ZeroFox Daily Intelligence Brief - August 17, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 17, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- France’s DGFiP Confirms 600,000+ Taxpayer Data Breach
- ZeroFox Intelligence Flash Report - European Intelligence Seeks Broader Authority to Defend Against Russian Hybrid Warfare
- NHS Patient Data Exposed via Unencrypted Pager Communications
France’s DGFiP Confirms 600,000+ Taxpayer Data Breach
What we know: France’s General Directorate of Public Finances (DGFiP) has confirmed that attackers used stolen credentials to access its systems in June and July 2026, extracting tax data on more than 600,000 individuals and businesses.
Context: Additionally, threat actor “ZeroBytes” has claimed to have breached France’s DGFiP and offered a 678,438-record dataset containing sensitive tax and personal information. The DGFiP has not attributed this attack to any threat actor. ZeroBytes has also separately claimed access to DGFiP's cadastral (related to real estate) system, allegedly obtaining 252,149 rows affecting approximately 2 million individuals. The claim remains unconfirmed at the time of writing.
Analyst note: The confirmed data breach is likely to increase the risk of targeted phishing and fraud against affected individuals and businesses, as exposed financial information can be used to make scams more convincing. Separately, if ZeroBytes’ claims are authentic, the reported access to two DGFiP systems is likely to indicate broader access within the agency and increase the risk of further data theft or targeting of French public-sector entities.
ZeroFox Intelligence Flash Report - European Intelligence Seeks Broader Authority to Defend Against Russian Hybrid Warfare
Source: https://www.zerofox.com/advisories/41502/
What we know: ZeroFox has observed an escalating Russian hybrid warfare campaign against European supporters of Ukraine, coinciding with the German cabinet's approval of draft legislation.
Context: The German reforms gained momentum following the detection of an explosive drone at Leipzig/Halle Airport on August 4, 2026 with several international intelligence agencies indicating Russian involvement. Recent incidents include a Russian Kh-101 cruise missile violating Polish airspace on July 30, a Russian drone striking a residential building in Romania in May 2026, and a December 2025 coordinated cyberattack on Poland's energy sector targeting over 30 sites across both IT and operational technology (OT) systems.
Analyst note: Russia likely views curtailing European aid to Ukraine as critical to reversing the war's trajectory and will likely escalate its hybrid attacks throughout Europe. These attacks are also likely to become more brazen as Russia seeks to probe NATO defenses and test the alliance's threshold to respond. Countries physically bordering Russia and those that have supported Ukraine likely face the highest risk of continued Russian hybrid warfare activity.
NHS Patient Data Exposed via Unencrypted Pager Communications
Source: https://www.bbc.com/news/articles/clyj92j210do
What we know: The UK’s National Health Service (NHS) has reportedly confirmed a data breach after patient information was sent via an unencrypted pager network used by healthcare staff for routine communication.
Context: The exposed information reportedly includes patient names, dates of birth, hospital numbers, medical information, and details concerning organ donation and transplantation. The data was transmitted through pagers that are small radio communication devices that use unencrypted broadcasts.
Analyst note: This incident highlights how unencrypted healthcare communication channels are likely an effective target for threat actors to passively intercept sensitive patient information, which can be exploited for medical fraud, extortion, impersonation, or other targeted scams.
DEEP AND DARK WEB INTELLIGENCE
Exploit user aura: Untested threat actor "aura" has advertised an alleged zero-day exploit targeting the Ledger Wallet desktop application, on dark web forum Exploit. The exploit allegedly leverages a "deeplink vulnerability" that can enable an attacker to load fully custom, native-looking overlay templates directly within the Ledger Wallet application on Windows and macOS. Once executed, the exploit allegedly renders a full recovery flow phishing template natively within the trusted application, potentially tricking victims into entering their private keys, which are then allegedly exfiltrated to an attacker-controlled Telegram bot and CLI output.
DATA BREACH INTELLIGENCE
Several organizations reported data breaches exposing customer information, with incidents involving third-party providers, threat actors, and exploited vulnerabilities.
- Crypto company, Trezor has reportedly disclosed a data breach at third-party shipping provider ShipMonk that exposed personal information of nearly 14,000 customers across seven countries. Metabase, a business intelligence company, was recently targeted by the ShinyHunters extortion group, although Trezor has not attributed the breach to any specific threat actor.
- Communication platform RingCentral has disclosed a data breach affecting some customers. ShinyHunters separately claimed to have targeted RingCentral and later leaked data linked to approximately 1.6 RingCentral million accounts.
- Crypto wallet company SafePal has disclosed a data breach involving unauthorized access to order information of approximately 39,798 customers, including names, addresses, and purchase data.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-58231: An improper authorization flaw in SAP Commerce Cloud’s Data Hub Adapter enables unauthenticated attackers to abuse a default authentication client and submit specially crafted input to insufficiently validated functions.This is likely to enable threat actors to carry out arbitrary code execution and compromise internal application components.
Affected products: The affected products are listed in this advisory.
Tags: DIB, tlp:green