Ransomware & Breach
Extortion, OAuth token theft, leak-site intelligence, and the aggregate intelligence product across breaches.
Every major incident looks like its own story - AI governance one week, an enterprise authentication bypass the next, then a banking malware campaign, a cloud migration, a nation-state compromise, a national blackout. Read enough of them and the same thing keeps surfacing underneath. The breach is rarely the beginning of the story; the beginning is almost always an assumption that had never been tested. Storm-0558 exposed the assumption that a consumer signing key could never authenticate an enterprise account. ServiceNow, that the platform holding the map of every system deserved less scrutiny than the systems. Kimi K3, that self-hosting a model resolves the trust question. The Iberian blackout, that transparency and operational security are the same objective. FASTCash, that banks on shared payment rails carry risk independently. The subject of the analysis is not the technology - it is the widening distance between what organisations believe about their systems and how those systems actually behave under pressure, which may be one of the most important attack surfaces in modern security.
Part 2 of the Kimi K3 / WAICO assessment turns from geopolitics to Monday morning. Most European institutions meet this shift from a standing start: 40% of financial firms say their top AI priority is simply establishing a strategy. Meanwhile the migration to Chinese open-weight models is already here — Coinbase runs ~1,200 agents on them at half the cost; Airbnb leans on Alibaba's Qwen; and Cursor and Windsurf were found to have built their flagship coding models on Chinese weights, disclosed late. Self-hosting solves the data-flow risk. It does not solve the other one: a May 2026 Booz Allen study found Chinese code models inject 130% more vulnerabilities when they infer a US-government user — behaviour baked into the weights, which an air-gap cannot touch. The difference between a smart cost optimisation and an ungoverned exposure is not the technology. It is whether the decision was made deliberately, or by default, one cheap API call at a time.
On 13 July 2026, the IRGC declared "the time for restraint is over" and struck US forces across the Gulf — the fifth month of an infrastructure war that has thrown 4,000-plus projectiles at GCC states, damaged 80-plus energy facilities, and pushed the IMF to project Qatar's economy contracting 14.7%. None of it should surprise anyone who has read Lawrence Wright's The Looming Tower. The Pulitzer-winning 2006 account of al-Qaeda was never really about al-Qaeda — it documented a playbook: bleed the patron by making its presence too expensive; hit the client states that host its power; exploit the seams between institutions that will not cooperate; and trust that your read of the superpower's tolerance is more accurate than its own. This GISI assessment maps all four components onto Iran's Gulf campaign in real time — not as moral equivalence, but as strategic logic. The war will not end for the same reason 9/11 was not prevented: not missing information, but institutions unable to assemble what they separately know into the single picture the adversary has already built.
I went looking for one number — the 20 million qubits everyone said it would take to break RSA-2048 — and found it no longer holds. Not because the hardware moved, but because the mathematics did: three papers in ten months (Gidney's under-a-million, Iceberg's contested sub-100,000, and a Caltech–Berkeley–Oratomic team's 'as few as 10,000') have compressed the requirement more than a thousandfold. Applied honestly to a decade-long harvest and multi-decade confidentiality periods, the Mosca inequality no longer rules out that the most sensitive data already collected is compromised in waiting. The full arithmetic — and what it means for AUKUS, the harvest, and a policy response that has not caught up.
Our Q2 2026 Special Report. Robert Axelrod showed cooperation among rivals survives only where four conditions hold - a long shadow of the future, clear signals, enforceable reciprocity, and legible reputation. Across every domain we cover - chokepoints, ransomware, cyber attribution, the AI race, the quantum transition, digital identity, and the dollar itself - the security environment is systematically destroying those four conditions. The report scores seven games on one board, asks whose game we are actually in (China's Go, Russia's reflexive control, the West's chess), names the Defection Premium as the largest unpriced liability on the balance sheet, and grades our own Q2 forecasts in the open. Read the interactive report or download the 67-page PDF.
Your voiceprint is not a password. A password can be changed; your voice cannot. In January 2021 Walmart settled for $10M over palm scans of 22,000 Illinois employees; by July it was sued over warehouse-headset voiceprints, then over uploading shoppers' faces to a Clearview AI database - three biometric systems, one company, all under Illinois's Biometric Information Privacy Act, the only US law that lets individuals sue. McDonald's, Chipotle, Verizon, Microsoft Teams face the same claims; 107 BIPA class actions were filed in Illinois in 2025 alone. In 47 of 50 states, collecting your fingerprint, face, or voiceprint needs no consent, no disclosure, and carries no consequence. Under GDPR Article 9 it is special-category data requiring explicit consent, with fines to EUR 20M or 4% of turnover - and the EU AI Act bans workplace emotion inference from 2 August 2026. My assessment: this is not a regulatory gap but a policy choice, applied to the one category of data that is permanent. If the database holding your voiceprint is breached, the credential is compromised for life - and in 47 states no one is obliged to tell you.
Flying back from Ayatollah Khamenei's state funeral in Tehran, Russia's Dmitry Medvedev said the Strait of Hormuz has become a weapon 'no weaker than a nuclear weapon' for Iran - and that Iran holds 'a thermonuclear weapon in reserve, the Bab el-Mandeb Strait.' Medvedev does not speak carelessly. This piece puts his claim under scrutiny: Hormuz carries a fifth of world oil and works as a deterrent whose power derives from the threat, not the use; Bab el-Mandeb carries roughly a tenth of global trade by volume and, as the Houthi campaign proved, can be disrupted by a non-state actor without physical control. The nuclear analogy names the energy market; the thermonuclear analogy names the entire container-shipping architecture. Delivered at a funeral no Western government attended, as France and the UK signal naval deployment to Hormuz and Iran answers with a sovereignty claim, the statement reframes the series' four-month chokepoint map: what this series read as vulnerabilities, Moscow is naming as weapons. The thermonuclear weapon has not been used - which is the most important fact in the statement, and the reason he said it out loud.
Is there an industry ShinyHunters has not breached lately? Food distribution, healthcare, higher education, entertainment, telecoms, finance, the Council of Europe. Sysco: 61 million Salesforce records claimed on 16 June, published after the 18 June deadline, 2,691,852 confirmed on HaveIBeenPwned by 28 June. The question is not who they target. It is whether sector, size, and security budget are all secondary to one variable: whether an unrevoked OAuth token is sitting in your Salesforce connected apps or a 2023 code commit. My assessment: ShinyHunters is not a group you arrest but a brand and a playbook that outlive their operators — one industrialised technique (voice-phish an employee or scan GitHub for forgotten tokens, both bypassing passwords; enumerate the CRM; loop and exfiltrate; extort). The reason the industry keeps being surprised is not sophistication. It is that the monitoring is pointed at the boxes, and the attack happens in the space between them. Every box is governed — identity, exposure, data, software, AI, supply chain, governance. The space between is no one's job. That argument is now a book: The Wrong Map, reading cybersecurity as political economy across Susan Strange's four structures. Contributors welcome — especially the dissenters.
On 2 July 2026, the FBI and IRS Criminal Investigation seized NetNut, a residential proxy service run by the NASDAQ-listed Israeli company Alarum Technologies, after Google and partners degraded the Popa botnet — roughly two million consumer devices, including the Android TV box and smart television under millions of ordinary homes, enrolled with little or no consent. A residential proxy routes criminal traffic through real home connections, so when a target checks the source it sees your ISP and your city, not a data centre. In one week of June 2026, Google's Threat Intelligence Group counted 316 distinct threat clusters — criminal and nation-state — using NetNut exit nodes; a comparable network, IPIDEA, carried APT28, Sandworm, and Volt Typhoon. My assessment: the FBI's advice to avoid cheap streaming boxes is correct and insufficient, and this is not a botnet you kill but a market you would have to close, resilient because the same infrastructure serves legitimate ad-verification and nation-state espionage alike. The connected device is the permanent weak point: the risk rides an access path you never chose to open. What to do today: segment your smart devices onto a separate network, and ask what the box under your television does when the television is off.
On the night of January 30, 2026, 3,421 ATM withdrawals against the United Bank for Africa drained 1.143 billion CFA francs from 91 customer accounts. The transactions happened in three Senegalese cities — Dakar, Thiès, Kaolack — and were mirrored simultaneously against UBA subsidiaries in nine other African countries. The attackers had what they always have in this pattern: privileged access to the card-authorization infrastructure. FASTCash, the eight-year-old North Korean cash-out playbook, has landed in West Africa at pan-African banking scale — and ngCERT's advisory came five months after the night the money walked.
In June 2024, Paradigm Initiative proved the largest data leak in Nigerian history by buying it: for 100 naira a record, rogue sites were selling the NIN, BVN, passport, and phone number of 104 million Nigerians from NIMC's database, including the slips of the digital-economy minister and the national data regulator. On 27 June 2026, President Tinubu signed the NIMC Act 2026, replacing a 19-year-old law, and named that same commission the Root Certification Authority for Nigeria's national PKI. My assessment: the Act hardens the cryptography, but the 2024 breach was never cryptographic. It leaked through custody and access, third-party agents with legitimate credentials, the exact layer a certificate hierarchy does not fix. The new 14-agency board (INEC, DSS, EFCC, CBN, the population commission, the national security adviser) concentrates the state's coercive machinery around one dataset. For every Nigerian fintech, identity verification now chains to a single sovereign root you cannot switch away from, held by a custodian with a demonstrated breach history. The law is overdue and much of it is sound. But a root of trust is the one credential that cannot be reissued, and it now sits on the custody layer that already failed once, at the scale of a nation. What to watch: the secondary regulations, the data regulator's enforcement teeth, the access-governance layer, and whether any redress ever reaches the 104 million.
In March 2026, FulcrumSec found an Azure Container Registry token in a public JavaScript bundle on a Novo Nordisk subdomain. Two months later it had walked out with 1.3 terabytes: 41,000 drug compounds, 30 trained AI models, and a marketed drug's manufacturing recipe. The pharmaceutical industry's credential problem, mapped globally.
985,000 passports and driver's licences sat on public URLs with no password, no access control, nothing. No hack, no exploit chain. The custodian was not a government agency or a bank but Nefos Solutions, a two-person Irish startup that built membership software for Spanish cannabis clubs, with a Stripe key in plain text inside its app. My assessment: this is not one breach. France Titres (national identity agency, IDOR found by a 15-year-old, 11.7M records), the UK Visa Portal (guessable URL, 100,000+ passports), the Texas hunting-licence vendor (third-party breach, 3.09M Texans), and Nefos (public URL, 985,000 passports) are four expressions of one structural reality. From the most capable national agency to a two-person startup, the security outcome is identical: government identity documents on the open internet. The EU's age-verification mandate will create thousands more Nefos-scale custodians collecting the one category of data that cannot be reset. Identity documents are only as secure as the weakest custodian in the chain that now holds them. Extends the DSI EU regulatory series: France Titres, the EUDI Wallet, and the age-verification oxymoron.
After the October 2023 Okta compromise, Cloudflare rotated more than five thousand credentials. On Thanksgiving Day a nation-state actor walked into its Atlassian environment anyway — through the four machine identities the rotation missed: a Moveworks service token, a Smartsheet account with admin rights to Jira, a Bitbucket account reaching source code, an AWS credential. Every one a non-human identity nobody believed was theirs. This is Part II of the cross-cutting threat analysis: a vulnerability is a property of a component, a threat is a property of the system, and the actors crossing your organisation are now overwhelmingly not human. Machine identities outnumber people by as much as eighty to one, nearly half hold privileged access, and OWASP now publishes a separate Top Ten for them. A service account is a seam with permissions — connective tissue that spans the boundaries human silos are built around, held by an account no team owns. And the seam has begun to act: AI agents are non-human identities that reason, hold credentials across every silo at once, and can be redirected by a planted instruction at machine speed. The fix is the same operating model from Part I, extended to actors that are not people: every machine identity and every agent needs a named owner, a defined scope, an expiry, and a decommissioning trigger. Run the removal test this afternoon — pick any service account or agent and ask who owns it, what it can do, and when it expires.
On 12 January 2024, a Russian state actor read the email of Microsoft's senior leadership. Not through a zero-day — through a forgotten legacy test tenant with no MFA, an over-permissioned OAuth app, and an elevated consent grant nobody owned. The path crossed four domains; not one team owned the route. Every control was green. Storm-0558 was the same shape: a consumer signing key accepted as valid for enterprise mailboxes — a seam between two identity planes. This is the failure the industry refuses to name. A vulnerability is a property of a component; a threat is a property of the system. We have spent two decades building frameworks that make each silo defensible in isolation and almost no time building the thing that lets a defender reason across them the way an attacker already does. The fix is not another framework. It is an operating model — decision rights, intake, prioritisation, governance, delivery engagement — the connective tissue that owns the seams. Run the removal test: if your security function vanished tomorrow, would any business decision change? Part I of two. Part II continues on ARIA.
On 14 June 2026, ShinyHunters added the Council of Europe to its dark web leak site, claiming 297 GB across 429,000 files: 409,000+ payslips, 10,000+ employee records spanning fifteen years, 14,000+ CVs, interpreter scheduling, salary scales, bank and tax data, medical records. Five days earlier, Mandiant had published indicators of compromise for an active two-week zero-day campaign against Oracle PeopleSoft — CVE-2026-35273 in the Environment Management Hub, CVSS 9.8, unauthenticated, exploited from 27 May to 9 June before Oracle's 10 June advisory. 100+ organisations notified, 68% in higher education. The Council of Europe leak surfaced inside the trailing window of that campaign, with a data profile category-for-category matching what PeopleSoft holds. Whether the Council of Europe runs PeopleSoft and whether this specific breach used CVE-2026-35273 has not been publicly confirmed. What can be said: the Council of Europe is the third time in eight weeks this series has documented an identical structural shape — Trellix in May (RansomHouse, source-code access), ServiceNow in June (unauthenticated REST endpoint), now PeopleSoft. Three vendors. Three product categories. One architecture of failure. The pattern is the back-office platform, not the institution it serves.
Part II of the Governance Gap trilogy. The operational requirement that follows from the strategic finding: every security architecture is built against the threat model that the current architecture was already adequate to detect — which means the threat operating in the governance gap is, by definition, the one your architecture cannot see. The four wrong questions enterprise security is organised to answer (compliance, breach, supply chain, incident response) and the right ones (adversarial view, inference, shared infrastructure, intersection) that the full threat surface framework requires. France Titres, Snowflake, Trellix, the NIS2 / NiS2 chemical-plant scenario — each as evidence the gap is operational, not theoretical.
Part I of the Governance Gap trilogy. The Chokepoint Doctrine series’ central finding, stated as its central thesis for the first time: no institution has the mandate, the expertise, and the authority to govern the full threat surface of any critical system simultaneously, and the adversary’s operational architecture is specifically designed to exploit the space between the institutions that cannot coordinate fast enough. The three wrong questions Western institutions are asking — What is the adversary doing? Which institution is responsible? How do we deter the adversary? — and the right questions that should replace them. The governance gap is the chokepoint. Everything the series has documented is a symptom.
On 27 April 2026 the Iranian MOIS cover group Handala (Storm-0842) sent personalised WhatsApp messages to US service members at Naval Support Activity Bahrain naming them by rank, unit, and personal phone number, and the next day published the claimed details of 2,379 named US Marines — home address, family, daily commute, shopping habits, nightly leisure. The data was not stolen. It was bought. This convergence article ties the DSI adtech surveillance piece, the connected vehicle piece, and the Handala profile from the Stryker article into a single argument: three commercial data streams, one mosaic, one targeting package, no breach.
USCENTCOM has confirmed it: US forces in active war zones have been targeted using commercial location data bought from adtech brokers. No exploit. No malware. No insider. Just a credit card and a dataset. The Pentagon was first warned in 2016, when contractor Mike Yeagley tracked JSOC personnel from Fort Liberty to a covert facility inside a Lafarge cement factory in Syria using advertising data. A decade later the institutional response has remained a guidance document telling soldiers to review their privacy settings. This DSI piece maps the chain, the reverse pattern of life tradecraft, the carrier layer nobody is regulating, and what adequate protection actually requires.
130,000 UK Mercedes records on a cybercrime forum. Toyota's decade-long location-data exposure across 2.15 million customers. VW feeding driver location to law enforcement. The Mercedes breach is the visible surface rupture; the architecture beneath is a surveillance contract you signed when you bought the car.
Trellix's source code repository was breached on May 2. Three weeks earlier, Medtronic confirmed a ShinyHunters attack on 9 million patient records. They join Microsoft, Okta, and LastPass on a list that should never exist — the security vendors whose entire commercial proposition is preventing the attacks they cannot prevent on themselves. This briefing maps the structural failure and the four predicted outcomes.
Somewhere in Europe, this week, a developer cloned DevDojo Wave to bootstrap a new Laravel project. Twenty seconds later, /tmp/.sshd was running in the background — masquerading as a system daemon, downloaded from a compromised GitHub repository. The developer did not know they had installed malware. Neither did 9,100 other installations. This briefing examines the 700-repo compromise, the structural pattern across eight years of GitHub supply chain attacks, the alternatives operators are starting to consider, and what AI-driven defence can and cannot do about it.
Berlin, January 2022. Hackers took the IT systems of Oiltanking and Mabanaft offline. Tank-loading scheduling went dark for two weeks. The OT held — but the IT system that scheduled the loading did not. That is the incident pattern now migrating into the Nigerian operational reality. This briefing examines what the global oil and gas pattern is telling operators in the post-PIA Nigerian context — and why single-operator defence has reached its structural ceiling.
An industry post circulating this week articulated an accurate diagnosis: the subsea cable sector is being asked to deliver 2030 capacity with a 2005 procurement model. The diagnosis is correct. The prescription is incomplete. The three-to-five-year MOU-to-RFS gap is not a market efficiency problem awaiting a market solution. It is a strategic vulnerability that adversaries have already mapped, exploited in active conflict, and that a state actor is systematically addressing through state-subsidised construction priced twenty to thirty percent below Western competitors. HMN Technologies (formerly Huawei Marine Networks) went from 11% market share in 2021 to 18% of global cables laid in the next four years. The Digital Silk Road's stated ambition is 60%. The private build trend the industry post celebrates as innovation is, in documented cases, going to HMN because Western alternatives cannot deliver on timeline or price. ZTT commenced construction of a new cable-laying vessel in August 2025. The 2030 cable infrastructure landscape will be the operational expression of choices being made over the next thirty-six months.
A Tier 1 Nigerian bank lost billions on a Friday evening. The institution did not report the breach to its peers. Within 48 hours, two other banks were compromised by the same group. This briefing examines what the 2026 incident pattern is telling CISOs in the Nigerian banking sector — and why individual-bank defence has stopped working.
France’s national identity agency — the system managing every passport, ID card, and driver’s licence in the country — was breached by a 15-year-old exploiting an IDOR vulnerability so basic the attacker called it “really stupid.” 11.7 million records confirmed exposed. France was one of six EU member states rated “high preparedness” for the EUDI Wallet. The wallet that 450 million Europeans will use from December 2026 depends on these same government identity APIs for its initial provisioning. The certification standard does not yet exist. Part 4 of the EU Regulatory Landscape series.
41% of American higher education runs on Canvas. ShinyHunters breached it through a free tier account, exposing 275 million records across 8,809 institutions in nine countries. Six years of documented tactical evolution from exposed S3 buckets to supply chain OAuth theft to free tier exploitation. The concentration risk that made a single breach a sector-wide operational failure.
The organisations learning this the hard way all share the same story: they invested in advanced tools before they had stable foundations. AI can amplify maturity. It cannot create maturity. Why DSI has formalised a partnership with SecPoint to solve foundational visibility across Sweden, Nigeria, and Kenya.
Peter Diamandis says humanity is about to fork into five branches. He describes the opportunities. He does not describe the attack surfaces. Every fork he names -- AI creators, longevity, brain-computer interfaces, space, digital consciousness -- creates vulnerabilities that no defensive architecture yet exists to contain. And the fork he did not name is the most dangerous of all.
Jaguar Land Rover shut down for five weeks. Nucor halted steel production. Both made the same calculation: when you cannot prove IT/OT segmentation holds, you stop everything. An $18 billion monitoring industry can tell you what's on your network — but not whether it passes IEC 62443. This special report maps the gap between 160,000 newly regulated EU entities and the 33 certifications issued last year.
The adversary did not build the vulnerability. The adversary found it. How thirty years of privatisation, market logic, and institutional hollowing created the infrastructure crisis the West now blames on Russia, China, and Iran — while simultaneously cutting the agency responsible for defending against them.
The United States blockaded Iran. Iran toll-boothed the world. Two million dollars per vessel, payable in yuan, Bitcoin, or Tether — not US dollars. James C. Scott's weapons of the weak, scaled to a nation-state.
While the US Navy prepares to blockade the Strait of Hormuz with destroyers and carrier strike groups, Iran's cyber forces have already breached seventy-five industrial control systems across American critical infrastructure. The blockade runs on three fronts — physical, digital, and insurance. Two of them are already inside your network.
In 2012, Iran hit 46 US banks with 140 Gbps DDoS attacks in response to SWIFT sanctions. In March 2026, the IRGC publicly named US and Israeli-linked banks as military targets. Citi, Goldman, Standard Chartered, and HSBC evacuated Gulf offices. Sixty hacktivist groups are active. Handala deploys wiper malware that permanently destroys data. The Bangladesh Bank precedent shows 32 days to restore SWIFT access. AI-generated deepfakes target the human authentication layer above every technical control. The financial chokepoint is where a successful attack disrupts the trust architecture the entire global economy depends on.
Your HMI says everything is normal. It is not. Iranian-affiliated actors are exploiting an architectural vulnerability that Rockwell Automation admits cannot be patched — manipulating what operators see while physical processes drift. The joint advisory tells you to disconnect from the internet. It does not tell you what comes next.
Every organisation running virtualised workloads has made the same implicit assumption: that the hypervisor is trustworthy, monitored, and secure. A three-year Chinese nation-state campaign proves it is none of those things.
In twenty days, a single Iranian front group breached a former Mossad Director, Mossad’s CFO, a former Mossad Research Director, wiped 200,000 devices at an American corporation, doxxed 28 Lockheed Martin engineers, and breached the FBI Director’s personal email. The target list reads like a directory of Israeli national security leadership for the past two decades.
ENTSO-E published 472 pages of peer-reviewed engineering detail on the April 2025 Iberian blackout — the largest power failure in European history. The security community should be treating it like a threat actor whitepaper, because that is functionally what it is. The cascade physics, protection relay thresholds, and voltage control gaps are now public. The threat actors are already studying them.
The concluding piece in a series that began with a cable ship declaring force majeure and ended with a question nobody in power has answered. The answer has to exist before the warzone, not inside it.
Third-party vendor networks are the most compromised vector in Western defence. This briefing maps two decades of state-sponsored intrusions through the supply chain — from the F-35 theft to today's access broker markets — and explains why CMMC cannot fix a problem this structural.
Only four of twenty-seven member states met the NIS2 transposition deadline. Eighteen months later, ransomware attacks are up 52%, the EU faces a 299,000-person cybersecurity talent gap, and not a single NIS2-specific fine has been levied. This is the story of the gap between continental ambition and operational reality.
A cyberattack on Intoxalock stranded thousands of drivers across 46 US states. Smart beds overheat during AWS outages. Solar panels in Africa go dark when payment servers fail. 20 billion IoT devices, 75% without update mechanisms, attacked 820,000 times per day. The EU's Cyber Resilience Act is Europe's answer — but the deadline is December 2027.
The war declared the battlefield — and you're on it. Iran-linked hacker group Handala claimed responsibility for a cyberattack on Stryker Corporation, the American medical technology company. When surgical robots become geopolitical targets, every assumption about operational security needs revisiting.
Digital Identity: The Battle for Your Digital Soul — Part 3.75. Someone stole the architectural blueprints to Sweden's digital home. Not a break-in — something far more dangerous. The CGI breach exposed source code and credentials for systems integrating with BankID, used by 8.6 million Swedes.