Region: uk
All entries tagged uk.
- A third AI evaluation environment loses containment — the UK AI Security Institute records 19 unsanctioned real-world actions, including an attempt to insert malicious code into a live open-source project using fabricated identities
- PNLD confirms the police contact-data breach and names a second affected service; researchers trace the ExfilSquad campaign to anonymously readable Power Pages portals, but not PNLD's own root cause
- Criminal claims outran confirmation in every direction this week — a victim list a vendor assesses is more likely fabricated than real, yet containing a confirmed government breach; a blast-radius claim on one outlet; an attribution the victim will not endorse
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad — a five-day-old extortion brand whose other 14 claims look fabricated
- Scattered Spider duo sentenced to 5.5 years each over the 2024 Transport for London intrusion — court evidence details the helpdesk-vishing/MFA-reset chain
- NHS England issues insider-access controls after staff 'snooping' on high-profile patients' records
- Attribution and accountability: Jaguar Land Rover and Scattered Spider
- Mass third-party exposures: Xsolis, Texas Parks & Wildlife, Canvas
- Education
- Healthcare
- ShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one week
- NYT investigation gives first named attribution for the Jaguar Land Rover ransomware attack — a Russian state-linked criminal group
- UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach — 160 universities, ShinyHunters extortion, ransom paid
- Two Scattered Spider members plead guilty over the 2024 Transport for London intrusion
- UK ICO left leaderless mid-restructure — Commissioner resigns with immediate effect
- Insider and process failures — Munich school data, a lost SSD, and an NHS records caution
- Healthcare — third-party exposure and a 16-month notification gap
- HCRG Care Group first notifies patients of a February 2025 Medusa breach — 16 months on
- UK Information Commissioner resigns with immediate effect — regulator left leaderless mid-restructure
- UK ICO issues criminal caution to London Clinic insider over Princess of Wales medical-record access
- Education — ShinyHunters' PeopleSoft campaign lands disproportionately on universities
- Oracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardest
- ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
- Oxford University CareerConnect (Group GTI) breach exposes students at multiple UK universities
- ICO secures Proceeds-of-Crime confiscation from former RAC employees who sold ~30,000 customer records
- Five Eyes joint bulletin: Chinese military intelligence recruiting cleared personnel through LinkedIn and job platforms
- UK National Federation of Subpostmasters hit by ransomware via a cPanel flaw; disruption persists into June
- Proofpoint TA4922: a China-nexus cybercrime cluster expands from Japan into Germany, the UK and Italy with native-language lures and DLL-side-loaded Atlas RAT
- TA4922 — China-nexus cybercrime cluster expands from Japan into Germany, UK and Italy with native-language lures and Atlas RAT
- Ghost Stadium PhaaS — 300+ FIFA domain clones, multi-language fake SSO, targeting UK/Germany/Portugal/Spain fan credentials before June 11 kickoff
- TechCrunch finds 100 K passport scans and selfies on a public-read S3 bucket behind a UK Visa Portal lookalike
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brands
- ShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seized
- UK Visa Portal — ~100,000 passport scans and selfies on a public-read S3 bucket behind a government-lookalike site
- ICO secures £355,880 POCA confiscation against former Markerstudy Insurance employee for off-hours bulk record access and sale
- GemStuffer — RubyGems weaponised as a one-way exfiltration channel scraping UK local-authority ModernGov portals; new abuse pattern targets the asymmetric monitoring gap between package pull and push
- NCSC-UK — "10 questions to ask when using AI models to find vulnerabilities"
- ICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record
- South Staffordshire Water — ICO £963,900 fine
- Canvas/Instructure — ShinyHunters claims a *second* intrusion despite May 8 patches; seven Dutch universities executed emergency disconnects on/before May 9
- Canvas/Instructure extortion — Oxford, Cambridge, Liverpool issue public statements; 44 Dutch universities confirmed; May 12 deadline active
- Education (NL, UK, DE)
- Canvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnects