ZeroFox Daily Intelligence Brief - August 4, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 4, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ExfilSquad Claims U.K. Police Database Compromise
- Liechtenstein Reports Data Breach Affecting 31,000 Legal Entities
- Compromised Hotel Wi-Fi Used to Deliver Malware
ExfilSquad Claims U.K. Police Database Compromise
Source: https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
What we know: The U.K.’s Police National Legal Database (PNLD) has confirmed that a cyberattack exposed names and email addresses of more than 100,000 police personnel, criminal justice professionals, and government partners. Extortion group ExfilSquad has claimed this breach.
Context: PNLD reportedly does not store information on victims, witnesses, or offenders. The group claimed that it stole 1.9 GB of data, including records relating to 114,000 PNLD subscribers and 21,000 “Ask the Police” users. ExfilSquad is observed to be an emerging, financially motivated threat group that surfaced in July 2026 and has since claimed to have targeted 15 major entities including U.K.’s Department for Education and U.S.-based semi-conductor company Analog Devices.
Analyst note: The exposure of police and criminal justice contact data is likely to increase phishing, impersonation, social engineering, and credential-targeting risks against U.K. law enforcement and government personnel. Since ExfilSquad is rapidly expanding its target list, further attacks against major global entities are likely in the near term.
Liechtenstein Reports Data Breach Affecting 31,000 Legal Entities
What we know: Liechtenstein’s government has reportedly disclosed a data breach affecting the European country’s register of beneficial owners between July 29–30, 2026. The incident has affected approximately 31,000 legal entities, including companies, foundations, and trusts.
Context: Authorities detected system irregularities, took the affected system offline, and confirmed there is currently no indication that records were altered or deleted. Bank and customer account details were not impacted. Established in 2021 as part of Liechtenstein’s anti-money laundering measures, the register maintains records identifying the ultimate beneficial owners of corporate structures registered in the country.
Analyst note: The exposure of beneficial ownership records could increase the risk of targeted spear-phishing, fraud, and financial reconnaissance against affected entities and individuals.
Compromised Hotel Wi-Fi Used to Deliver Malware
What we know: A global cyberattack campaign dubbed “CaptiveCrunch” has reportedly been targeting corporate travelers through compromised hotel and hospitality Wi-Fi networks to deliver malware and steal credentials.
Context: The campaign has been attributed to Storm-2945, an operational sub-cluster of Russia's Foreign Intelligence Service (SVR)-linked Midnight Blizzard. The attackers manipulate DNS and HTTP traffic on networks to deploy two malware families—Cornflake and ChocoShell—enabling persistent device-level access and credential theft.
Analyst note: As remote work and business travel continue to expand the attack surface beyond organizational perimeters, threat actors are very likely going to continue refining social engineering and stealth techniques that exploit the gap between enterprise security controls and the external networks employees often connect through.
DEEP AND DARK WEB INTELLIGENCE
PwnForums/Spear user TheHatman: Untested threat actor "TheHatman" advertised alleged internal employee databases belonging to InterContinental Hotels Group (IHG), Wyndham Hotels & Resorts and Hexaware Technologies on the dark web forum PwnForums. The threat actor claimed the data was extracted from Azure/Entra portals using compromised credentials. The actor also posted three identical advertisements on Spear. The advertised datasets allegedly contained employee names, email addresses, job titles, phone numbers, addresses and other tenant account records. The threat actor further claimed to have additional organizational data dumps available upon request.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-18577: This is an authentication bypass vulnerability in N-able N-central, actively exploited following the incomplete remediation of a related flaw, CVE-2026-18556. Attackers exploited the residual bypass to gain remote administrator access, using the platform's Take Control feature to reach managed customer endpoints, and installed persistent Cloudflare tunnels. CISA has added this vulnerability to its Known Exploited Vulnerability (KEV) Catalog.
Affected products: N-able N-central all versions prior to 2026.3.1.7
Tags: DIB, tlp:green