Cybersecurity headlines are data-layer warnings.
Threat analysis, breach lessons, and Cyberstorage guidance for organizations defending unstructured data.
Latest Threat Briefs
Analysis of active threats and what they mean for data at the storage layer.

ExfilSquad skips the encryption and publishes stolen files as torrents
A new extortion crew surfaced in late July claiming fifteen victims in a single day, confirmed breaches at two UK institutions, and no ransomware at all. When deadlines passed, ExfilSquad began seeding stolen data as torrents, making the leak effectively permanent.
August 12, 2026

INC ransomware is stealing the identity layer, not just the perimeter
A pair of SonicWall SMA 1000 vulnerabilities gives attackers root on the VPN appliance, and INC ransomware is using that access to read passwords off the wire, copy live session databases, and lift MFA seeds. When credentials are stolen rather than bypassed, every login that follows is authentic, and only file activity still shows the attack.
August 4, 2026

Six days inside, three months to say what left: the CareCloud breach
Attackers had access to a CareCloud electronic health record environment for six days in March. It took until late June to determine what they took, and until the end of July for at least 345,000 people to be told. The gap between intrusion and answer is an audit problem.
August 4, 2026

The gap in ransomware protection: Stadler Rail’s data theft never encrypted a thing
Attackers reportedly used compromised credentials to reach a data-exchange platform Stadler Rail shares with a supplier, took technical documents, and demanded 10 million Swiss francs. Nothing was encrypted, which is why ransomware protection built around encryption events would not have seen it, and why data theft protection has to run at the storage layer.
July 29, 2026

Nichirei and the second clock: shipments came back, the files did not
A ransomware crew claims it took internal files from Japanese frozen-food and logistics company Nichirei and reportedly posted samples as proof. Deliveries were restored within about a week. The company was still notifying people whose personal information may have been exposed.
July 29, 2026

The Craneware breach: when attackers read your file names before your files
Healthcare revenue-cycle vendor Craneware says attackers viewed and exfiltrated a significant volume of file names, plus a percentage of employee data and a subset of customer records, before it contained the intrusion. Nothing was locked. The detail worth sitting with is that enumerating a file estate at scale is itself a storage-layer event, and it happens on live data long before anyone notices.
July 21, 2026

Silent Ransom Group is stealing law firm files without ransomware
The FBI has warned twice about Silent Ransom Group, an extortion crew that talks its way into law firms by posing as IT support, then copies client files out with ordinary remote-access and file-transfer tools. Nothing gets encrypted. By the time the ransom note arrives, often within a half hour of the exfiltration, the only question left is what exactly they took.
July 21, 2026

The app was trusted. The files behind it were the target: Oracle breaches and the data layer
A 2026 wave of attacks against Oracle enterprise applications, including a PeopleSoft zero-day behind the NAIC data dump and an E-Business Suite flaw under active exploitation this week, keeps ending the same way: mass reads of files and regulated records through a trusted path, with no encryption and no obvious alarm.
July 14, 2026

The breach that does not trip the alarm
Ransomware is loud. Data theft is quiet. A credentialed insider or a patient attacker can read sensitive files for months while every dashboard stays green, because nothing is watching the data itself. Data Centric Zero Trust and Cyberstorage exist to change that.
July 12, 2026

One stolen token, 700,000 files: what the Novo Nordisk breach says about the data layer
An extortion group says it copied roughly 1.3 TB, more than 700,000 files, from Novo Nordisk after finding a single access token, then spent more than two months reading source code, research, and manufacturing data. No systems were locked. The leverage was the files themselves.
July 7, 2026

A government paid $1 million to Kairos — and the blockchain shows it recovered nothing
Fresh analysis this week traces a roughly $1 million extortion payment from a U.S. government entity to the Kairos group, for data that was never encrypted, only stolen. The payment is visible on the blockchain. The files were taken anyway.
July 7, 2026

The Tata Electronics leak: 200,000 files, and not one of them encrypted by the attacker
Attackers published more than 200,000 files allegedly taken from Tata Electronics: engineering drawings, manufacturing records, employee passport scans. No systems were locked. The extortion was the data itself, which makes this a pure data-layer failure.
July 1, 2026

Extortion without encryption: the steal-and-leak business model
A growing share of extortion groups no longer bother encrypting anything. They steal files and threaten to publish them, a model that makes backups irrelevant and puts all the weight on stopping the theft itself.
June 30, 2026

Most breach headlines are data-layer warnings
Strip the logos and dollar figures from this year’s breach headlines and the same pattern remains: attackers reached unstructured data and the storage layer could not see or stop them.
June 18, 2026
RackTop Perspective
Points of view from the team that pioneered Cyberstorage.

Before the ransom note: what hackers learn from your files
Ransomware is the loudest threat to unstructured data, but it is not the first one. Hackers and APTs read your files long before they encrypt anything, and what they learn shapes the entire attack. Cyberstorage exists because protection has to start at the read, not the ransom note.
August 9, 2026

Two exabytes, and no one agrees who owns it: the AI World Cup and the data layer
The 2026 World Cup is projected to generate roughly 90 petabytes of tournament data, and some two exabytes overall. Almost none of it is rows in a database. The harder problem is not storing it: ownership is a bundle of contractual rights, and only the data layer can prove who actually touched what.
July 14, 2026

Backup is necessary. It is not a security control.
Immutable backups matter. But a recovery copy cannot see an attack, cannot stop exfiltration, and cannot tell you that data was stolen. Treating backup as security leaves the live data undefended.
July 12, 2026

Your security stack watches everything except the data
Endpoints, networks, identities, email, cloud posture: modern security programs instrument all of it. The one thing almost nobody instruments is the file data attackers are actually after.
July 12, 2026
Cyberstorage Explainers
Plain-language explanations of the architecture and the category.

What Cyberstorage is, and why it exists
Cyberstorage builds security and recovery into the data storage layer itself. Here is what that means, the thirty-year assumption that made the category necessary, why Gartner named it in 2021, and how it differs from backup and traditional NAS.
July 12, 2026

Ransomware protection at the storage layer: how it actually works
What real ransomware protection looks like at the layer attacks actually touch: the visibility, detection, policy, response, recovery, and evidence chain, explained link by link.
July 12, 2026
Executive Briefings
Board-level framing of unstructured-data risk and resilience.

Recovery time is now a disclosure question
Regulators, insurers, and customers increasingly ask the same two questions after an incident: how fast were you back, and what exactly was taken? Both answers are determined at the data layer, before the incident ever happens.
June 30, 2026

A board-level view of unstructured data risk
Most of an organization’s data is unstructured files, and most of its risk concentrates there. A short briefing for executives on why the storage layer belongs on the risk register.
May 28, 2026
Practitioner Guides
Hands-on guidance for storage, security, and SOC teams.

NAS ransomware protection: catch the attack by how it behaves
Real NAS ransomware protection is not a signature list or a nightly backup. It is user behavior analytics on every file operation, active defense that terminates a hostile session in under a second, and a cybervault that survives even administrative compromise.
August 9, 2026

File activity telemetry: what your SOC actually needs from storage
Most NAS audit feeds were designed for compliance checkboxes, not threat detection. Here is what detection-grade file activity telemetry looks like, how to wire it into SIEM and SOAR workflows without drowning the license, and the two tests that prove the integration is real.
June 30, 2026

Hardening NAS against ransomware: a practitioner checklist
A working checklist for storage and security teams: seven areas to verify on your file infrastructure so an attack on a share is detected and contained in progress, not just recovered from later.
May 20, 2026
Federal & Defense Notes
Zero Trust, classification, and mission-data guidance for government.

Harvest now, decrypt later: post-quantum encryption reaches the data layer
Two executive orders, three NIST standards, and NSA’s CNSA 2.0 have turned post-quantum cryptography from research topic into procurement requirement. What the mandates actually say, and how BrickStor SP is post-quantum ready for data at rest and data in transit.
July 27, 2026

Sharing without surrender: NATO’s data strategy and the storage layer
NATO’s Data Strategy for the Alliance sets a 2030 target: federated data sharing across the Alliance while every ally keeps control of its own data. Sharing and sovereignty at once is not a networking problem. It is a mandate for enforcement that lives where the data lives.
July 17, 2026

Zero Trust reaches the data pillar
What Zero Trust security is, where it came from, and how the CISA and DoD Zero Trust Maturity Models differ, who each applies to, and why both converge on the data pillar.
July 12, 2026

CUI lives in files. Protect it there.
Controlled Unclassified Information is overwhelmingly unstructured: drawings, specs, contract documents on file shares. CMMC compliance increasingly comes down to whether you can label, control, and account for those files, which is exactly what data labeling and ABAC at the storage layer deliver.
July 12, 2026

Understanding CMMC: A Practical Guide for Defense Contractors
What CMMC is, who must comply, the three levels, the phased enforcement timeline through 2028, and the path to certification for defense contractors handling FCI and CUI.
July 10, 2026
Healthcare, Critical Infrastructure & Enterprise IT
Sector-specific data-defense pressures and lessons.

Why healthcare keeps paying the highest breach costs
Healthcare has carried the highest average breach cost of any industry for more than a decade. The five reasons why trace back to the data itself: sensitive, regulated, sprawling, and largely unstructured.
July 12, 2026

Critical infrastructure’s quiet exposure: the IT file share
Utilities invest heavily in OT security while the IT side (engineering diagrams, SCADA documentation, customer data on ordinary file servers) remains the softer target attackers actually take.
July 12, 2026
Looking for datasheets, validations, and case studies? Visit the Resource Library →
See data-layer defense in your environment
In a 30-minute demo we’ll show Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your data and your threats.

