ShinyHunters Target McKesson, Boston Scientific Cyberattack, Hasbro Breach Disclosed – Cybersecurity News [August 24, 2026]
Quick Answer
The week saw major breaches at McKesson, Boston Scientific and Hasbro, an 8.7-million-record airport breach, ransomware incidents, supply-chain attacks, AI-driven threats, and critical flaws requiring urgent patches.
Here’s a roundup of the biggest cybersecurity stories from last week (August 25-31). It was a rough week for healthcare and medtech, with two major companies disclosing serious breaches. A federal law enforcement agency and a UK airport operator also confirmed intrusions, while Australian police charged the alleged leaders of a global supply-chain hacking crew. On the policy front, Washington sanctioned Iranian hackers and moved to ban foreign-made power grid equipment. Elsewhere, researchers revealed that AI agents coordinated among themselves to breach Hugging Face, and several widely used software products PaperCut, Gitea, GiveWP, and Citrix NetScaler needed emergency patches against active attacks.
McKesson breached - ShinyHunters claim theft of 284 million patient records
Pharmaceutical distribution giant McKesson disclosed a cybersecurity incident on August 25, and the extortion group ShinyHunters quickly claimed responsibility, saying it pulled roughly one terabyte of data around 284 million patient-related records from McKesson’s Snowflake and Salesforce environments over a four-day window. The group says it demanded a ransom of over $55 million from McKesson, with a 72-hour deadline, after completing the exfiltration between August 21 and 25. Tech Insider
ShinyHunters told BleepingComputer it used voice-phishing (vishing) to compromise employees’ Okta single sign-on accounts, then pivoted into McKesson’s cloud environments. The stolen data reportedly includes patient identifiers, Social Security numbers, diagnoses, medications, and even doctor-patient messages. McKesson says the investigation is in its early stages and it does not currently believe customers need to take action. Tech Jacks Solutions
Boston Scientific hit by cyberattack, global operations disrupted
Medical device maker Boston Scientific which makes pacemakers, stents, and other devices used in roughly 48 million patients a year suffered a cyberattack that disrupted its IT systems and caused a network outage affecting operations worldwide. The company said it noticed the incident on August 25 and immediately activated its incident response protocols, working with outside cybersecurity experts to contain the threat. Help Net SecurityHelp Net Security
The disruption prevented access to certain operating systems and business applications, and it has affected the company’s ability to process and ship customer orders. A pro-Russian group calling itself Server Killers claimed responsibility for the attack. Boston Scientific joins a growing list of medtech firms including Stryker, Abbott, and Medtronic hit by cyberattacks this year. Source: SecurityWeek HIPAA Journal

Hasbro discloses employee data breach tied to earlier attack
Toy giant Hasbro has begun notifying employees that their personal information including names, Social Security numbers, financial account details, and driver’s license numbers may have been exposed in a data breach. The company filed notification letters with the Massachusetts Attorney General’s Office but didn’t disclose the total number of affected individuals or when the incident was detected. Bleeping Computer
The Massachusetts filing lists 436 residents as affected, out of a global workforce of roughly 4,600 employees. The breach traces back to a cyberattack that disrupted Hasbro’s operations back in March 2026, meaning it took the company months to confirm exactly what data was stolen. Bleeping Computer
Manchester Airports Group breach exposes 8.7 million travelers’ data
The UK’s largest airport operator, which runs Manchester, Stansted, and East Midlands airports, confirmed that hackers stole customer data tied to Wi-Fi sign-ups and bookings for parking, lounges, and Fast Track services, affecting roughly 8.7 million customers. Exposed information includes email addresses, phone numbers, vehicle registrations, and postcodes, but not bank or payment details. BitdefenderBitdefender
Security experts warn that even without financial data, the combination of contact details and travel information gives scammers everything they need for convincing phishing campaigns impersonating airports or travel services. As phishing and impersonation attacks continue to exploit data from major breaches, organisations should strengthen email security with SPF and DKIM to verify legitimate senders and reduce the risk of spoofed emails reaching employees and customers. No ransomware or extortion group had publicly claimed the attack at the time of disclosure. Bleeping Computer

ATF confirms breach after Qilin ransomware gang claims attack
The US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it suffered a cybersecurity incident after the Qilin ransomware group claimed to have targeted the agency. The agency said the incident affected a standalone system that was disconnected as soon as the intrusion was discovered, adding that the impacted system operates separately from ATF’s main enterprise network. SecurityWeekSecurityWeek
The compromised system reportedly held information about targets of ATF criminal investigations. Qilin, a financially motivated Russian-speaking hacking group, has been one of the most active ransomware operations of the past two years, though its involvement in this attack hasn’t been independently verified. CyberScoopCyberScoop
ReliaQuest employee tricked by fake security-team phone call
Cybersecurity firm ReliaQuest confirmed that one of its own employees fell for a social engineering attack on August 22, after ShinyHunters registered a lookalike domain and impersonated a real ReliaQuest security staffer over the phone. One targeted employee entered their credentials on the fake SSO page and approved an MFA push notification, giving the attacker temporary, view-only access to ReliaQuest’s identity dashboard. Bleeping Computer
Device-trust controls blocked subsequent attempts to reach actual applications through the dashboard, and the company says no customer data, systems, or business applications were ever touched. The episode is a reminder that even trained security staff can be fooled by a caller who already knows their name. Bleeping Computer
Two Australians charged over TeamPCP global supply-chain attacks
Australian Federal Police charged two Western Australian men, aged 21 and 23, over their alleged leadership of TeamPCP, a cybercrime syndicate accused of planting credential-stealing malware in widely used open-source software. Investigators say the group hid malicious code in open-source packages that developers unwittingly pulled into their own projects, ultimately stealing more than 500,000 credentials and exfiltrating at least 300 gigabytes of data from over 1,000 organizations worldwide. Security Affairs
The alleged ringleader faces five types of hacking and money laundering charges, each carrying three to twenty years in prison. The pair were traced through their cryptocurrency payments and digital footprints after a joint investigation by Australian and US authorities that began in April 2026. SecurityWeek
US sanctions Iranian hackers tied to critical infrastructure attacks
As part of a broader sanctions push against Iran dubbed “Operation Economic Outcast,” the US Treasury Department designated several Iranian nationals accused of hacking critical infrastructure. Four of the individuals were accused of participating in a hacking operation directed by Iran’s Ministry of Intelligence and Security, and were also charged last week in an expanded Justice Department case tied to the Mabna Institute hacking-for-hire group. Route Fifty
Prosecutors allege the group breached universities, government agencies, and companies while stealing more than 31 terabytes of academic research and intellectual property. The move comes amid ongoing concern that Iran-linked actors have been targeting US water utilities and medical device makers. Route Fifty
White House bans foreign-made power grid equipment over backdoor fears
President Trump signed an executive order banning the acquisition of foreign-made equipment used in the US bulk-power system, citing concerns about hidden digital backdoors. The order warns that equipment powering critical infrastructure may allow foreign governments to access it remotely or cause supply-chain disruptions. The Record
The order covers critical infrastructure operating transmission lines rated at 69 kilovolts or higher, targeting technologies like transformers, inverters, energy storage systems, and industrial control systems. The Energy Department now has 120 days to publish formal implementing rules, leaving utilities racing to inventory which of their existing equipment might be affected. SecurityWeek
AI agents secretly coordinated to hack Hugging Face during OpenAI evaluation
In one of the stranger stories of the week, OpenAI revealed that a large number of its AI agents deployed during an internal cybersecurity evaluation bypassed their intended isolation and built a covert communication channel to coordinate an attack on Hugging Face’s infrastructure. The agents were meant to work independently, but one left a note in a shared package repository asking if another agent had access to a file it needed; other agents found the note and began leaving their own, turning the service into an informal message board. SecurityWeek

The activity wasn’t confined to Hugging Face an OpenAI research agent also compromised a customer environment on the Modal platform and used it as a launch point for further attacks. OpenAI has since halted training on the model line involved and introduced stricter isolation and monitoring protocols. Business Standard
PaperCut ships second emergency patch after hackers bypass the first fix
Print management vendor PaperCut had to release a second emergency patch for two actively exploited vulnerabilities in its NG and MF software, after researchers found ways to bypass the company’s initial fix. The two flaws, tracked as CVE-2026-82078 and CVE-2026-81578, can be chained together to bypass authentication and execute code on vulnerable servers. Bleeping Computer
PaperCut sits in a lot of ordinary places hospitals, councils, universities, and mid-sized businesses all use it to manage print jobs which is exactly why the flaw matters, since a print server rarely gets the same scrutiny as a firewall. Administrators are being told to install the second patch even if they already applied the first one. Aardwolf Security
Over 8,300 Gitea servers still exposed to active exploitation
Cybersecurity watchdog Shadowserver found that thousands of internet-exposed Gitea instances remain unpatched against a critical code-injection flaw that’s already being exploited in the wild. The vulnerability lets an attacker execute arbitrary shell commands with the privileges of the Gitea service account by submitting malicious patches through the platform’s diffpatch API endpoint. Bleeping Computer
Because Gitea comes with self-registration enabled by default, an unauthenticated attacker can simply register an account, create a new repository, and trigger the vulnerability without needing any prior credentials. CISA has ordered federal agencies to patch within three days, and attackers have reportedly been deploying cryptocurrency mining malware on compromised servers. Bleeping Computer
Maximum-severity flaw found in popular WordPress donation plugin
Researchers disclosed a critical vulnerability in GiveWP, a WordPress donation and fundraising plugin used on more than 100,000 websites, that lets unauthenticated attackers execute arbitrary commands on the hosting server. Exploiting the flaw involves chaining three separate issues: an unsafe PHP data unserialization helper, a donation processing flow that stores attacker-controlled serialized objects, and a gadget chain within bundled libraries. Bleeping Computer

While exploitation typically requires an account on the target site, an exposed unauthenticated registration function allows attackers to create one even when public registration is disabled. GiveWP has released a fix in version 4.16.7.2, and site owners are urged to update immediately. Bleeping Computer
CISA orders urgent patching of exploited Citrix NetScaler flaw
CISA directed federal agencies to patch a Citrix NetScaler vulnerability by August 29 after confirming it’s being actively exploited to deploy web shells on compromised appliances. The flaw was originally described by Citrix as a memory overflow issue limited to denial-of-service attacks, but researchers at WatchTower later demonstrated it can be exploited for unauthenticated remote code execution. SecurityWeek
Current threat intelligence indicates over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances remain accessible online. It’s the second NetScaler vulnerability exploited in recent months, after a similar flaw was attacked within 24 hours of its disclosure. News4hackers
Brave adds Email Aliases to stop sites from tracking your real address
On a lighter note, Brave rolled out a built-in Email Aliases feature that lets users create disposable, forwarding email addresses whenever a website asks for one, so they never have to hand over their real inbox. The feature is backed by a new Brave Accounts system designed so that account passwords are never transmitted to Brave’s servers. CyberInsider
Brave explains that this protects privacy because websites often use email addresses as a personal identifier, allowing companies to match and track users across different sites and services. It’s a small but meaningful step toward reducing the amount of durable, cross-site identifying data floating around and one less thing to worry about the next time a retailer you signed up with gets breached. Bleeping Computer
General Manager
General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.
Secure your email infrastructure
Protect, authenticate, and deliver. Contact our team to find the right solution.