As your dedicated cybersecurity services provider, CyberOne equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape.
Weekly Cybersecurity Report | Week 28, 2026
Information security updates and events from the past week
1. The attack group called Nocturne claims to have hacked two giant companies at once: apparel maker Nike and eyewear maker Alcon.
It claims to have millions of customer records from Nike and sensitive information from Alcon (a $10 billion manufacturer of eyewear and contact lenses)
According to the publication, over 40GB of uncompressed CSV files were stolen, containing millions of customer records.
The information includes names, email addresses, contact information, order details and transaction data.
2. Hahn International Airport in Germany has been added to the SafePay ransomware group’s leak site
This came a day after the airport confirmed it was handling a cyber incident.
Hahn Airport is mainly used by cargo flights and low-cost airlines and has also been linked to Chinese investments in the past. It is another reminder that aviation remains a hot target for ransomware groups, after the cases of Vienna Airport, Air Creebec and others.
3. Canadian airline Air Creebec falls victim to CHAOS ransomware: 70GB of data stolen
The CHAOS ransomware group has named Canadian airline Air Creebec as a victim, claiming to have stolen around 70GB of data.
4. Agricultural equipment company Kubotausa claims that hackers were in some of its network systems for more than a month
Between March 16 and April 20, the attackers accessed files with personal information of employees and their families. Kubotausa is a Japanese industrial giant that mainly produces agricultural and construction equipment.
What was exposed?
- Full names, including those of family members
- Social Security numbers, including those of family members
- Dates of birth, taxpayer identification numbers, and driver’s license or government ID numbers
- Bank account details for direct deposit, and corporate payment card details
- Benefit enrollment data and limited claims information, including those of family members
The company began sending personalized email alerts on June 30, detailing exactly how each person was affected
5. Hackers breach U.S. Department of Homeland Security (DHS) data-sharing network as U.S. secures World Cup
An unknown attacker has breached a central data-sharing database for the U.S. Department of Homeland Security (DHS), allegedly exposing sensitive information exchanged between federal, state, local and industry partners.
The breach comes as the U.S. secures World Cup games across the country.
What exactly happened?
- According to two sources familiar with the matter, an unknown attacker accessed the Homeland Security Information Network (HSIN) in recent weeks
- The intrusion apparently occurred between late May and early June, targeting HSIN servers and a SharePoint system used for collaboration
- The identity of the attackers and whether documents were stolen from the system are still unclear
- DHS’s Office of Intelligence has already conducted a damage assessment
The office said it acted immediately to isolate the affected systems, mitigate the vulnerability, and launch a comprehensive forensic investigation
This breach is worrisome not only because of the information that may have been stolen, but because of what the system represents: HSIN is a central nerve center for security coordination between dozens of U.S. agencies.
A breach during a major event like the World Cup is exactly the scenario that security officials fear, not just as an information leak, but as a disruption to the ability to coordinate and protect in real time.
6. Mount Royal University in Canada reports cyberattack, CMD group takes responsibility
In a statement released by the university, it states that attackers managed to steal and delete information from the corporate network, and because of the attack, various university services are being disrupted. The CMD group lists the university as a victim on the leak website, demanding a ransom of 30 Bitcoins (~$1.9 million).
The cybersecurity attacks highlighted in this report aren’t just incidents, they’re blueprints of the adversary’s arsenal. To protect your business you need the right partner. CyberOne is here to help! Check out our services.