Weekly Threat Brief

Week of Sunday, September 27, 2026

Key Insights

1. The Filings Said American. The Owners Were Russian.

In every place a buyer's check would look, the public corporate filings and the chief executive's own word, Oxygen Forensics read American for the four years it was Russian-owned.

Oxygen Forensics is a Virginia company that sells software police and federal agents use to pull data off seized phones and computers. On Thursday the Justice Department announced the arrest of its chief executive, Lee Reiber, in Boise, Idaho, and of a Russian national, Oleg Davydov, at London's Heathrow airport. Both are charged with conspiracy to commit wire fraud. The complaint says the company was Russian-owned and Russian-built the entire time it was selling to the Secret Service; to Homeland Security Investigations, the Department of Homeland Security's investigative arm; to that department's inspector general; and to the Department of Defense.

The arrangement dates to March 2022. The United States had just expanded sanctions on Russia after the invasion of Ukraine, and a Russian-owned vendor selling forensic tools into federal law enforcement was about to become unsellable. So, the complaint says, Davydov, Reiber and other Russian co-conspirators changed what the company looked like from the outside. Reiber became chief executive, president and chairman of the board. The Russian owners came off the public corporate filings. Control moved to a holding company registered in Cyprus, through which Davydov and four other Russian nationals kept ownership. The engineering stayed where it had been, with a team in Russia that Davydov directed.

The cover held for four years. This February, Reiber told the Secret Service's National Computer Forensics Institute, the training center that buys these tools and teaches state and local investigators to use them, that the company was US-owned. That was a direct statement to a federal customer, not a blank left on a form. Since March 2022 the company has won more than $2 million in contracts and purchases from the Secret Service and the institute. Prosecutors put the harm plainly: procurement officials "would not have awarded or renewed contracts... had they known that OxygenUS was a Russian-owned company."

Set that against how a vendor-risk program actually works. Most check two things: whether the vendor or its owners appear on a sanctions list, and whether the vendor has attested, in a signed questionnaire, to who owns it and where its people sit. Both checks ask the vendor's own paperwork to testify against the vendor. A company willing to route ownership through a third-country holding entity and put a US citizen in the chairman's seat passes both, and passes them by design. The federal government has more screening capacity than any mid-market buyer, and the customer lied to here employs agents who investigate this exact kind of fraud for a living.

The category of software sharpens the exposure. Forensic tools, HR platforms, identity systems and anything handling biometrics sit inside your data at a depth nothing else reaches. If the developers writing that code turn out to answer to owners you cannot lawfully do business with, the exposure runs to every record the software touched in the meantime, with no clean way to establish what left.

The Takeaway
Somewhere in your vendor file is an ownership attestation nobody has ever tested against anything except the vendor's own filings. Whoever owns vendor risk at your company should start this quarter with the vendors that sit inside your HR, identity, or forensic data, because a false answer there is the hardest to unwind after the fact. For each one, the question that would have caught Oxygen is where the engineering team physically sits and who pays them, and the answer has to come from somewhere other than the questionnaire.
Sources: DOJ: Tech CEO and Russian national arrested on complaint alleging they hid Russian ownership of forensics company · CyberScoop: Oxygen Forensics CEO arrested over concealed Russian ownership · OCCRP: US charges tech CEO and Russian national over hidden ownership

2. He Extorted AT&T With the Vice President's Own Phone Records

A soldier with a stolen login spent twenty months inside at least ten telecom companies' networks, and when he wanted attention, he posted what he said were the phone records of the sitting Vice President and the incoming President.

Cameron John Wagenius, a 22-year-old former active-duty Army soldier last stationed in Texas, was sentenced on Friday to 70 months in federal prison and ordered to pay $294,978 in restitution. He had pleaded guilty more than a year earlier to wire fraud conspiracy, extortion, aggravated identity theft and trafficking in confidential phone records. Between April 2023 and December 2024, while still in uniform, he and co-conspirators used a credential-harvesting tool to get into the networks of at least ten telecommunications companies in the United States and abroad, then demanded more than $1 million combined not to publish what they took. In November 2024, operating under the handle "kiberphant0m," he posted what he said were the call records of then-Vice President Kamala Harris and then-President-elect Donald Trump on a cybercrime forum, alongside a ransom demand to AT&T. He bragged about the theft on the same forums where he sold the data, and coordinated the operation over Telegram. Prosecutors said he "targeted U.S. and foreign telecommunications companies, compromised the sensitive data of countless people, and even sought to traffic stolen information to a foreign intelligence service."

Call detail records don't carry a word anyone said. They carry something else: who called whom, when, for how long, and from roughly where. A harvested employee login carried Wagenius through carrier systems the way a real employee's would, for twenty months before anyone caught the breach. Does your company's metadata sit behind anything stronger than the same kind of login?

The Takeaway
Metadata is not the boring part of your data inventory. Does your company protect call and text metadata with the same rigor as the rest of its sensitive data, or treat it as an afterthought behind a single login? Whoever gets past that login can reconstruct who your leadership talks to, when, and how often, without ever reading a word they wrote, and it can take twenty months before anyone notices.
Sources: DOJ: Former US soldier sentenced for hacking and extortion scheme that exposed sensitive data · Krebs on Security: US soldier gets 70 months in prison for AT&T, Verizon extortions · The Register: US Army soldier who allegedly stole Trump's AT&T call logs arrested

3. A Vendor Asked Its Customers to Unplug on a Tip It Won't Show

On Friday, Kiteworks told its global customer base to shut down its file-transfer system in a rolling window that ran roughly six hours per region and about nine hours end to end, on the strength of intelligence the customer cannot see, about an attack that has not happened.

Kiteworks sells the software many companies use to move large or sensitive files with outside parties: payroll files to a processor, loan documents to a bank, patient records between providers. Its chief information security officer, Frank Balonis, said the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems..." There is no vulnerability identifier, no patch, and no indicator a customer could search its own logs for. Kiteworks says it is not aware of any compromise and calls the advisory preventative. As of Sunday, the company has not issued any follow-up confirming the window closed without incident. The FBI declined to comment. The Cybersecurity and Infrastructure Security Agency, the federal agency that normally coordinates warnings like this, did not respond. Jake Knott of the security research firm watchTowr spoke for much of the industry: "nobody requests that their entire customer base unplug production systems over the weekend because of a hunch."

The company has been here before, under another name. As Accellion, in 2020, it suffered a serious breach when a Russian-linked extortion group called Clop exploited a flaw nobody had yet patched — a breach that did lasting reputational damage, and by the following year, a new name. Whatever the intelligence actually says, asking an entire customer base to go dark for a weekend is not a small step, and a vendor with that history has more reason than most to move fast and loud on a warning rather than risk being slow again.

Comply, and you own an unplanned outage with no confirmed incident behind it. Whether that outage counts as a covered business interruption depends on the policy and the insurer, and nobody should assume the answer either way without reading their own contract. Stay online instead, and if something later does go wrong, an insurer or a regulator can point to the fact that you were warned and chose to keep running anyway. Six hours is a manageable window. The harder question is what happens the day that system, or any other single critical system, goes unavailable for longer than a weekend.

The Takeaway
If you don't already have a plan for what happens when a critical system, not just this one, goes unavailable without warning, a Saturday afternoon with a matter of hours on the clock is the wrong time to write one. The next vendor warning may not come with that much notice, or resolve that quickly.
Sources: The Record: Kiteworks urges customers to stop using systems, citing threat intelligence · Kiteworks: precautionary shutdown advisory · The Hacker News: Kiteworks urges customers to shut down

4. An Appeals Court Upheld Barring a Vendor for the Limits It Put on Its Own Product

The acceptable-use clause is the paragraph in a software contract most people don't read even once. On Friday a federal appeals court treated one as grounds to bar the vendor from every defense information system.

The D.C. Circuit Court of Appeals, the federal appeals court that hears most challenges to federal agency action, ruled 2-1 on Friday that the Pentagon acted lawfully when it designated Anthropic's Claude models a supply-chain risk and ordered them out of Defense Department information systems, including those run by contractors. Judge Gregory Katsas, joined by Judge Neomi Rao, wrote that the department "had ample support for its conclusion that the continued integration of Claude into the Department's information systems, by the Department or its contractors, presented a statutorily covered national-security risk." Judge Karen LeCraft Henderson dissented.

The dispute underneath is a contract term. The Pentagon wanted the right to use Claude for "all lawful purposes." Anthropic's usage policy carries two exclusions it would not drop: mass domestic surveillance of Americans, and lethal autonomous weapons. The risk the department identified was the refusal itself, rather than any technical flaw or misuse; the disqualifying fact was a vendor keeping limits on what its own product could be used for. The panel delayed its ruling from taking effect to give Anthropic time to seek rehearing before the same three judges, or ask the full eleven-judge D.C. Circuit to rehear the case en banc, a second round where every judge on the court, not just the three who ruled, votes on the outcome. A separate ruling last month, from a federal judge in San Francisco, struck down a different Pentagon designation of Claude on First Amendment grounds. That was a different case, over a different designation, decided by a district court one level below Friday's appeals-court ruling. Neither ruling cancels the other. Both stand at the same time, reaching opposite conclusions on two closely related questions, and nothing requires either court to change its answer to match the other.

Every contract you sign or write has a clause like this one, limiting what the product can be used for, meant to protect the seller from liability. Refusing to widen that use has always read as caution. This ruling is the first time a court has read it instead as the defect. If you hold a federal contract, or sell to a company that does, the terms flowing down to you may now arrive with a demand to drop your own use restrictions, backed by this exact ruling.

The Takeaway
Whether you write software contracts or sign them, know what your acceptable-use clause actually says. A restriction written to protect you from liability can now be read in court as the reason to exclude you instead, and that's true on both sides of the clause. This is new legal ground, and it applies whether you're the one making the software or the one running it.
Sources: CNBC: Appeals court upholds Pentagon designation of Anthropic AI as supply-chain risk · The Hill: D.C. Circuit upholds Anthropic blacklist · CNN: Anthropic loses appeal against Pentagon blacklist in D.C. Circuit ruling

5. Two of Your Vendors May Actually Be One Point of Failure

If your two largest vendors went down on the same afternoon, would your continuity plan count that as one event or two?

Swiss Re Institute, the research arm of the reinsurer Swiss Re, and the London School of Economics' Systemic Risk Centre published a joint study on Friday that reads the risk-factor sections of corporate filings from 91 Fortune 100 companies between 2019 and 2026. The authors, Jérôme Haegeli, Jón Daníelsson and Jean-Pierre Zigrand, count how often one category of risk is disclosed as depending on another. Those interconnections rose 24% over the period, and AI and supply-chain dependencies are the main new wiring, with AI-related disclosures up about 30% across the same filings. The report also points to how few hands the underlying infrastructure sits in: just three companies now supply about seven in ten cloud-computing dollars spent worldwide, and another three clear roughly 97 cents of every dollar run through a credit card.

It isn't hypothetical. When Iranian drone strikes hit Amazon Web Services data centers in the UAE and Bahrain this spring, the outage reached well past whatever military or intelligence target the strikes were actually aimed at: Abu Dhabi Commercial Bank, Emirates NBD, the payment platforms Hubpay and Alaan, and the ride-hailing app Careem all went dark too, because they happened to run in the same cloud region. A continuity plan that treats vendor failures as independent events multiplies small probabilities together and arrives at a small number. If your payroll processor and your customer database both run on one of the three clouds that supply most of that market, they don't fail independently of each other. They fail together, at whatever rate that one cloud provider fails, not some smaller number built by multiplying two separate risks. The same research flags a physical version of the same concentration: more than four in ten US data centers sit somewhere tornadoes are a real risk, so the shared dependency comes with a shared weather map as well.

The Takeaway
Your continuity plan has a loss estimate in it somewhere. The Gulf strikes already showed what happens when that estimate assumes independence: a bank, a payment platform and a ride-hailing app that had nothing to do with each other went down at the same time, for the same reason, because none of them knew how much infrastructure they actually shared.
Sources: Reinsurance News: AI and supply-chain dependencies drive systemic stress surge as risks become more interconnected (Swiss Re Institute / LSE) · Technology Magazine: Iran targets US tech firms as AWS infrastructure is damaged · CNBC: Iran war: Digital services down in UAE after data center drone strikes

6. Fifteen Governments Declare Intent to Criminalize Helping 24 Cartels

Fifteen governments told the UN this week they intend to make knowingly helping any of 24 criminal groups a crime. None of it is law yet.

On September 22 and 23, on the sidelines of the UN General Assembly in New York, the United States and fourteen Latin American and Caribbean governments, among them Argentina, Chile, Colombia, Peru, Panama and Guyana, issued a joint statement as members of a new coalition called the Shield of the Americas. Brazil and Mexico did not sign. Mexico's president, Claudia Sheinbaum, said Mexico didn't need an invitation, pointing to a separate bilateral security understanding with the United States reached in February 2025; Brazil gave no public reason. The statement declares the signatories' intention to impose asset freezes, visa and immigration restrictions, and criminal liability for anyone "knowingly providing material support, including logistical support," to 24 named criminal organizations, MS-13, the Sinaloa Cartel and Venezuela's Tren de Aragua among them. All 24 are already designated by the United States as foreign terrorist organizations. President Trump pressed the coalition toward the action at the summit. Reporting describes it as the coalition's first joint action, so what exists today is a statement of intent, with no statute, regulation or enforcement body yet behind it in any of the fifteen countries.

Sanctions screening works off a list: a government names an entity, the name goes on the list, your software checks names against it. This is a different kind of exposure. "Knowingly providing material support" doesn't wait for a name to be added anywhere. It reaches whoever moved the cargo, stored it, or cleared the payment, whether or not that company or person is ever designated. This is also just the opening move. Which specific counterparties end up caught, and how aggressively any of the fifteen governments actually enforces it, is genuinely unclear this early — a company doing business with an unlisted logistics partner in the region could find itself explaining a relationship that looked fine last month.

The Takeaway
If your company does business in Latin America, or with any counterparty who does, this is worth watching now, not after the first country legislates. A supplementary screen against the 24 named groups, run alongside your standard sanctions check, is the cheap first step. The harder step is the one to start now: know which of your logistics, payment, or sourcing partners in the region you could actually replace on short notice, because if this standard gets real teeth, you may not get much warning before you have to.
Sources: Al Jazeera: Trump rallies 'Shield of the Americas' coalition against drug cartels at UN · Demerara Waves: Guyana to impose sanctions on Haitian, Venezuelan and other narco-terrorist groups · Mexico News Daily: Why isn't Mexico part of Trump's new 'Shield of the Americas'?

7. When the Broker Is Also the Carrier It's Supposed to Independently Vet

A broker is supposed to independently vet the carriers it hires. Two of the country's largest are accused of secretly being carriers themselves.

Six trucking carriers, Stevens Trucking and Western Flyer Express among them, filed a racketeering suit on Wednesday in federal court in the Eastern District of Texas against two large freight brokers, C.H. Robinson and Total Quality Logistics. Brokers are supposed to match shippers' loads with independent trucking companies and vouch for the ones they hire, a separation that lets a broker skip the safety-reporting and registration requirements that apply to an actual motor carrier. The complaint alleges "a pattern of racketeering activity predicated on forced labor and wire fraud," claiming C.H. Robinson and TQL functioned as unregistered motor carriers themselves, blurring the line the whole arrangement depends on.

The complaint's named example, Super Ego Trucking, is a separate company, not one C.H. Robinson owns or runs. It operates more than 1,000 trucks, and C.H. Robinson designated it "carrier of the year" roughly a year ago; the complaint now calls it an "Illegal Carrier." The complaint alleges Super Ego drivers were regularly pushed to violate federal hours-of-service limits, and separately quotes unnamed former employees on other operational practices at the company. The complaint doesn't allege a kickback or a side payment for keeping Super Ego in the network. The financial motive it describes is broader: C.H. Robinson and TQL "knowingly derive a substantial financial benefit" from routing freight through non-compliant carriers generally, the kind of profit that comes from skipping the cost of the safety and registration compliance a real motor carrier has to carry. C.H. Robinson says every carrier it works with is federally authorized and meets safety and insurance standards above the legal minimum. Racketeering claims carry triple damages if they succeed, and because the plaintiffs are competitors rather than accident victims, discovery reaches the brokers' entire vetting record, not a single load file.

The Takeaway
The real exposure here isn't that a broker's vetting can end up in a lawsuit. It's the structural question the suit raises: a broker that's also functioning as the thing it's supposed to independently vet has no real reason to vet it honestly. That isn't unique to trucking. Anywhere you rely on a middleman to certify who they hire on your behalf, find out whether that middleman also operates the underlying service itself. If it does, the certification was never independent, and you're the one left holding the risk it was supposed to screen out.
Sources: FreightWaves: New lawsuit approach accuses C.H. Robinson and TQL of RICO violations

Get this brief in your inbox every Sunday.

No tracking. No spam. One email per week.

Subscribe