August 2026 Cyberthreat Intel Report by Cynet

During August, Cynet’s CyOps Threat Intelligence Team recorded 1,011 ransomware victims claimed by threat groups, ten critical and high-severity CVEs, and three newly identified malware families. Yet the event most likely to remain memorable involved none of those victims directly. A small power generation facility in the United Kingdom was forced completely offline for four days. Even now, UK government officials and cybersecurity researchers have not reached a common conclusion about what the incident ultimately signifies. The following sections cover what happened and the other major developments highlighted by CyOps during the month.

Four Days Without Power

In July, a UK power plant remained offline for four straight days after what has been reported as a cyberattack associated with Iran. The affected facility was relatively small. Officials characterized it as a small-scale electricity generator that fell well below the threshold requiring formal reporting as a major incident. At no point was the wider national power grid considered to be at risk.

That limited scale is also what makes the case significant. Security researchers concluded that the likely objective was not widespread disruption. Instead, the incident may have been intended to show that Iran-linked groups, including actors connected with the Islamic Revolutionary Guard Corps, are capable of penetrating UK critical infrastructure and turning access to a network into a real-world operational shutdown.

The timing also corresponds with a broader trend. The incident occurred around the same period when U.S. agencies issued warnings about Iran-linked activity targeting water utilities. More than 30 U.S. water utilities reportedly experienced coordinated attacks during roughly the same timeframe.

Robert M. Lee, CEO of Dragos, cautioned against drawing premature conclusions about attribution. He noted that quickly assigning blame can make observers vulnerable to false-flag operations. In his assessment, Iran was probably responsible, but probability alone is not sufficient when geopolitical attribution is involved.

The official response, however, is clear

Michael Shanks, the UK Minister of State for Energy Security and Net Zero, confirmed the incident. He also stated that his department continues to work with industry representatives, regulators, and the National Cyber Security Centre to evaluate threats and improve protections.

Energy-sector CEOs have subsequently received additional guidance, while officials have indicated that cybersecurity regulations covering the industry are being revised. The NCSC has also said that it is already dealing with several nationally significant cyberattacks against the UK every week. Against that backdrop, a four-day outage at a single facility can be viewed as an unusually limited outcome.

Ransomware Reaches a New Record: 1,011 Claimed Victims

August established a new monthly record for publicly claimed ransomware victims. A total of 1,011 organizations were listed on ransomware leak sites during the month.

The United States continued to be the most frequently targeted country, while Manufacturing remained the leading targeted industry. Both patterns have persisted throughout most of the year.

Qilin ranked first with 164 claimed victims. The Gentlemen followed with 113. A broader group of ransomware operations – including Clop, Incransom, Direwolf, Storm, Krybit, Orova, Coinbasecartel, and Akira – each reported between 23 and 45 victims.

Two newer groups deserve particular attention. Doommageddon operated with little public visibility for approximately four months before launching a leak site on July 6. The group then retroactively listed its first six victims, linking them to compromises that had taken place weeks or even months earlier.

So far, Doommageddon has named nine organizations across Turkey, Brazil, India, Paraguay, and the United States. Manufacturing and healthcare have been the most heavily affected sectors.

FadeSEC represents the opposite end of the sophistication spectrum. It is a basic but highly automated operation capable of self-propagation through SMB, including through EternalBlue. The group does not maintain a leak site and demands only $150 in Bitcoin. Detailed analyses of both operations are included in the full August CTI report.

The Recovery Company That Wasn’t

One of the more unusual ransomware-related developments in August emerged not from the initial intrusion phase but from the supposed recovery process.

GuidePoint Security reported that an organization calling itself Ransom Busters LTD had been contacting ransomware victims before their incidents became public. The group claimed that it could recover stolen files and erase copies held by the attackers.

Those claims were false because Ransom Busters LTD was not a legitimate recovery company. It was the same ransomware affiliate responsible for compromising the organizations in the first place. The operators used their existing access to the stolen information to demand a second payment ranging from $20,000 to $60,000.

Researchers connected the activity to intrusions involving DragonForce, Settra, and Anubis by identifying common tools and infrastructure. Across multiple compromised environments, the attackers used the same SoftPerfect Network Scanner for discovery, the same password for a local backdoor, and the same attacker-controlled hostname.

The defensive takeaway is straightforward even though the scheme itself is complex. Any unsolicited offer to recover data following a ransomware incident should initially be treated as a potential secondary extortion attempt. Its legitimacy should be verified through the organization’s incident response team and law enforcement rather than through contact details supplied in the unsolicited message.

Vulnerability Spotlight: ShieldBreak

On August 11, security researcher Nightmare Eclipse released a functional proof of concept for an unpatched privilege-escalation vulnerability in Microsoft Defender. The researcher named the flaw ShieldBreak.

Microsoft acknowledged the issue three days later and assigned it CVE-2026-69414, with a CVSS score of 7.8. At the time of writing, no patch or temporary mitigation was available.

The exploit takes advantage of the Windows Cloud Filter API used to manage placeholder files. It manipulates Defender’s own remediation process into loading a DLL controlled by the attacker. Successful exploitation ultimately provides a SYSTEM-level shell.

Also This Month

Microsoft retires WMIC:

Windows 11 24H2 and 25H2 builds have begun removing the legacy WMIC command-line utility. The tool has existed for roughly 25 years and has also become a commonly abused LOLBin for activities such as reconnaissance, disabling security controls, and deleting shadow copies. The underlying WMI service itself is not being removed. However, scripts and tools that still invoke wmic.exe directly must transition to PowerShell CIM cmdlets. The role of legitimate administrative tools such as WMIC in fileless attacks and LOLBin abuse has been documented previously. Removing WMIC therefore eliminates at least one useful component from the attacker toolkit.

Sakura Internet investigates a potential compromise affecting 1.36 million accounts:

The Japanese cloud and hosting provider disclosed that attackers may have gained access to customer sales information, contract records, and service-related data. The exposure occurred through a system connected to an earlier breach involving Sakura Rental Server. No payment card information was stored in the affected environment. Investigators have also not confirmed that any data was actually exfiltrated.

Ransom Cartel creator receives a 16-year prison sentence:

Maksim Silnikau, the Belarusian administrator behind the Ransom Cartel ransomware operation, was sentenced to 16 years in a U.S. federal prison. According to prosecutors, the group extorted at least $5.2 million from 18 known victims around the world. Actual losses are believed to exceed $6.7 million when incidents that were never reported are included.

ShinyHunters targets ReliaQuest:

A ReliaQuest employee was deceived by a fraudulent SSO page designed to impersonate the company’s own security team. The attack temporarily gave the threat actors view-only access to an identity dashboard. ReliaQuest’s device-trust controls prevented every subsequent attempt to access production systems or company data. The incident provides a useful example of why identity-based access controls and device-trust mechanisms should operate as separate security layers.

INTERPOL’s Operation Jackal IV:

The monthly darknet analysis also examines INTERPOL’s latest operation targeting the Black Axe syndicate. The action resulted in 58 arrests and identified another 263 suspects. It also exposed a 196-member crime-as-a-service network in Argentina that had been quietly providing domains and money-laundering services to West African fraud groups. A complete analysis is available in the CTI report.

Get Cynet Demo



    Subscribe to news