The Record (Recorded Future News)
therecord · B · active
Cybersecurity journalism owned by Recorded Future. The homepage / lists recent dated articles. /news/cybercrime is a navigation/podcast hub with NO articles — never cite this path. Article slugs are top-level — do not GUESS slugs from headlines; always start at the homepage and follow the actual link. RSS at https://therecord.media/feed. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://therecord.media/ (homepage) OR feed https://therecord.media/feed 5, then webfetch the top-level /<slug> article. AVOID: Never cite /news/cybercrime (navigation/podcast hub, no articles); do not GUESS slugs from headlines — follow the actual link from homepage/feed. | 2026-07-05 admiralty audit: B — original, corroborated cybersecurity journalism; live. Keep active. Follow homepage/feed links, never guess slugs or cite /news/cybercrime.
Cited in 53 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 35).
- Water-utility PLC lockouts reach at least twelve US states, and Clayton County publicly confirms a distribution-side consequence as its own2026-08-06
- Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed2026-08-05
- Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution2026-08-04
- Criminal claims outran confirmation in every direction this week — a victim list a vendor assesses is more likely fabricated than real, yet containing a confirmed government breach; a blast-radius claim on one outlet; an attribution the victim will not endorse2026-08-02
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad — a five-day-old extortion brand whose other 14 claims look fabricated2026-07-31
- Russian state actor LAUNDRY BEAR weaponised a Zimbra webmail zero-click (CVE-2025-66376) for mailbox exfiltration — now exposed in a 16-nation joint advisory2026-07-24
- CERT.LV: ransomware crew breaches Latvia's state forestry operator LVM via a 2-year-unpatched system, hits essential-services provider Olpha, and is probing other EU/NATO institutions2026-07-10
- Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus2026-07-03
- Public administration & government2026-06-29
- Turla's STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection2026-06-27
- Citizen Lab: Cellebrite UFED used by Russian authorities three months after the vendor's Russia pull-out2026-06-27
- Ukrposhta digital services disrupted by an overnight attack; pro-Russian hacktivists claim a prior data theft2026-06-26
- The Gentlemen — EDR-killer framework documented, OT-adjacent victim claimed, operator named2026-06-22
- UK Information Commissioner resigns with immediate effect — regulator left leaderless mid-restructure2026-06-21
- The Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian national2026-06-20
- South Korea fines Coupang a record ₩624.7 bn over an unrevoked signing key2026-06-14
- South Korea fines Coupang a record ₩624.7 bn over an unrevoked signing key held by a former employee2026-06-13
- ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records2026-06-12
- Five Eyes joint bulletin: Chinese military intelligence recruiting cleared personnel through LinkedIn and job platforms2026-06-06
- Nightmare Eclipse / Chaotic Eclipse — Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop2026-05-30
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brands2026-05-29
- Iran MOIS attributed to LACMTA destructive breach via "Ababil of Minab" hacktivist front — 700 GB exfiltrated, backups and VMs deliberately destroyed2026-05-28
- FBI FLASH CSA 260526 — Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails2026-05-28
- Dutch National Police arrest 35-year-old over AFC Ajax fan-data breach — misconfigured API access-control and shared keys exposed 300,000+ accounts and 42,000 season-ticket records2026-05-28
- Lithuania's Centre of Registers loses ~600,000 state-register records to abused institutional credentials; foreign-state actor suspected2026-05-27
- Transport — Iran-MOIS destructive breach against LACMTA with deliberate backup and VM destruction2026-05-25
- Looking ahead — 2026-W222026-05-25
- AFC Ajax — 300,000+ fan accounts exposed via misconfigured API access control; Dutch suspect arrested2026-05-25
- Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed2026-05-24
- Kimwolf / "Dort" DDoS-for-hire operator arrested — 30+ Tbps IoT botnet, U.S. DoD-range targeting, AISURU variant2026-05-23
- FBI PSA260521 — Kali365 OAuth device-code PhaaS bypasses M365 MFA without credential capture2026-05-23
- TeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root cause2026-05-21
- Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations2026-05-20
- Huawei VRP enterprise-router zero-day caused POST Luxembourg nationwide telecom outage (July 2025) — no CVE filed 10 months later2026-05-20
- THORChain GG20 Threshold Signature Scheme vault drain — ~$11M across nine chains; Switzerland-based protocol2026-05-18
- THORChain — ~$11M cross-chain vault drain on a Switzerland-based protocol2026-05-18
- Telecom — sustained pressure from espionage tradecraft and fragile carrier infrastructure2026-05-18
- Six German university hospitals — patient records exfiltrated via billing processor Unimed2026-05-18
- Healthcare (DACH) — the soft surface is the administrative intermediary, not the hospital2026-05-18
- BKA arrests Dream Market lead administrator "Speedstepper" in Germany — cryptocurrency-to-physical-gold OPSEC failure after seven years at large2026-05-16
- TeamPCP / Mini Shai-Hulud — OpenAI named as victim; code-signing certificate rotation enforced for all macOS apps2026-05-15
- Instructure Canvas — US House Homeland Security Committee opens formal investigation; Instructure paid ransom2026-05-13
- Foxconn confirms Nitrogen ransomware crippled North-American manufacturing sites; 8 TB / 11M files claimed2026-05-13
- ICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record2026-05-12
- South Staffordshire Water — ICO £963,900 fine2026-05-11
- Manufacturing2026-05-11
- Foxconn — Nitrogen ransomware confirmed against North-American manufacturing sites2026-05-11
- Canvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigation2026-05-11
- Canvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploited2026-05-11
- DAEMON Tools Lite supply chain — QUIC RAT deployed via signed installer; EU governments among targeted victims2026-05-09
- Media and political (HU, DE)2026-05-04
- Healthcare (CH, NL)2026-05-04
- DAEMON Tools Lite supply-chain compromise — China-nexus QUIC RAT delivered via signed installers; ~12 selective government / scientific / manufacturing targets2026-05-04