Connect with us

Infosecurity

One Government Agency Hit by Ransomware Every Day: New Data Shows a Relentless Surge

Published

on

ransomware government agencies

Attack Frequency Reaches a New Milestone

Ransomware is no longer a periodic threat for public-sector organizations — it’s a daily reality. New data from cybersecurity researchers at Comparitech shows that, on average, one government agency somewhere in the world has its systems encrypted and services crippled every single day.

The study, published on July 16, tracked ransomware incidents targeting government bodies between January and June 2026. It recorded 187 attacks over 182 days — a pace that works out to just over one per day. That marks a 13% jump from the 165 attacks logged in the second half of 2025.

Of those 187 incidents, only 89 — roughly half — were publicly acknowledged by the affected organizations. The rest either went undisclosed or remained unconfirmed at the time of reporting.

Why Governments Are Prime Targets

Government agencies hold a toxic combination of assets: vast troves of sensitive citizen data and systems that the public depends on daily. When ransomware locks up a municipal billing system or a state health portal, the pressure to restore services fast is immense.

“From weeks-long disruptions due to system encryption to extensive data breaches, governments are the ideal target for hackers,” said Rebecca Moody, head of data research at Comparitech.

That pressure often translates into a higher likelihood that the victim will pay the ransom. Attackers know this. A city hall can’t afford to be offline for a month while IT teams rebuild from scratch — so the calculus for paying up shifts dramatically.

The United States Leads as the Most Frequent Target

The geographic distribution of attacks is lopsided. The US absorbed 31% of all ransomware incidents against government agencies during the six-month period. No other country came close.

Germany was the second-most targeted nation, accounting for just 7% of attacks. Spain and Italy each registered 4%. The gap between the US and the rest of the world is partly explained by population size — more government bodies means more attack surfaces — but it also reflects the aggressive focus of ransomware groups on high-value English-speaking targets.

Ransom Demands: A Calculated Gamble

The median ransom demand during the period sat at $100,000. That figure is relatively modest compared to the multimillion-dollar demands seen in the private sector. The logic is straightforward: ask for too much from a taxpayer-funded entity, and the chance of payment plummets.

Still, outliers exist. The most extreme case was a $3.1 million demand directed at the Land and Agricultural Development Bank of South Africa following a January 2026 attack. The bank refused to pay, and its systems were only fully restored in April. The perpetrator of that attack remains unknown.

Known Threat Groups and Their Methods

While some attackers fly under the radar, many incidents can be traced to established ransomware crews. The most active groups between January and June 2026 were:

  • The Gentlemen — responsible for 10% of attacks
  • Qilin — linked to 9% of incidents
  • LockBit — accounted for 7%

These groups frequently exploit well-known, publicly disclosed vulnerabilities. They move fast once a patch is available — often faster than government IT departments can deploy it.

How Agencies Can Fight Back

Prevention, Comparitech argues, comes down to fundamentals. Moody outlined a set of measures that are unglamorous but effective: keep systems updated, patch vulnerabilities as soon as they are flagged, perform regular backups, and invest in continuous employee training.

“Making sure employees are regularly trained and are on high alert at all times are crucial to mitigating the risks of attacks,” she said.

That last point matters more than many realize. A single phishing email opened by a busy clerk can undo months of security work. For agencies already stretched thin, the cost of proactive defense is far lower than the cost of a recovery operation that takes weeks — or, in the case of the South African bank, months.

The takeaway is sobering: ransomware is not going away, and government networks remain in the crosshairs. The question is not whether another agency will be hit tomorrow. It’s whether they’ll be ready when it happens.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Hackers stole employee and customer data from Craneware, the software backbone of 2,000 US hospitals

Published

on

Craneware data breach

A quiet but serious intrusion

On Monday, Craneware — a British software firm whose products run across more than 2,000 U.S. hospitals — told investors that attackers broke into its internal network and made off with employee and customer records. The company, headquartered in Edinburgh and listed on London’s AIM market, said it detected unauthorized access to a “subset” of its data environment and has since called in outside forensic investigators.

The breach has been reported to the FBI and to the UK’s Information Commissioner’s Office. Craneware said the intrusion is contained and the attackers no longer have access to its systems. Crucially, the company added that neither its own operations nor the services it provides to hospitals were disrupted.

But the details that remain unknown are troubling. Craneware did not say who was behind the attack, when the hackers first got in, how long they roamed the network, or whether a ransom was demanded. It also did not name any of the affected customers — and it did not say whether patient health information was among the stolen files.

What was taken — and what wasn’t

Craneware disclosed that a large number of file names were viewed and copied out of its network. Most of that material was non-sensitive or already publicly available regulatory data, the company said. But some employee data and customer and partner records were definitely taken.

The company said it is still working to determine the full scope of the theft and expects to notify affected organizations and individuals once it has a clearer picture. That timeline is vague, which is not unusual for breaches of this scale, but it leaves hospitals and their staff in an uncomfortable limbo.

The biggest open question: was patient data involved? If the stolen records include protected health information, the breach would trigger notification requirements under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Craneware has not addressed that directly.

A sprawling target in healthcare IT

Craneware was founded in 1999 and sells billing, pricing and pharmacy software to American healthcare providers. The company says its tools are used by more than 2,000 hospitals and close to 10,000 clinics and retail pharmacies across the United States.

That makes it a juicy target. Healthcare vendors hold a goldmine of sensitive data — patient records, insurance details, billing information, employee credentials. And attackers know it. In recent years, hackers have repeatedly targeted the vendors that hospitals rely on, often with devastating results.

In March 2026, software firm CareCloud warned that patients’ electronic health records may have been leaked after hackers gained access to its systems. Two weeks before that, healthcare analytics firm Insightin told state regulators that 1.1 million people were affected by a data theft that happened in September 2025.

Those are not isolated incidents. In 2024, hackers breached healthcare technology company TriZetto Provider Solutions, exposing the data of 3 million people. Another 5 million were impacted when technology firm Episource was attacked. The pattern is clear: cybercriminals are going after the vendors, not just the hospitals themselves.

Why vendor breaches hit harder

When a single hospital gets hacked, it’s bad. But when a vendor like Craneware gets compromised, the blast radius is enormous. A single intrusion can ripple across thousands of hospitals and clinics, each one potentially exposed by the same weak link in the supply chain.

That’s why the FBI is involved. And it’s why regulators on both sides of the Atlantic are likely to scrutinize Craneware’s response closely. The company said it has engaged outside forensic investigators, but it has not disclosed which firm is handling the probe.

For the hospitals using Craneware’s software, the immediate priority is damage control. They need to know whether their patients’ data was stolen, and they need to know fast. For the rest of the healthcare industry, this breach is yet another reminder that healthcare cybersecurity is only as strong as the weakest vendor in the chain.

What comes next

Craneware said the attackers no longer have a foothold in its systems. That’s the good news. The bad news is that the data is already out — copied and likely sold or leaked. The company’s forensic investigation will take weeks, possibly months, to fully map what was taken.

Affected employees, customers and business partners will be notified once that work is done. But for now, the clock is ticking. Every day without answers is a day the stolen data could be used for phishing, identity theft or extortion.

This breach is a stark reminder that the software that keeps hospitals running is also a high-value target. And as long as attackers see healthcare vendors as a soft underbelly, the attacks will keep coming.

Continue Reading

Infosecurity

Opera GX Zero-Click Flaw Allowed Websites to Auto-Install Mods and Steal User Data

Published

on

Opera GX flaw

No Clicks, No Permissions: How a Critical Opera GX Flaw Worked

A serious security hole in Opera GX, the gaming-focused browser from Opera, allowed any website to silently install a customization mod — and then use that mod to siphon data from sites the victim had visited. The attack required zero user interaction. No clicking. No permission prompts. Just a hidden frame loading a file.

Discovered by an independent researcher known as zhero_web_security, the Opera GX flaw exploited the browser’s GX Mods system. Unlike standard browser extensions, GX Mods are supposed to be lightweight — they customize the browser’s look, sounds, and website styling, but carry no permissions and can’t execute JavaScript. That’s what made the discovery so unsettling: the mods weren’t supposed to be dangerous. Yet the researcher found a way to weaponize them.

Auto-Install: The Core of the Opera GX Vulnerability

Here’s the mechanical problem. When a user downloads a GX Mod file, it installs automatically. No dialogue box asks for approval. No permission request pops up. The researcher realized that an attacker could place a mod file inside a hidden HTML frame on a malicious website. As soon as the page loads, the mod lands in the browser — completely silent.

Once installed, the mod’s CSS (cascading style sheets) applies to every single tab and page the victim opens. Ordinary CSS injection is usually confined to one page. This was different. The Opera GX vulnerability gave the attacker a persistent foothold across the entire browser session.

Gmail Addresses and Browser Crashes: Proof of Concept

CSS cannot read a page’s content directly. But it can be cleverly crafted to trigger network requests based on what a page contains. That technique, known as an XS-Leak (cross-site leak), lets an attacker extract data bit by bit, character by character.

Using this method, the researcher built a zero-click exploit that recovered a victim’s full Gmail address. The attack silently redirected the browser to a Google account page, then used the injected CSS to leak the email address character by character. The researcher noted the method is not limited to Gmail — any data rendered on a page could theoretically be targeted.

The same auto-install behavior also enabled a denial-of-service (DoS) attack against both Opera and Opera GX. Chromium-based browsers block extensions in private or Incognito windows. Forcing a mod to install in Incognito mode caused the browser to crash — and wiped all open tabs in the process. Any file with a .crx extension triggered the crash, whether or not it was a legitimate mod.

From Low Priority to Critical: Opera’s Bug Bounty Response

The researcher reported the Opera GX flaw in February 2024 through Opera’s Bugcrowd bug bounty program. Initially, the team triaged it as low priority. That changed quickly. Opera’s security team reassessed the issue and reclassified it as critical.

A patch shipped on May 8, 2024, and the researcher received a $5,000 bounty payment. The full proof of concept was published on July 3, tested against Opera GX version 127.0.5778.41 — after the fix had already been distributed.

What This Means for Browser Security and Users

This isn’t the first time browser customization features have opened unexpected attack surfaces. But the Opera GX vulnerability is a sharp reminder that even permissionless systems can be dangerous. GX Mods were designed to be safe because they lack extension-level privileges. But CSS injection, combined with auto-installation, turned that safety assumption into a liability.

For users, the fix is straightforward: update Opera GX to the latest version. The browser should update automatically, but it’s worth checking. Anyone running a version prior to the May 8 patch is still exposed.

For the broader security community, the case raises questions about how browsers handle file-based installations and whether similar flaws exist in other Chromium-based browsers. The researcher’s work demonstrates that even a seemingly harmless mod can become a data theft tool — as long as it arrives without a click.

Continue Reading

Infosecurity

23andMe Hit With $18m Settlement and Strict New Security Mandates After 2023 Breach

Published

on

23andMe data breach settlement

A Landmark Settlement for Genetic Privacy

More than two years after cybercriminals stole the genetic profiles of over six million people, 23andMe has agreed to pay $18 million and submit to a sweeping set of new security mandates. A bipartisan coalition of 42 US state attorneys general, led by New York Attorney General Letitia James, finalized the deal in July 2025.

The settlement is not just about the money. It forces the company—and its new owner, TTAM Research—to adopt a far stricter data protection regime. New York alone will receive more than $705,000 from the payout.

“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures,” James said in a statement. “New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet.”

How the 23andMe Data Breach Happened

The October 2023 incident was not a sophisticated hack of 23andMe’s core servers. It was a credential stuffing attack—a brute-force method where attackers use usernames and passwords leaked from other sites to break into accounts.

The company admitted at the time that the breach was enabled by customers’ weak password habits and the widespread absence of multi-factor authentication (MFA). Once inside, the attackers scraped profile information tied to ancestry results, eventually accessing data from 6.9 million users.

The fallout was immediate and lasting. By March 2025, 23andMe filed for Chapter 11 bankruptcy protection. In June, James and 27 other attorneys general sued the company to safeguard Americans’ genetic information during the bankruptcy process.

What the $18m Settlement Requires

The settlement imposes several binding security requirements on 23andMe and TTAM Research, the nonprofit formed by former CEO Anne Wojcicki that purchased the customer data.

  • Mandatory risk analysis: The company must conduct regular, documented assessments of its security posture.
  • An Advisory Board on data security: A new oversight body will monitor compliance and recommend improvements.
  • Consumer right to delete: Customers must retain a clear, easy-to-use option to erase their genetic data from the company’s systems.

These measures are designed to prevent a repeat of the 2023 disaster. The settlement also prohibits misleading statements about data protection practices.

This is not the only financial penalty 23andMe faces. A US bankruptcy judge approved a separate $46.75 million fund on July 7, 2025, to compensate victims directly. However, on July 10, the same judge ruled that California cannot seek additional damages from the company due to the Chapter 11 reorganization plan, though the state has 14 days to amend its lawsuit to remove monetary claims.

Regulatory Fines Pile Up Globally

The US settlement is just one piece of a much larger global enforcement puzzle. In July 2026, the Spanish privacy watchdog fined 23andMe €2.4 million ($2.75 million) after finding that 2,642 customers residing in Spain were affected by the breach.

A year earlier, in June 2025, the UK’s Information Commissioner’s Office levied a £2.3 million ($3.1 million) fine for failing to protect customers’ special category data—a classification that includes genetic information, which is among the most sensitive types of personal data under UK law.

These overlapping penalties signal that regulators on both sides of the Atlantic are taking genetic privacy breaches with extreme seriousness.

What This Means for the Future of Genetic Testing

The 23andMe case is a cautionary tale for the entire direct-to-consumer genetic testing industry. When customers mail in a saliva sample, they are trusting the company with data that cannot be changed—unlike a password or credit card number. A leaked genetic profile is permanent.

The new security mandates at TTAM Research set a precedent. Other firms in the space, including AncestryDNA and MyHeritage, will be watching closely. If state attorneys general are willing to impose structural reforms—not just fines—on a bankrupt company, the bar for data protection across the industry just got higher.

For consumers, the lesson is blunt: enable MFA on every account that holds sensitive data, and think twice before sharing your DNA with any private company. The settlement may close the legal case, but the questions about trust in the genetic testing industry are far from settled.

Continue Reading

Trending