ZeroFox Daily Intelligence Brief - August 31, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 31, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Berlin Government Refuses to Pay Ransom to Rhysida Ransomware
- ShinyHunters Claims Theft of 284 Million Patient Records from McKesson
- Hasbro Data Breach Exposes Employee Personal Information
Berlin Government Refuses to Pay Ransom to Rhysida Ransomware
What we know: Berlin’s government has confirmed a cyberattack which reportedly resulted in data being exfiltrated by an unconfirmed threat actor. Ransomware group Rhysida has claimed responsibility and is threatening to publish the compromised data if extortion demands are not met.
Context: The group claims it stole more than 5 TB of data, which includes about 46,000 contracts, emails, phone numbers, and passwords belonging to the Berlin state network of the Senate Department for Mobility, Transport, and Climate Protection and the Environment. Berlin officials have said they will not comply with the ransom demands.
Analyst note: Stolen passwords or authentication information likely risk unauthorized access to government or third-party systems if passwords are left unrotated.
ShinyHunters Claims Theft of 284 Million Patient Records from McKesson
What we know: Healthcare and pharmaceutical distribution giant McKesson has confirmed unauthorized access to third-party applications and exfiltration of data. ShinyHunters has claimed responsibility and alleged the theft of approximately 284 million patient-related records.
Context: ShinyHunters claims to have gained initial access through vishing attacks against McKesson employees. Stolen data reportedly includes patient names, Social Security numbers (SSNs), medical record numbers, medication and allergy information, diagnoses, and prescription data. ShinyHunters demanded a ransom of USD 55.2 million.
Analyst note: ShinyHunters' vishing and SSO compromise strategy targeting victim organizations’ employees appears to be successful and is likely to continue. Targeting of healthcare entities is almost certainly driven by the high leverage that sensitive patient data provides in extortion negotiations. This attack is consistent with an ongoing ShinyHunters campaign that Health-ISAC has flagged.
Hasbro Data Breach Exposes Employee Personal Information
Source: https://www.securityweek.com/hasbro-data-breach-exposed-employee-personal-information/
What we know: American Toy company Hasbro has notified current and former employees that their personal information may have been compromised in a data breach, with exposed information potentially including names, addresses, phone numbers, national ID numbers, and financial information.
Context: While the cause of the recent data breach is unknown, Hasbro had suffered a cyberattack in March that caused operational disruptions and forced the company to take some systems offline. The toy company has not confirmed the incidents are connected. As of writing, no threat actor has claimed the breach.
Analyst note: Employee personal information is likely to be leveraged for identity theft, fraud, and targeted social engineering against affected individuals and the organization. Phishing templates with employee information for convincing scams are also likely. The data is likely to be sold on dark web forums to other threat actors.
DEEP AND DARK WEB INTELLIGENCE
Telegram user 313 Team: On August 27, 2026, hacktivist group 313 Team claimed to have carried out a distributed denial-of-service (DDoS) attack on Proton's internal servers, allegedly disrupting Proton Mail, VPN, Wallet, and more. On the same day, Proton confirmed that it had experienced service disruptions due to a cooling failure at one of its data centers in Frankfurt and shifted traffic to backup sites. There is no confirmation that 313 Team’s attack led to the outage. The hacktivist group is likely opportunistically claiming the disruption to gain attention and portray the service outage as the result of its capabilities.
THREAT ACTOR WATCH
TTPs to Watch
Target: Government and military entities, international bodies, and critical infrastructure entities across NATO member states, Ukraine, and other geopolitical targets of interest to Russia.
Method: Macro-enabled Microsoft Word documents bearing diplomatic-themed lures deliver the HOOKEDGE backdoor, which uses webhook[.]site services for command-and-control, payload staging, and data exfiltration.
Aim: Intelligence collection and cyber espionage against European government and diplomatic targets on behalf of Russian state interests.
IoCs: Outbound connections to webhook[.]site endpoints; scheduled task abuse; headless Microsoft Edge execution; macro-enabled Word documents with diplomatic-themed lures.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2023-49105: This is an already-patched critical WebDAV API authentication bypass vulnerability in ownCloud, which has been reportedly exploited by a suspected Chinese-speaking threat actor to steal nuclear records from a Philippine research body. The flaw enables an unauthenticated attacker with knowledge of a valid username to access, modify, or delete files without credentials.
Affected products: ownCloud core versions 10.6.0 to 10.13.0
Tags: DIB, tlp:green