Content 

01. News Bites
  • Pro-Russian hackers claim major cyberattack on Norwegian government services

  • Cyberattack shuts down small UK Power Plant for four days

  • Global Police operation targets West African cybercrime networks

  • Cyberattack on Canada’s largest children’s Hospital exposes employee data

  • Cyberattack disrupts global operations at Boston Scientific

02. Conclusion

Quick News Bites

Pro-Russian hackers claim major cyberattack on Norwegian government services

A pro-Russian hacking group has claimed responsibility for a series of denial-of-service attacks targeting Norwegian Government digital services over three days.

Norway’s Digitalisation Agency, Digdir, described the campaign as the largest attack its systems have experienced. Attackers flooded the agency with malicious traffic in an attempt to disrupt services, including a platform that allows citizens to use a single login across multiple public services.

Despite the scale of the attacks, Digdir said its services remained available for almost the entire period.

The Server Killers group claimed responsibility on Telegram, saying the attacks were retaliation for Norway renewing its security cooperation with Ukraine. Norwegian officials have not confirmed the attribution.

The incident comes amid heightened concern over pro-Russian cyber and sabotage activity across Europe, with governments warning that such campaigns are increasingly being used to disrupt public services, intimidate populations and place pressure on countries supporting Ukraine.

Cyberattack shuts down small UK Power Plant for four days

A cyberattack forced a small UK power generator offline for four days, prompting the government to warn energy companies about the continuing threat to critical infrastructure.

The Department for Energy Security and Net Zero said the incident affected a small-scale generator and stressed that there was no risk to the wider UK energy system. For security reasons, officials have not identified the facility involved.

According to reports, the attack was carried out by hackers affiliated with the Iranian regime, although UK authorities have not publicly confirmed the attribution.

The incident comes as the government strengthens cybersecurity requirements for the energy sector and prepares a new energy resilience strategy.

While the affected facility was not considered an essential service, the disruption demonstrates how cyberattacks can still cause significant operational impact. Energy operators are being encouraged to review their resilience, incident response capabilities and protections against emerging state-linked cyber threats.

It also highlights the growing cyber threat facing operational technology (OT) and critical national infrastructure (CNI), where attacks can move beyond IT systems to disrupt physical operations and essential services.

Global Police operation targets West African cybercrime networks

Law enforcement agencies across 22 countries have identified 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by West African organised crime groups.

Operation Jackal IV, coordinated by INTERPOL between November 2025 and June 2026, focused on disrupting networks involved in business email compromise, investment fraud, cryptocurrency scams, romance scams and money laundering.

The operation also targeted Black Axe, a cybercrime syndicate associated with large-scale financial fraud. In Argentina, police arrested 17 people and linked 196 suspects to a Crime-as-a-Service network providing domains and money-laundering support.

South African authorities arrested 39 individuals, blocked 257 bank accounts and seized $2.67 million from a syndicate targeting retirees through investment and romance scams.

INTERPOL said criminal groups are increasingly outsourcing key activities through Crime-as-a-Service providers, highlighting how organised cybercrime is becoming more specialised, scalable and internationally connected.

Cyberattack on Canada’s largest children’s Hospital exposes employee data

Canada’s largest paediatric health centre, the Hospital for Sick Children, has confirmed a cybersecurity incident that exposed personal information belonging to current and former employees.

The Toronto-based hospital, known as SickKids, believes the breach was linked to a third-party software application. The incident temporarily disrupted its careers website and triggered an investigation.

Potentially affected individuals include current and former employees, job applicants and staff at related organisations, including the SickKids Foundation. The hospital has not disclosed exactly what information was stolen, but confirmed that clinical systems and patient data were not affected.

SickKids has contacted potentially impacted individuals and offered two years of credit monitoring.

The hospital was previously targeted by ransomware in 2022, when an attack disrupted several systems for weeks. The latest incident highlights the continuing risks third-party applications and supply chains pose to healthcare organisations holding significant volumes of sensitive information.

Cyberattack disrupts global operations at Boston Scientific

Medical device manufacturer Boston Scientific has confirmed a cyberattack that has disrupted parts of its global operations, including systems used to process and ship customer orders.

The US multinational detected the incident on Tuesday and activated its incident response procedures, bringing in third-party cybersecurity specialists to investigate and contain the attack.

Boston Scientific, which employs more than 7,000 people in Ireland, said the disruption is expected to continue affecting some business operations while the investigation remains ongoing. The company has not yet determined the full scope or nature of the incident, or whether it is likely to have a material impact on the wider business.

Shares in Boston Scientific fell 3.5% before markets opened following disclosure of the incident.

The attack is the latest cyber incident to affect a major healthcare and medical technology organisation, highlighting the operational and supply chain risks facing the sector.

Closing Summary

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation. 

Disclaimer

The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.