Content
01. News Bites
-
Cyberattack on Latvia’s Road Traffic Agency exposes data of 1.2 million people
-
Oz Hair and Beauty cyberattack may have exposed two million customer records
-
RingCentral breach exposes data from 1.6 million accounts
-
CareCloud data breach victim count revised up to 3.75 Million
-
Belgian retailer WEBA hit by Ransomware attack and Customer data breach
02. Conclusion
Cyberattack on Latvia’s Road Traffic Agency exposes data of 1.2 million people
A large-scale cyberattack targeting Latvia's Road Traffic Safety Directorate (CSDD) has compromised data linked to 1.2 million individuals and 200,000 companies, the agency said.
The attack reportedly secured information last week such as first and last names, payment details, vehicle licence plates and the address registered on the day the service was provided.
Latvia has a population of around 1.9 million, the breach potentially impacts 63% of the nation’s population. It was initially unclear who was behind the incident.
Prime Minister Andris Kulbergs said that a cyberattack originating from another country could not be ruled out, according to the Leta news agency.
Latvia's cybersecurity authority and the CSDD warned that the stolen data could be misused by fraudsters.
Kulbergs ordered an investigation into the incident and criticized the CSDD management for informing him about the data theft only after a delay.
"I have to say that I am unpleasantly surprised by a certain IT-security infantilism that exists in some regulatory authorities and government institutions," the prime minister said. He referred to a previous hacker attack on the state forestry administration in June.
Two "serious cyber incidents" occurring within a short period were a clear signal that additional security measures were needed, he said. "This is now quite literally a matter of national security," Kulbergs said.
Oz Hair and Beauty cyberattack may have exposed two million customer records
Australian retailer Oz Hair and Beauty has confirmed a cyber incident after an unauthorised third party gained access to its systems, potentially affecting up to two million customers.
The company said exposed information relating to purchases made before August 2026 included customer names, email addresses, phone numbers, locations, postcodes and previous purchase details. Credit card information, payment data and invoice details were not compromised.
Oz Hair and Beauty has not confirmed the total number of affected customers. However, threat group xpl0itrs reportedly claimed on its dark web leak site to have obtained approximately 2.1 million customer records.
The retailer said it immediately launched a forensic investigation and containment measures with support from its cloud e-commerce provider.
The incident has been reported to cybersecurity and privacy authorities in Australia and New Zealand, while the company is reviewing its cybersecurity posture and data retention policies to reduce the risk of future incidents.
RingCentral breach exposes data from 1.6 million accounts
Personal information linked to 1.6 million RingCentral accounts was reportedly stolen following a July cyberattack claimed by the ShinyHunters extortion group.
RingCentral, which provides cloud-based calling, messaging and collaboration services to more than 600,000 businesses, disclosed the incident on 28 July and said it resulted from a sophisticated social engineering campaign.
Have I Been Pwned later analysed data leaked by ShinyHunters and identified records containing names, email addresses, phone numbers and physical addresses.
The cybercrime group claimed to have stolen 623GB of data before publishing a compressed archive containing around 280GB after RingCentral reportedly refused to pay a ransom.
RingCentral said the incident affected only a limited portion of its customers and did not impact its core platform or disrupt services. The company also said it had seen no further unauthorised activity following remediation measures and was contacting affected customers directly.
CareCloud data breach victim count revised up to 3.75 Million
The number of people affected by the CareCloud data breach has been revised up to more than 3.75 million, making it one of the largest healthcare data breaches reported in 2026 so far.
CareCloud confirmed the updated figure in filings with US federal regulators following a cyberattack first disclosed in March. Hackers reportedly accessed one of the company’s cloud storage environments for six days and exfiltrated data from its Amazon Web Services account.
The stolen information includes names, postal addresses, Social Security numbers, medical and health records, government-issued identification numbers and banking information.
CareCloud provides electronic medical record and billing services to tens of thousands of healthcare organisations across the United States, giving it access to significant volumes of sensitive patient data.
The latest disclosure substantially increases the known scale of the incident, although it remains unclear whether the total number of affected individuals could rise further.
Belgian retailer WEBA hit by Ransomware attack and Customer data breach
Belgian home furnishings retailer WEBA has confirmed a cyberattack in which hackers accessed customer data and deployed ransomware across parts of its IT environment.
The attack began on 10 August and temporarily disrupted operations, although stores and the company’s online shop were restored by 12 August using backups.
Stolen information included customer names, phone numbers, email addresses, physical addresses and details of previous orders and purchases. WEBA said online accounts and passwords were not compromised.
The Qilin ransomware group has reportedly claimed responsibility for the attack. WEBA said it did not pay a ransom and had no direct contact with the attackers.
The company has since worked with cybersecurity specialists and IT partners to investigate the incident, strengthen its systems and restore services following testing. Customers are being warned to remain vigilant for phishing attempts that could use the stolen personal information to make fraudulent messages appear more convincing.
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation.
Disclaimer
The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.