
Weekly CISO Digest — Week of 2026-08-03: Coordinated Attacks Hit Water Utilities
Headline Incident: Coordinated Cyberattack Targets 30+ Minnesota Water Utilities
Between July 26 and 27, 2026, over 30 community water utilities in Minnesota were hit by coordinated cyberattacks targeting their operational technology. Attackers exploited CVE-2021-22681 to change passwords and IP addresses on internet-exposed programmable logic controllers (PLCs), resulting in loss of control, outages, and boil water notices for affected communities. Impacted organizations include Braham Water Utility, Maple Plain Water Utility, Plymouth Water Utility, and South St. Paul Water Utility. The incident underscores the vulnerability of critical infrastructure to remote exploitation and the urgent need to remove internet-exposed OT assets. CISA has issued advisories urging utilities to immediately audit and secure their PLCs. Immediate action is required to prevent further disruption and potential public health risks.
This Week's Incidents
Atomic MacOS (AMOS) stealer infection targeting macOS users
What: The Atomic MacOS (AMOS) stealer malware was distributed via malicious web pages, tricking users into pasting harmful commands into Terminal, leading to credential theft and persistent infection.
Who's at risk: macOS users, especially those downloading software from unofficial sources.
Action: Block IOCs (getmacouscloud.com, macostruecloud.xyz, SHA256 hashes), educate users on safe command-line practices, and monitor for suspicious Terminal activity.
CareCloud Breach Exposes Medical and Financial Data of 345,000
What: CareCloud suffered a data breach exposing sensitive medical and financial data of 345,000 individuals, compromising patient privacy.
Who's at risk: Healthcare providers and patients using CareCloud services.
Action: Review access controls, notify affected individuals, and monitor for identity fraud.
Ransomware Attack on Dienst Pack Systems in Germany
What: Dienst Pack Systems, a German manufacturing company, was hit by Qilin ransomware, causing operational disruption and ransom demands.
Who's at risk: European manufacturing and supply chain organizations.
Action: Segment OT networks, update backups, and review ransomware response plans.
Bacoor City Government Allegedly Breached, 57,000+ Business Permit Records Leaked
What: Bacoor City Government in the Philippines was breached, leaking over 57,000 business permit records, with threat actor dopePanda issuing a one-week ultimatum.
Who's at risk: Public sector entities and local governments.
Action: Investigate breach scope, patch vulnerabilities, and prepare for potential escalation.
CRPxO Ransomware Targets DOĞAN HOLDİNG in Turkey
What: DOĞAN HOLDİNG, a Turkish media and energy conglomerate, suffered a ransomware attack with 3.1 GB of data leaked by the CRPxO group.
Who's at risk: Large enterprises in media and energy sectors.
Action: Monitor for leaked data, strengthen endpoint defenses, and review incident response protocols.
Ransomware Attack on The Saturday Evening Post
What: The Saturday Evening Post in the US was disrupted by a Qilin ransomware attack, impacting operations and data availability.
Who's at risk: US-based media organizations.
Action: Validate backup integrity, enhance email filtering, and train staff on phishing risks.
Ransomware attack on Pointe Property Group by Qilin
What: Pointe Property Group in the US was targeted by Qilin ransomware, resulting in disrupted access and potential data exposure.
Who's at risk: Real estate and property management firms.
Action: Conduct forensic analysis, notify stakeholders, and update ransomware playbooks.
Hijacked Hotel Wi-Fi Pushes Fake Updates Delivering Surveillance Malware
What: Attackers hijacked hotel Wi-Fi to push fake browser/OS updates, delivering CornFlake RAT for surveillance, impersonating Microsoft and ReliaQuest.
Who's at risk: Business travelers, hospitality sector, and organizations with remote staff.
Action: Advise users to avoid public Wi-Fi for sensitive work, deploy endpoint detection, and block related IOCs.
Ransomware Incident at Sigma Plastics Group by Play Group
What: Sigma Plastics Group, a US manufacturing firm, was targeted by Play ransomware, with the incident publicly claimed but unconfirmed.
Who's at risk: Manufacturing and industrial companies.
Action: Review lateral movement controls, monitor for Play ransomware TTPs, and test recovery procedures.
Baltas Online Allegedly Breached, 750+ Turkish Companies Exposed
What: Baltas Online, an HR assessment vendor, was allegedly breached by WInQ7wk9sA3a, exposing data of 750+ Turkish corporate clients including psychometric profiles and source code.
Who's at risk: HR tech providers and their enterprise clients.
Action: Validate vendor security, request breach confirmation, and monitor for leaked data.
Qilin ransomware targets Schreiner Trockenbau GmbH
What: Schreiner Trockenbau GmbH in Austria was targeted by Qilin ransomware, resulting in file encryption and operational disruption.
Who's at risk: Construction and engineering firms in Europe.
Action: Isolate affected systems, notify partners, and review endpoint protection.
Adform JavaScript Supply Chain Attack Swaps Crypto Wallet Addresses
What: Attackers compromised Adform’s JavaScript (trackpoint-async.js), injecting code to rewrite crypto wallet addresses on customer websites.
Who's at risk: Adform clients, e-commerce, and crypto-payment platforms.
Action: Audit third-party scripts, replace compromised files, and alert users to payment risks.
Ransomware Attack on MTCO (Mahmoud Altaheni & Partners Trading Co)
What: MTCO, a Saudi Arabian professional services firm, was hit by Gammax ransomware, with ransom demands posted online.
Who's at risk: Professional services and consulting firms in the Middle East.
Action: Assess exposure, communicate with law enforcement, and bolster ransomware defenses.
CRPxO Ransomware Attack on ANADOLU SİGORTA
What: ANADOLU SİGORTA, a Turkish insurance company, was attacked by CRPxO ransomware, leaking 1.2 GB of data.
Who's at risk: Insurance and financial services in Turkey.
Action: Monitor for data misuse, enhance DLP controls, and inform affected clients.
This Week's Pattern
- Ransomware remains the dominant threat, with Qilin, CRPxO, Play, and Gammax groups targeting diverse sectors (manufacturing, media, real estate, insurance) across multiple regions.
- Data breaches and supply chain attacks are rising, with major exposures at CareCloud, Bacoor City Government, Baltas Online, and Adform impacting hundreds of thousands of records and critical business operations.
- Critical infrastructure and OT assets are increasingly targeted, as seen in the Minnesota water utility attacks leveraging CVE-2021-22681, highlighting the urgent need for asset visibility and network segmentation in essential services.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

