17 articles
Latest Threat Briefs
Analysis of active ransomware, data-extortion, and breach incidents, and what each one means for data at the storage layer. New briefs added as incidents develop.

Valid logins, an MFA bypass, and 678,000 records: the French tax breach
France’s tax administration disclosed that an attacker used a staff account and a contractor account, plus a multi-factor bypass, to consult and extract data on 678,000 people and businesses. Nothing was encrypted. Every query looked like work.

Six terabytes, allegedly: the hospital breach nobody can yet bound
A ransomware crew says it took six terabytes of the most sensitive records a health system holds. The health system says the claim is unverified. Weeks after the attack, both statements can still be true, and that gap is the leverage.

Gunra ransomware: a six-agency warning that ends at your file shares
A joint advisory from the FBI, CISA, NSA, and international partners details how Gunra ransomware moves from a firewall CVE to file servers over SMB, stealing documents and databases before encrypting. The advisory is a case study in why NAS ransomware protection has to live at the storage layer.

ExfilSquad skips the encryption and publishes stolen files as torrents
A new extortion crew surfaced in late July claiming fifteen victims in a single day, confirmed breaches at two UK institutions, and no ransomware at all. When deadlines passed, ExfilSquad began seeding stolen data as torrents, making the leak effectively permanent.

INC ransomware is stealing the identity layer, not just the perimeter
A pair of SonicWall SMA 1000 vulnerabilities gives attackers root on the VPN appliance, and INC ransomware is using that access to read passwords off the wire, copy live session databases, and lift MFA seeds. When credentials are stolen rather than bypassed, every login that follows is authentic, and only file activity still shows the attack.

Six days inside, three months to say what left: the CareCloud breach
Attackers had access to a CareCloud electronic health record environment for six days in March. It took until late June to determine what they took, and until the end of July for at least 345,000 people to be told. The gap between intrusion and answer is an audit problem.

The gap in ransomware protection: Stadler Rail’s data theft never encrypted a thing
Attackers reportedly used compromised credentials to reach a data-exchange platform Stadler Rail shares with a supplier, took technical documents, and demanded 10 million Swiss francs. Nothing was encrypted, which is why ransomware protection built around encryption events would not have seen it, and why data theft protection has to run at the storage layer.

Nichirei and the second clock: shipments came back, the files did not
A ransomware crew claims it took internal files from Japanese frozen-food and logistics company Nichirei and reportedly posted samples as proof. Deliveries were restored within about a week. The company was still notifying people whose personal information may have been exposed.

The Craneware breach: when attackers read your file names before your files
Healthcare revenue-cycle vendor Craneware says attackers viewed and exfiltrated a significant volume of file names, plus a percentage of employee data and a subset of customer records, before it contained the intrusion. Nothing was locked. The detail worth sitting with is that enumerating a file estate at scale is itself a storage-layer event, and it happens on live data long before anyone notices.

Silent Ransom Group is stealing law firm files without ransomware
The FBI has warned twice about Silent Ransom Group, an extortion crew that talks its way into law firms by posing as IT support, then copies client files out with ordinary remote-access and file-transfer tools. Nothing gets encrypted. By the time the ransom note arrives, often within a half hour of the exfiltration, the only question left is what exactly they took.

The app was trusted. The files behind it were the target: Oracle breaches and the data layer
A 2026 wave of attacks against Oracle enterprise applications, including a PeopleSoft zero-day behind the NAIC data dump and an E-Business Suite flaw under active exploitation this week, keeps ending the same way: mass reads of files and regulated records through a trusted path, with no encryption and no obvious alarm.

The breach that does not trip the alarm
Ransomware is loud. Data theft is quiet. A credentialed insider or a patient attacker can read sensitive files for months while every dashboard stays green, because nothing is watching the data itself. Data Centric Zero Trust and Cyberstorage exist to change that.

One stolen token, 700,000 files: what the Novo Nordisk breach says about the data layer
An extortion group says it copied roughly 1.3 TB, more than 700,000 files, from Novo Nordisk after finding a single access token, then spent more than two months reading source code, research, and manufacturing data. No systems were locked. The leverage was the files themselves.

A government paid $1 million to Kairos — and the blockchain shows it recovered nothing
Fresh analysis this week traces a roughly $1 million extortion payment from a U.S. government entity to the Kairos group, for data that was never encrypted, only stolen. The payment is visible on the blockchain. The files were taken anyway.

The Tata Electronics leak: 200,000 files, and not one of them encrypted by the attacker
Attackers published more than 200,000 files allegedly taken from Tata Electronics: engineering drawings, manufacturing records, employee passport scans. No systems were locked. The extortion was the data itself, which makes this a pure data-layer failure.

Extortion without encryption: the steal-and-leak business model
A growing share of extortion groups no longer bother encrypting anything. They steal files and threaten to publish them, a model that makes backups irrelevant and puts all the weight on stopping the theft itself.

Most breach headlines are data-layer warnings
Strip the logos and dollar figures from this year’s breach headlines and the same pattern remains: attackers reached unstructured data and the storage layer could not see or stop them.
See data-layer defense in your environment
In a 30-minute demo we’ll show Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your data and your threats.
