Resources

Cybersecurity Roundup, August 2026

Written by Chloe Schofield | Aug 28, 2026, 10:00:00 AM

From a near-autonomous AI attack in Taiwan to a single CRM breach affecting more than 1,500 UK charities, the past few weeks show how often cyber risk sits inside the platforms and vendors organisations already rely on.

This month’s roundup also shows that attackers do not always need advanced exploits to cause serious exposure. Misconfigured portals, compromised credentials and trusted third-party systems continue to create real risk across public sector, charity and supplier environments.

Read more in our August Cybersecurity Roundup.

Cyber-attacks in the news

ExfilSquad breaches UK Department for Education and Police National Legal Database

A group calling itself ExfilSquad breached two Department for Education portals, the Help Desk Self-Service Portal and the Turing Scheme Portal, compromising more than 600,000 pieces of data.

A separate breach also affected the Police National Legal Database, with around 135,000 records exposed through a misconfigured Microsoft Power Platform/Power Pages portal. The exposed information was largely contact details, including names, emails and phone numbers belonging to DfE staff, educators, police officers and government partners.

ExfilSquad is demanding payment to avoid releasing the data. The UK government’s policy is not to pay ransoms.

The incident shows how far a portal misconfiguration can travel once it is found. Even where the exposed data is limited to contact details, it can still be useful for phishing, impersonation and targeted social engineering.

For public sector organisations and their suppliers, access reviews, credential security and configuration audits remain essential.

Beacon CRM breach exposes data from 1,500+ UK charities

Beacon, a CRM platform used by more than 1,500 UK charities, discovered on 29th July that compromised credentials had given attackers access to its systems.

The company said copies of database backups had been made and were likely downloaded by an unauthorised third party. Beacon has told every customer with an account created before 27th July to assume all their data, including attachments, donor records and beneficiary details, may have been downloaded.

Affected organisations reportedly include the Molly Rose Foundation, The Upper Room and Macmillan Cancer Support Jersey.

This is a sharp example of how a single SaaS breach can quickly become a much wider issue. One compromised platform can create hundreds or thousands of separate data incidents for the organisations that rely on it.

For MSPs and channel partners, it reinforces the need to treat vendor risk as part of everyday security. That means knowing where client data sits, how platforms are accessed and what controls protect credentials, backups and admin accounts.

China-linked hackers run near-autonomous AI cyberattack on Taiwan

Suspected Chinese operators reportedly ran a four-day campaign against Taiwanese targets using up to eight AI agents at the same time.

According to reporting, the campaign targeted more than 21 Taiwanese government systems, a nuclear safety agency and seven energy companies. The toolkit was built from open-source AI frameworks rather than novel exploits and reportedly reassessed its own priorities and adjusted tactics as it moved through the attack.

More than 85 accounts were compromised and over 2,500 personnel records were extracted. Attribution remains sensitive, with Taiwan not officially confirmed as the target by all parties, although the available reporting points strongly in that direction.

This marks a real shift in attacker tooling. AI-supported reconnaissance and lateral movement are no longer purely theoretical, and the use of publicly available frameworks suggests the barrier to entry could fall quickly.

For organisations with limited security resource, that makes visibility, identity controls and response planning even more important.

Stadler Rail rejects $12.3 million ransom demand

Swiss rail manufacturer Stadler Rail confirmed the Everest ransomware gang accessed a data exchange platform shared with one of its suppliers in mid-July.

The company said technical information was stolen but described it as not security relevant. No personal data was taken and rail vehicle production continued without disruption.

Everest demanded 10 million Swiss francs, around $12.3 million. Stadler refused to pay and filed a criminal complaint with local police.

This is a useful example of a public non-payment stance, backed by contained impact and law enforcement involvement.

It also shows how supplier-linked platforms can still create exposure, even when core operations remain unaffected.

The cybersecurity landscape

Security leaders warn autonomous AI could threaten critical infrastructure

Security leaders are now warning that AI-enabled attack capability is advancing quickly, especially around critical infrastructure.

The Register reported that figures from the FBI’s Cyber Division, former NSA leadership and Google Threat Intelligence have all raised concerns about open-source AI agents making adaptive attack capability more accessible to less-resourced groups. The Taiwan campaign has been pointed to as evidence that this is already moving from theory into practice.

The concern is not only that AI tools could make attacks more sophisticated. It is that they could make certain stages of an attack faster, cheaper and easier to repeat.

For channel partners, this gives AI risk a more practical shape. It is not just about what tools employees are using internally. It is also about how attackers may use AI to speed up reconnaissance, exploit weak access controls and adapt during an intrusion.

Threat landscape snapshot

AI-enabled attacks are becoming operational

The Taiwan campaign and warnings from security leaders show that AI-assisted attacks are no longer only a future planning concern. Organisations need to prepare for faster, more adaptive attack methods.

Trusted platforms are still a major source of exposure

Beacon CRM shows how one SaaS vendor breach can affect a large number of downstream organisations. The same applies to portals, data exchange platforms and supplier systems.

Access hygiene remains a practical weak spot

The DfE, PNLD and Beacon CRM incidents all point back to access, credentials or configuration. Stronger controls in these areas can reduce a lot of real-world risk.

Ransomware impact depends on preparation

Stadler Rail’s response shows the value of containment, clear communication and law enforcement involvement. Not every ransomware incident has to become an operational crisis.

Resilience depends on knowing where data and access sit

Across these stories, the same practical questions keep coming up: who has access, where is data stored, which vendors are involved and what happens if a trusted platform is compromised?

At Brigantia, we support channel partners in protecting their clients with our selected vendor portfolio, product specialists and dedicated support.

To explore our vendors or discuss how we can support your security offering, visit our vendor page or get in touch with the Brigantia team.