Image
Episode 33  •  Sep 4, 2026  •  42 Min

IDScan Leak, Vished Hospitals, Berlin's Ransom Refusal & a Grid Under Fire

Four stories on the table this week. A dark web marketplace put more than 150 million driver's license scans up for sale, all traced back to one identity-verification vendor. ShinyHunters walked out of McKesson with hundreds of millions of patient records after a single vished login. Berlin refused to pay a ransomware group that stole nearly six terabytes of government data weeks before a regional election. And a suspected Iran-linked group spent several days inside a small UK power plant this summer. Here's what stood out from the operator chair.

A verification vendor's breach becomes every one of its customers' breach. A dark web marketplace called Nexus began selling more than 150 million driver's license scans traced to a single identity-verification firm, idscan.net, whose clients include Hertz, Target, FedEx, and Caesars Entertainment. The data includes the infrared and ultraviolet scan layers idscan.net's own systems produce, not a stolen photo but the full verification package the vendor was hired to generate. Any company that outsources ID checks inherits that exposure the moment their vendor gets popped, and a count that's still climbing by the hundreds of thousands a day means nobody yet knows where this blast radius stops.

ShinyHunters didn't need an exploit, they needed a phone call. McKesson confirmed a breach after the extortion group claimed it voice-phished employee credentials into Okta, then pivoted into the company's Snowflake and Salesforce environments and pulled roughly a terabyte of patient data. The 284 million figure making headlines is database rows, not patients, but the access method is the real story: one employee talked out of a login unlocked the exact platforms built to hold everyone's records at once. Vishing keeps working because it skips every control built for phishing email, and the weak link isn't Snowflake or Salesforce, it's whoever picks up the phone.

Disconnecting first and negotiating never is still the fastest way out of a ransomware story. Rhysida claimed responsibility for stealing 5.79 terabytes of Berlin government data and demanded a ransom, but the city had already pulled the affected departments offline before the group went public, then simply refused to pay. Governments get an option most companies don't: the leverage of a criminal investigation instead of a ransom clock, and Berlin used it to isolate the intrusion and call the bluff. Every ransom paid funds the next operation, so Berlin eating the loss in public gives the next target proof that refusing doesn't have to be fatal.

A four-day outage at one small plant is a demonstration, not a target list. Officials said a suspected Iran-linked actor knocked a small UK power plant offline for several days in July, timed close to a separate wave of Iranian activity against US water utilities, and British officials have been clear the national grid was never at risk. Hitting an asset this small isn't about the disruption itself, it's proving the access exists and can be repeated against anything running the same PLC hardware sold across the industry. Operators running decades-old control systems from vendors that no longer exist should read this as a capability test they already failed once.

Security Headlines:


Sean McMillan Headshot

Sean McMillan

Community Manager

Sean McMillan is Community Manager at Bishop Fox, focused on making complex security topics easier to understand and more interesting to follow. He holds a bachelor’s degree in Mass Communication and Media Studies from Arizona State University and brings over a decade of experience in podcasting, live hosting, and audience engagement. As host of Initial Access, he works with practitioners to explore how real-world attacks actually happen.


Sergio Villegas BF Headshot

Sergio Villegas

Senior Managing Analyst

Sergio Villegas is a Senior Managing Analyst in the Attack Surface Intelligence team at Bishop Fox where he is one of the lead researchers. His main areas of focus are emerging threats, attack surface mapping, and tactical lead generation. Sergio has over 11 years of experience in cybersecurity during which he has worked as a researcher and consultant to help companies improve their procedures, technologies, and techniques around threat intelligence and threat hunting.


Shad Malloy Headshot

Shad Malloy

Sr. Managing Consultant II

Shad Malloy is a Sr. Managing Consultant II at Bishop Fox focused on network penetration testing, vulnerability risk management, and application security. He has advised multiple industries including health care, financial services, energy, and technology. In addition to time working and managing security for education, health care, and national government agencies. Shad holds a Bachelor of Science in Computer Information Systems as well as industry certifications like the CISSP.


Subscribe to our PODCAST

Real talk on the threats, trends, and tactics shaping security today

Listen Anywhere