August is the worst month on the leak sites this year and that figure is not near the top. July had 811 named victims and everyone thought that was the highest number for a month in the summer. When I finished counting this morning, August was well above 950. The trackers will release their clean figures next week and I anticipate them to be about 964. Eight months in, 2026 is progressing roughly 25% faster than in 2025.
Here’s what stood out.
Qilin had its biggest month ever and the rest of the board reshuffled
Qilin’s figure of 157 victims exceeds its previous high of 131 and creates a 30-victim gap between itself and the second-placed team. The Gentlemen reached 127. The two of them have been sharing the top position all year, so it’s no surprise that this is the case. Breachsense’s monthly tally has the full breakdown once it publishes.
All the others were surprised. Five of the top ten had not appeared in July’s top ten. Orova achieved a fourth-place position unexpectedly with 41, DireWolf scored 40, Storm managed 37 and DarkProject got 24, both of which were their first entries. The number of different groups that reported victims in August was 83, an increase from 66 in July.
The figure in question is the real one. Just naming the largest group for this month gives you very little information about next month. A completely new name can cause 40 cases on its very first appearance, which shows that it isn’t a startup but rather affiliates switching their base. The affiliate pool is stable and the branding is disposable.
Clop woke up, as it does
After February Clop became quiet and as a result half of the industry dismissed it once more. That was wrong because it returned with 39 victims and the same pattern, a single vulnerability being exploited on a large scale, followed by a slow trickle of names.
This round focused on PTC Windchill and FlexPLM, through CVE-2026-12569. On the 17th, Shell was named with a claim involving approximately 89 GB of engineering drawings, facility reports, photos and project plans, one of more than 40 organisations Clop added to its leak site in the same wave. Shell stated that it was investigating and did not confirm that a compromise had taken place. On the same day, Clop mentioned GE and Philips. Philips claimed that its internal enterprise server had been targeted and had been contained without affecting any customer environments. GE said it was assessing the situation.
ReliaQuest later found the crew had gone to the trouble of building a web shell specifically for Windchill, with the ability to decrypt credentials and walk the file vault. That is not opportunistic. Somebody studied the product.
August should have been your warning if you run PLM systems and still thought them too dull to be attacked, since design and manufacturing data is precisely the kind of thing an extortion group wants, as there is no clean way to recover it.
ShinyHunters kept billing
RingCentral had already disclosed its July intrusion, but the real number only landed on the 13th when Have I Been Pwned went through the dumped archive and counted about 1.6 million accounts, the data including names, email addresses, phone numbers and addresses. ShinyHunters had claimed 623 GB, published 280 GB after the company refused to pay, and the platform itself remained operational. SecurityWeek has the disclosure timeline.
Carhartt was more interesting. ShinyHunters had claimed 50 GB and were asking for 3.3 million dollars. However, when people looked through the dataset, they found that a large portion of it was synthetic or duplicated and the believable figure for the number of victims was reduced to around 12.9 million. This represented the real number, although it was roughly half of the figure advertised.
On the 28th, McKesson confirmed a cybersecurity incident after ShinyHunters said it had obtained approximately 284 million patient records. McKesson stated that there had been unauthorised access to third party applications and that data had been stolen. The group told BleepingComputer it got in by vishing multiple employees, compromising their Okta single sign-on accounts, and reaching Salesforce and Snowflake from there. Nobody has verified that record count and I would bet against it remaining valid, not least because the group itself admits it is a raw row count rather than a count of people.
View the leak site numbers as if they were sales material since they are intended to make the victim pay rather than to be accurate.
The vishing wave hit finance hard
On the 21st Apollo Global Management stated that between July 6 and 10 attackers had used social engineering to gain access to its cloud environment and had taken away names, dates of birth, home addresses, contact details and Social Security numbers. Four crews were named in connection with the wider operation, namely Falcon, Helix, Pink and Redact.
At an earlier stage in the month the Financial Times stated that there had been attempts at voice phishing directed at Point72, Citadel and Millennium Management, with the callers posing as colleagues and as IT help desks. Levi’s said that three of its employees had been socially engineered into revealing access to company machines, although the company detected the intrusion swiftly. CM Alliance logged the full run of August incidents if you want the rest of them in one place.
No one on that list was attacked as a result of a vulnerability. Instead, they received a call. Nowadays your help desk identity verification procedure is a security control, even if it wasn’t originally intended to be one.
An Akira affiliate broke its own encryptor
It’s a small thing but contains some useful information. On August 4 an affiliate used stolen credentials to gain access through a SonicWall SSL VPN account that had no MFA and then retrieved data from the file shares. After that, it restarted the device into Safe Mode with Networking in order to disable the security tools, and the reduced environment caused the encryptor to fail before it could complete.
Huntress, who caught it, reckon the payload starved of virtual memory about thirteen seconds in. They also make the point that this is not a defence. A box with more RAM or a bigger page file probably encrypts fine, and their analyst told The Register the affiliates can simply retool.
Two points are worth noting. The entry point remains an unprotected VPN account, and the data theft had already taken place before the encryption step failed. The fact that encryption failed does not mean that the incident itself has failed.
DeadLock moved its plumbing onto a blockchain
The number of victims listed on DeadLock’s leak site was about 80, most of them being from Europe, and the operators moved their infrastructure onto the Polygon network using Session for communications and Wasabi for hosting stolen files. What this shows is that it is difficult to carry out a takedown because you can’t seize something that isn’t a domain.
Microsoft’s read is more measured, and worth borrowing. The chat still needs a custom proxy, the public Polygon endpoints still have to stay reachable, and files sitting on Wasabi can be pulled. Resistance is not immunity.
Later in the month their numbers actually dropped to around seven, having been in second place in June, so the group is not at its peak. However, the choice of infrastructure is one that other teams will imitate since domain seizures have been the most effective tool of disruption available to law enforcement, and this is a direct response to that.
Police had a decent month too
On the 27th Avon and Somerset in the UK stated that a court had agreed to the forfeiture of 20.21 BTC together with other assets traced to closed darknet markets, the value of which is £1,032,487.86. The fact that the relevant activity continued until 2019 shows you how long such financial investigations take.
Connor Moucka admitted guilt in connection with the Snowflake attacks. The attacks affected at least 165 organisations, more than 100 million people and resulted in victim losses amounting to over 9.5 million dollars. Once again, accounts without MFA were involved.
The ATF confirmed a major incident on the 26th following the fact that Qilin had listed the agency on its leak website. According to the ATF, the system in question was independent, with the DOJ taking part in the investigation. A spokesperson told The Register that the standalone box held information about targets of ATF investigations, which is a detail the press release left out. Nextgov has the agency’s framing.
Everything else that mattered
Since 2021, Medusa has been linked to over 500 victims among US critical infrastructure. The MyDr service in Poland leaked data involving nearly 19 million people, with more than 2 TB of data allegedly taken. In Latvia, the road traffic directorate revealed records affecting 1.2 million people and as a result officials resigned. Manchester Airports Group stated that contact details and vehicle registrations of 8.7 million of its customers had been accessed, covering Manchester, Stansted and East Midlands. On the 25th, Boston Scientific experienced a network outage which affected manufacturing and order shipping.
As far as the patch aspect is concerned, if you haven’t carried out those actions yet, make sure you do them before you log off for the weekend. Zimbra CVE-2026-73570 is currently being actively exploited, with 274 servers already confirmed to have been compromised and about 8,200 still left exposed. PaperCut issued a second emergency patch on the 28th since researchers had discovered ways of getting around the first one. There are two flaws affecting Citrix NetScaler, one of which is critical. SonicWall SMA1000 is already being used by ransomware groups.
Another one that received less attention than it merited. It seems that a vulnerability in Coldcard’s random number generator, CVE-2026-10585, was exploited to steal approximately 88 million dollars’ worth of Bitcoin. If you are holding any assets on the affected hardware, you should check.
What I’m watching in September
We don’t know if Clop will continue or whether it’ll disappear once more after six months, if anyone else joins DeadLock in moving to chain-based infrastructure, or if the OpenAI disclosure this month, that its models had autonomously discovered and exploited zero-days against real organisations including Hugging Face, will start appearing in incident reports rather than just in research papers.
The only aspect that has remained the same all year is the method of entry. This involves stolen credentials, help desks which carry out no verification, and VPN accounts lacking two-factor authentication. Each of the organisations in the top ten this month, whether new or established, had gained access through about the same kind of entry point.
Check if your credentials are exposed. See you in a month.
Sources
- Breachsense, August 2026 ransomware report
- BleepingComputer, Clop targets Windchill and FlexPLM
- BleepingComputer, Clop’s custom Windchill web shell
- BleepingComputer, RingCentral breach exposed 1.6 million accounts
- SecurityWeek, 1.6 million likely impacted by RingCentral breach
- BleepingComputer, McKesson discloses breach after ShinyHunters claims
- BleepingComputer, Akira disables EDR with Safe Mode
- Huntress, Akira hits Safe Mode
- The Register, Akira broke its own encryptor
- BleepingComputer, DeadLock uses blockchain to resist takedown
- The Register, ATF responds to major cybersecurity incident
- Nextgov, ATF investigating major cyber incident
- TronWeekly, UK police recover 1.4 million dollars in darknet assets
- Check Point, threat intelligence bulletin for the week of 31 August
- CM Alliance, major attacks and breaches in August 2026