Global Cybersecurity Roundup: Ransomware Shifts, Major Breaches, and Law Enforcement Crackdowns
This week’s cybersecurity landscape saw ransomware gangs adapt to declining payments, high-profile data breaches, and aggressive law enforcement actions targeting cybercrime enablers and fraud rings.
Ransomware Payments Drop, But AI-Powered Gangs Rise
Ransomware victims are paying less, forcing attackers to innovate. According to ReliaQuest, ransomware groups like The Gentlemen are leveraging AI to accelerate tool development and recruit affiliates, while Deadlock has refined evasion tactics. Despite a 51% year-over-year increase in victim listings (2,252 in Q2 2024), median ransom payments fell to $698,000 down from $1.3 million in 2023 per Sophos. Recovery costs, however, rose 11% to $1.7 million over the past year. Payment rates varied by sector: 72% of local/state governments paid, compared to 32% of retailers. Encryption success rates also climbed, with 56% of attacks locking systems in 2023.
U.S. Sanctions Cybercrime Enablers
The U.S. Treasury sanctioned Dmytro Rashevskyi (Ukraine) and Yegeniy Silayev (Belarus) for facilitating ransomware operations. Rashevskyi administered 1VPNS, a VPN service used by ransomware groups to conceal attacks, while Silayev sold cryptors to obfuscate malware. The VPN, dismantled in May, was linked to billions in losses across hospitals, businesses, and governments.
Celine Dion Fans Targeted in Ticket Scam
Scammers exploited demand for Celine Dion’s Paris concerts, using Facebook groups and cloned ticketing sites to defraud fans. Group-IB identified 20+ fraudulent domains mimicking Ticketmaster, AXS, and Dion’s official site, selling duplicate digital tickets via Shopify payments. Victims received seemingly legitimate transfers, but only the first buyer gained entry others were denied. The scam likely reused phishing kits from past high-profile tours.
23andMe Settles $18M Over 2023 Breach
Genetic testing firm 23andMe (now Chrome Holding) agreed to an $18 million settlement with 43 U.S. states over a 2023 data breach exposing 7 million users. The breach stemmed from credential stuffing, with hackers advertising stolen data online. California’s lawsuit was partially dismissed, but the state may pursue non-monetary penalties. A separate $46.75 million settlement was approved for victims, including 855,000 Californians.
China-Linked Malware Found in Taiwan Tech Firm
Symantec discovered Backdoor.Daxin, a 13-year-old rootkit, on a compromised host at a Taiwan-based tech subsidiary. The malware, attributed to a Chinese state-sponsored group, hijacks legitimate TCP connections to evade detection. A new backdoor, Stupig, was also found, sharing code similarities with Daxin. Stupig exploits Windows’ keyboard-layout DLL to execute commands before login, bypassing security audits.
Spiral Ransomware Hits IT Firm in Rapid Attack
A South Asian IT services company was breached by Spiral, a Rust-based ransomware deployed within hours of initial access. Attackers exploited Microsoft IIS to upload a web shell, escalated privileges via UAC bypass, and exfiltrated credentials. The ransomware, active since June, features defense evasion, lateral movement, and encryption capabilities.
Microsoft Patches 2 Zero-Days in July Update
Microsoft fixed 622 vulnerabilities, including two actively exploited zero-days:
- CVE-2026-56164 (SharePoint Server): Allows unauthenticated privilege escalation.
- CVE-2026-56155 (Active Directory): Enables elevated access to enterprise systems.
CISA ordered immediate patching for federal agencies, warning of ongoing attacks on SharePoint servers. The update also addressed a BitLocker bypass (CVE-2026-50661) and a SharePoint auth bypass (CVE-2026-55040).
Spanish Police Dismantle €140M Cybercrime Ring
A joint Europol-Interpol operation arrested four suspects linked to a €140 million ($160M) fraud ring spanning Spain, Portugal, and Panama. The group used 800+ bank accounts and 120 business fronts to launder funds from BEC scams and investment fraud. Authorities seized 15 computers, 170 phones, and froze $3.4 million in assets.
Argentine Football Association Probes Fake Emails
The AFA investigated a cyberattack after hackers sent fraudulent emails to journalists, falsely claiming Argentina’s World Cup win over Egypt was due to "corrupt refereeing." The messages, sent from an official AFA account, referenced Egypt’s support for Palestine. Early findings suggest credentials were leaked from an Egyptian online forum. The AFA is enhancing security measures.
Source: https://www.govinfosecurity.com/breach-roundup-extortionists-annoyed-by-waning-ransomware-a-32250
23andMe cybersecurity rating report: https://www.rankiteo.com/company/23andme
"id": "23A1784263022",
"linkid": "23andme",
"type": "Breach",
"date": "5/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '7 million',
'industry': 'Healthcare',
'location': 'USA',
'name': '23andMe',
'type': 'Genetic testing firm'},
{'industry': 'Entertainment',
'location': 'Global',
'name': 'Celine Dion concert ticket buyers',
'type': 'Consumers'},
{'industry': 'Technology',
'location': 'South Asia',
'name': 'South Asian IT services company',
'type': 'IT firm'},
{'industry': 'Technology',
'location': 'Taiwan',
'name': 'Taiwan-based tech subsidiary',
'type': 'Tech firm'},
{'industry': 'Sports',
'location': 'Argentina',
'name': 'Argentine Football Association (AFA)',
'type': 'Sports organization'},
{'industry': 'Multiple',
'location': 'Spain, Portugal, Panama',
'name': 'Fraud ring victims',
'type': 'Businesses and individuals'}],
'attack_vector': ['AI-powered tool development',
'VPN exploitation',
'credential stuffing',
'web shell upload',
'TCP hijacking',
'DLL exploitation',
'fake ticketing sites',
'phishing'],
'customer_advisories': ['23andMe settlement notices',
'Celine Dion ticket scam warnings'],
'data_breach': {'data_encryption': ['yes (Spiral ransomware)',
'yes (Backdoor.Daxin)'],
'data_exfiltration': ['yes (23andMe)',
'yes (Spiral ransomware)'],
'number_of_records_exposed': '7 million (23andMe)',
'personally_identifiable_information': ['yes (23andMe)'],
'sensitivity_of_data': ['high (genetic data)', 'high (PII)'],
'type_of_data_compromised': ['genetic data',
'personally identifiable '
'information',
'credentials',
'ticketing data']},
'description': 'This week’s cybersecurity landscape saw ransomware gangs '
'adapt to declining payments, high-profile data breaches, and '
'aggressive law enforcement actions targeting cybercrime '
'enablers and fraud rings.',
'impact': {'brand_reputation_impact': ['23andMe',
'Celine Dion ticketing',
'Argentine Football Association'],
'data_compromised': ['7 million 23andMe users',
'genetic data',
'personally identifiable information',
'credentials',
'ticketing data'],
'financial_loss': ['€140 million ($160M)',
'$1.7 million (recovery costs)',
'$18 million (23andMe settlement)',
'$46.75 million (victim settlement)'],
'identity_theft_risk': ['7 million 23andMe users'],
'legal_liabilities': ['$18 million settlement (23andMe)',
'$46.75 million victim settlement'],
'operational_impact': ['hospital operations',
'business operations',
'government services'],
'systems_affected': ['Microsoft SharePoint Server',
'Active Directory',
'BitLocker',
'Microsoft IIS',
'Windows systems']},
'initial_access_broker': {'backdoors_established': ['web shell (Spiral)',
'DLL exploitation '
'(Stupig)'],
'data_sold_on_dark_web': ['23andMe data'],
'entry_point': ['Microsoft IIS',
'credential stuffing',
'phishing']},
'investigation_status': 'ongoing',
'motivation': ['financial gain', 'espionage', 'fraud', 'data exfiltration'],
'post_incident_analysis': {'corrective_actions': ['patching (Microsoft)',
'VPN dismantling',
'domain takedowns',
'enhanced security measures '
'(AFA)'],
'root_causes': ['credential stuffing (23andMe)',
'unpatched vulnerabilities '
'(Microsoft)',
'fraudulent domains (Celine Dion '
'scam)']},
'ransomware': {'data_encryption': ['56% of attacks (2023)'],
'data_exfiltration': ['yes (Spiral)'],
'ransom_paid': ['$698,000 (median)',
'72% of local/state governments',
'32% of retailers'],
'ransomware_strain': ['Spiral', 'Backdoor.Daxin', 'Stupig']},
'references': [{'source': 'ReliaQuest'},
{'source': 'Sophos'},
{'source': 'Group-IB'},
{'source': 'Symantec'},
{'source': 'U.S. Treasury'},
{'source': 'Europol'},
{'source': 'Microsoft'}],
'regulatory_compliance': {'fines_imposed': ['$18 million (23andMe '
'settlement)'],
'legal_actions': ['43 U.S. states lawsuit',
'California partial dismissal'],
'regulations_violated': ['data protection laws '
'(23andMe)']},
'response': {'communication_strategy': ['public advisories',
'settlement announcements'],
'containment_measures': ['VPN dismantling',
'domain takedowns',
'account freezing'],
'law_enforcement_notified': ['U.S. Treasury',
'Spanish Police',
'CISA'],
'remediation_measures': ['patching (Microsoft updates)',
'credential resets',
'enhanced monitoring'],
'third_party_assistance': ['Group-IB',
'Europol',
'Interpol',
'Symantec']},
'threat_actor': ['The Gentlemen',
'Deadlock',
'Dmytro Rashevskyi',
'Yegeniy Silayev',
'China-linked state-sponsored group',
'Spiral ransomware group'],
'title': 'Global Cybersecurity Roundup: Ransomware Shifts, Major Breaches, '
'and Law Enforcement Crackdowns',
'type': ['ransomware',
'data breach',
'fraud',
'malware',
'phishing',
'credential stuffing',
'BEC scam'],
'vulnerability_exploited': ['Microsoft IIS',
'UAC bypass',
'SharePoint Server (CVE-2026-56164)',
'Active Directory (CVE-2026-56155)',
'BitLocker bypass (CVE-2026-50661)',
'SharePoint auth bypass (CVE-2026-55040)']}