Briefing β€” 8 September 2026

🎧 Subscribe to the podcast feed | Download episode

Security News

Dark Storm Team targets German Federal Ministry of Justice (Threat Feed) β€” The hacktivist group, which spent 7 September DDoSing Estonian government and financial institutions, escalated overnight by targeting Germany's Federal Ministry of Justice and Consumer Protection.

BD Anonymous attacks Estonian Defence Forces Support Command (Threat Feed) β€” A separate hacktivist actor hit the support command of the Estonian military, adding a direct defence-sector dimension to the ongoing Baltic-state targeting campaign.

Alleged US Social Security Administration 5TB data leak (Threat Feed) β€” A threat actor claims to have leaked 5TB of data from the US SSA, allegedly including social security numbers at scale. Unverified, but significant enough to warrant monitoring.

20TB Indian military movement data alleged for sale (Threat Feed) β€” Seller claims 25,000 documents and 600 videos related to BSF and NSG deployments 2026–2028. If genuine, a serious operational security breach for Indian defence forces.

NorthShore Health Centers falls victim to INSOMNIA ransomware (Threat Feed) β€” US healthcare provider added to INSOMNIA group's leak site, reinforcing the healthcare sector's status as the most heavily targeted this week.

Alleged sale of Epic Hyperdrive/EpicCare access to US health org (Threat Feed) β€” A threat actor claims to be selling RDP access to an unidentified US health sector organisation with Epic EMR systems in scope. Epic powers patient records for hundreds of hospitals.

Coordinated breach campaign against Indian universities (Threat Feed) β€” A single forum thread claims student data from 12+ institutions including Amity, Manipal, Aligarh Muslim University, and Amrita Vishwa Vidyapeetham β€” contact records and personal identifiers.

SmartSearch Inc β€” 18.05 million records alleged breach (Threat Feed) β€” US background-check and talent-screening firm allegedly had applicant IDs, names, and employment screening data exfiltrated. Background-check firms hold deep verified personal data.

Pakistani government employee data for sale β€” includes Atomic Energy Commission (Threat Feed) β€” Forum listing claims national ID numbers and contact details for Pakistani government staff, specifically naming the Pakistan Atomic Energy Commission in the dataset.

Nafath (Saudi Arabia national identity platform) webmail access alleged for sale (Threat Feed) β€” Nafath underpins digital identity across Saudi government services. Alleged webmail access being sold represents a high-value single point of failure.

ValueFirst alleged 12TB breach (Threat Feed) β€” India-based enterprise messaging and CPaaS provider. Breach, if real, could expose client SMS campaign data and customer contact lists at enterprise scale.

French contacts database β€” 9 million records (Threat Feed) β€” Threat actor claims to be selling 9M French contact records including names, phone numbers, addresses, and birthdates.


UK & Critical National Infrastructure

There are no new NCSC advisories published in the past 48 hours.

On the UK ransomware front, Ben Leeds Properties (πŸ‡¬πŸ‡§ UK) has appeared on the ShadowByt3$ leak site β€” the only confirmed UK victim in this 48-hour window.

The story most relevant to UK defenders today is the Dark Storm Team escalation. The group moved from Estonian civilian infrastructure to the German Federal Ministry of Justice within 24 hours, demonstrating both sustained operational capacity and willingness to target Western European government institutions. UK critical services β€” particularly NHS, transport networks, and financial infrastructure β€” should treat DDoS resilience as a live operational concern. The current threat tempo from hacktivist groups aligned with this campaign warrants active monitoring, not passive alerting.


Ransomware Victims (48h) β€” 50 victims Β· 18 groups

GroupVictimCountrySector
auroraJinny Beauty SupplyUSRetail & E-Commerce
chaosevergenbio.comUS⚠️ Healthcare/Biotech
Dark ProjectMaster Manufacturing Co., Inc.USManufacturing
Dark ProjectAlurwallsBRManufacturing
direwolfPrecision Vehicle LogisticsUS⚠️ Transportation/CNI
direwolfTrainMeCOEducation
direwolfLightcastUSProfessional Services
direwolfSemper LaserSEManufacturing
direwolfeAssist Dental SolutionsUS⚠️ Healthcare
DYSPHOR1ARTAD GOV MMMM⚠️ Government & Defense
everestGGS Information Servicesβ€”Technology
everestKΓ–RBERDEManufacturing
incransomWellness Partners networkUS⚠️ Healthcare
interlockNFM LendingUSFinancial Services
kazuMSM Unify: Global Education PlatformCAEducation
lockbit5vsbattorneys.co.zaZAProfessional Services
metaencryptorEllisDon CorporationCAProfessional Services
metaencryptorSIFCO Industries INC.USManufacturing
metaencryptorST EngineeringSG⚠️ Government & Defense
metaencryptorHologic, Inc.US⚠️ Healthcare
PanzerKHALED ALFAGIH ENGINEERING CONSULTANCYSAProfessional Services
PanzerEdacentrumDEβ€”
qilinPartners Group SKSKFinancial Services
qilinJbcESβ€”
rhysidaRug & HomeUSRetail & E-Commerce
ShadowByt3$Ben Leeds Properties πŸ‡¬πŸ‡§GBReal Estate
shinyhuntersState of Florida DMVUS⚠️ Government & Defense
shinyhuntersMedela.com ⚠️ FINAL WARNINGCH⚠️ Healthcare
thegentlemenSuperstoreGERetail & E-Commerce
thegentlemenEl CarrielCOAgriculture & Food
thegentlemenAbacoViaggiITHospitality
thegentlemenComin SacPEβ€”
thegentlemenRitz SafetyUSManufacturing
thegentlemenBiotipo JeansBRRetail & E-Commerce
thegentlemenMetroDERetail & E-Commerce
thegentlemenDomisDKRetail & E-Commerce
thegentlemenZaniniBRManufacturing
thegentlemenSoni Dwarkadas VirchandINOther
thegentlemenYapΔ± MerkeziTRManufacturing
thegentlemenS A ChileCL⚠️ Energy & Utilities
thegentlemenSharp OfficeAUProfessional Services
thegentlemenChip7PTTechnology
thegentlemenNile Projects TradingEGOther
thegentlemenUniversity of San FranciscoUSEducation
thegentlemenMutantBROther
thegentlemenDrogueria Saporiti SacifiaARRetail & E-Commerce
thegentlemenHollard Insurance GroupZAFinancial Services
Vexy RansomwareUnited GroupINOther
Vexy RansomwareLIBRERIA SANTA FE A P S SRLARRetail & E-Commerce
Show Comments