Banking and Government Lead Global Breach Wave

Events tracked
158
Critical exposure
45

Summary

Opportunistic exposure claims are concentrating on institutions that hold high-trust data, while attackers are pairing familiar campaign brands with many small sellers and access brokers. The mix raises verification and prioritization costs: defenders must separate credible intrusions from recycled listings without losing sight of actively exploited software and compromised delivery channels.

Today's developments

The financial sector is a primary target today, with multiple alleged breaches reported across three continents. Actors claimed incidents against BNP Paribas in France, Bank of Baroda in India, QiCard in Iraq, FlowAccount in Thailand, and the South African Reserve Bank. The diversity of both victims and threat actors -- from ParkJiSung to dhando to ki4tane -- indicates that financial data remains a high-value commodity on underground markets. Separately, actors claimed sales of large document collections tied to Iraq, the United States, and the financial services firm Transak, allegedly spanning multiple countries.

Government and public sector entities also feature prominently. Alleged breaches were reported against the Bogor City Government in Indonesia, the Government of the State of Carabobo in Venezuela, and the Punjab Information Technology Board. The Indonesia-focused activity is particularly dense, with multiple actors -- including DEWATA BLACKHAT and For Close System - F.C.S -- claiming incidents against national and municipal targets. This clustering suggests an active campaign against Indonesian digital infrastructure, likely exploiting common misconfigurations or shared service providers.

Healthcare and education are not spared. Actors claimed breaches of Private Egekent Hospital and Denizli Egekent Hospital in Turkey, as well as the University of Ruhuna in Sri Lanka and Sri Rakum School for the Blind in India. The hospital incidents, claimed by different actors, may indicate a coordinated interest in Turkish healthcare data. Industry researchers this week also highlighted a separate physical-world risk: a hijacked hotel Wi-Fi operation, tracked as CaptiveCrunch and attributed to Storm-2945, delivered the CornFlake RAT via fake browser updates, underscoring that supply-chain and physical-adjacent attack vectors remain active.

On the vulnerability front, security reporters flagged critical patches that defenders should prioritize. Adobe addressed CVE-2026-48449, a CVSS 10.0 flaw in Campaign Classic that could allow unauthenticated code execution, while Ruby on Rails patched a critical issue enabling arbitrary file read and potential RCE. Separately, a reported Coldcard hardware wallet flaw was linked to a $70 million Bitcoin theft, and a poisoned Adform script was used to swap cryptocurrency wallet addresses on customer sites -- both reminders that client-side and hardware trust boundaries are under active attack.

Threat landscape signals

The actor landscape today is fragmented but with clear repeat offenders. NoName057(16) leads with 12 events, consistent with its known DDoS-focused operations, while Hider_Nex, CRPx0, and CoupDeGrace each logged 10-11 events. The presence of multiple actors claiming both breaches and leaks suggests a low barrier to entry for data theft operations, with many groups likely repackaging or reselling access. The high number of DDoS events (32) alongside breach activity indicates that some actors may be using DDoS as a distraction or pressure tactic while data theft operations proceed.

Geographically, the United States (25 events), Israel (18), and Indonesia (12) are the most targeted, with Romania and Turkey close behind. The Israel figure is notable given regional tensions and the historical pattern of hacktivist campaigns against Israeli targets; NoName057(16)'s involvement suggests politically motivated DDoS activity remains a persistent background threat. For defenders, the actionable takeaway is clear: validate exposure claims against your own telemetry, prioritize patching for the Adobe and Ruby on Rails flaws, and treat financial and government sectors as high-probability targets for the coming week.

All incidents are reported as alleged claims by threat actors and have not been independently verified by GrayscaleInsight.

Threat intelligence is reported for security awareness purposes only and does not constitute endorsement of any actor, group, or activity.

Recent editions