1D ago
6 sources
France’s tax authority says hackers got into its systems and copied data belonging to individuals and businesses. The Economy Ministry said the intrusion hit the Directorate General of Public Finances (DGFiP) in late June after someone’s identity was stolen or misused, letting the attacker access internal systems and extract data. A hacker using the name ZeroBytes claims more than 600,000 records were taken, including names, tax IDs, email addresses, family details, and tax-status information, though that scope has not been independently verified.
— Tax-agency data can be used for identity theft, tax fraud, and highly convincing phishing or impersonation attacks. People and businesses notified by DGFiP should watch for scams, review tax-related accounts and correspondence, and treat unsolicited messages referencing tax details with extra caution.
Sources: France investigates tax authority breach after hacker claims 600,000 victims, French tax authority admits data heist after crook touts 2M records, French tax authority data breach affects 678,000 individuals (+3 more)
2D ago
2 sources
Berlin cut two state ministries off the city government network after authorities found a security breach affecting their shared IT environment. The ministries for urban development and for mobility and environment were isolated as a precaution, leaving staff without normal email and internet access and disrupting some public services. Officials have not yet named the attacker, confirmed data theft, or disclosed a CVE, but local reporting says a vulnerability in one ministry’s systems may have been exploited.
— This is a live government-network intrusion with real service disruption, affecting ministry operations and residents who rely on housing and benefits systems. Berlin agencies and other public-sector defenders should watch for follow-up details on the intrusion path, patch any related exposed systems quickly, and prepare for possible wider containment steps.
Sources: Berlin cuts two state ministries off government network after security breach, Berlin investigates new data leak after hackers publish stolen login credentials
13D ago
4 sources
The U.S. says it disabled two Chinese hacking platforms used to break into federal agencies and other sensitive networks, including the Federal Reserve, DOJ, the U.S. Senate, NASA, and healthcare and critical-infrastructure victims. According to a DOJ affidavit, QScan was used to scan for and infect internet-connected devices such as routers and cameras, while QTRouter acted as an obfuscation network to relay attacks and hide their origin. The infrastructure was allegedly operated by Nanjing Xinjiuwei Network Technology Company for users tied to China’s Ministry of State Security, the People’s Liberation Army, and other customers, with FBI tracking activity back to 2018 and linking one 2019 NASA attack to a Pulse Secure VPN exploit.
— This matters because the same infrastructure was used to hide real-world intrusions into government, healthcare, telecom, energy, and defense networks for years. Defenders should review past traffic and compromises involving QScan/QTRouter-linked infrastructure, especially around edge devices and older VPN intrusion activity, and treat this as a concrete indicator of China-linked operational tradecraft.
Sources: US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate, FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations, FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks (+1 more)
13D ago
3 sources
A large distributed denial-of-service attack knocked parts of Norway’s public digital services offline for more than a day, disrupting identity checks, government logins, data exchange, and access to records. Norwegian Digitalisation Agency Digdir said the attack began Monday and targeted infrastructure run by its IT partner Vivicta, with 10 services affected. Impacted systems included ID-porten, used by more than 4.5 million people to access thousands of government services via BankID and MinID, and some health services that depend on it for authentication.
— This affects everyday access to essential government and health services, not just internal IT. Norwegian agencies and users should expect service instability and use alternate channels where available while defenders review DDoS resilience and third-party dependency exposure.
Sources: Large DDoS attack knocks Norwegian public services offline, Massive DDoS attack disrupts Norway’s government digital services, Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services
22D ago
1 sources
Ukraine’s Asset Recovery and Management Agency (ARMA) said it was hit by a cyberattack while handling assets seized from sanctioned Russians, and it is also probing unauthorized access to an internal database of ARMA officials. The agency said the incident came as it prepared to choose a manager for seized corporate rights in IDS Ukraine, a major beverage company. Ukraine’s security service, the SBU, is investigating, but ARMA did not attribute the attack or provide technical details.
— This matters because a government agency handling politically sensitive seized assets says attackers may be trying to disrupt or influence its work. Ukrainian authorities and organizations connected to sanctions enforcement should watch for related intrusion and espionage activity, especially around staff accounts and internal databases.
Sources: Hackers target Ukrainian agency managing assets seized from sanctioned Russians
26D ago
3 sources
Researchers say attackers targeted and likely breached multiple systems at Thailand's Ministry of Finance, then used the open-source Hermes AI agent in unattended mode to automate parts of the intrusion. Hunt.io found exposed attacker directories containing 585 files, including stolen credentials, web shells, custom scripts, and logs showing Hermes was used for privilege-escalation checks, service enumeration, filesystem traversal, and Linux post-exploitation; the ministry had not confirmed the breach at publication.
— This matters because it is a real-world example of AI being used to speed up hands-on intrusion work inside a government network, which could lower the skill and time needed for follow-on attacks. Government defenders and anyone running exposed admin tools should review logs for web-shell activity, credential misuse, and suspicious enumeration, and treat exposed attacker artifacts as indicators of compromise.
Sources: Hermes AI agent used to automate attack on Thai Finance Ministry, 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency, Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
1M ago
4 sources
Cyber extortionists say they stole data from the UK Department for Education and are demanding payment not to release it. The Department for Education said two systems were affected: the DfE Help Desk Self-Service Portal and the Turing Scheme Portal, with the stolen information limited to customer-service contact details; the same report also says the Police National Legal Database was separately impacted, exposing names, police forces, and work email addresses tied to about 135,000 data records. No encryption or ransomware deployment was reported.
— This is a public-sector data theft and extortion case affecting government services and potentially police personnel contact data. Affected organizations should investigate access paths, notify impacted users as needed, and watch for follow-on phishing or impersonation using the stolen contact information.
Sources: Cyber extortionists steal data from UK Department for Education, In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research, PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web (+1 more)
1M ago
1 sources
South Korea says hackers broke into the National Diplomatic Academy’s online education system and stole personal data tied to current and former foreign ministry staff, including diplomats posted abroad. The intrusion reportedly began in April 2025 when an unknown attacker exploited a server vulnerability and remained undetected until February 2026. Exposed data includes IDs, names, email addresses, and encrypted passwords for at least 6,000 people, with some reports putting the total closer to 10,000.
— This affects government personnel, including overseas diplomats, whose exposed details could now be used in targeted phishing or espionage. Affected users should treat unexpected messages cautiously and reset or review any reused credentials, while defenders should investigate the vulnerable system and related monitoring gaps.
Sources: South Korea discloses data breach impacting diplomats worldwide
2M ago
2 sources
Brazil says an unauthorized emergency alert was sent to mobile phones across multiple states and the federal district, prompting an investigation into its public warning system. The bogus 'extreme' alert, containing the word 'misanthropy,' was reportedly issued through the Defesa Civil Alerta dispatch platform used for severe-weather and disaster warnings. SEDEC, Federal Police, and Anatel are investigating, and the platform was taken offline after the suspected intrusion.
— A compromised emergency warning system can cause public panic and undermine trust in life-safety alerts people rely on during real disasters. Mobile users in Brazil should verify unusual emergency messages with official channels, while public-sector operators should review access controls, monitoring, and recovery plans for alerting infrastructure.
Sources: Brazil probes emergency warning system after nationwide rogue alert, Suspected cyberattack triggers false emergency alerts across parts of Brazil
2M ago
1 sources
Estonia says emails sent from Russian .ru addresses to government officials will be automatically isolated for extra screening before recipients can open them. The policy takes effect August 31 and adds .ru domains to the Estonian public sector's existing email quarantine rules for suspicious messages. Officials say the move responds to increased phishing and malware delivery from Russian servers since 2022 and is part of broader defenses against Russian hybrid threats.
— This affects how Estonian public institutions handle potentially hostile communications and could reduce phishing and malware exposure for government staff. Organizations and individuals that use .ru email addresses to contact Estonian authorities may need to switch providers, and defenders should note the policy as a concrete state response to sustained Russian cyber risk.
Sources: Estonia to quarantine emails sent from Russian .ru domain before they reach government officials
3M ago
4 sources
MI5 and allied intelligence agencies warned that Chinese intelligence officers and their proxies are using job and networking platforms including LinkedIn, Indeed, and Upwork to spot and cultivate people with access to classified or otherwise sensitive government information. The advisory says the operators pose as recruiters, consultancies, think tanks, or research clients, rank applicants by likely access, request trial reports, then move conversations to encrypted messaging and pay through services such as PayPal, Zelle, Wise, Western Union, or cryptocurrency in exchange for non-public information.
— This is a real-world espionage and social-engineering threat aimed at government, defense, foreign-affairs, academic, media, and policy workers. People in or near sensitive roles should treat unsolicited research, consulting, or recruiter outreach on these platforms as potentially hostile, report suspicious contact, and avoid sharing resumes or non-public work details casually.
Sources: Five Eyes: Watch out for odd LinkedIn connection requests, China's back on the hunt for state secrets, Five Eyes warn Chinese spies are using job sites to recruit insiders, Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities (+1 more)