|
As an antidote to historical siloed risk management methods, we investigate the Ten Domains of Risk framework, which all organizations should consider incorporating into their risk management plans.
Risk Nodus Weekly Intelligence Brief
|
|
France: 15.8M Medical Records Stolen from Health Ministry Supplier
Attackers stole approximately 15.8 million administrative medical records after breaching Cegedim Santé, a software supplier to France’s Health Ministry, in late 2025. The attack targeted the Mon LogicielMedical (MLM) platform used by roughly 3,800 doctors, affecting about 1,500 physicians. Stolen data includes patient names, birth dates, contact details, and administrative information. Around 165,000 files contained doctors’ notes, which in limited cases referenced sensitive health details such as HIV/AIDS status and sexual orientation. Authorities are investigating the breach as Cegedim cooperates with regulators amid growing concerns about healthcare data security.
|
|
|
Explosion at US Embassy in Oslo Investigated as Potential Terror Attack
An explosion struck the U.S. Embassy in Oslo, Norway, at approximately 1:00 a.m. on March 8, 2026, causing minor structural damage but no reported injuries, according to Norwegian police. The blast occurred at the public entrance of the embassy compound in the Morgedalsvegen district, about four miles west of central Oslo. Authorities deployed drones, dogs, and helicopters while searching for suspects, describing the incident as likely a deliberate act. The attack occurred amid heightened security concerns following U.S. and Israeli strikes on Iran and recent attacks on U.S. diplomatic facilities in Saudi Arabia and Kuwait.
|
|
|
Federal Judge Invalidates Kari Lake's Voice of America Layoffs
A U.S. federal judge ruled that actions taken by Kari Lake while serving as acting CEO of the U.S. Agency for Global Media (USAGM) in 2025 were unlawful, invalidating decisions including major layoffs at Voice of America (VOA). U.S. District Judge Royce C. Lamberth determined Lake’s appointment violated the Federal Vacancies Reform Act and the Constitution’s Appointments Clause, as she lacked Senate confirmation and was not eligible to hold the role. The ruling nullifies actions taken between July 31 and November 19, 2025, including staff reductions that significantly curtailed VOA operations. Lake said she plans to appeal the decision.
|
|
|
Deepfake CEO Impersonation Scams Escalate Across Financial Sector
Deepfake-enabled fraud is emerging as a significant corporate and market integrity risk, with executives increasingly impersonated in scams involving financial manipulation and social engineering. The Bombay Stock Exchange said a fake video of its CEO, Sundararaman Ramamurthy, circulated in early 2026, falsely promoting stock advice to investors. The threat reflects a broader pattern: LastPass reported a deepfake impersonation attempt against CEO Karim Toubba in 2024, while Arup lost $25 million the same year after a Hong Kong employee joined a video call featuring deepfake versions of senior staff. Experts warn attack costs are falling even as detection tools improve.
|
|
|
Spain Confirms Swine Flu Case with No Known Pig Exposure
Spanish health authorities confirmed a human case of variant H1N1 swine influenza (H1N1v) in Catalonia in February 2026, marking the country’s first detection since 2024 and only the fourth recorded case since 2009. The patient is asymptomatic, and all identified contacts have tested negative. The case was reported to the European Centre for Disease Prevention and Control (ECDC), which assessed the likelihood of further human transmission as very low. Notably, investigators found no known contact with pigs, the typical source of infection, raising the possibility of rare human-linked exposure pathways under investigation.
|
|
|
Google Pays $135M to Settle Background Data Transfer Lawsuit
A U.S. federal court has granted preliminary approval for a $135 million settlement resolving claims that Google transferred user data from Android devices to its servers without consent. The class action covers U.S. Android users from November 12, 2017, onward, potentially affecting over 100 million people. Plaintiffs alleged the operating system transmitted information even when devices were idle, consuming users’ cellular data. Individual payouts are capped at $100, with attorneys seeking about $40 million in fees. A final approval hearing is scheduled for June 23, 2026, and Google must implement clearer disclosures about background data usage.
|
|
|
Pakistan-Linked APT36 Uses AI to Mass-Produce Polyglot Malware
The Pakistan-linked hacking group Transparent Tribe (APT36) is using AI-assisted coding tools to mass-produce malware targeting the Indian government, diplomatic missions, and Afghan entities, according to Bitdefender research published March 6, 2026. The campaign generates large volumes of disposable malware written in uncommon languages such as Nim, Zig, Crystal, Go, and Rust, designed to overwhelm detection systems. Phishing emails with LNK files or PDF lures trigger PowerShell scripts that deploy backdoors and tools, including Cobalt Strike and Havoc. Researchers warn that AI is enabling the rapid industrialization of cyber espionage operations despite relatively unsophisticated code quality.
|
|
|
ASIC Escalates Enforcement After $1.1B Fund Collapse
Australia’s Australian Securities and Investments Commission (ASIC) has intensified enforcement actions following the collapse of investment schemes linked to First Guardian and Shield Master funds, which together exposed roughly $1.1 billion in investor savings and affected about 12,000 Australians. Investigations allege inadequate due diligence, misleading advice, and governance failures by financial advisers, research firms, and trustees who promoted the funds. ASIC has launched multiple Federal Court proceedings against more than a dozen defendants, while compensation efforts continue for some victims. Regulators say the crackdown signals a broader push to strengthen oversight of high-risk investment products and retirement savings platforms.
|
|
|
North Korea Deploys AI Tools to Infiltrate Western Tech Firms
North Korean operatives are reportedly using artificial intelligence tools to infiltrate Western technology firms by securing remote IT jobs under stolen or synthetic identities, according to Microsoft. The scheme uses voice-modulation software, FaceSwap-style image tools, and AI-generated resumes, cover letters, and email accounts to support fraudulent applications for software and IT roles. Microsoft links the activity to the groups Jasper Sleet and Coral Sleet. Once hired, the workers allegedly funnel earnings to the North Korean state while retaining access to corporate systems, blending financial gain with potential long-term espionage opportunities.
|
|
|
Hungary Detains Ukrainian Bank Staff, Seizes $80M in Cash-Gold Convoy
Ukraine has accused Hungary of detaining seven employees of the state-owned Oschadbank and seizing a convoy carrying $40 million, €35 million, and 9 kilograms of gold during a transit operation in Budapest on March 5, 2026. Ukrainian officials say the funds were being transferred from Austria’s Raiffeisen Bank for domestic circulation, while Hungarian Foreign Minister Péter Szijjártó questioned the origin of the cash and launched an investigation. Kyiv labeled the action “state terrorism,” demanded consular access to the detainees, and signaled potential EU-level legal action, escalating tensions amid a broader dispute over Druzhba pipeline oil flows.
|
Organizations must stay vigilant and adopt proactive methods to predict and manage risk across various domains. By understanding and addressing the Ten Domains of Risk, organizations can not only protect themselves from potential threats but also position themselves for growth and success in a competitive marketplace.
The Risk Nodus Pulse delivers cross-domain intelligence on emerging threats and strategic shifts. Speak with our team about how Presage Global leverages predictive risk intelligence services to help you expect the unexpected and make well-informed decisions. Contact us today.
Know someone who would be interested in subscribing to Risk Nodus? Forward this email and invite them to join.
|
|
|
Edward V. Marshall, Founder & CEO
Presage Global
|
|
|