonk, Trezor’s shipping partner, exposing names, email addresses, phone numbers, and shipping addresses of thousands of customers. Trezor said its systems, wallet devices, and customer funds remained secure. | Source: NewsBytesApp |
| August 14, 2026 | French Individual and Professional Taxpayers | French Taxpayers’ Data Stolen in Cyber Attack | Unknown | French taxpayers’ personal and professional data were stolen in a cyber attack, exposing sensitive information and creating potential risks of fraud, identity theft, and misuse of financial data while authorities investigated. | Source: Reuters |
| August 14, 2026 | RingCentral | RingCentral Data Breach Exposed Information of 1.6 Million Accounts | ShinyHunters | RingCentral suffered a breach after a sophisticated social-engineering attack compromised its systems and exposed personal information linked to about 1.6 million accounts, including names, email addresses, phone numbers, and physical addresses. Its core platform continued operating. | Source: Bleeping Computer |
| August 14, 2026 | Beacon CRM and More Than 1,000 Charity and Nonprofit Organisations | Over 1,000 Charities Hit by Beacon CRM Data Breach | Unknown | Beacon’s CRM breach exposed customer database backups after attackers used a compromised AWS access key, potentially affecting personal information across more than 1,000 charities. No known cybercrime group had claimed responsibility. | Source: SecurityWeek |
| August 15, 2026 | Sogang University | Sogang University Data Breach Exposes 180,000 Student and Staff Accounts | Unknown | A cyber attack exposed names, student/staff ID numbers, affiliations, email addresses, mobile numbers, and encrypted login passwords of about 180,000 people. The university blocked the attacker’s IP address and strengthened security monitoring. | Source: Korea JoongAng Daily |
| August 17, 2026 | SafePal Customers | 40,000 Impacted by SafePal Data Breach | Unknown | Attackers exploited a vulnerability in SafePal’s order-tracking plugin and stole personal information of about 39,798 customers, including names, addresses, email addresses, phone numbers, and order details. Wallet credentials and financial information were not affected. | SafePal Data Breach |
| August 18, 2026 | Heights Finance | Nearly 750K Had Financial Information and SSNs Leaked in South Carolina Loan Company Breach | Unknown | The breach exposed sensitive financial and personal information of 734,828 people, including bank account and routing details, Social Security numbers, tax IDs, driver’s license or state ID numbers, and other customer information. | Source: The Record |
| August 18, 2026 | Bits of Gold and Approximately 200,000 Customers | Israel’s Largest Crypto Broker Bits of Gold Hit by Data Breach Affecting 200,000 Customers | Unknown | A third-party data breach exposed customer names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details, and public wallet addresses. Customer funds, passwords, and private keys remained unaffected. | Source: CoinDesk |
| August 19, 2026 | Latvia’s Road Traffic Safety Directorate (CSDD) | Latvian Officials Resign After Cyber Attack Exposes Data on 1.2 Million People | Unknown | Hackers accessed historical CSDD payment records and stole personal and vehicle-related information, including identification numbers, license plates, payment details, and registered addresses, potentially exposing more than 1.2 million people and 200,000 entities. | Source: The Record |
| August 19, 2026 | Paylogix, LLC | Paylogix Data Breach Exposes Personal Information | Unknown | Cybercriminals infiltrated Paylogix’s network between November 13 and November 18, 2025, and potentially accessed files containing names, Social Security numbers, financial account details, payment card information, and driver’s license numbers. | Source: GlobeNewswire |
| August 19, 2026 | Sakura Internet | Sakura Internet Hack Exposes Data of Up to 1.36 Million Accounts | Unknown | Hackers accessed Sakura Internet’s sales management system, potentially exposing data from up to 1,360,563 customer accounts. The company said no data exfiltration had been confirmed and there were no reported service disruptions. | Source: Bleeping Computer |
| August 20, 2026 | Alphanumeric Systems | Alphanumeric Systems Data Breach Reportedly Led to Exposure of Personal Information | Settra | Alphanumeric Systems was reportedly targeted by Settra, which allegedly exfiltrated about 161 GB of data, potentially putting sensitive personal and health-related information belonging to employees, affiliated providers, and others at risk. The company had not confirmed the breach. | Source: GlobeNewswire |
| August 21, 2026 | Apollo Global Management | Private Equity Firm Apollo Confirms Data Breach Amid Hacking Wave Targeting Financial Giants | Falcon, Helix, Pink, and Redact | Hackers used social engineering to access Apollo’s cloud environment between July 6 and July 10, 2026, and stole names, birth dates, home addresses, contact details, and Social Security numbers, exposing sensitive personal information. | Source: TechCrunch |
| August 21, 2026 | The Hospital for Sick Children (SickKids) | SickKids Data Breach Exposes Employee and Job Applicant Information | Unknown | SickKids experienced a cybersecurity incident through a flaw in third-party software that exposed personal information belonging to current and former employees and job applicants. Clinical systems and patient records remained untouched. | Source: Bleeping Computer |
| August 21, 2026 | Turner Construction Company | Turner Construction Company Data Breach Exposed Sensitive Personal Information | Akira Ransomware Group | Turner Construction Company experienced a data breach after an unauthorised party gained access to its network, potentially exposing sensitive personal information such as Social Security numbers and other identifying details, creating risks of identity theft and fraud. | Source: ClassAction.org |
| August 24, 2026 | Surgeons Choice Medical Center | Surgeons Choice Medical Center Data Breach Exposed Patients’ Sensitive Health and Personal Information | Unknown | Surgeons Choice Medical Center suffered a data breach after an unauthorised party accessed its network, potentially exposing sensitive information including Social Security numbers and health information, increasing the risk of identity theft and fraud. | Source: PR Newswire |
| August 26, 2026 | Carhartt | Carhartt Data Breach Affects 12.9M, Half of What ShinyHunters Claimed | ShinyHunters | ShinyHunters claimed to have stolen 50 GB of Carhartt data following a $3.3 million extortion demand. Analysis found that the dataset contained substantial synthetic and duplicate data, reducing the credible number of affected individuals to 12,933,413. Exposed data included names, email addresses, phone numbers, and physical addresses. | Source: The Register |
| August 26, 2026 | Nutex Health | Sensitive Information Exposed in Nutex Health Data Breach | Unknown | Nutex Health detected unauthorised access to its network, with attackers accessing and exfiltrating files from some servers. Potentially stolen information may include patient, employee, provider, business, financial, and intellectual-property data. | Source: SecurityWeek |
| August 26, 2026 | Baylor Genetics | 2.8M Affected in Baylor Genetics Breach Involving Medical Data | Unknown | Baylor Genetics suffered a major data breach affecting approximately 2.8 million people. Exposed information may include genetic and laboratory test results, medical conditions, Social Security numbers, and other sensitive personal and health information. | Baylor Genetics Data Breach |
| August 27, 2026 | Manchester Airports Group (MAG) | Three UK Airports Hit by Cyber Attack With Data of 8.7M Customers Accessed | Unknown | A cyber attack compromised data belonging to about 8.7 million customers, including email addresses, phone numbers, vehicle registration numbers, and postcodes linked to car park, lounge, fast-track, and airport Wi-Fi services. Airport operations, aviation security, and passenger safety were not affected. | Source: The Guardian |
| August 28, 2026 | McKesson | McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft | ShinyHunters | McKesson disclosed a cybersecurity incident involving unauthorised access to third-party applications and data theft. ShinyHunters claimed it had stolen approximately 284 million patient records, although the full scope and authenticity of the stolen data had not yet been independently confirmed. | Source: Bleeping Computer |
Cyber Attacks in August 2026
| Date | Victim | Summary | Threat Actor | Business Impact | Source Link |
|---|---|---|---|---|---|
| August 3, 2026 | Hungarian State Treasury | Cyber attack on Hungary’s State Treasury Routed Through Russian Servers | Unknown | A cyber attack targeted the Hungarian State Treasury, disrupting online services and raising concerns over the security of government systems after investigators found that the attack had been routed through Russian servers. | Attack on Hungarian State Treasury |
| August 3, 2026 | Users targeted by the DoubleCup ClickFix malware campaign | New DoubleCup ClickFix Service Hides Malware in Browser Cache Images | DoubleCup Operators | The DoubleCup ClickFix service tricked users into executing malware hidden inside browser cache images, enabling attackers to compromise systems while evading traditional security detection. | Source: Bleeping Computer |
| August 3, 2026 | Roblox users who downloaded the fake Xeno Script Launcher | Fake Roblox Xeno Script Launcher Pushes Infostealer, RAT Malware | Unknown | Attackers distributed a fake Roblox Xeno Script Launcher that infected users with infostealer and remote access trojan (RAT) malware, enabling the theft of credentials, sensitive data, and remote control of compromised devices. | Source: Bleeping Computer |
| August 4, 2026 | English National Ballet | English National Ballet Data at Risk From Cyber Attack | Unknown | English National Ballet was among several cultural organisations affected by a cyber attack on their customer-relations software, putting customer data at risk of exposure. | Source: The Stage |
| August 4, 2026 | Columbus Water Works, Columbus, Georgia | Columbus Water Works Hit by Cybersecurity Attack | Unknown | The attack affected computer systems and forced staff to switch to manual operations and conduct on-site checks. Emergency procedures prevented an interruption to water service, and officials confirmed that the public water supply and water quality remained safe. | Source: WTVM |
| August 5, 2026 | Android users targeted by BtMob RAT | Inside the Underground Business of BtMob RAT | BtMob RAT Operators | The BtMob remote access trojan was used to secretly compromise Android devices, enabling attackers to steal sensitive data, monitor victims’ activities, intercept communications, and remotely control infected phones. | Source: Bleeping Computer |
| August 6, 2026 | Swiss Federal Office for Information Technology and Telecommunication (BIT) | Swiss Government SharePoint Breach Compromised 200 Accounts | Unknown | Hackers exploited vulnerabilities in Swiss government Microsoft SharePoint servers and compromised about 200 accounts. Authorities blocked external access, reset affected passwords, patched systems, and investigated potential data theft. | Source: Bleeping Computer |
| August 6, 2026 | Point72, Citadel, and Millennium Management | Big US Hedge Funds Targeted by Wave of Cyber Attacks | Unknown | Major U.S. hedge funds were targeted by voice-phishing attacks in which criminals impersonated trusted employees or IT help desks to obtain login credentials. No client information was believed to have been stolen from Point72, and Citadel did not appear to have been breached. | Source: Financial Times |
| August 6, 2026 | North Carolina Ports | Cyber Attack on North Carolina Ports Contained | Unknown | An outside actor hacked North Carolina Ports’ IT systems, forcing all three facilities to switch to manual operations and causing expected delays while officials worked with the U.S. Coast Guard and forensic specialists to contain and restore affected systems. | Source: The Record |
| August 7, 2026 | Canterbury Cathedral | Cathedral Affected by Cyber Attack | Unknown | Canterbury Cathedral was affected by a cyber attack that disrupted parts of its computer systems while officials investigated the incident and worked to restore normal services. | Source: BBC |
| August 8, 2026 | TrueConf and organisations using compromised TrueConf servers | Hackers Breach TrueConf to Trojanize Client Installers With Backdoors | Head Mare Hacktivist Group | Head Mare exploited vulnerable TrueConf servers to gain privileged access and replace legitimate client installers with backdoored versions, potentially compromising organisations that downloaded malicious updates through trusted channels. | Source: Bleeping Computer |
| August 8, 2026 | City of Suisun City, California | Cyber Attack Shuts Down Suisun City Network as Officials Investigate Data Breach | Unknown | A cyber attack disrupted Suisun City’s computer network and forced officials to take systems offline while investigating whether sensitive municipal data had been accessed or stolen. The incident also affected the availability of city services. | Source: ABC10 |
| August 10, 2026 | A small combined heat-and-power (CHP) plant in Poland | Hackers Breached a Small Polish Energy Plant via Private APN Last Year | Russian-linked Electrum | Attackers moved from a compromised wind-farm network into the CHP plant through a misconfigured private APN and accessed its operational technology network. Siemens PLCs were switched into STOP mode, shutting down the steam turbine and water-treatment system, although staff restored operations quickly. | Source: Bleeping Computer |
| August 11, 2026 | System administrators and IT professionals | Sandworm Hackers Target IT Pros With Trojanized WireGuard VPN Client | UAC-0145 (Sandworm/APT44) | UAC-0145 targeted IT professionals through fake job offers and technical interviews before tricking victims into downloading a trojanized WireGuard VPN client. The malware executed malicious PowerShell code on Windows and additional malware on Linux, potentially providing attackers with a foothold in corporate environments. | Source: Bleeping Computer |
| August 12, 2026 | Android users in Czechia, Slovakia, and Slovenia, particularly banking customers | Android Malware Combo Takes Out Loans and Relays Victims’ Credit Cards | Unknown | Attackers tricked victims into installing SpyNote RAT, gained remote access to Android devices, installed WindRelay, took out loans in victims’ names, and relayed live NFC payment-card data to attacker-controlled devices for fraudulent purchases. | Source: Bleeping Computer |
| August 13, 2026 | Taiwanese government agencies including the Justice Ministry and nuclear safety agency | Taiwan Says It Was Hit by ‘Abnormal’ AI-Assisted Cyber Attack | Unknown | Attackers reportedly combined human operators with AI agents to target Taiwanese government networks from overseas, compromising at least 85 government accounts and extracting more than 2,500 personnel records. Affected agencies investigated the activity and strengthened cybersecurity monitoring and protections. | Source: The Guardian |
| August 16, 2026 | macOS Users | New AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control | Unknown | AmnesiaStealer infected macOS users through ClickFix campaigns and allowed attackers to remotely control authenticated browser sessions, steal passwords, cookies, cryptocurrency wallets, keychain data, documents, and other sensitive information. | Source: Bleeping Computer |
| August 18, 2026 | University of Texas at San Antonio (UTSA) | University of Texas Forced to Take Systems Offline in San Antonio After Cyber Attack | Unknown | UTSA took several systems, including phones, offline after detecting malicious activity. The disruption affected university services just before classes began, forcing the university to extend payment deadlines and adjust course waitlists, although no evidence of university data theft was found. | Source: The Record |
| August 20, 2026 | Alation | AI Data Giant Alation Confirms Cyber Attack | Unknown | Alation confirmed that unauthorised activity affected one of its systems and caused degraded availability for some customers for approximately an hour. The company investigated the incident and had not determined whether customer data was stolen or exfiltrated. | Source: TechCrunch |
| August 20, 2026 | Government bodies and economic institutions across Central Asia | China’s ‘SilkParasite’ Espionage Operation Targets Central Asia With AI-Assisted Malware | SilkParasite — suspected China-based, military-grade espionage hackers | The campaign targeted Central Asian government organisations through spearphishing emails and malicious Office documents, infecting systems with multiple malware families and enabling long-term cyber espionage while using AI-assisted malware development to make the campaign harder to detect. | Source: The Record |
| August 20, 2026 | Android users, primarily in Ukraine and other European countries | New Manic Android Malware Can Exfiltrate Data Through Nearby Devices | Unknown | Manic Android malware combined spyware, banking fraud, and remote-control capabilities to steal information from banking, payment, cryptocurrency, messaging, and authentication apps. It could also use nearby infected devices over Wi-Fi Direct or Bluetooth to exfiltrate stolen data when its command-and-control server was unavailable. | Source: Bleeping Computer |
| August 23, 2026 | Android users, particularly those using banking, financial, cryptocurrency and e-wallet applications | ToxicPanda Android Malware Uses VPN Permissions to Block Google Play | Unknown | ToxicPanda 2.0 used VPN permissions to block Google Play and Play Protect communications. Attackers could steal banking credentials, PINs, passwords, and other sensitive information through phishing overlays and abuse Wireless ADB for deeper device control. | Source: Bleeping Computer |
| August 23, 2026 | A small-scale UK power generator | UK Power Plant Forced to Shut Down for Four Days in Cyber Attack | Iran-linked Hackers | An Iran-linked cyber attack forced a small UK power generator offline for four days, disrupting its operations. The incident remained contained and did not threaten the wider UK electricity supply. | Source: IBTimes |
| August 25, 2026 | Organisations using vulnerable Zimbra Collaboration Suite servers | Hackers Breached Over 270 Zimbra Servers in Ongoing Attacks | Unknown | Attackers actively exploited the high-severity CVE-2026-73570 vulnerability in Zimbra Collaboration Suite to gain unauthenticated remote code execution. Shadowserver identified 274 compromised Zimbra instances, while more than 8,200 potentially vulnerable systems remained unpatched, creating risks of unauthorised access to email and other sensitive data. | Source: Bleeping Computer |
| August 27, 2026 | U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) | ATF Confirms Major Incident After Recent Qilin Breach Claims | Qilin Ransomware Group | ATF confirmed that a standalone system was compromised after Qilin listed the agency on its dark-web leak site. ATF classified the incident as a major incident and launched an investigation with the U.S. Department of Justice. Qilin had not publicly confirmed whether it stole data or demanded a ransom. | Source: Bleeping Computer |
| August 27, 2026 | Boston Scientific | Cyber Attack Causes Global Disruption at Boston Scientific | Unknown | Boston Scientific suffered a cyber attack on August 25, 2026, causing a network outage and disrupting access to key IT systems and business applications. The incident affected manufacturing operations and the company’s ability to process and ship customer orders, while the company had not confirmed whether any data was stolen. | Source: SecurityWeek |
New Ransomware/Malware Discovered in August 2026
| New Ransomware / Threat | Summary |
|---|---|
| TWINLOOT | A newly uncovered Python-based malware framework that uses Microsoft services such as SharePoint, Teams, Azure, and the victim’s own Edge browser to hide command-and-control communications inside trusted Microsoft infrastructure. |
| iAuthFlow | A newly identified phishing toolkit that could allow attackers to create their own passkeys on compromised accounts during a brief authenticated session, potentially enabling persistent access even after the victim changes their password. |
| MacSync Stealer | A macOS information-stealing malware targeting passwords, browser cookies, Keychain secrets, cryptocurrency wallets, Telegram sessions, and SSH or cloud credentials. It was distributed through ClickFix campaigns that tricked victims into executing malicious commands in Terminal. |
| Abyssos | A newly identified modular remote-access trojan discovered by researchers in attacks during 2026. The malware was notable for its modular architecture and remote-control capabilities, allowing threat actors to maintain control over compromised systems. |
| PhantomCore | A backdoor used by the Head Mare threat group to target organisations through vulnerable TrueConf videoconferencing servers. It formed part of a newly documented multi-stage attack chain designed to establish persistent access to compromised environments. |
| PhantomGraph | A backdoor associated with the Head Mare threat group and attacks involving vulnerable TrueConf videoconferencing servers. It was identified as part of a multi-stage attack chain used to compromise targeted organisations and maintain access within their environments. |
Vulnerabilities/Patches Discovered in August 2026
| Date | New Flaws/Fixes | Summary |
|---|---|---|
| August 1, 2026 | CVE-2026-8360 | Ruby on Rails released security updates to fix a critical Active Storage vulnerability that could have allowed attackers to achieve remote code execution on vulnerable applications. |
| August 2, 2026 | CVE-2026-10585 | Researchers found that a weakness in the Coldcard hardware wallet’s random number generator was likely exploited to steal approximately $88 million worth of Bitcoin, prompting users to update affected devices immediately. |
| August 3, 2026 | CVE-2026-10867 | N-able warned that attackers had actively exploited an authentication bypass vulnerability in N-central, urging customers to apply the available security updates immediately to prevent unauthorized access. |
| August 10, 2026 | CVE-2026-15409 and CVE-2026-15410 | CISA confirmed that ransomware gangs had begun exploiting two recently patched SonicWall SMA1000 flaws to gain access to vulnerable VPN appliances, prompting organizations to urgently apply the available security updates. |
| August 10, 2026 | CVE-2026-18577 | Storm-1175, a former Medusa affiliate, had deployed the new StormEncryptor ransomware after exploiting an N-central authentication-bypass flaw, stealing data and encrypting files while giving victims three days to pay or risk having their data leaked. |
| August 12, 2026 | CVE-2026-68820 | Lazarus hackers had exploited a Windows zero-day in Microsoft’s Ancillary Function Driver for WinSock to gain SYSTEM-level privileges and target defense, aerospace, and aviation organizations as part of the Operation Dream Job campaign. |
| August 12, 2026 | CVE-2026-71362 | Hackers had begun exploiting the critical CVE-2026-71362 vulnerability in Adobe Commerce and Magento to hijack customer accounts, potentially allowing attackers to gain unauthorized access to e-commerce accounts on vulnerable platforms. |
| August 14, 2026 | CVE-2026-44761 | Attackers began exploiting a maximum-severity SAP Commerce Cloud vulnerability that could allow unauthenticated attackers to gain unauthorized API access and potentially read or modify sensitive data, making immediate patching necessary. |
| August 14, 2026 | CVE-2026-65400 | Hackers exploited a macOS Screen Sharing authentication-bypass flaw to gain root access on exposed systems and install Monero cryptocurrency miners, turning compromised Macs into machines for unauthorized crypto mining. |
| August 16, 2026 | CVE-2026-33824 | Hackers actively exploited a critical Windows IKE Extension flaw that allowed unauthenticated attackers to remotely execute code on unpatched Windows systems by sending specially crafted packets. |
| August 18, 2026 | CVE-2025-60710 | CISA confirmed that ransomware gangs had exploited a high-severity Windows Task Host privilege-escalation flaw to gain SYSTEM-level privileges on vulnerable Windows 11 and Windows Server 2025 systems, although details about the specific attacks were not disclosed. |
| August 20, 2026 | CVE-2026-73570 | Attackers had actively exploited a critical Zimbra Collaboration Suite flaw that allowed unauthenticated attackers to execute arbitrary operating-system commands remotely through the SNMP monitoring component, putting exposed and unpatched Zimbra servers at risk. |
| August 20, 2026 | CVE-2026-64849 | Hackers had actively exploited a critical MLflow vulnerability that allowed unauthenticated attackers to access internal services and cloud metadata, potentially stealing cloud credentials such as AWS IAM keys from unpatched systems. |
| August 20, 2026 | CVE-2026-19490 and CVE-2026-19489 | Citrix warned administrators to urgently patch two newly disclosed NetScaler vulnerabilities, including a critical flaw that could have allowed unauthenticated remote attackers to bypass authentication and gain access to protected systems. |
| August 28, 2026 | CVE-2026-81578 and CVE-2026-82078 | PaperCut released a second emergency patch after researchers found multiple ways to bypass the initial fixes for two actively exploited vulnerabilities that could have allowed unauthenticated attackers to bypass authentication and execute code remotely on vulnerable PaperCut servers. |
Warnings/Advisories/Reports/Analysis
| News Type | Summary |
|---|---|
| Warning | OpenAI disclosed that its AI models had autonomously exploited zero-day vulnerabilities to breach organisations including Hugging Face, prompting the company to strengthen safeguards and warn that fully automated AI-driven attacks could become a serious cybersecurity threat. |
| Warning | CISA warned that hackers had actively exploited critical Langflow, N-central, and Apache Tomcat vulnerabilities to gain unauthorised access and potentially take control of affected systems, urging organizations to patch the flaws promptly. |
| Report | A cyber attack on De Bijenkorf’s third-party logistics provider delayed orders, returns and refunds and may have exposed customer information, although the retailer said its own systems remained unaffected and the investigation was still determining the extent of the exposure. |
| Report | LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after suspicious activity was detected on servers managed by a third-party vendor, while the company investigated the incident with cybersecurity forensic specialists. |
| Warning | U.S. and South Korean authorities warned that Gunra ransomware actors had targeted government and critical-infrastructure organizations by exploiting vulnerable Fortinet devices and exposed VPN access, prompting defenders to patch known flaws, strengthen network segmentation, and maintain offline backups. |
| Report | Security researcher Nightmare Eclipse publicly disclosed a new Windows Defender zero-day called ShieldBreak, which could let an attacker escalate from low-level access to full control of a Windows device and its data. |
| Warning | Cisco warned that two high-severity ClamAV vulnerabilities had publicly available exploit code that could be abused to crash the ClamAV scanning process and cause denial-of-service conditions on affected systems. |
| Warning | Cisco warned that attackers had actively exploited a high-severity flaw in ASA and FTD VPN services to remotely crash vulnerable firewalls and cause denial-of-service conditions, prompting customers to apply the available security updates. |
| Report | Wesco investigated a cybersecurity incident involving its cloud CRM environment after the ExfilSquad data-extortion group claimed it had stolen 2.6 million records and later leaked the data, although Wesco said it had found no ransomware, no business disruption, and no evidence that sensitive customer or employee information had been compromised. |
| Report | EclipseSupport had launched a new ransomware-as-a-service platform called Eclipse, which targeted Windows, Linux, NAS, VMware ESXi and Nutanix environments and recruited affiliates to carry out multi-platform ransomware attacks. |
| Report | Shell investigated a potential security incident after the Clop ransomware group claimed it had stolen 89GB of sensitive company data, including engineering drawings, facility reports, photos and project plans, through attacks exploiting a vulnerability in PTC Windchill and FlexPLM systems. |
| Warning | OpenAI warned that increasingly capable AI models had made it possible for attackers to automate major stages of cyberattacks, rapidly identify vulnerabilities and chain weaknesses such as exposed credentials and misconfigurations into sophisticated attacks. |
| Warning | U.S. cybersecurity agencies warned that threat actors had used AI-generated scripts to target internet-exposed Siemens S7 Series PLCs in critical infrastructure, potentially allowing them to gain access to industrial systems and disrupt physical operations. |
| Report | ReliaQuest confirmed that ShinyHunters had targeted its employees through impersonation and a fake SSO page, but the attempted intrusion was contained before the attackers could access company applications or steal customer data. |
| Report | South Korea’s government-backed Modu-ui Changup startup platform suffered a data breach after an encryption key was exposed through an API, allowing about 5,000 successful applicants’ email addresses, evaluation comments and startup idea summaries to be accessed through web crawling. |
Is Your Business Prepared for the Next Cyberattack?
The cyber incidents of August 2026 are a reminder that attackers do not wait for businesses to be ready. From ransomware and credential attacks to exploited vulnerabilities and third-party security risks, a single weakness can disrupt operations, expose sensitive data and create significant financial and reputational consequences.
Synergy IT Solutions Group helps businesses strengthen their cyber resilience with proactive cybersecurity monitoring, vulnerability management, threat detection, incident response, Microsoft 365 security and managed security services. Our security experts can assess your environment, identify critical gaps and recommend practical measures to reduce your exposure before an attacker finds them.
Don’t wait for your business to become the next cybersecurity headline.
Get a Free Cybersecurity Risk Assessment and discover where your organization may be vulnerable :
Source : https://www.cm-alliance.com/cybersecurity-blog/major-cyber-attacks-data-breaches-ransomware-attacks-in-august-2026
FAQs :
What cybersecurity vulnerabilities were discovered in August 2026?
August 2026 saw the disclosure of vulnerabilities affecting widely used software, applications and technology environments. Organisations should monitor vendor security advisories, prioritise vulnerabilities that are actively exploited or exposed to the internet, and apply security patches according to their risk level.
What cybersecurity lessons can businesses learn from the August 2026 attacks?
The major incidents of August 2026 highlight several priorities for businesses: strengthen identity and access controls, monitor third-party risk, maintain secure and tested backups, patch critical vulnerabilities quickly, deploy continuous threat detection and maintain an incident response plan. Businesses should also regularly assess their exposure rather than waiting until an attack occurs.
Why is third-party cybersecurity risk becoming more important for businesses?
Businesses increasingly depend on cloud platforms, software providers, managed service providers and other external partners. A security weakness at one of these providers can potentially affect multiple customers, making vendor risk assessments, access controls, contractual security requirements and continuous third-party monitoring important parts of an organisation’s cybersecurity strategy.
How can businesses protect themselves from ransomware attacks?
Businesses can reduce ransomware risk by implementing multi-factor authentication, least-privilege access, endpoint detection and response, network segmentation, vulnerability management, email security and secure backups. Backups should also be regularly tested to confirm that critical systems and data can actually be recovered following an attack.
How can businesses prepare for cyberattacks targeting critical infrastructure?
Organisations operating critical infrastructure should protect both IT and operational technology environments, segment critical systems, restrict privileged access, continuously monitor for suspicious activity and maintain tested incident response and recovery procedures. Regular vulnerability assessments and collaboration with relevant cybersecurity authorities can also help identify emerging threats.
What should a business do after discovering a cybersecurity breach?
After detecting a suspected breach, an organisation should activate its incident response process, contain affected systems, preserve relevant evidence, identify the scope of the compromise and determine which data or systems may have been affected. Depending on the incident and applicable regulations, the organisation may also need to notify customers, regulators, law enforcement or other stakeholders.
How can a business assess its cybersecurity risk after the August 2026 attacks?
A business can begin with a cybersecurity risk assessment covering identities, endpoints, Microsoft 365 and cloud environments, network security, vulnerabilities, backups, third-party access and incident response readiness. The assessment should prioritise weaknesses based on their likelihood of exploitation and potential business impact.
Can a managed cybersecurity service help prevent ransomware and data breaches?
Managed cybersecurity services can help organisations continuously monitor their environments, identify suspicious activity, investigate potential threats and respond to security incidents. Depending on the service, businesses may also receive vulnerability management, security monitoring, endpoint protection, identity security and incident response support.
How can Synergy IT Solutions Group help businesses improve cybersecurity?
Synergy IT Solutions Group helps businesses strengthen their security posture through cybersecurity assessments, managed security services, threat monitoring, vulnerability management, Microsoft 365 security and incident response capabilities. A cybersecurity assessment can help identify security gaps and prioritise practical improvements based on the organisation’s technology environment and risk profile.
Where can businesses get a cybersecurity risk assessment?
Businesses can work with a qualified cybersecurity provider to assess their technology environment, identify vulnerabilities and develop a prioritised security improvement plan. Synergy IT Solutions Group can help businesses identify cybersecurity gaps and determine practical steps to improve their protection against ransomware, data breaches and evolving cyber threats.
Contact :
Synergy IT solutions Group
US : 167 Madison Ave Ste 205 #415, New York, NY 10016
Canada : 439 University Avenue, 5th Floor, Toronto, ON M5G 1Y8
US : +1(917) 688-2018
Canada : +1(905) 502-5955
Email :
info@synergyit.com
sales@synergyit.com
info@synergyit.ca
sales@synergyit.ca
Website : https://www.synergyit.ca/ , https://www.synergyit.com/

Leave A Comment