Luxshare Precision Industry, a major Chinese electronics manufacturer and key Apple supplier, is alleged to have been hit by a ransomware attack in December. Bad actors are claiming they encrypted company systems and exfiltrated sensitive data linked to multiple customers. R&D data samples were leaked as proof by RansomHouse. They said: “Dear management of Luxshare Precision Industy Co. Ltd. We were waiting for you for quite some time, but it seems your IT department decided to conceal the incident that took place in your company. We strongly recommend you to contact us to prevent your confidential data, projects documents from being leaked.” The dark web post claims stolen details include internal documentation, and limited employee data, and…
Kirsten Doyle
Brightspeed, a US fiber broadband provider, began an internal cybersecurity investigation in early January after a cybercriminal group, Crimson Collective, said it accessed company systems and stole sensitive customer data affecting more than 1 million individuals. The allegation was made public on 4 January 2026 via Telegram. Screenshots and small data samples were shared as apparent proof, but their authenticity has not been confirmed. Brightspeed claimed to be reviewing the claims and said it would notify customers, employees, and authorities as more information becomes available. As of now, Brightspeed has not announced customer notifications, credit monitoring, compensation programs, or even confirmed data exfiltration or a compromise of…
More than 45M French records have been exposed in an open database more than likely compiled by malicious data collectors, reports Cybernews. Researchers said the database is a combination of data stolen in at least five breaches. It was exposed on a cloud server. Cybernews notified the server’s owners and helped take the archive down. The open database was filled with millions of French-language personal records, which seem to have been collected from multiple databases, Cybernews added. The repository appears to include a population registry, a healthcare professionals’ register, financial and KYC data, and automotive insurance CRM information. “Unlike traditional leaks caused by corporate misconfigurations, this exposure appears to be the work of a data broker or…
European travel company, Eurail BV, also known as Interrail to EU residents, has suffered a data breach in its systems that led to unauthorized access to customer data. The organizations initially announced the news on 10 January, however, affected customers, the number of which has not been disclosed, started receiving emails on 13 January. “Following the discovery, we immediately began work to secure our systems and initiated an investigation with the support of external cybersecurity specialists and legal advisors,” the company said. Interrail said it is taking the matter “very seriously” and is conducting a full investigation to determine the scope of the incident and its potential impact on customers. “The investigation is still ongoing,”…
A study by the Center for Universal Education at the Brookings Institution has found that given the current trajectory of GenAI and its implementation and use, the potential risks to students outweigh the benefits. However, it stressed that it’s “not too late to bend the arc of AI use to enrich, rather than diminish, student learning and development.” The report, dubbed “A new direction for students in an AI world: Prosper, Prepare, Protect”, provides a framework for action for all parties including schools, businesses, governments, and families. Since the introduction of ChatGPT and with the public’s growing familiarity with GenAI, the education community has been debating its promises…
Attackers are claiming to be selling Target’s internal source code and developer documentation having published a sample of stolen repositories on Gitea, a public software development platform, BleepingComputer reports. The listings reference roughly 57,000 files and directory names, with the threat actor claiming an overall dump size of approximately 860 GB being offered for sale. The repositories appear to stem from Target’s private development environment and reportedly reveal internal naming conventions, commit metadata containing engineer names, and references to internal systems. After security researchers alerted Target to the exposed repositories, the sample files were removed and the company’s developer Git server (git.target.com) was taken offline, effectively pulling its development infrastructure from public access…
In 2026, it’s clear that cyber risk isn’t coming from one major new threat. It’s coming from lots of different ones adding up. More apps. More identities. More suppliers. More automation. And more AI quietly doing work in the background. Most organizations are moving faster than their ability to see who has access, what’s trusted, and what’s acting on their behalf. Malefactors are taking advantage of that gap. They’re abusing tokens instead of passwords, exploiting on supply chains instead of direct breaches, and using automation and AI just as comfortably as defenders. At the same time, regulators, insurers, and boards are asking harder questions. They want evidence, not promises. This 2026 Cyber Predictions series brings together perspectives…
A Chinese-born billionaire wanted by US authorities for allegedly stealing at least $11 billion in bitcoin through a so-called “pig butchering” scam targeting Americans and others has been detained in Asia, according to the Wall Street Journal. Chen Zhi, the chairman of Cambodia-based multinational conglomerate Prince Group, was arrested by Cambodian law enforcement and extradited to China, government officials in Cambodia said. The country’s interior ministry stated that Chen was taken into custody at the request of the Chinese government as part of ongoing cooperation to combat transnational crime. In October, the US Justice Department said it was seeking Chen’s arrest on charges of wire fraud and money laundering, after…
Every scam tells a story. This one begins with a single email. At first glance, it looks ordinary: a polite message about a missed payment sent on behalf of an executive. It carries the right tone, the right formatting, even a convincing chain of prior correspondence. A PDF is attached: an invoice for professional services that is slightly overdue. The amount is just under $50,000. The forged email trail also makes it seem that the company authorized the payment, and it was sent to the intended victim’s accounting email to deceive the team. Instead of ransomware or a breach, it’s clever persuasion. The group behind this scheme, which Fortra has identified and named Scripted Sparrow, has spent the past year…
In our third set of predictions, the AI narrative takes a back seat, as our experts land on a more uncomfortable truth: very little of this is actually new. The same attacks are coming back, just better dressed, more convincing, and operating at a far greater scale. Social engineering, impersonation, identity abuse, and broken trust haven’t disappeared: AI has simply made them easier, faster, and harder to spot. Looking across these perspectives, 2026 appears to be the year when humans and machines become fully entangled, for better and for worse. Malefactors aren’t breaking down doors so much as slipping through the cracks: identity systems, human–AI handoffs, APIs, autonomous agents, and the…
