1H 2026 Examination of Cyber Hostility and Operations

August 2026 Cyberthreat Intel Report: How a Small UK Power Plant Became a Very Public Warning

Cynet’s CyOps Threat Intelligence Team tracked 1,011 claimed ransomware victims, ten critical and high-severity CVEs, and three new malware families in August. But the story that will stick is the one that didn’t touch a keyboard belonging to any of them directly: a small UK power generator got knocked fully offline for four days, and there’s still no agreement, from UK government officials to cybersecurity researchers, on what it actually means. Here’s what happened this month, and the rest of what CyOps flagged along the way.

Four Days in the Dark

In July, a UK power plant went offline for four consecutive days following what’s being reported as a cyberattack linked to Iran. The facility was small: officials described it as a small-scale energy generator, well below the threshold that requires major incident reporting, and the broader national grid was never at risk. That’s also what makes it notable. Security researchers assessed the goal wasn’t to cause widespread damage but to demonstrate that Iran-linked groups, including actors associated with the Islamic Revolutionary Guard Corps, can reach into UK critical infrastructure and turn a network intrusion into a physical shutdown.

The timing lines up with a broader pattern. The attack came around the same period U.S. agencies warned about Iran-linked targeting of water utilities, and more than 30 US water utilities reportedly saw coordinated attacks around the same window. Robert M. Lee, CEO of Dragos, put a useful check on the attribution rush: “People jumping to conclusions are very susceptible to false flag operations. It’s probably Iran. But probably isn’t enough in geopolitics.”

What isn’t in dispute is the response. Michael Shanks, UK Minister of State for Energy Security and Net Zero, confirmed the incident and said his department is working “continually with industry, regulators and the National Cyber Security Centre to assess threats and strengthen protections.” Energy CEOs have since been briefed with additional guidance, and officials have indicated that cybersecurity regulations for the sector are being updated. The NCSC, for its part, has said it’s already handling multiple nationally significant cyberattacks against the UK every week. Four days without power at even one site is a strange kind of good outcome next to that math.

Ransomware’s New Record: 1,011 Claimed Victims

August set a new high-water mark for claimed ransomware victims, with 1,011 organizations named across leak sites this month. The United States remained the most targeted country and Manufacturing the most targeted sector, continuing a trend that’s held for most of the year. Qilin led the pack with 164 claimed victims, followed by The Gentlemen at 113 and a longer tail of groups (Clop, Incransom, Direwolf, Storm, Krybit, Orova, Coinbasecartel, and Akira) that each claimed between 23 and 45.

Two new entrants are worth watching. Doommageddon ran quietly for roughly four months before standing up a leak site on July 6 and back-dating its first six victims to intrusions that had already happened weeks or months earlier; nine organizations across Turkey, Brazil, India, Paraguay, and the United States have been named so far, with manufacturing and healthcare the hardest hit. On the opposite end of the sophistication spectrum, FadeSEC is a bare-bones, highly automated operation that self-propagates over SMB (EternalBlue included), skips the leak site entirely, and asks for just $150 in Bitcoin. Full breakdowns of both are in this month’s CTI report.

The Recovery Firm That Wasn’t

One of the stranger stories this month came out of the recovery side of ransomware, not the intrusion side. GuidePoint Security reported that a group calling itself Ransom Busters LTD has been contacting ransomware victims before their incidents go public, claiming it can recover stolen files and delete the attacker’s copies. It can’t, because it isn’t a recovery firm: it’s the same ransomware affiliate that hit them in the first place, using its own insider access to the stolen data to demand a second payment of $20,000 to $60,000. Researchers tied the activity to intrusions involving DragonForce, Settra, and Anubis through shared tooling: the same SoftPerfect Network Scanner for discovery, the same local backdoor password, and the same attacker-controlled hostname across multiple victim environments.

The lesson for defenders is simple even if the scheme is elaborate: treat any unsolicited recovery offer as a second extortion attempt until it’s verified through your incident response team and law enforcement, not the number in the email.

Vulnerability Spotlight: ShieldBreak

On August 11, researcher Nightmare Eclipse published a working proof of concept for an unpatched elevation-of-privilege flaw in Microsoft Defender, which he named ShieldBreak. Microsoft acknowledged the bug three days later and assigned it CVE-2026-69414 (CVSS 7.8), but as of this writing there’s still no fix and no interim mitigation. The exploit abuses the Cloud Filter API that Windows uses for placeholder files, tricking Defender’s own remediation flow into loading an attacker-controlled DLL that hands back a SYSTEM-level shell.

Also This Month

  • Microsoft retires WMIC: Windows 11 24H2 and 25H2 builds have started removing the legacy WMIC command-line tool, a 25-year-old utility that’s also been a favorite LOLBin for attackers doing recon, disabling defenses, and deleting shadow copies. The underlying WMI service isn’t going anywhere, but scripts and tooling still calling wmic.exe directly need to move to PowerShell’s CIM cmdlets. We’ve written before about how legitimate admin tools like WMIC get weaponized in fileless attacks, and this removal is a small but real dent in that toolkit.
  • Sakura Internet investigates a possible breach of 1.36 million accounts: The Japanese cloud and hosting provider disclosed that attackers may have accessed customer sales, contract, and service records through a system connected to an earlier Sakura Rental Server breach. No payment card data was stored in the affected environment, and investigators haven’t confirmed exfiltration.
  • Ransom Cartel’s creator gets 16 years: Maksim Silnikau, the Belarusian administrator behind the Ransom Cartel ransomware operation, was sentenced to 16 years in a US federal prison. Prosecutors said the group extorted at least $5.2 million from 18 known victims worldwide, with real losses likely well above $6.7 million once unreported incidents are counted.
  • ShinyHunters targets ReliaQuest: A ReliaQuest employee was tricked by a lookalike SSO page impersonating the company’s own security team, giving attackers temporary view-only access to an identity dashboard. ReliaQuest’s device-trust controls blocked every follow-on attempt to reach real systems or data, a useful case study in why identity access and device trust need to be separate controls.
  • INTERPOL’s Operation Jackal IV: Our monthly look at the darknet covers INTERPOL’s latest action against the Black Axe syndicate: 58 arrests, 263 further suspects, and the surfacing of a 196-member crime-as-a-service network in Argentina that quietly supplied domains and money-laundering support to West African fraud groups. Full analysis is in the CTI report.

Get the Full Report

Cynet’s August 2026 Cyberthreat Intelligence Report has the complete technical breakdowns of ShieldBreak, Doommageddon, Maximum Overdrive, and FadeSEC, plus the full vulnerability review and ransomware activity data behind the numbers above.

SUBSCRIBE

Briefings in your Inbox

Original CyOps research, monthly threat intel, and early access to webinars. No fluff. Unsubscribe anytime.

Related Posts

Unix Stealer Takes Aim at VPN Credentials and Crypto Wallets
DeadLock's Quiet Extortion Campaign
1H 2026 ECHO Report Insights: The Anatomy of an Akira Intrusion
wp2shell: How Two “Low-Severity” WordPress Bugs Chain Into Full Remote Code Execution
The AI Model That Breached Hugging Face, and 848 Other Reasons July Was a Bad Month

Reading is great. Seeing is better.

See Cynet's unified AI-powered platform in a 30-minute walkthrough tailored to your environment.

Search results for: