Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIBoston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents
Three healthcare organizations have reported significant data breaches affecting patient information. Boston Healthcare for the Homeless Program experienced the largest incident with at least 185,000 Massachusetts residents affected after unauthorized network access exposed comprehensive patient data including SSNs, financial information, and health records. Additional breaches were reported at Mo
AIRansomware Hits Colombian Justice Ministry Days Before Presidential Transition
Colombia's Justice Ministry suffered a ransomware attack just days before a presidential transition, highlighting the ongoing targeting of critical government infrastructure. This incident reflects a broader trend of escalating cyberattacks against government and critical infrastructure organizations throughout Latin America.
AIData Breaches Announced by Five Small Healthcare Organizations
Five small healthcare organizations have disclosed data breaches affecting patient information, with incidents ranging from ransomware attacks to email account compromises occurring between October 2025 and May 2026. The breaches exposed sensitive patient data including names, Social Security numbers, medical records, and health insurance information, with threat actors Genesis ransomware group an
AIGunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
The Gunra ransomware gang is successfully targeting critical infrastructure by exploiting known vulnerabilities in Fortinet firewalls and VPN appliances while bypassing multi-factor authentication. The group operates as a ransomware-as-a-service (RaaS) model and leverages leaked Conti ransomware code to execute their attacks. This highlights the ongoing risk posed by unpatched legacy vulnerabiliti
AIDeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The DeadLock ransomware group is leveraging decentralized infrastructure, including Polygon blockchain smart contracts and the Session messaging network, to enhance the resilience of their extortion operations. This approach makes their victim communication channels and data leak infrastructure significantly harder for law enforcement and security teams to disrupt or take down.
Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, FBI, and international partners have issued a joint advisory warning about the Gunra ransomware-as-a-service operation targeting healthcare organizations and critical infrastructure globally. The group, which transitioned to a RaaS model in 2026, offers affiliates an 80% ransom cut and exploits known vulnerabilities in VPNs and firewalls to gain network access, conducting double extortion at
AIChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has identified Storm-1175, a China-linked financially motivated threat actor, deploying a new ransomware variant called StormEncryptor, marking a shift from their previous use of Medusa ransomware. The C++-written malware appends the .encrypted extension to compromised files. This development represents an evolution in the threat actor's toolkit and operational capabilities.
AICanadian Man Pleads Guilty in Snowflake Extortions
Connor Riley Moucka, a 26-year-old Canadian cybercriminal, has pleaded guilty to orchestrating a massive data breach campaign targeting over 165 Snowflake cloud storage customers, including AT&T, TicketMaster, and other major enterprises. The attacks exploited accounts lacking multi-factor authentication, resulting in the theft of billions of sensitive customer records and over $2.5 million in ran
Ransom Cartel Mastermind Sentenced to 16 Years in Prison
Maksim Silnikau, a 40-year-old Belarusian cybercriminal and administrator of the Ransom Cartel ransomware-as-a-service operation, has been sentenced to 16 years in prison for orchestrating attacks on at least 18 companies worldwide. Operating between 2021 and 2023, Silnikau's operation caused over $6.7 million in losses while attempting to extort $5.2 million from victims through a network of recr
AIRansom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
Maksim Silnikau received a 16-year prison sentence for creating and operating Ransom Cartel, a ransomware-as-a-service (RaaS) platform that operated from 2021 to 2023. The operation targeted at least 18 companies across the United States and internationally, representing a significant law enforcement action against cybercrime infrastructure providers.
AIINC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
INC Ransomware has become the primary threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. According to Resecurity, the ransomware operation has significantly escalated its attacks since early August 2026, with multiple victims appearing on its data leak site.
OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation
OSF Healthcare System agreed to pay $552,250 to settle a HIPAA investigation following a 2021 Nephilim ransomware attack that compromised the protected health information of 53,907 patients. The OCR investigation found OSF Healthcare failed to conduct proper risk analysis, made impermissible PHI disclosures, and did not provide timely breach notifications to affected individuals and HHS. The settl
Soniva Dental Care Data Breach Affects At Least 30,000 Patients
Four healthcare service providers have disclosed significant data breaches affecting tens of thousands of patients. Soniva Dental Care experienced the largest incident with 30,000 affected individuals after a ransomware attack by TheGentlemen group targeted their remote desktop infrastructure, while Optalis Management Solutions, CareCloud, and Hudson Valley Medical Billing reported breaches affect
Global Data Breach Costs Rise 12% to Almost $5 Million
The IBM 2026 Cost of a Data Breach Study reveals that global data breach costs have surged 12% to nearly $5 million, with U.S. organizations facing the highest costs at $11.5 million per incident. AI-driven attacks have increased 56% year-over-year, adding approximately $1 million to average breach costs, while ransomware attacks affecting breached organizations jumped from 24% to 39% over four ye
Florida SUD Treatment Provider Announces 145,700-record Data Breach
Four healthcare and service providers have disclosed significant data breaches affecting over 180,000 individuals combined. Operation PAR, a Florida addiction treatment provider, suffered the largest breach impacting 145,714 individuals with exposed PHI including SSNs and financial data, while Eyemart Express, Vanderbilt Health, and Averhealth Holdings also reported incidents involving unauthorize
INC Ransomware Thrives by Mastering the Basics
INC ransomware group has achieved success by focusing on fundamental attack strategies rather than sophisticated techniques. The group strategically targets sectors like healthcare where operational disruptions create urgent pressure to pay ransoms quickly, maximizing their likelihood of payment.
Data Breaches Announced by Open Arms Care; Elmwood Home Care
Two healthcare providers, Open Arms Care Corporation in Tennessee and Elmwood Home Care in Rhode Island/Massachusetts, have disclosed significant data breaches compromising patient information. Open Arms Care experienced unauthorized email account access from June to August 2025, while Elmwood Home Care suffered a suspected LockBit5 ransomware attack between January and February 2026. Both inciden
AI'Lorem Ipsum' Malware Pivots to ClickFix Delivery
A malware campaign utilizing compromised WordPress sites has shifted its delivery method to ClickFix techniques. Security researchers have identified potential connections between this campaign and Vice Society, a known ransomware and data extortion group, raising concerns about escalating threat sophistication.
Clinical Registry Solutions; Jason R Egbert OD PC; VNC Health Announce Data Breaches
Three healthcare-related organizations have announced data breaches affecting patient information in early 2026. Clinical Registry Solutions experienced an Akira ransomware attack compromising patient and employee data, while First Sight Family Vision and VHC Health were impacted by breaches at their third-party vendors RXNT and Xsolis respectively, exposing sensitive patient information including
