Ransomware, data breaches, and fraud surge globally
A wave of separate attacks hit organizations worldwide at once. Ransomware gangs Qilin and Akira kept extorting companies, healthcare tech firm Craneware had employee and customer data stolen, Chick-fil-A customer accounts were broken into, and South Korea's foreign ministry ran a breached training system for almost 10 months.
- Report priority
- High
- Involves
- Craneware
What is known
Each incident had its own entry point: ransomware crews break into networks and encrypt files for payment, someone reused stolen passwords to log into Chick-fil-A accounts (credential stuffing), and South Korea's diplomatic training platform sat compromised for months before anyone caught it.
What to do
Check for a direct breach notice from any of those organizations.
If you got a notice from Chick-fil-A, Craneware, or South Korea's foreign ministry, change that account's password and any reused password elsewhere, and turn on multi-factor authentication where it is offered. There is no single patch for a roundup like this, so watch each organization's own advisory for specifics.
Reported details
An attacker takes usernames and passwords already leaked from other, unrelated breaches. They feed the list into an automated tool that tries each pair on Chick-fil-A's login page. Any pair that works hands the attacker a real account, exposing that customer's name, email, membership details and limited payment data.
SC World's roundup, citing The Cyber Express, notes the US absorbed close to half of all ransomware attacks tracked in H1 2026, with Qilin and Akira among the most active groups. Craneware, a healthcare revenue-cycle software vendor used by many US hospitals and pharmacies, confirmed attackers stole employee and some customer data. Chick-fil-A disclosed a credential-stuffing attack that reached customer accounts, exposing names, emails, membership data and limited payment details.
South Korea's Ministry of Foreign Affairs disclosed a nearly 10-month breach of its National Diplomatic Academy e-learning system, exposing employee IDs, names, emails and encrypted passwords. The DOJ's Operation Offsides also seized over 1,000 piracy domains streaming the FIFA World Cup.