Page 1 of 1

Recent Cyber Attacks & Emerging Cybersecurity Trends

Posted: 29 Aug 2026, 16:38
by Mexico_b
The growing impact of cyber attacks
The world is becoming more interconnected because of expanding digital ecosystems. This has led to the expansion of the attack surface. Moreover, the growing interdependence forces organizations to prepare for threats shaped by geopolitical tensions and technological shifts. Adversaries are advancing quickly, often outpacing traditional defenses. As a result, enterprises are facing increased pressure to strengthen resilience and coordinate security strategies across sectors.

According to Fortinet’s FortiGuard Labs 2025 global threat landscape report:

Automated cyber reconnaissance surged, with attackers conducting around 36,000 malicious scans per second, a 16.7% year-over-year increase.

Exploitation volume grew sharply, with over 97 billion exploitation attempts recorded in 2024.

Many attacks targeted years-old, unpatched vulnerabilities, reflecting patch gaps.

Adversaries increasingly “live off the land,” using legitimate tools for stealthy post-compromise activity.

Moreover, another report by the World Economic Forum 2025 states that:

54% of large organizations see supply-chain interdependencies as their biggest barrier to building true cyber resilience.

Nearly 60% report that shifting geopolitical dynamics have forced them to rethink and refine their cybersecurity strategies.

1 in 3 CEOs now considers cyber espionage and the theft of sensitive information or IP a top concern.

66% expect artificial intelligence to play a major role in shaping cybersecurity in 2025, yet only 37% have put proper safeguards in place for the AI tools they are already using.

Together, these insights reveal a cyber landscape that is not only expanding but becoming more complex.Notable recent cyber attacks
As stated, cyberattack patterns in 2025 have shifted toward AI-assisted automation and higher-impact supply-chain and third-party compromises. Adversaries increasingly exploit unpatched enterprise software to scale disruption across critical sectors.

Here are a few key cybersecurity incidents to consider.

UNFI (United Natural Foods Inc.) food-supply disruption: This cyber attack occurred in mid-June 2025 and impacted electronic ordering and delivery systems for a major U.S. grocery wholesaler. It led to measurable grocery shortages and forced retailers to find alternate suppliers. The incident highlights the fragility of digital supply chains.

Bank Sepah massive data theft: This breach occurred in March 2025 and was carried out by the “Codebreakers” collective. It exposed a million customer records and involved extortion attempts of $42 million. The attack was one of 2025’s largest financial-sector compromises, reflecting serious risks to banking data and confidence.

Marks & Spencer (M&S) retail outage from social engineering: The Easter-weekend compromise conducted by Scattered Spider disabled online shopping. It led to multi-week retail disruption. It caused losses of up to £300m. This attack shows the cascading business impact of targeted social engineering.

SAP NetWeaver zero-day (CVE-2025-31324) enterprise software exploitation: This incident occurred in April and involved the disclosure of a critical RCE vulnerability. It allowed web-shell uploads and active exploitation across hundreds of instances. The incident is proof of how a single flaw can put cloud and public-sector infrastructure at risk.

Kettering Health (Interlock ransomware) healthcare disruption: This incident happened in June 2025. The ransomware attack disrupted internal systems, phone lines, and EHRs across 14 medical centers. This led to forced procedure cancellations and ambulance diversions. It’s clear that healthcare remains a high-impact target with direct public-safety consequences.

Significant cyber attacks that shaped cybersecurity
U.S. Treasury vendor breach: The incident took place in December 2024. Chinese hackers accessed a third-party contractor that provided IT services to the U.S. Treasury. It is reported that around 3,000 unclassified documents linked to senior officials and financial oversight offices were exposed. The breach highlighted serious risks in government supply-chain security.

North Korean crypto exchange hacks: North Korean hackers stole millions of dollars from crypto platforms in January 2024. The funds were moved through mixing services. The stolen funds were laundered through crypto mixing services to hide their origin. This activity helped finance North Korea’s weapons programs and impacted trust in cryptocurrency platforms.

Romania election cyber targeting: The attack occurred in December 2024, ahead of Romania’s presidential election. The Russian hackers launched more than 85,000 attacks against election-related systems. The credentials they stole were later leaked on Russian hacker forums. This activity threatened election integrity and public confidence.

Salt Typhoon global telecom espionage: Chinese hackers infiltrated telecom providers in the U.S. and more than twenty other countries. They gain unauthorized access to call data, surveillance requests, and private communications. The breach enabled long-term intelligence collection on political figures. The campaign was revealed publicly in November 2024.

FINTRAC cyber incident: The incident happened in March 2024, and Canada had to shut down its financial intelligence system. The attacker remains unidentified, but the anti-money laundering operations were disrupted. This shutdown temporarily limited the government’s ability to monitor and investigate financial crime.

Pro-Russian cyberattacks on South Korea: The attacks followed political developments in November 2024. South Korean government and civilian websites were targeted by hackers, and several pro-Russian groups claimed responsibility. The attacks aimed to pressure South Korea over Ukraine-related decisions.

Iranian hack of Israeli Nuclear IT: Iranian hackers breached a connected IT network. They leaked sensitive documents online. This incident took place in March 2024. The operational systems remained secure, but the incident heightened regional security and geopolitical tensions.

Chinese breaches of Canadian government networks: Chinese hackers accessed at least twenty Canadian government systems. This activity was confirmed in October 2024. The operations involved espionage and political surveillance. Canada raised concerns over national security risks.

Trump and Harris campaign phone hack: Chinese hackers accessed phones used by senior U.S. political figures in October 2024. The FBI launched an investigation into the incident, but it raised election security concerns.

Major global cyber attacks
Ukraine power grid cyber probing: This cyber activity was detected in December 2023. The Russian hackers scanned Ukrainian energy networks. No blackout occurred, but access attempts increased sharply. The probing signaled preparation for future attacks.

Russian cyberattacks on Baltic States: The Russian hackers targeted government portals in Estonia and Latvia in November 2023. As a result, services experienced temporary outages. The attacks were politically motivated.

Chinese surveillance of Southeast Asian governments: The campaign was revealed in October 2023 and conducted by Chinese hackers. They infiltrated government networks across Southeast Asia and gained long-term access. This allowed the attackers to monitor data. The operation focused on regional political intelligence.

Iranian hack of Albanian government: Reports state that Iranian hackers disrupted Albanian government digital services because of public systems being taken offline for days. The incident was reported in October 2023 and followed diplomatic tensions.

Ransomware attack on Sri Lankan government: Hackers gained unauthorized access and deleted months of government cloud data in September 2023. Their backup systems failed to restore information, and public services suffered long-term disruption.

Russian hijacking of Pakistani hacker infrastructure: Russian hackers secretly took control of systems used by a Pakistani hacking group in December 2024. They viewed sensitive data stolen from South Asian government and military targets. The case showed how state actors exploit other cybercriminal groups for intelligence.

Phishing campaign against Ukrainian armed forces: Russian attackers sent phishing messages to Ukrainian military personnel and defense companies in December 2024. They used malware tools to steal credentials from messaging platforms and internal systems. The effort risked exposing sensitive military operations.

Fake cloud emails targeting Ukraine: This campaign took place in October 2024. Russian hackers sent emails disguised as Amazon and Microsoft messages to users. They stole credentials from Ukrainian military and government users. This increased the risk of unauthorized access to sensitive systems and operations.

Kazakhstan diplomatic spearphishing attack: In January 2025, suspected Russian-linked hackers launched phishing attacks against Kazakhstan’s diplomatic institutions. The hackers embedded malicious code inside fake official-looking diplomatic documents. Their goal was cyber espionage, focusing on sensitive foreign policy communications.

North Korean cryptocurrency theft: North Korean hackers carried out the largest cryptocurrency theft ever in February 2025. They exploited a vulnerability in third-party wallet software to steal around $1.5 billion worth of Ethereum from the ByBit exchange.

Fake recruitment targeting U.S. federal workers: Front companies linked to a Chinese tech firm targeted recently laid-off U.S. federal employees in March 2025. The operation used fake job advertisements to initiate contact. Authorities warned the campaign resembled foreign intelligence recruitment tactics.

OCC email surveillance breach: In April 2025, it was disclosed that hackers had secretly monitored emails from over 100 U.S. bank regulators. The attackers used a compromised administrator account to conduct the act. The exposed emails had several sensitive details about regulated financial institutions.

Moroccan social security data leak: Hackers linked to Algeria breached Morocco’s National Social Security Fund in April 2025. The hackers leaked personal and financial information of around two million customers.

Microsoft SharePoint exploitation: China-linked attackers exploited critical vulnerabilities in Microsoft SharePoint software in July 2025. This incident impacted U.S. government agencies and international companies.

Heathrow and European airport disruption: Hackers launched a ransomware attack and impacted airport operations platforms used across Europe in September 2025. Several functions, like check-in and boarding systems at major airports, including Heathrow, were shut down. The airlines had to carry out the functions manually.

Biggest data breaches
Data breaches grew larger and more frequent from 2023 to 2025, impacting worldwide users. Attackers used advanced methods, such as ransomware, supply-chain attacks, and cloud misconfigurations. Many organizations faced service outages, financial losses, and regulatory scrutiny. These incidents also caused long-term damage to customer trust and brand reputation.

Below is an overview of some of the most significant data breaches recorded in recent years.

SAP SE Bulgaria: SAP SE was impacted after Kubernetes Secrets were found exposed in public GitHub repositories in November 2023. It granted access to over 95 million artefacts. The exposed data included credentials and deployment permissions related to hundreds of organizations. SAP quickly remediated the issue. However, the incident showed how leaked secrets can enable large-scale supply-chain exposure.

TmaxSoft: South Korean IT firm TmaxSoft leaked over 56 million sensitive records in November 2023. The data included employee contact details, internal emails, and contract information, and remained exposed for two years. Such exposure increased the risk of phishing and supply-chain attacks.

Indian Council of Medical Research (ICMR): Data of around 815 million Indian citizens in October 2023. It was reportedly stolen from a COVID-testing database and offered for sale on the dark web. Exposed details included Aadhaar numbers, passport numbers, and home addresses. The breach represented one of the largest health data exposures ever recorded.

23andMe: Consumer genetics company 23andMe suffered credential-stuffing attacks that exposed data from up to 20 million profiles in October 2023. The stolen information included genetic ancestry data, with specific targeting of Ashkenazi Jewish users. The incident underscored the risks of password reuse and weak authentication controls.

Palau government breach: In June 2024, Palau’s government reported a breach that led to theft of more than 20,000 official documents. The breach happened soon after Palau finalized a long-term economic and security agreement with the U.S. The incident was considered the country’s first large-scale compromise of government records.

Snowflake: Cloud data platform Snowflake suffered a major breach in May 2024. It impacted over 100 customer organizations, including AT&T, Ticketmaster, and Santander Bank. Hackers linked to the Scattered Spider group gained unauthorized access by exploiting compromised employee credentials. They stole information, including billions of AT&T call records and personal data from Ticketmaster and Santander customers. The attackers demanded ransoms ranging from $300,000 to $5 million.

UK Ministry of Defence: The UK Ministry of Defence suffered a data breach in May 2024 after a cyberattack compromised a payroll system. The attackers misused personal and financial information of around 270,000 current and former military personnel. The data exposed names, bank details, and some home addresses. The breach highlighted serious supply-chain security risks.

The North Face: The North Face suffered a credential-stuffing attack in June 2025. The breach exposed nearly 3,000 customer accounts. Attackers accessed personal details, such as names, addresses, and purchase history. The incident was linked to the Scattered Spider cybercrime group and highlighted ongoing risks facing retail brands from reused credentials.

Cartier: Luxury brand Cartier disclosed a data breach in June 2025. The hackers gained access to limited customer information. While the company said financial data was not affected, the breach added to a growing list of cyber incidents targeting high-end fashion brands. The attack was also associated with activity linked to Scattered Spider.

Illinois State agencies: Hackers compromised a TxDOT account and downloaded nearly 300,000 crash reports in June 2025. The data had personal and licensing data. At the same time, a phishing campaign against Illinois Health and Family Services employees exposed sensitive data of 933 individuals. The attacks demonstrated how weak account security can impact public-sector systems.

Zoomcar: Indian car-sharing company Zoomcar reported a data breach in June 2025. It impacted nearly 8.4 million users. The incident exposed information including names, contact details, addresses, and vehicle registration numbers. Although no financial data was accessed, the scale raised serious privacy concerns.

Episource: Healthcare technology firm Episource suffered a breach in June 2025. The incident exposed sensitive personal and medical data of over 5.4 million individuals. The breach included social security numbers, insurance details, and medical records. No threat actor has claimed responsibility, but the incident underscored risks in healthcare SaaS platforms.

Scania: Truck manufacturer Scania confirmed that its insurance claims portal was breached using stolen third-party credentials in June 2025. They stole thousands of claim documents and later offered them for sale on the dark web. The breach was part of an extortion attempt by a hacker known as “Hensi.” Stolen data is commonly sold on these hidden marketplaces, and understanding dark web vs deep web vs surface web helps organizations recognize where compromised information circulation and how threat actors operate.

Cybersecurity trends redefining digital defense
Recent cyberattacks reflect that threat actors are no longer relying on isolated exploits. They are combining several tactics, like automation and social engineering, to achieve maximum impact. Here are a few cybersecurity trends that define how cyber risk has evolved in 2025.

Third-party and supply-chain compromise is a primary attack vector

Many of 2025’s most damaging incidents began with compromised vendors or shared platforms. For instance, attacks on UNFI, the U.S. Treasury, Snowflake customers, and the UK Ministry of Defence all highlight how third-party vulnerabilities can lead to disruptions.

Credential-based attacks are replacing complex malware

Threat groups increasingly conduct phishing and credential stuffing over complex malware. Campaigns targeting M&S, Ukrainian government users, retailers, and SaaS platforms show how stolen credentials enable rapid access without triggering alarms. This trend highlights the critical role of MFA, identity monitoring, and user awareness.

Zero-day and unpatched software exploitation is accelerating

Today, attackers are actively scanning for vulnerable enterprise software and weaponizing flaws within days. The SAP NetWeaver zero-day and Microsoft SharePoint exploits reveal how a single unpatched flaw can expose hundreds of organizations at once. Patch management delays now directly translate into systemic risk.

Cyber incidents are causing real-world operational disruption

Incidents in 2025 increasingly disrupted food supply chains, healthcare services, airports, and government operations. Ransomware attacks forced hospital diversions, grounded flights, and manual airport operations. Cybersecurity has become a public safety and economic stability concern.

State-linked cyber operations are blending espionage and cybercrime

Attacks related to China, Russia, Iran, and North Korea reflect a growing overlap between espionage and political influence. From election interference to crypto theft funding weapons programs, cyber operations are now strategic tools of national power. Attribution may remain unclear, but the geopolitical consequences are not.

These evolving threats and cyber attacks require faster detection and automated response. Fortinet’s SIEM and SOAR solutions, including FortiSIEM and FortiSOAR, can help organizations detect advanced attacks. These solutions can help correlate signals across IT and OT environments and enable teams to respond proactively. Backed by FortiGuard threat intelligence, Fortinet enables security teams to stay ahead of high-impact cyber risks.

When major data breaches and fast-moving cyber threats outpace defenses, every delayed detection increases risk — the right intelligence can make the difference. Discover FortiGuard Services. ~

soucr : https://www.fortinet.com/resources/cybe ... er-attacks