When did you last hand your driver's license to a rental-car counter, a retail checkout, or a venue door? The scan doesn't disappear after that transaction. It may still exist, and as of last week it may have been for sale.
Ceva Logistics suffered a ransomware attack in September 2025 that it never disclosed. Ten months later, on July 29, 2026, it happened again, this time much bigger, and a former employee's lawsuit says the first attack should have been the wake-up call that prevented the second.
KKR, one of the world's largest private equity firms, just paid the largest fine ever issued under a federal merger-review law, and none of it has to do with whether its deals were bad for competition.
LockBit listed U.S. Bancorp on its leak site this week and set a deadline: pay by September 3 or the data goes public. The bank says its own systems were never touched.
North Korea's hacking units funded roughly $2.84 billion of the regime's nuclear and missile programs through cryptocurrency theft between January 2024 and September 2025, according to the Multilateral Sanctions Monitoring Team, the eleven-nation coalition that took over UN sanctions monitoring after the original UN Panel of Experts was disbanded. No toolkit built for ordinary criminals has stopped it, and the broader losses Congress itself cites, billions lost to Americans annually through crypto scams, ransomware, and fraud, are real. Indictments against people who never see a US courtroom genuinely are losing that fight. Congress and the White House are now moving on separate tracks to close the gap by commissioning the private sector to hit back, and they're not alone.
Tariffs on imported goods are higher this year than they've been in decades, which makes it more valuable than ever for a company to fudge where a product actually came from, since the tariff rate usually depends on that answer. DOJ's response to that problem isn't new or hypothetical: a joint DOJ–Homeland Security task force built for exactly this, the Trade Fraud Task Force, has already recovered more than $1 billion in penalties, forfeitures, and charged losses since it launched in August 2025.
Amgen, the world's largest biotechnology company by revenue, disclosed in July that attackers stole patient health data and business data from a cloud system run by an outside vendor. Amgen hasn't named that vendor. It doesn't yet know how many patients are affected, or how the attackers got in. What it does know is that it's now running two separate regulatory deadlines, and neither one waits for the other.
Most companies with remote or hybrid employees use a device sitting at the edge of their network, a box that lets people log in securely from home the same way they would sit at a desk in the office. SonicWall makes one of the most common versions of this box. Security researchers at Volexity, who investigate breaches for a living, discovered that attackers had been breaking into these devices and taking full control of them, not just peeking in, since June 22. SonicWall did not have a fix ready until July 14, more than three weeks later.
An investigation by OCCRP deserves a place on your security radar, because it lands on the single most sensitive tool most companies run: the password manager, the vault that holds the keys to everything else. This is not a story you will catch in your regular feeds.
For two months the Strait of Hormuz was an oil story: whether the barrels would flow and what they would cost. This week it became a compliance story, and the calm oil price is the part that will mislead you.
Going after the marketplace instead of the seller is not new. The government shut down Silk Road and prosecuted its operator; it seized Backpage and charged the people who ran it. The lesson from Alibaba's $600 million settlement on July 1 is that the same theory now reaches a legitimate business, not just a criminal one.
For three years the United States has tried to keep advanced computing out of China's hands by cutting off the chips. This month China answered. A system called LineShine took the number one spot on the TOP500, the closely watched ranking of the world's fastest supercomputers, and it did it without a single American chip inside.
There is a kind of theft where the payoff arrives years after the crime. An adversary copies your encrypted data today, sits on it, and waits for a quantum computer powerful enough to pry the encryption open. The shorthand for it is harvest now, decrypt later, and it is the reason a problem that always sounded like a 2035 concern is suddenly a 2030 one.
The magnets that turn electricity into motion, in your electric vehicles, your factory robots, your building's ventilation, your hard drives, almost all trace back to one country. A June paper from the Royal United Services Institute, a British defense think tank, set out the dependency using International Energy Agency data: China holds 91 percent of the world's capacity to refine and process the rare-earth elements those magnets are made from. There is no close second.
For years the comfortable assumption in due diligence was simple: an EU passport meant a vetted person, and a Cyprus company meant a regulated one. It turns out the people running the vetting were the ones selling the way around it.
In 2007 the question was whether your bank held mortgage-backed securities. Most companies had no idea, because the risk was bundled and resold under names that hid what was inside. The same structure is forming now, and it is concentrated in one sector.
On June 12, the US government ordered a private company to switch off a product worldwide. The company was Anthropic, a US artificial-intelligence developer, and the product was its two newest models, Claude Fable 5, released three days earlier, and Claude Mythos 5.
The security hardware meant to keep attackers out, and the outside firm hired to run a company's technology, are the two places monitoring rarely reaches. They are also where a patient intruder settles in for a year or more.
On May 26, the FBI issued a flash alert warning that the Silent Ransom Group, an extortion operation also tracked as Luna Moth, has begun sending operatives into US law firm offices posing as IT support technicians. They walk past reception, plug USB drives into workstations, and copy files. No malware. No ransomware encryption. No locked screens. The systems keep running while the data walks out the door. According to BleepingComputer, 38 firms have already had client data leaked, with demands ranging from $1 million to $8 million.
The FIFA World Cup kicks off June 11, with matches across 11 US cities and additional venues in Mexico and Canada. The fraud is not coming with it. It is already here. More than 4,300 fraudulent domains spoofing FIFA ticketing, hotels, and merchandise are already live. Banking malware is being distributed through pirate streaming apps promising free match access. A Chinese-speaking threat group tracked as Ghost Stadium has been identified running credential-harvesting campaigns against tournament infrastructure. The FBI issued a public service announcement on May 27 warning of spoofed FIFA websites. Recorded Future published a threat assessment flagging state-sponsored espionage targeting executives at matches and influence operations using the event as a platform.
California Attorney General Rob Bonta sued Chrome Holding Co., the entity that emerged from 23andMe's bankruptcy, on May 28. The complaint alleges the company failed to protect 6.9 million users' genetic profiles, took five months to detect the breach, paid a ransom to the threat actor while publicly claiming no systems were compromised, and shifted blame to customers for reusing passwords.
On the Friday before Memorial Day, Microsoft updated its Data Processing Agreement (DPA, the contract governing how Microsoft handles your organization's data) to reduce the notice period for introducing new AI subprocessors from six months to 30 days. A subprocessor is a third-party company Microsoft contracts to process your data. In the AI context, that includes companies like Anthropic powering features inside Copilot and Azure.
[Earlier this month](https://stateofthethreat.com/weekly/2026-05-10) we flagged the Financial Stability Board's estimate of $220 billion in bank exposure to private credit across its member jurisdictions. JPMorgan moved first.
Data center power demand is outrunning what utilities can build. AI is the dominant new driver, layered on top of existing cloud and streaming growth. The Department of Energy has started giving grid operators emergency authority to curtail data centers before residential neighborhoods.
Senator Tom Cotton sent a letter to the Department of Justice (DOJ) this week asking it to investigate whether Chinese-controlled last-mile parcel carriers operating in the United States are a national security risk. The story is not the letter. It is the question the letter forces every retailer to answer.
Your outside counsel knows your acquisition targets, your deal timing, and your pricing strategy. Your incident response firm knows your insurance limits, your negotiating position, and your network architecture. Your compliance auditor knows where your security controls are weakest. You handed all of it over voluntarily because the relationship required it.
General Motors agreed on May 8 to pay $12.75 million to settle allegations that it sold the names, geolocation data, and driving behavior of hundreds of thousands of California drivers to data brokers Verisk Analytics and LexisNexis Risk Solutions through OnStar from 2020 to 2024. It is the largest fine in the California Consumer Privacy Act's (CCPA) history. GM made approximately $20 million from the data sales nationwide. The fine consumed nearly two-thirds of the revenue. GM is now banned from selling driving data to consumer reporting agencies for five years.
Poland's internal security agency warned in early May that Russian-linked hackers breached the control systems at five municipal water treatment facilities and gained the ability to change how the equipment operates. In April, Sweden attributed a cyberattack against a thermal power plant to actors connected to Russian intelligence. Two NATO members, two types of critical infrastructure, the same adversary, within weeks of each other.
Nearly a dozen governments and their intelligence agencies published a joint advisory on April 23 naming what they found inside consumer-grade network equipment worldwide. The answer was the Chinese military.
The FBI issued a public service announcement on April 30 warning that cybercriminals are stealing physical cargo by impersonating legitimate trucking companies on digital load boards (online platforms where shippers post freight and carriers bid on it). Losses hit nearly $725 million in 2025, up 60 percent from the prior year. The average theft is now worth nearly $274,000.
Two cybersecurity professionals hired to defend companies against ransomware were running it against them instead. On April 30, Ryan Goldberg, a former incident response manager at Sygnia, and Kevin Martin, a former ransomware negotiator at DigitalMint, were each sentenced to four years in federal prison for deploying BlackCat ransomware against multiple US victims during a six-month spree in 2023.
A $32 million compliance startup fabricated the security certifications your vendor assessment depends on. The cascade that followed exposed how thin the trust layer beneath the AI supply chain actually is.
The DOJ created the National Fraud Enforcement Division on April 7. Eleven days later, NFED published its first weekly enforcement tally. $340 million in fraud actions across seven days. COVID relief fraud in Kentucky, Indiana, and Colorado. An $11.4 million Medicare fraud case in Florida. Oregon pandemic unemployment-insurance fraud. New Mexico identity theft. Individual sentences ran from twenty-eight months to nine years.
Fleet-management firm Geotab published its 2025 cargo-theft report in March. North American cargo theft hit $6.6 billion last year. Incidents rose 18 percent year over year. The average theft value climbed 36 percent to roughly $274,000 per event. Strategic theft (fraud, identity theft, falsified paperwork) is displacing traditional smash-and-grab crews. Geotab surveys show about a quarter of fleet professionals now cite strategic theft as their top threat.
A tool called Webloc can track 500 million mobile devices in real time. Not through malware. Not through a warrant. Through the advertising data your phone broadcasts every time an app checks for ads.
The White House proposed cutting CISA's budget by $491 million in FY2026 and another $707 million in FY2027. The combined effect eliminates more than a thousand positions and drops the agency from 3,400 people two years ago to under 2,500. Election security is gone entirely. Chemical facility security is gone. The Joint Cyber Defense Collaborative lost $14 million. There is no Senate-confirmed director.
Three research teams published findings in February and March 2026 that shrank the estimated resources needed to break widely used encryption by a factor of 20.
On June 3, the SEC's amended Regulation S-P takes effect for thousands of smaller financial firms. Investment advisers managing under $1.5 billion, smaller broker-dealers, fund companies, and transfer agents must have a written incident response program, notify affected customers within 30 days of a breach, and require their service providers to report breaches within 72 hours. The rule was adopted in May 2024. The first compliance deadline passed in December for larger firms. The majority of SEC-registered investment advisers fall under the $1.5 billion threshold, which means most of the industry hits the deadline in June. This is the first major update to Reg S-P since it was written in 2000.
Global losses from financial fraud hit $442 billion in 2025, according to INTERPOL's March threat assessment. Behind that number is an industrial operation. Criminal syndicates across Southeast Asia, Africa, and Latin America run fraud compounds housing hundreds of thousands of people trafficked from nearly 80 nationalities. Passports confiscated. Fourteen-hour days running pig butchering schemes (long-con investment fraud where victims are groomed over weeks), romance scams, and business email compromise campaigns. The UN Office of the High Commissioner for Human Rights estimates more than 220,000 people are held in scam compounds across Myanmar and Cambodia. INTERPOL found that AI-enhanced fraud is now 4.5 times more profitable than traditional methods.
In September 2024, Hurricane Helene flooded a Baxter International plant in Marion, North Carolina. That single facility produced 60% of all IV solutions used in the United States. Hospitals rationed IV bags for five months until production resumed in February 2025. One hurricane. One building. Months of shortages across the country.
On March 20, China's Foreign Ministry called for an immediate end to the war in the Middle East, warning that the "still widening war" harms the "common interests of all countries." Spokesman Lin Jian said "force is not the solution to problems and armed conflict will only breed new hatred." Beijing demanded unimpeded energy flows from the Persian Gulf and positioned itself as the responsible voice calling for restraint while the United States conducts airstrikes across Iran.
On March 11, a group called Handala deployed wiper malware across Stryker Corporation's global network. Within hours, 200,000 systems, servers, and mobile devices were erased across 79 countries. Stryker's 56,000 employees were told to power down everything. Order processing, manufacturing, and shipping stopped. In its 8-K filing with the Securities and Exchange Commission, Stryker said it found "no indication of ransomware or malware" and believed the incident was contained, but acknowledged the timeline for full restoration is unknown and has not yet determined whether the incident is "reasonably likely to have a material impact."
While the shooting war dominates headlines, a separate conflict is increasing the cost of defending against it. US tariffs on Chinese imports have pushed the production cost of network security appliances up 14 to 18 percent. That increase hits the same whether your organization spends $5,000 or $50,000 on a firewall. This is not your vendor inflating quotes. The cost increase traces back to raw materials and components.
A leaked FSB document calls China "the enemy." A Chinese APT spent five months in a Russian defense contractor's build systems. Russia stayed quiet because it can't afford not to. Most businesses operating with Chinese partners are making the same calculation without realizing it.