Posts

Aesto Health Data Breach Affects Over 9.5 Million Patients

September 1, 2026 Healthcare technology company Aesto Health has reported a major data breach potentially affecting 9,540,683 individuals . According to Aesto, an unauthorized actor accessed a portion of its AWS infrastructure between December 2 and December 18, 2025 . The company detected the incident on December 18 and launched an investigation with the help of external cybersecurity experts. The investigation found that personal and protected health information belonging to patients of Aesto's healthcare-provider clients may have been accessed or acquired. What Information Was Exposed? The potentially affected information varied by individual and may have included: Names and dates of birth Medical and health insurance information Social Security numbers Government identification numbers Driver's license information Financial account information Aesto has stated that it currently has no evidence of identity theft or financial fraud connected to the incident. The Cybersecuri...

Merrimack County Cyberattack: What Happened?

  September 2026 Merrimack County in New Hampshire, USA, recently experienced a network security incident that disrupted several county computer systems and temporarily affected government services. The earliest documented impact occurred on August 25, 2026 , when county dispatchers lost access to criminal-information data through New Hampshire's IMC system. The county publicly confirmed the incident on August 26 and began working with cybersecurity specialists to investigate the unauthorized activity. What Happened? Merrimack County dispatchers were unable to access important law-enforcement information, including: Criminal records Driving information Active warrants Nearly 20 law-enforcement departments rely on Merrimack County's dispatch services. Alternative procedures were used while access to the affected system was unavailable. Despite the disruption, emergency call-taking and response operations continued . The county also took some systems offline as a precaution whil...

Apollo Global Management Data Breach: When Hackers Target People, Not Just Systems

On July 6–10, 2026, attackers gained unauthorized access to cloud systems belonging to Apollo Global Management , a major private-equity firm. Apollo confirmed the incident on August 21, reporting that sensitive personal information had been compromised. The incident is part of a wider wave of cyberattacks targeting financial-sector organizations and highlights an important reality of modern cybersecurity: sometimes, attackers don't need to break through the technology—they simply convince someone to let them in. What Happened? According to reports, attackers used social engineering to gain access to Apollo's cloud environment. Social engineering is a technique in which attackers manipulate people into revealing information or performing actions that compromise security. In this broader campaign, attackers reportedly impersonated IT or help-desk personnel and contacted employees by phone. Victims were then directed toward fraudulent login pages designed to capture credentials ...

GenAI Adoption Is Growing, but Data Security Remains a Concern

Generative AI (Gen AI) is becoming a regular part of business operations. Employees are using AI tools to write content, analyze information, solve problems, and improve productivity. But as AI usage grows, so does the risk of sensitive data being shared without proper protection. AI Usage Is Increasing According to Check Point’s August report, high-risk Gen AI prompts fell to their lowest level in several months. However, overall AI usage continued to rise. The average enterprise user generated 106 prompts in August , compared with 95 in July and around 78 in June. This shows that while some organizations may be improving their awareness and security controls, the growing use of AI is creating more opportunities for sensitive information to be entered into AI tools. The Risk Is Still Widespread The report found that: 86% of organizations regularly using Gen AI were affected by high-risk prompt activity. Organizations used an average of seven different AI tools . About 1 in every 43 p...

You don't have to hack the company!!

What if hackers don't need to break into your company to steal your customers' data? That's exactly what makes the recent Pokémon Center incident interesting. Instead of directly compromising Pokémon Center's systems, attackers targeted its trusted third-party logistics provider, CEVA Logistics . What Happened? Pokémon Center uses CEVA Logistics to ship orders to customers in the United Kingdom and Germany . On July 30 , CEVA informed Pokémon Center that it had experienced a cyberattack. While Pokémon Center itself was not directly hacked, customer information handled by the logistics provider was potentially exposed. The incident also caused disruptions to shipping and order fulfillment, including delays and cancellations. What Data Was Exposed? The potentially affected information included: Names Email addresses Phone numbers Shipping addresses Order information However, payment card details and Pokémon Center account credentials were not part of the exposed informati...

New Call Forwarding Scam in India: How Fraudsters Can Steal Your OTPs Without Asking for an OTP

Beware! A Dangerous Call Forwarding Scam Is Targeting Indian Smartphone Users Cyber scams in India are evolving every day, and fraudsters are finding new ways to steal money from unsuspecting users. One scam that has gained attention involves call forwarding , allowing criminals to receive your OTPs without ever asking you for them. Many victims are shocked because they never shared an OTP, never clicked a suspicious link, and never installed any unknown app. Yet, money disappears from their bank account. So how does this happen? How the Scam Works Imagine you've ordered something online and you're away from home. You need to contact the delivery executive, so you call the number shown in the app or sent via SMS. Sometimes, scammers impersonating delivery personnel or posing as customer support may ask you to dial a number that begins with codes such as *21* or other call forwarding codes, claiming it is required to contact the delivery agent or verify your identity. The momen...

🚨 Generative AI Phishing Attacks in 2026: How AI is Making Cybercrime More Dangerous

Introduction: The Rise of AI-Powered Cyber Threats The year 2026 has introduced powerful advancements in artificial intelligence, but along with innovation comes new cybersecurity risks. Generative AI tools are now being exploited by cybercriminals to create highly convincing phishing attacks, fake login pages, and malicious websites at unprecedented speed. As AI technology becomes more accessible, users must understand that everything online cannot be trusted without proper verification and research. 🤖 How Hackers Use Generative AI for Phishing Attacks Generative AI platforms allow attackers to create realistic websites and content with minimal effort. By using simple prompts such as: 👉 “Build a website that looks exactly like Okta but isn’t the same,” hackers can generate fake login portals that closely mimic legitimate services. These AI-generated phishing sites are designed to: Steal login credentials Capture authentication tokens Trick users into revealing sensitive info...