The week in breach news

End users were firmly in cybercriminals’ crosshairs this week, with Greatness phishing-as-a-service (PhaaS) platform operators targeting Microsoft 365 users via fake RingCentral alerts and a coordinated cyberattack draining more than $100 million from users of the popular Bitcoin wallet COLDCARD. Meanwhile, government agencies were also in the spotlight, with Switzerland’s federal administration confirming a data breach and Colombia’s Ministry of Justice grappling with a ransomware attack.

The week in breach news

North America

Microsoft 365 users

Industry: TechnologyExploit: Phishing

A sophisticated phishing campaign is using the Greatness phishing-as-a-service (PhaaS) platform to target Microsoft 365 accounts by impersonating RingCentral notifications.

Greatness is a subscription-based PhaaS platform that has been active since at least 2022, providing cybercriminals with ready-to-use phishing toolkits. The platform has now expanded beyond credential phishing to adversary-in-the-middle (AiTM) attacks and device-code phishing targeting Microsoft 365 accounts. In a recent campaign observed by researchers, Greatness operators are abusing the RingCentral communications platform to bypass recipients' email security filters. Attackers impersonate RingCentral by claiming messages originate from service@ringcentral[.]com and target actual users of the service with fake voicemail and performance-review notifications designed to entice them to open the emails.

Although the messages originate from an unknown IONOS mail server, fail SPF and DMARC checks and lack a DKIM signature, they are still accepted by receiving systems because RingCentral is whitelisted. The emails also include a fraudulent banner claiming the sender has been verified through the organization's safe-sender list, further reducing suspicion and making the phishing messages appear more credible to recipients.

Source

How it could affect your business

Greatness PhaaS is currently being offered to cybercriminals for less than $300 per month through a Telegram channel with thousands of subscribers. Such as-a-service platforms lower the barrier to cybercrime, enabling even attackers with limited technical expertise to launch sophisticated phishing campaigns at scale. Organizations should prioritize ongoing user awareness training to help employees recognize evolving phishing tactics, question seemingly trusted communications and verify suspicious requests before taking action.

Europe

Swiss Federal Administration

Industry: Government & Public SectorExploit: Misconfiguration

The federal administration of Switzerland confirmed that more than 200 accounts were compromised in a data breach after attackers exploited a vulnerability in Microsoft SharePoint.

Attackers breached SharePoint servers operated by Switzerland's Federal Office for Information Technology and Telecommunication (FOITT) and stole login credentials associated with roughly 200 accounts. The servers were operated by FOITT within the federal government's own data centers. According to the federal administration, unknown attackers exploited an unpatched SharePoint vulnerability to compromise the user and technical accounts.

As a precautionary measure, FOITT is reinstalling the affected SharePoint servers. Internet access for external users remains blocked until the work is completed.

Source

How it could affect your business

Unpatched vulnerabilities can provide attackers with a direct pathway into critical systems, potentially leading to credential theft, unauthorized access and broader network compromise. Automated patch management can help organizations quickly and consistently identify and deploy critical security updates, keeping systems and applications up to date and eliminating the window of opportunity for attackers.

North America

COLDCARD users

Industry: FinanceExploit: Hacking

A coordinated cyberattack targeting popular Bitcoin wallet COLDCARD reportedly resulted in estimated losses of more than $100 million across thousands of users.

COLDCARD is a popular Bitcoin-only hardware wallet developed by Canadian company Coinkite. A major cyberattack in late July and early August 2026 reportedly compromised multiple COLDCARD hardware wallet models, including MK2, MK3, MK4, Q and MK5, resulting in the theft of more than $100 million in Bitcoin. The attackers reportedly exploited a firmware flaw traced to a March 2021 firmware integration error that made supposedly unguessable seed phrases computationally enumerable, allowing attackers to reconstruct private keys without physically accessing the devices.

The incident is the latest in a wave of attacks targeting the cryptocurrency sector this year. TRM Labs has counted more than 200 incidents and nearly $950 million in losses in 2026, while Blockaid estimates losses exceeded $1 billion during the first half of the year alone.

Source

How it could affect your business

The growing number of attacks targeting cryptocurrency firms continues to drive the need for stronger enterprise cybersecurity across the sector. Hardware wallets are physical devices designed to store cryptocurrency private keys offline, offering stronger protection against malicious software and online theft. However, as this latest incident demonstrates, they are far from foolproof, and vulnerabilities in firmware or other underlying technologies can still put digital assets at risk.

Latin America & the Caribbean

Ministry of Justice and Law, Colombia

Industry: Government & Public SectorExploit: Ransomware & Malware

Colombia's Ministry of Justice was hit by a ransomware attack on August 2, 2026, affecting part of its technology infrastructure and reducing the availability of several public-facing digital services.

According to the ministry, the attack affected several services, including those related to illicit-drug monitoring and legal processes. After detecting the attack, the ministry isolated compromised systems to prevent it from spreading to other parts of the network. It also began working with Colombia's Ministry of Information and Communications Technologies and other authorities to investigate the incident.

The attack came just one day after Colombia's national cybersecurity emergency response team (ColCERT) published a threat intelligence warning that ransomware groups had increased their focus on the country. Colombia has faced an increasing number of cyberattacks targeting government agencies and government-backed or government-owned organizations in recent times. In March, the country's national tax authority was allegedly compromised, while in July, Colombia's largest oil and gas company, Ecopetrol SA, acknowledged a breach.

Source

How it could affect your business

Ransomware attacks are growing in both sophistication and frequency, putting organizations across sectors at risk of data theft, service disruption and prolonged downtime. Organizations should strengthen their ransomware defenses with proactive monitoring, timely patching, strong access controls and network segmentation, while maintaining ransomware-resilient backups and a robust business continuity and disaster recovery (BCDR) strategy to enable rapid recovery and continuity of operations.

North America

Developer ecosystems

Industry: TechnologyExploit: Supply Chain Attack

Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers.

The supply chain attack has affected packages associated with major enterprise software ecosystems, including keyv, flat-cache and cache-manager. The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a large, heavily obfuscated Bun-based JavaScript payload. The malware typically executes automatically via an npm preinstall lifecycle hook before package installation completes.

Once executed, the malware searches developer workstations and continuous integration and continuous delivery (CI/CD) environments for npm, GitHub, cloud and infrastructure credentials, potentially exposing sensitive access credentials across development environments.

Source

How it could affect your business

Supply chain attacks can have far-reaching consequences, allowing a single compromised software package to expose credentials and potentially put numerous organizations and development environments at risk. Organizations should carefully vet third-party packages, keep dependencies up to date, continuously monitor for malicious or unexpected activity and limit access to sensitive credentials using least-privilege controls. Regularly reviewing CI/CD environments and rapidly rotating potentially exposed credentials can also help reduce the impact of a compromise.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Autotask quarterly product innovation update

Autotask quarterly product innovation update

Read more
Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Read more
Compliance as a Service: The MSP revenue stream clients can't opt out of

Compliance as a Service: The MSP revenue stream clients can't opt out of

Read more