grc-scanSecurity & governance
News digest31 July 2026Archived edition

Cybersecurity News

This edition was published on 31 July 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

This week's biggest breaches didn't exploit clever code — they exploited a person on the phone or in a chat window who was trying to be helpful, and a vendor or domain-registrar account nobody had asked hard questions about.

  • Tell every employee, out loud, that IT support never asks them to approve a login or install software over an unsolicited call or chat.
  • Put offline, tested backups and multi-factor authentication on your domain registrar account in place before you need them, not after.
  • Never action a payment or bank-detail change from an email alone — always confirm by phone on a number you already know.

Cybersecurity News — 2026-07-31

Generated: 2026-07-31 | Sources: BleepingComputer, The Hacker News, SecurityWeek, Sophos, CISA, NCSC, HIPAA Journal, Cloudswitched


1. A Home-Security Giant Was Breached With Nothing More Than a Phone Call

Brinks Home confirmed that criminals calling themselves ShinyHunters broke into its systems using "vishing" — voice phishing — by phoning an employee, posing as internal IT support, and talking them through what looked like a routine Microsoft sign-in step that actually registered the attacker's own device as a trusted way into the company's Microsoft Entra login system. From there the attackers walked past the password and any existing multi-factor authentication and pulled data straight out of Brinks' Salesforce system: over a million customer records, thousands of employee records, and millions of support chat logs. The same group has used this exact call-the-helpdesk trick against several other large companies this month — it needs no software flaw at all, only a convincing voice and a distracted employee.

Why it matters for your business: if your business uses Microsoft 365, Google Workspace, or any system with single sign-on, tell every employee — today, out loud, not buried in an email nobody reads — that IT support will never call and ask them to approve a login prompt or register a new device on someone else's say-so, and that anyone unsure should hang up and call back on a number they already know. That one habit is exactly what would have stopped this.


2. A Fake "IT Helpdesk" Video Call Led to Ransomware in Under 17 Hours

Researchers at Sophos exposed a campaign, running since February and hitting dozens of North American organisations, where attackers impersonate a company's own IT helpdesk over Microsoft Teams — messaging or calling an employee and talking them into opening a remote-access tool (the kind IT staff genuinely use to fix a laptop from afar) or installing a piece of software. Once that access is granted, the attackers move through the network and, in several confirmed cases, deploy Chaos ransomware — in the fastest case, encrypting files in under 17 hours from the very first message. The targets were mostly ordinary mid-sized firms in services, manufacturing, energy, and construction, not global brands.

Why it matters for your business: any employee at any size of company can get a Teams message or call from someone claiming to be "IT," and the danger is precisely that it looks routine. Set one simple rule and repeat it: nobody installs remote-access software or a new app because of an unsolicited chat or call — real IT requests go through a channel your staff already know, and anything else gets verified with a second person first.


3. A Billing Company's Breach From Last September Only Reached 1.26 Million Patients This Week

Medical Computer Business Services (MCBS), a US medical billing firm, has finally notified 1.26 million patients that their names, Social Security numbers, health insurance details, and treatment information were stolen — in a break-in that actually happened in late September 2025. The roughly ten-month gap between the intrusion and the notification is typical of theft-only attacks: nothing visibly broke, so nobody went looking until the stolen data turned up for sale. A group calling itself PEAR claims responsibility and says it took 3.3 terabytes of data.

Why it matters for your business: almost every small business hands sensitive customer or patient data to at least one outside vendor — a billing company, a payroll processor, a booking platform — and that vendor's breach becomes your problem, since it's your customers' data and often your name on the notification letter. When you sign up with any vendor that holds customer data, get in writing how they'd detect a breach and how quickly they're contractually required to tell you; "trust us" isn't an answer worth accepting.


4. A Drone-Software Company Lost Control of Its Own Website's Address for a Day

CubePilot, an Australian firm whose flight-control hardware is used in drones worldwide, had its main domain's DNS records — the internet's address-book entry that tells the world where a website actually lives — hijacked by an attacker who redirected traffic and even obtained genuine-looking security certificates for the company's subdomains. For about a day, anyone visiting CubePilot's customer portal or forum may have been talking to the attacker's servers instead, with the little padlock in their browser showing everything looked fine. CubePilot has since regained control, revoked the fraudulent certificates, and is warning users not to trust anything downloaded during the hijack window.

Why it matters for your business: your website's domain and DNS settings are usually managed through a registrar account (GoDaddy, Cloudflare, 123-reg, and similar) that's rarely thought about once it's set up — and that makes it exactly the kind of account criminals target, because whoever controls it controls where your customers actually land. Turn on multi-factor authentication on your domain registrar account specifically, not just your email, and make sure more than one trusted person knows how to get back into it if needed.


5. Two Widely-Used Network Devices Are Being Actively Attacked Right Now

CISA, the US government's cyber-defence agency, added two more flaws to its list of vulnerabilities confirmed under active attack: one in Fortinet's FortiOS, the software running FortiGate firewalls used by businesses of every size, and one in Arista's VeloCloud Orchestrator, used to manage business network connections across multiple sites. The Fortinet flaw lets an attacker sneak past an earlier patch using a "symbolic link" trick — a filesystem shortcut abused to slip past a security check — without needing a password at all.

Why it matters for your business: if your business or IT provider runs a Fortinet firewall, or manages network connections across more than one site, this is a patch-this-week situation, not a patch-this-quarter one — these flaws are already being used against real targets. Ask directly: "has our firewall's firmware actually been updated since this alert?" rather than assuming a managed service handles it automatically.


6. UK Ransomware Is Hitting Ordinary Mid-Sized Firms, Not Just Household Names

New figures show 323 UK businesses were confirmed hit by ransomware in the past 12 months — roughly 26 a month — with an average loss of around £270,000 per incident. This week alone saw a UK retailer, The Mountain Company, and a UK IT services firm, Caspian One, both claimed by ransomware gangs threatening to leak stolen HR, financial, and customer data. Neither is a household name; both are the kind of ordinary mid-sized business that makes up most of the UK economy.

Why it matters for your business: "we're too small to be a target" is the single most common — and most wrong — assumption a UK small business owner can make; these gangs run attacks at scale and don't check company size before hitting "send." If you don't already have offline, tested backups — a copy a ransomware attack on your live network genuinely can't reach — that is the single highest-value fix available this month, and the difference between a bad week and a company-ending one.


7. The UK's Cyber Agency Published a Free Playbook for Surviving an Attack

The National Cyber Security Centre published detailed, free guidance titled "What to do when cyber-attacks disrupt your organisation," walking through the three phases of a real incident in plain terms: the first hours (get control of communications, work out what's actually still running), recovering to a bare-minimum working state, and the longer rebuild afterwards. It's written for organisations of any size, not only large enterprises with a dedicated security team.

Why it matters for your business: most small businesses have no written plan for "what do we actually do if our systems go down tomorrow morning," and the middle of a real incident — customers calling, staff panicking — is the worst possible time to write one from scratch. Spend an hour this month reading the guidance and jotting down, even informally, who calls whom and what "good enough to keep trading" looks like for your business specifically.


8. Scam Emails Are Getting Better at Looking Like Routine Business Admin

Researchers tracking phishing trends through 2026 report a sharp rise in AI-generated scam emails that mimic ordinary business correspondence — invoices, calendar invites, shipping notices — rather than the obviously-fake "urgent" messages of a few years ago, alongside continued growth in business email compromise (BEC), where a criminal impersonates a supplier or a boss to redirect a real payment. BEC alone cost businesses reporting to the FBI over $3 billion in the past year, and small businesses are disproportionately targeted because they typically have less staff training and no second person checking payment changes.

Why it matters for your business: any email asking you to change a bank account, approve an invoice, or open a calendar invite from an unfamiliar sender deserves one extra step — a phone call to a known number to confirm — before money moves or a file opens, because the email itself is designed to look completely unremarkable. Put a simple rule in writing: no payment or bank-detail change is ever actioned from an email alone, no matter how convincing or how senior the sender appears to be.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.