Four stories on the table this week. A dark web marketplace put more than 150 million driver's license scans up for sale, all traced back to one identity-verification vendor. ShinyHunters walked out of McKesson with hundreds of millions of patient records after a single vished login. Berlin refused to pay a ransomware group that stole nearly six terabytes of government data weeks before a regional election. And a suspected Iran-linked group spent several days inside a small UK power plant this summer. Here's what stood out from the operator chair.
A verification vendor's breach becomes every one of its customers' breach. A dark web marketplace called Nexus began selling more than 150 million driver's license scans traced to a single identity-verification firm, idscan.net, whose clients include Hertz, Target, FedEx, and Caesars Entertainment. The data includes the infrared and ultraviolet scan layers idscan.net's own systems produce, not a stolen photo but the full verification package the vendor was hired to generate. Any company that outsources ID checks inherits that exposure the moment their vendor gets popped, and a count that's still climbing by the hundreds of thousands a day means nobody yet knows where this blast radius stops.
ShinyHunters didn't need an exploit, they needed a phone call. McKesson confirmed a breach after the extortion group claimed it voice-phished employee credentials into Okta, then pivoted into the company's Snowflake and Salesforce environments and pulled roughly a terabyte of patient data. The 284 million figure making headlines is database rows, not patients, but the access method is the real story: one employee talked out of a login unlocked the exact platforms built to hold everyone's records at once. Vishing keeps working because it skips every control built for phishing email, and the weak link isn't Snowflake or Salesforce, it's whoever picks up the phone.
Disconnecting first and negotiating never is still the fastest way out of a ransomware story. Rhysida claimed responsibility for stealing 5.79 terabytes of Berlin government data and demanded a ransom, but the city had already pulled the affected departments offline before the group went public, then simply refused to pay. Governments get an option most companies don't: the leverage of a criminal investigation instead of a ransom clock, and Berlin used it to isolate the intrusion and call the bluff. Every ransom paid funds the next operation, so Berlin eating the loss in public gives the next target proof that refusing doesn't have to be fatal.
A four-day outage at one small plant is a demonstration, not a target list. Officials said a suspected Iran-linked actor knocked a small UK power plant offline for several days in July, timed close to a separate wave of Iranian activity against US water utilities, and British officials have been clear the national grid was never at risk. Hitting an asset this small isn't about the disruption itself, it's proving the access exists and can be repeated against anything running the same PLC hardware sold across the industry. Operators running decades-old control systems from vendors that no longer exist should read this as a capability test they already failed once.
Subscribe to our PODCAST
Real talk on the threats, trends, and tactics shaping security today
Recommened Resources
Download
Your download is starting in a new tab. If it does not start automatically, use the button below.