|
As an antidote to historical siloed risk management methods, we investigate the Ten Domains of Risk framework, which all organizations should consider incorporating into their risk management plans.
Risk Nodus Weekly Intelligence Brief
|
|
"TheHatman" Claims 3.6M Corporate Directory Theft from Azure Environments
A threat actor using the handle "TheHatman" has advertised internal employee directories from the Microsoft Azure and Entra environments of nine large companies, including McDonald's, TCS, Vodafone, Kyndryl, and HCL Technologies. Listings began July 31 and total approximately 3.64 million records, with McDonald's the largest at about 1.7 million, followed by TCS at 800,000 and Vodafone at 425,000. Hudson Rock assessed the samples as highly likely authentic, citing field names and corporate email addresses consistent with standard Azure directory exports, and linked infostealer infections to compromised credentials at several of the named firms. Researchers found no evidence of an Azure vulnerability, and TCS and Gap dispute the claims.
|
|
|
Johannesburg Businessman Rescued in Ransom Sting; Four Arrested
South African police rescued a Johannesburg businessman kidnapped from his business premises in Cleveland on August 15 and arrested four suspects during a controlled ransom drop. Police said several transactions were made from the victim's bank account before a ransom demand was issued. Officers seized two vehicles and four cellphones allegedly used in the crime, and the victim was recovered unharmed. The four suspects were due to appear before the Johannesburg Magistrate's Court on August 19. Authorities are currently investigating possible links to other offenses.
|
|
|
SEC Alleges $74M Pre-IPO Fraud Targeted More Than 800 Investors
The US Securities and Exchange Commission charged New York resident Andrew Spaventa and three entities he owned and controlled in the Southern District of New York, alleging a $74 million private-offering fraud involving more than 800 mostly retail investors. According to the complaint, the defendants marketed access to pre-IPO shares in companies, in particular SpaceX, Anduril, Anthropic, and Perplexity, through 11 private funds between December 2020 and June 2025. More than 100 sales agents cold-called prospective investors, many of them retirees. Investors were allegedly told they would pay no upfront fee or at most 12.5%, while paying prices averaging 46% above acquisition cost, generating approximately $23 million in undisclosed fees.
|
|
|
Slovakia Halts Rollout of 279 Speed Cameras with Russian-Origin Remote Access
Slovakia's National Security Authority issued a cyber-threat warning covering NERO R-ONE road speed cameras attributed to Cyprus-registered SODASUS, along with Cordon-series devices from Russia's Simicon and Croatia's NEROline. Analysis of a NERO R-ONE sample identified discrepancies between the declared and actual origin of the hardware and software, undocumented communication interfaces, preconfigured remote-management mechanisms not fully visible to the operator, and measurement software that differed from what was declared. The same assessment describes an undocumented module linked to 12 Russian telephone numbers; an SMS sent from one of those numbers, with a password, could open shell access to the device. The Interior Ministry, which procured 279 units, halted the rollout and ordered an independent audit.
|
|
|
CareCloud Breach Exposes Medical and Financial Data of 3.76M Patients
CareCloud confirmed to the Department of Health and Human Services that 3,756,469 people were affected by a March 2026 breach, revising the figure upward from an earlier count of about 345,000 in state AG filings. The company said an unauthorized third party accessed one of its Amazon Web Services environments between March 10 and March 16 and claimed to have exfiltrated data from databases in that environment. Breach notification letters filed with state regulators cite names, addresses, Social Security numbers, government-issued identification, medical records, insurance data, and payment card details. The incident now ranks among the largest US healthcare data thefts disclosed this year.
|
|
|
Meta Faces 29-State Child Safety Trial in Oakland
Meta is on trial in federal court in Oakland, where an eight-person advisory jury is hearing claims brought by a bipartisan group of 29 US states. US District Judge Yvonne Gonzalez Rogers will decide liability, and the trial is expected to run about six weeks. California, Colorado, Kentucky, and New Jersey lead the design and addiction claims, arguing Meta knew its platforms could harm teen well-being while designing them to maximize engagement; all 29 states join in alleging the company improperly collected data from children under 13. Meta denies the allegations. The states are seeking penalties that could run into the tens or hundreds of billions of dollars, plus product changes including limits on infinite scroll and public like counts.
|
|
|
German Port Strikes Threaten North Sea Freight and Logistics Flows
Germany's port labor dispute deepened on August 17, as ver.di called a 24-hour warning strike from the night shift across six seaports: Hamburg, Bremen, Bremerhaven, Wilhelmshaven, Emden and Brake. Those ports handle roughly 74% of German seaborne cargo throughput. The dispute covers about 11,000 workers, who rejected an employer offer of 5.1%, €300 in additional holiday pay and a €460 increase in the container-terminal allowance over a 19-month term. ver.di is seeking 8.2%, or at least €2.50 more per hour, over twelve months. Operations at major HHLA and EUROGATE terminals faced temporary shutdowns, with truck and rail bookings suspended, and no further negotiating date has been set.
|
|
|
China Launches First Scheduled Arctic Container Service to Europe
Chinese carrier Sea Legend began a scheduled seasonal container service between Asia and Europe via Russia's Northern Sea Route in mid-August, with the vessel Dubai Tower departing Ningbo for Felixstowe. The company plans seven vessels across eight sailings, at roughly weekly intervals into early October, advertising transit times of about 20 days against approximately 32 to 40 via the Suez Canal. New New Shipping, OVP Shipping and South Korea's PanStar announced services on the same corridor this month. The route offers an alternative to the Red Sea and Strait of Hormuz corridors but remains seasonal. Several major container lines, including MSC, have stated they will continue to avoid the route.
|
|
|
Brazil and Germany Dismantle Network Behind €30M Commerzbank Fraud
Brazil's Federal Police launched Operation Klonen against a criminal network suspected of electronic banking fraud, money laundering, and asset concealment linked to a €30 million cyberattack on Commerzbank's customers' accounts in late 2023. Authorities executed 21 search warrants and made four preventive arrests, and courts ordered the seizure of assets worth up to R$106 million. Three additional suspects face proceedings in Spain and Bulgaria. German investigators say the attackers exploited a vulnerability introduced by a faulty software update at a third-party payment provider and carried out unauthorized withdrawals over four days. Investigators say the proceeds moved through payment cards issued without the cardholders' consent, pass-through accounts, companies, payment institutions, and virtual-asset platforms.
|
|
|
Myanmar Clears Land by Force for Russia-Backed Dawei Port
Myanmar's military has deployed hundreds of troops around the Dawei Special Economic Zone since July 2026, as authorities seek to revive a Russia-backed deep-sea port and power project on the Andaman Sea. Conflict monitor ACLED reported in August that a column of roughly 700 soldiers has advanced through surrounding areas. A local civil society group says three aid workers were detained and killed in Yebyu Township on July 9. President of Myanmar Min Aung Hlaing discussed the project with Vladimir Putin in Moscow on August 18, and Russian Prime Minister Mikhail Mishustin said Russian companies intend to work with the zone. Dawei is promoted as an alternative to the Strait of Malacca and would extend Russia's reach into Southeast Asia and the Indian Ocean.
|
Organizations must stay vigilant and adopt proactive methods to predict and manage risk across various domains. By understanding and addressing the Ten Domains of Risk, organizations can not only protect themselves from potential threats but also position themselves for growth and success in a competitive marketplace.
The Risk Nodus Pulse delivers cross-domain intelligence on emerging threats and strategic shifts. Speak with our team about how Presage Global leverages predictive risk intelligence services to help you expect the unexpected and make well-informed decisions. Contact us today.
Know someone who would be interested in subscribing to Risk Nodus? Forward this email and invite them to join.
|
|
|
Edward V. Marshall, Founder & CEO
Presage Global
|
|
|