As your dedicated cybersecurity services provider, CyberOne equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape.
Weekly Cybersecurity Report | Week 24, 2026
Information security updates and events from the past week
1. ShinyHunters claims Ralph Lauren hack: 220GB of data, including future collections that have not yet been launched
The ShinyHunters attack group claims to have hacked fashion chain Ralph Lauren and stolen over 220GB of data.
In addition to personal customer information, the group also claims to have details of future collections and products planned for launch in 2027 and beyond, making this breach particularly dangerous for a fashion company.
2. French government encrypted messaging platform Tchap hacked after user account taken over
The French government’s digital directorate (DINUM) has warned that hackers have breached Tchap, the French government’s official encrypted messaging platform, after taking over an existing user’s account.
The attacker claims to have gained access through a social engineering attack, and has extracted hundreds of thousands of messages and documents.
What is Tchap?
- An encrypted messaging app developed in 2018 by DINUM in collaboration with the French cyber agency ANSSI
- The platform is based on the decentralized Matrix protocol, and is intended exclusively for the French public sector
- It has over 300,000 monthly users and over 500,000 downloads, after Prime Minister François Bayrou made it mandatory for all civil servants to use it and banned foreign apps for work communication in August 2025
The ANSSI agency detected the hack on Sunday, finding that an attacker accessed the platform through a compromised user account
The account from which the malicious requests came was identified and immediately blocked to remove the attacker’s access
The investigation is ongoing, including analyzing Event Logs to understand which conversations and information the attacker accessed
There is an irony here that France built its own encrypted app and banned foreign apps precisely to maintain sovereignty and data security, and in the end, one account is enough who are taken over by social engineering to hack everything. Even the best encryption does not protect against a user who is persuaded to give up access.
3. The University of Oxford reported a new attack, after its third-party provider Group GTI informed it that the career services platform CareerConnect had been hacked.
The same platform is also operated by other British institutions such as the University of Manchester and King’s College London.
What was revealed:
- The platform was hacked on May 28, and the attackers gained access to first names, last names, email addresses and encrypted passwords
- The passwords belong to users who do not log in via SSO, who are mainly graduates, researchers and employers
Attackers no longer need to directly hack a large, protected institution.
It is enough to hack one third-party provider such as a career platform, an LMS system and all the institutions that use it are exposed at once. The supply chain is the weakest link.
4. Widespread outage hits North Carolina education system
Onslow County schools in North Carolina are dealing with a major cyberattack that has knocked out phone and internet services across the county
The outage affects 43 schools and more than 28,000 students.
The incident has disrupted regular activities, including testing, parental communications and end-of-year events. No one has claimed responsibility for the cyber incident currently, and authorities are working to restore services.
5. Instagram bug allowed attackers to take over accounts
Meta has admitted that a glitch in Instagram’s account recovery system allowed some users’ accounts to be reset without their permission.
This means that an attacker could have taken over the account and gained full access to it. According to the company, more than 20,000 users were affected by the issue. Following the discovery, Meta disabled the vulnerable reset mechanism and disabled the AI component associated with the process.
6. Hackers hit deportation airline GlobalX, leak flight manifests, and leave an unsubtle message for “Donnie” Trump
A charter airline used by the US government for deportation flights, GlobalX Airlines, has been attacked by activists who stole what they say are detailed flight records and passenger manifests.
The attackers, who claim to operate under the umbrella of Anonymous, not only quietly extracted data from the airline that assists with deportations, they also defaced the company’s website. Hackers hit deportation airline GlobalX, leak flight manifests, and leave an unsubtle message for “Donnie” Trump
7. Education giant Pearson hit by cyberattack that exposed customer data
Education giant Pearson has been hit by a cyberattack that allowed threat actors to steal corporate data and customer details.
Pearson is a UK-based education company and one of the world’s largest providers of Academic publishing, digital learning tools and credentials. The company works with schools, universities and individuals in over 70 countries through its print and online services. Pearson confirmed it had suffered a cyberattack and that yearbooks had been stolen, but said it was mostly “old data”.
The cybersecurity attacks highlighted in this report aren’t just incidents, they’re blueprints of the adversary’s arsenal. To protect your business you need the right partner. CyberOne is here to help! Check out our services.