TheCyberExpress

TCE Weekly Roundup: Ransomware & Data Breaches


This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure. 

The latest developments reinforce that cyber threats are no longer limited to direct attacks on organizations. Threat actors are exploiting ransomware-as-a-service ecosystems, compromising government registries, targeting law enforcement databases, and abusing third-party platforms that support retail and healthcare operations.  

Organizations must strengthen third-party risk management, improve data protection measures, and enhance incident response capabilities to reduce the impact of evolving cyber threats. 

The Cyber Express Weekly Roundup 

Qilin Dominated Ransomware Attacks in H1 2026 

Qilin emerged as the most active ransomware group during the first half of 2026, targeting organizations worldwide through its ransomware-as-a-service (RaaS) operation. Manufacturing, healthcare, construction, and professional services were among the sectors most affected as the group continued expanding its global reach. Read more… 

Hackers Breach Beneficial Owners Registry, Expose Data of 31,000 Firms 

Hackers breached the Register of Beneficial Owners (VwbP), gaining unauthorized access to data associated with approximately 31,000 legal entities. Authorities temporarily took the registry offline, launched an investigation, and established a crisis response team, stating there is currently no evidence that records were altered or deleted. Read more… 

PNLD Data Breach Leaks Police and Government Contact Details 

A data breach involving the Police National Legal Database (PNLD) exposed names, organizations, and work email addresses belonging to police officers, government partners, criminal justice professionals, and some Ask the Police users after the information appeared on the dark web. Authorities are investigating the incident and assessing its potential impact. Read more… 

De Bijenkorf Logistics Cyberattack Delays Orders and Raises Data Exposure Concerns 

A cyberattack targeting a third-party logistics provider disrupted deliveries, returns, and refunds for Dutch retailer De Bijenkorf. While the retailer confirmed its internal systems were not compromised, investigators are assessing whether customer contact details and order information were exposed. Payment information, passwords, and financial data were not affected, and customers have been advised to remain vigilant against phishing attempts. Read more… 

Updoc Data Breach Exposes Customer Contact Information 

Australian telehealth provider Updoc disclosed a data breach after unauthorized access to a third-party operational platform exposed some customers’ names, email addresses, and postal addresses. The company confirmed that its internal systems remained secure and that no medical records, payment information, or financial data were compromised. Read more… 

Weekly Cybersecurity Takeaway 

This week’s incidents highlight the continued evolution of cyber threats across ransomware operations, government data breaches, and third-party supply chain compromises. 

A common theme across these events is the growing risk posed by trusted third-party platforms and shared digital ecosystems. Attackers are targeting external service providers, government databases, and ransomware affiliate networks to expand their reach and maximize operational disruption. 

Organizations should prioritize stronger third-party risk management, continuous monitoring, robust access controls, and timely incident response to reduce the impact of supply chain attacks and data breaches.

As businesses become more interconnected, strengthening the security of partner ecosystems is becoming just as important as protecting internal infrastructure. 



Source link