Ceva Logistics suffered a ransomware attack in September 2025 that it never disclosed. Ten months later, on July 29, 2026, it happened again, this time much bigger, and a former employee's lawsuit says the first attack should have been the wake-up call that prevented the second.
The Government Accountability Office counted the cybersecurity regulations sitting on top of American companies: 117 of them, across 37 federal agencies. The finding that deserves board attention is the overlap.
In a ransomware attack, your security team's one reliable advantage is time. The intruder breaks in, then works for hours, sometimes days or weeks, looking around, moving sideways, hunting for what matters, and somewhere in that window your monitoring is supposed to catch them. A report published July 1 shows that window closing.
The head of ASIO, Australia's domestic intelligence agency, used his annual threat assessment this month to describe a kind of breach that should change how you read the word. A foreign government's hackers had been inside an Australian critical infrastructure provider for months. They had not stolen data or sent a ransom note. They had taken the login credentials of the network's active users, including the IT staff guarding it, mapped the entire system, and quietly held on to their access. The purpose, ASIO concluded, was sabotage: "mapping out the network and maintaining access so they could cripple it at a time of their choosing."
On April 1, the ShinyHunters extortion group social-engineered a Charter Communications employee into handing over their Microsoft Entra (formerly Azure Active Directory) credentials through a voice phishing call. From that single set of credentials, the attacker pivoted into Charter's Salesforce CRM (customer relationship management system) and extracted customer and employee records before Charter detected the intrusion.
Delta Dental Insurance Company and Delta Dental of New York paid New York's financial regulator $2.25 million last month for a cybersecurity incident. The incident itself was modest. The penalty was driven by a six-month delay in notification. New York's rules require notification of a covered cybersecurity event within 72 hours. Delta Dental detected a webshell in June 2023 and did not notify the regulator until December 2023. The consent order makes the timing the central finding.
Comcast agreed this week to pay $117.5 million to settle a class action over a 2023 data breach that exposed approximately 36 million Xfinity customer records. Individual payouts reach up to $10,000 for documented out-of-pocket losses. The breach happened three years ago. The settlement landed this week. But don't let the timeline mislead you. Class actions now file within days of a disclosure, not months. The litigation machinery is automated. Plaintiff firms monitor SEC (Securities and Exchange Commission) filings and breach notifications in real time. The moment you disclose, the clock starts.
CISA's (the federal cybersecurity agency) Cyber Incident Reporting for Critical Infrastructure Act has been law since 2022. The implementing rule, the one that actually triggers compliance obligations, is expected any week. When it lands, approximately 316,000 entities across sixteen critical infrastructure sectors will have seventy-two hours to report covered cyber incidents to CISA. Twenty-four hours if they make a ransom payment. A covered incident is anything that substantially disrupts your operations, compromises your systems, or arrives through a compromised vendor. Non-reporters face DOJ (Department of Justice) referral, contempt proceedings, and suspension from government contracting.
Last week we covered Handala's wiper attack on Stryker Corporation, the medical device manufacturer that initially reported 200,000 systems destroyed across 79 countries. This week, three separate forces closed in on the company at once.