ZeroFox Daily Intelligence Brief - August 18, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 18, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Chaos Ransomware Group Leaks 235 GB of Healthcare Highways Data
- Researchers Analyze TeamPCP Archive Exposing Nearly 2,500 Organizations
- Threat Actor “TheHatman” Advertises 3.6 Million Records From Nine Fortune 500 Firms
Chaos Ransomware Group Leaks 235 GB of Healthcare Highways Data
What we know: Ransomware-as-a-service (RaaS) group Chaos has publicly leaked 235 GB of data allegedly stolen from Healthcare Highways, a medical provider network company.
Context: Chaos added Healthcare Highways to its data leak site on August 5, 2026, threatening to publish sensitive company and client records if contact was not established. Inspection of the alleged leaked files reportedly confirmed the presence of extensive protected health information (PHI) from employee health plans. The breach also exposed employee data belonging to Healthcare Highways’ clients, including employees' and their dependents' full Social Security numbers (SSNs), dates of birth, and contact details.
Analyst note: The public leak of high-cost and high-risk patient records is particularly sensitive, and their disclosure is almost certainly irreversible. As RaaS groups continue to target healthcare-adjacent organizations with access to aggregated PHI, downstream client organizations are very likely to face increasing exposure through third-party relationships they may not have adequately assessed for risk.
Researchers Analyze TeamPCP Archive Exposing Nearly 2,500 Organizations
What we know: Researchers have obtained and analyzed an archive of the data TeamPCP collected from compromised CI/CD build machines in its March 2026 supply-chain campaign. The data reportedly includes credentials and other information from nearly 2,500 organizations, including major technology and industrial companies. The exposure of credentials does not necessarily mean the affected organizations were breached, or that the data is new, but some credentials can remain usable if they were not rotated.
Context: The compromised data reportedly amounts to at least 153 GB and contains more than 433,000 files, including cloud credentials, API keys, tokens, and other sensitive authentication data. Some of the stolen data is now reportedly being offered for sale on Telegram. In the March 2026 compromise, TeamPCP reportedly compromised Trivy, with stolen credentials subsequently used to compromise additional software, including the LiteLLM Python package.
Analyst note: The credentials were likely harvested opportunistically from the earlier Trivy/LiteLLM supply chain campaign, rather than through individual breaches of each affected organization. Since some of the stolen data is reportedly being sold on Telegram, any credentials that remain valid are likely to be leveraged by threat actors to access associated cloud environments, repositories, or other services, enabling further attacks. More information on TeamPCP can be found in this advisory.
Threat Actor “TheHatman” Advertises 3.6 Million Records From Nine Fortune 500 Firms
What we know: A threat actor using the alias “The Hatman” is selling employee databases of multiple Fortune 500 companies. The data was allegedly extracted from internal identity management portals using compromised credentials.
Context: Zerofox observed the threat actor claiming 3.64 million records across nine major organizations between August 1 and August 16, with the recent post claiming three global corporations on DarkForums. The data allegedly includes personally identifiable information (PII) including employee IDs, job titles, postal addresses, service accounts, and other tenant account records.
Analyst note: The threat actor’s low reputation reduces the credibility of the claims, while some organizations have stated that the advertised data is years old. However, if authentic, the compromised accounts are likely to provide access to tenant structures and service accounts, enabling follow-on phishing, credential attacks, or business email compromise. Additionally, repeated targeting of major enterprises suggests that the threat actor is likely using a repeatable source of compromised cloud credentials, such as infostealer infections, rather than independent breaches.
DEEP AND DARK WEB INTELLIGENCE
Exploit/DarkForums user Hey, exfilar: Untested threat actors “Hey” and “exfilar” have advertised a dataset allegedly associated with TaxAct on the Russian-language Exploit forum and English-language DarkForums, respectively. “Hey” shared approximately 450,000 user records via an external download link, while “exfilar” later claimed to have breached the same dataset and exfiltrated it through a proprietary pipeline. The dataset reportedly contains 449,996 unique email addresses, 450,000 unique usernames, 347,293 unique U.S. phone numbers, and 357,221 email-phone pairs in a 115 MB JSONL file. “exfilar” likely redistributed the dataset originally published by “Hey” rather than obtaining it through a separate compromise of TaxAct’s systems. The dataset reportedly does not contain passwords, Social Security numbers, tax returns, or financial information.
DATA BREACH INTELLIGENCE
Bits of Gold data breach: Israeli cryptocurrency broker Bits of Gold reported that hackers stole personal data belonging to approximately 200,000 customers after gaining unauthorized access to a third-party data analytics network. The compromised information reportedly includes customer names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details, and public wallet addresses. The company said that funds, private keys, passwords, CVV codes, and scanned ID documents were not exposed and that initial findings indicate the incident may be part of a broader attack affecting multiple companies simultaneously.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-19478 and CVE-2026-19650: GitLab has disclosed two vulnerabilities that could allow unauthenticated attackers to perform unauthorized actions on affected instances. CVE-2026-19478 could enable attackers to remotely modify or delete public projects and user data through a GraphQL directive without credentials or user interaction. CVE-2026-19650 is a cross-site request forgery (CSRF) weakness in the GraphQL multiplex query handler that could enable attackers to execute mutations through GET requests due to improper request validation, although exploitation requires user interaction.
Affected products: The affected products are listed in this advisory.
Tags: DIB, tlp:green