ZeroHour

Search: “cambodia”

1,052 stories

Florida water agency latest to confirm cyber incident as feds warn of nation

A ransomware gang hit Florida's St. Johns River Water Management District as CISA warned of IRGC-linked CyberAv3ngers attacks on exposed Unitronics water-sector PLCs.

The St. Johns River Water Management District, which oversees Florida drinking-water supply planning, confirmed suspicious activity in its IT environment and said containment measures were implemented; a ransomware gang claimed the attack and shared samples of stolen data. Separately, CISA, FBI, NSA, EPA and Israel's INCD warned that IRGC-affiliated CyberAv3ngers are actively compromising Israeli-made Unitronics Vision Series PLCs in the water sector using default credentials since at least November 22. The group, motivated by opposition to Israel-linked products, defaces controller interfaces and could cause deeper cyber-physical effects. Shadowserver found at least 539 Unitronics PLC instances still exposed online, and CNN reported fewer than 10 US water facilities faced recent attacks.

The Record · 9d agoRansomware in the wild 3 sources

Healthcare facilities operator Nutex says patient, employee data stolen in August incident

The Gentlemen ransomware gang claims the theft of patient and employee data from healthcare operator Nutex Health, which disclosed the extortion in SEC filings.

Nutex Health said in an 8-K filing that intruders broke into its servers and exfiltrated patient, employee, provider and confidential financial data, and that it is being extorted with threats to publish the information. A Texas class action was filed after the company's August 24 disclosure, and Nutex cannot yet estimate the incident's impact. The Gentlemen ransomware-as-a-service gang, active since September 2025 and believed Russia-based, listed Nutex on its leak site; Dragos ranked it third among groups attacking industrial organizations in Q2 2026 with 125 claimed attacks.

The Record · 15d agoRansomware

Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack

Pharmaceutical giant McKesson disclosed a cyberattack on a third-party application that exfiltrated customer data, claimed by ShinyHunters.

McKesson reported a cybersecurity incident involving an unnamed third-party application, with attackers exfiltrating data tied to its oncology and surgical business units. The company filed with the SEC, offered credit monitoring, and said it had received reasonable assurance the attackers were no longer inside its systems. The ShinyHunters group claimed responsibility and threatened leaks; McKesson reported $106 billion in revenue last quarter and distributes about one-third of North American prescriptions.

The Record · 16d agoRansomware in the wild

DOJ firearms agency says hackers breached system containing investigation targets

ATF confirmed a cyberattack on a standalone system containing investigation target data, calling it a major incident; Qilin listed ATF on its leak site.

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a cyberattack on a standalone computer system containing information about targets of ATF investigations, with no connection to case management, laboratory, or eForms systems. The agency designated the breach a major incident and immediately terminated connections, initiating incident response and forensics. The Qilin ransomware gang added ATF to its leak site without providing stolen data samples. Qilin was the second most active ransomware gang in July 2026 with 127 reported attacks, and has previously hit Kuala Lumpur International Airport, Asahi, and Palau's government.

The Record · 20d agoRansomware in the wild

More than 200 victims of Medusa ransomware identified over the last year, CISA says

CISA and FBI update Medusa ransomware advisory, reporting more than 500 total victims and warning the gang operationalizes newly disclosed exploits within 24 hours.

CISA and the FBI updated their March 2025 advisory, stating Medusa actors had hit more than 500 victims as of April 2026, up from 300 in 2025, with a focus on healthcare and critical infrastructure. The agencies say Medusa rapidly adopts newly announced exploits, sometimes using them up to a week before public vulnerability disclosure, but does not develop its own zero-days, preferring access obtained from unknown sources. The gang moved to an affiliate model in 2023, offers up to $1 million for exclusive initial access brokers, and uses credential stealers plus legitimate remote access tools including AnyDesk, Atera, ConnectWise and Splashtop. No new victims have appeared on its leak site since April, after the shutdown of the University of Mississippi Medical Center drew significant law enforcement attention.

The Record · 29d agoRansomware in the wild1

Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout

'The Gentlemen' ransomware group hijacked AnMed's Facebook page, claiming theft of 6TB of sensitive patient data during an ongoing cyberattack on the hospital system.

AnMed, a nonprofit medical system with four hospitals in Georgia and South Carolina, is still responding to a July 26 cyberattack involving malware, with 10 facilities remaining closed as of Monday. On Tuesday its Facebook page displayed unauthorized posts claiming 'The Gentlemen' ransomware group exfiltrated 6 terabytes of data, including records on sexual assault, mental health, abortions and harassment; AnMed said the claims are unverified and patient data impact has not been confirmed. The Gentlemen, believed founded by a former Qilin affiliate using the moniker 'hastalamuerte,' extorted 332 victims in the first five months of 2026 per CheckPoint and claimed 125 industrial attacks in Q2 2026 per Dragos. The group typically breaches networks through edge devices, credential brute-forcing and known vulnerabilities, and offers affiliates tools to disable EDR.

The Record · Aug 11, 2026Ransomware in the wild

Local governments in four states dealing with cyberattacks that have shut down services

Ransomware and cyberattacks disrupted local governments in California, Oklahoma, South Dakota, Texas and Wisconsin, taking Suisun City's 911 offline.

Suisun City, California (population 30,000) shut down its IT network after malicious software hit 911 routing, police and fire dispatch; the city declared a state of emergency and the FBI is investigating. Coweta, Oklahoma confirmed a ransomware attack affecting all computers and digital services, with off-site backups slated for restoration. Mitchell (South Dakota), Coryell County (Texas) and Washburn County (Wisconsin) also disclosed cyberattacks that shut down networks and disrupted phone and payment systems.

The Record · Aug 11, 2026Ransomware in the wild