DPRK's Kimsuky built an in-house AI toolkit to power cyberattacks
Chinese components in UK military drones secretly transmitted data, Cali city declares emergency after cyberattack, Turkey's new cyber law sparks fears of sweeping digital censorship, OpenAI's Hugging Face hack reveals deeper AI safety failures, Claude Code's autonomous mode is now the default

Metacurity is the cybersecurity news you'd need hours to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
A paid subscription to Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
South Korean cybersecurity firm Genians reports that North Korean hacking group Kimsuky built large language model tools and collected software that could help automate cyberattacks, analyze stolen material, and produce more convincing phishing campaigns.
Genians said it found evidence that Kimsuky had set up tools for running and managing AI models locally, including Ollama, GPT4All and Msty, alongside document search technology known as retrieval-augmented generation (RAG).
According to the company, the tools could allow operators to process documents without sending sensitive information to outside AI services.
Genians also found AI agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool, on infrastructure it linked to the campaign.
The findings suggest Kimsuky is moving beyond using generative AI to create phishing lures and is building capacity to integrate existing AI models into malware development, data analysis and attack automation, Genians said.
Genians also said it found finance and cryptocurrency-themed decoy documents that appeared to have been generated with AI. The materials were designed to resemble legitimate investment reports and other workplace documents, it said. (Joyce Lee / Reuters)
Related: Genians, Techzine, The Next Web, The Chosun Daily, UNN, Korea JoongAng Daily, Business Standard, AMB Crypto, Current Ukraine, Chosun Biz, Digital Today, NDTV, Seoul Economic Daily

UK Royal Navy spy drones used by Britain’s elite special forces secretly sent data to China.
The cameras on the K3 Scout surveillance drones had components made in China which were secretly transmitting information to a device in the country.
The Royal Marines have been using the £12m fleet since March and the Ministry of Defence (MoD) was forced to remove all internet connectivity from the cameras after discovering the breach.
The revelation raises fears that Beijing has been attempting to spy on Britain’s military after years of security warnings about the threat from the country.
The drones were supplied by a major British defense contractor, Kraken Technology Group, which sourced the cameras from a third party who had given assurances about their security.
An investigation into the drones revealed that the cameras were transmitting “heartbeat communications” – data to confirm they were online and functioning normally – to an IP address in China. The MoD insisted that there was no evidence that any sensitive data or systems had been sent abroad.
The discovery triggered national security fears that security-cleared staff at the Special Boat Service (SBS) headquarters in Poole, Dorset could have been exposed.
A defence source familiar with the matter said that the K3 drones made up part of a future defence package offered by the UK to secure the freedom of navigation in the Strait of Hormuz.
The source said that preparations for Britain’s plans in the Gulf had been conducted on the drones, adding: “This is major failure to check origins of components and we have lost confidence in the platform.”There are also concerns that the surveillance drones have been near highly sensitive meetings between senior special forces staff, and that cameras remained active even when the drones were switched off. (Richard Holmes / The Telegraph)
Related: The Sun, Metro.co.uk, Neowin, GB News, Mirror, NewsMax.com, r/CanadianInvestor, r/ukpolitics, r/Intelligence

The Suisun City Council declared a state of emergency Saturday after a cyberattack that shut down computer systems including 911 public safety operations.
"Malicious software infected and compromised" the East Bay community's information technology systems beginning about 5:45 a.m. Friday, the city said on social media.
"The cybersecurity incident hit critical public safety operations, including 911 routing, police and fire dispatch, records and city services," the city said.
"There is no imminent threat to the public," the city said. "All public safety services remain active."
The city shut down its computer network "to contain the threat and preserve evidence for a federal investigation," it said.
The state of emergency, approved at a special meeting of the council Saturday morning, allows the city to access emergency support services and to recoup costs of the cybersecurity incident, it said. (NBC Bay Area)
Related: Los Angeles Times, KQED, The Vacaville Reporter, KCRA, The Mercury News, Contra Costa News, ABC10, Databreaches.net, The Reporter, San Francisco Chronicle
Rights groups have warned that a new Turkish cyber security law risks creating a system of “absolute digital obedience”, by giving the presidency sweeping powers over internet services, gaming platforms and social media accounts.
About 90 percent of Turkey’s national media outlets are already under government control, according to Reporters Without Borders, meaning that platforms such as X, YouTube and Meta’s Instagram are among the few spaces still relatively open to critical reporting and dissent. Turkey ranks 163rd of 180 countries in RSF’s latest index of press freedom.
“The new measure is straight out of the standard rule book for information control in authoritarian contexts,” said Tomiwa Ilori, a senior researcher in Human Rights Watch’s technology and rights division. “Cybersecurity powers should not be concentrated in the executive. They should also be subject to adequate safeguards.”
Under the law, powers of digital oversight are officially centralized in Turkey’s Cybersecurity Directorate, which is attached to President Recep Tayyip Erdoğan’s office. It can now prescribe urgent measures on its own initiative or at the request of security agencies. Telecom operators, access providers and other online platforms must comply within two hours, with orders reviewed by a judge after implementation.
The law, which came into force at the end of July, justifies the approach on national security grounds, describing cyberspace as a domain “as vital as conventional defense” for safeguarding digital sovereignty, critical infrastructure and public order. Concentrating cyber powers also avoids duplicating the functions of different state agencies, saving TL30bn (US$630mn), according to Ersan Aksu, an MP from Erdoğan’s governing AK party. (John Paul Rathbone / Financial Times)
Related: The Arab Weekly, Turkish Minute, Stockholm Center for Freedom
At this year's Black Hat, OpenAI researchers Michael Dalton and Eric Wallace gave an unscheduled talk about exactly what happened when an OpenAI agent escaped its sandbox to attack Hugging Face.
In a very abbreviated summary, what follows is a summary of what happened, based partly on the OpenAI talk as filtered by Zvi Mowshowitz.
OpenAI models-in-training, without the excuse of ‘they were doing a cyber eval,’ created a message board where they shared information on how to hack and cheat, and were trained on that basis.
Then OpenAI only figured this out when the models crashed the server. OpenAI’s response was to rebuild the server and patch that particular exploit, but they continued training the models that trained using the message board.
Those models then recreated the message board, hacked OpenAI again, got internet access, and used an agent swarm to attack HuggingFace in order to get the answers to a cyber evaluation.
After more than a week, OpenAI figured this out. They are taking a wide array of at least somewhat costly precautions.
OpenAI delayed plans to release their new model Astra, despite Astra not being directly involved in the HuggingFace hack, although owner Sam Altman now says it will still ship. That one hurts a lot.
OpenAI still has no idea how badly they messed up, or in what ways, or what needs to be fixed. They don’t get it. (Zvi Mowshowitz / Don't Worry About the Vase)
Related: Wired, Simon Willison's Blog, Interconnects AI, The Deep View, TestingCatalog AI News, Hacker News
Anthropic is turning Claude Code’s auto mode on by default
Programming with Claude Code will soon require even less human oversight, as Anthropic says it’s making auto mode the default for Pro, Max, and Team accounts, starting on August 14.
The company first unveiled a test version of auto mode in March, pitching it as a way to balance speed and control. As Anthropic explained in its announcement on Friday, when Claude Code is in auto mode, instead of presenting prompts asking for human approval at each step, it will proceed unless an action is determined to be “irreversible, destructive, or aimed outside your environment.”
Anthropic also said that in testing, auto mode proved safer than manual review — in a study with 1,053 paid testers, auto mode caught 89% of harmful actions, while human review only caught 13.6%. (Perhaps that’s because “manual review can become habitual: users approve 97% of permission prompts in Claude Code.”)
In a post on X, Claude Code Head Boris Cherny said, “The team and I use Auto mode exclusively, and have been for many months. I couldn’t imagine going back to permission prompts!”
The company also said it’s been adding new safety features like prompt injection screening and customizable hard deny rules to prevent things like data exfiltration. (Anthony Ha / TechCrunch)
Related: Claude, Simon Willison, Help Net Security, Techzine, The New Stack, The Times of India, 9to5Mac, Kucoin, Firstpost

An Australian man unintentionally triggered what researchers describe as the country's first known autonomous AI cyberattack after asking an AI agent to book him into a gym class.
The user employed the OpenClaw AI agent framework running Anthropic's Claude model to automate the booking. Instead of simply reserving a spot, the agent identified a vulnerability in the gym's booking software that allowed it to bypass booking restrictions, reserve classes weeks or months ahead of schedule, and remove another member from the waiting list without being instructed to do so.
The incident follows a string of recent disclosures from AI companies including OpenAI, Anthropic and Meta involving AI models that autonomously exploited systems during testing. Unlike those cases, however, the gym incident occurred on a live production system after the AI was given an ordinary consumer task rather than being instructed to conduct security testing. (Cam Wilson and Rhiannon Hobbins / ABC.net.au)
Related: Simon Willison's Weblog, Neowin, Android Authority, RuntimeWire, Cyber Security News, Hacker News, r/australia, r/aussie
Hackers obtained access to the email inbox of a military device manufacturer, according to an SEC filing by IEH Corporation, which produces specialized products used in military satellites, missiles and fighter jets.
IEH said it discovered a cyberattack on Tuesday and immediately tried to contain it.
The company told investors that an employee fell victim to a phishing attack that gave intruders access to their mailbox, which included “email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information.”
The company said there is no evidence emails or other data were taken out of the email account, but “sensitive information was accessible to the unauthorized party during the compromise period,” according to the filing.
Corrective actions are currently being taken to secure the mailbox and preserve any evidence. The investigation into the incident is ongoing, but as of Friday, there is no evidence that the incident will impact the company’s business operations. (Jonathan Greig / The Record)
Related: SEC, The Register, Security Affairs, The Globe and Mail
A series of suspected Iranian cyberattacks targeting municipal water systems has renewed scrutiny of a Republican-led legal challenge that blocked the Environmental Protection Agency from imposing cybersecurity requirements on water utilities, prompting new legislation to restore the agency's authority explicitly.
In 2023, the EPA directed states to incorporate cybersecurity assessments into sanitary surveys of public water systems and require utilities to address significant vulnerabilities, with federal grants available to help offset costs. Attorneys general in Arkansas, Iowa and Missouri sued, arguing the agency exceeded its authority and imposed an undue burden on small communities. A federal appeals court halted the rule, and the EPA withdrew it.
The legal challenge has come under renewed criticism after a water utility in Arkansas—one of the states that sued—was struck by a cyberattack that U.S. intelligence agencies believe is part of a broader Iranian campaign now affecting water systems in at least a dozen states. Cybersecurity experts told The Washington Post that the EPA rule would not have eliminated all risk but likely would have addressed many easily exploitable weaknesses.
In response, Sen. Adam Schiff (D-CA) introduced legislation that would explicitly authorize the EPA to regulate cybersecurity in the water sector, effectively reinstating the requirements the agency had attempted to implement administratively. The bill would require water utilities to conduct cybersecurity assessments and remediate significant vulnerabilities.
Support for mandatory standards appears to be growing. The American Water Works Association, which previously opposed the EPA's 2023 approach and participated in the legal challenge, now says voluntary measures are insufficient and is backing legislation to establish minimum cybersecurity requirements for the sector under EPA oversight. (Ellen Nakashima and Amy B Wang / Washington Post)
Related: Sen. Adam Schiff
In an SEC filing, Levi Strauss disclosed a recent cybersecurity incident in which an unauthorized third party gained access to the company's systems through a social engineering attack targeting three employees.
The incident has not disrupted business operations, and the company does not expect a material impact on its operations or financial results, it said.
The apparel maker joins a growing list of major firms worldwide that are facing a rise in cyberattacks and ransomware incidents that steal sensitive data and disrupt operations. (Raphael Satter, AJ Vicens and Anirban Sen / The Record)
Related: The Record, Human Resource Director, Bleeping Computer, GBHackers, Silicon Republic, Cyber Security News
The personal information of Victorian court users has been posted on the dark web, sparking a police investigation, with the names, emails and job titles of people who attended online hearings in regional courts posted on an underground hacking forum in July.
A user has claimed responsibility in a post.
The data breach comes after a ransomware cyber attack in 2024, suspected to be the work of Russian hackers, and an incident in 2021, when the Children's Court inadvertently posted case information online.
Court Services Victoria (CSV) confirmed the latest breach related to participants of online hearings in the Magistrates' Court and Children's Court divisions.
The ABC understands some of the leaked data includes highly sensitive details, such as the names of parties in family violence intervention order hearings and children's court cases.
CSV said the data, spanning from 2022 to 2026, related to hearings in Bendigo, Castlemaine, Echuca, Kerang, Kyneton, Maryborough, Mildura, Ouyen, Robinvale and Swan Hill.
Other publicly available information, such as case names and courtrooms, was also included in the data dump, CSV confirmed.
The forum user who said they posted the material wrote that they had acquired 28,600 lines of court records. (Kristian Silva and Danny Tran / ABC.net.au)
Related: Court Services Victoria, Victoria Crime News, Cyber Daily, Magistrates Court of Victoria

Framework, a company that makes modular repairable computers, said it has notified all of its customers that hackers stole their names, email addresses, phone numbers, and physical addresses, due to an incident at a company that provides business intelligence.
Several Framework customers said on social media that they had received an email from the company notifying them of the data breach.
The company blamed the data breach on an upstream cyberattack at Metabase. Metabase disclosed its own breach in a blog post on its official website, where it said that it was hacked by someone using an unknown security flaw, a so-called zero-day. The company said the hackers exploited the bug to give them the ability to access customers’ databases stored on Metabase’s cloud servers.
In its email to customers, Framework also included the email Metabase sent to the company, which says hackers accessed Framework’s cloud instance. (Lorenzo Franceschi-Bicchierai / TechCrunch)
Related: Metabase, Videocardz, CNET, PCMag, Engadget, Notebookcheck, Heise, r/cybersecurity, r/framework

International law firm WilmerHale paid an $18 million ransom to the Luna Moth threat group following a 2026 data breach, with coverage provided by insurer CNA.
The firm is now facing a federal class-action lawsuit regarding the incident, which highlighted escalating security threats targeting major legal firms.
Separately, law firm Goodwin Procter paid approximately $10 million in ransom to the Luna Moth extortion group following a data security breach, with Brit serving as the lead insurer. (James Thaler / Cyber Risk Insurer from Reuters and James Thaler / Cyber Risk Insurer from Reuters)
A former employee at SK Hynix has been sentenced to 18 months in jail for leaking information on semiconductor manufacturing technology to a Chinese firm, the Yonhap news agency reported.
The Seoul High Court made the ruling in an appeal case against the defendant, upholding the lower court's sentence, for leaking classified information on so-called CMOS image sensors, a technology used fornon-memory chips, opens new tab in smartphone cameras and laptops, to a Chinese company in 2022, Yonhap said.
The court found that the employee, who formerly worked at SK Hynix's office in China, printed out or took photos of documents containing trade secrets downloaded from the company's internal server, a violation of its security rules, according to Yonhap.
The defendant disclosed some of the information in a resume submitted to a Chinese firm, Yonhap said, without naming the Chinese company.
The man admitted all of the charges and most of the information he took was retrieved by the company, the report said. (Heejin Kim / Reuters)
Related: Benzinga, The International News, SBS, Digitimes, Maeil Business
Former Secretary-General Jo Seoung-lae of the Democratic Party of Korea apologized on the 9th for a data breach on the party’s member community site that exposed the personal information of 17,088 people.
Jo posted a statement on Facebook that morning, saying, “As the former secretary-general at the time, I deeply feel the weight of responsibility and sincerely apologize with my head bowed.”
He explained, “During my tenure as secretary-general, suspicious signs of intrusion were detected, so I requested an inspection from the website management company. However, the company responded that no abnormalities were found. Additionally, I asked the Korea Internet & Security Agency (KISA) for support regarding security vulnerabilities, but they replied that immediate assistance was difficult due to ongoing incidents like the KT and Lotte Card data breaches at the time.”
He continued, “Although the party later formed an ‘Information System Diagnosis Task Force’ to address security vulnerabilities and establish fundamental countermeasures, I deeply regret that this data breach occurred and went unnoticed for so long.”
Jo added, “The party is currently taking all measures to prevent further damage, such as expiring all account sessions and enforcing password resets, in cooperation with relevant agencies. We are also investigating the cause of the breach. As a former secretary-general, I will cooperate responsibly throughout the process to ensure this incident is fully resolved and the party’s security system is fundamentally overhauled.”
The Democratic Party announced on the 7th that an external cyberattack on its member community site, ‘Blue Wave,’ had leaked members’ IDs, names, encrypted passwords, and email addresses. The party estimated the breach occurred on September 2 of last year, during the leadership of Chung Chung-rae. It was not detected until the 6th, 11 months after the breach. (Kim Kyeong-pil / The Chosun Daily)
Related: Seoul Economic Daily, Korea JoongAng Daily, Asia Business Daily, The Chosun Daily, Maeil Business
Two South Korean hacking teams finished among the top three at a renowned global hacking competition, the science ministry said.
They were among six teams from South Korea that made it to the finals of the 2026 DEFCON Capture the Flag (CTF) 34 held in Las Vegas, the United States, from Thursday to Sunday (U.S. time), the ministry said.
Founded in 1993, the competition is considered the "Olympics" for white hackers. A total of 686 teams globally competed in the preliminaries this year, among which only 12 teams made it to the finals.
The science ministry vowed support in nurturing top-tier cybersecurity experts with practical skills, so that they can preemptively react to ever-advancing digital security threats in the era of artificial intelligence (AI). (Kang Jae-eun / Yonhap News Agency)
Related: Korea JoongAng Daily, Korea Bizwire, Yonhap News
More than 460,000 pieces of personal data, including bank account and credit card information, were exposed in a breach at South Korean financial media outlet 3Pro TV.
E-Broadcasting, the company that operates 3Pro TV, posted a notice on the outlet's website saying it had confirmed that "an external actor illegally accessed the 3Pro TV application early this month and maliciously gained unauthorized access to other users' personal data," according to industry sources on the 9th.
E-Broadcasting estimates the scale of the leaked personal data at more than 460,000 records. The exposed information included two addresses, 2,979 bank account records and 317 credit card records. The company believes the breach affected data including names, profiles, mobile phone numbers, email addresses, addresses, bank account details (bank name, account number and account holder name), records generated during service use, device information, card names, masked card numbers and service usage logs.
The company said that unique identifying information such as resident registration numbers and other sensitive data were not collected and therefore were not leaked. E-Broadcasting reported the incident to the Personal Information Protection Commission and the Korea Internet & Security Agency.
E-Broadcasting asked 3Pro TV members to "be especially careful of calls, text messages and other contact impersonating 3Pro TV that may be suspected of misusing personal data," and requested that "if you receive calls, text messages or emails from unclear or suspicious sources, do not click on any links (URLs) or attachments, and instead delete and report them." (Park Hyo-jung / Seoul Economic Daily)
Related: Asia First News Agency, Databreaches.net
Chief State Attorney Ivan Turudić announced the arrest of Serbian entrepreneur Georgije V, whose data hacking was linked to the Serbian secret service BIA.
He is reportedly suspected of hacking into the Croatian Interior Ministry, the Central Register of Pension-Insured Persons, the Croatian Health Insurance Fund, the Croatian Regulatory Agency for Network Activities, the Croatian Pension Insurance Institute, the Croatian Tax Administration and the Croatian Automobile Club.
Croatian daily Jutarnji list has reported that the arrest took place on July 28, when Georgije V. was on holiday in Croatia. He had arrived with his wife, two children and mother at a tourist resort on the Adriatic coast a few days earlier.
Following his arrest, police searched his electronic devices, vehicle and accommodation under court orders. They seized items and digital data allegedly linking him to criminal acts, including two mobile phones and a laptop containing a large amount of data.
The court ordered one month of pre-trial detention, despite the man offering 20,000 euros in bail money and his family home in Novi Sad as collateral. (Balkan Insight)
Related: Jutarnji list, Balkan Insight, razglas, Hrvatska Danas, Srpske Novine
According to MakeUK, a lobby group for British manufacturers, nearly a third of British manufacturers have been hit by a cyber-attack on them or a company in their supply chain.
The group found that 30% of manufacturers had experienced a cyber-incident in the past 12 months, leading in many cases to lost production time and increased costs. However, only half had a plan in place to respond to an attack. (Jasper Jolly / The Guardian)
Related: MakeUK, The Engineer, The Manufacturer, Cybersecurity Insiders

Poland’s computer emergency response team (CERT) has published a report detailing a second attack on the country’s power grid.
The attackers targeted industrial control systems (ICS) and their objective was “purely destructive”.
In late December 2025, threat actors linked to the Russian government, specifically the APT named Sandworm, targeted communication and control systems at roughly 30 sites, including combined heat and power (CHP) plants and renewable energy dispatch centers for wind and solar facilities.
In that attack, the hackers gained access to ICS, but mainly targeted grid safety and stability monitoring systems rather than active power generation systems. While some ICS devices were permanently damaged, the attack did not cause any electrical outages.
CERT.PL revealed that the country’s energy sector was targeted in a second attack in December 2025. An investigation revealed that this attack, conducted in parallel with the previously disclosed hack, was aimed at a smaller CHP plant supplying heat to 50,000 residents.
The Polish CERT’s report highlights that this appears to be the first time threat actors used a private APN as an attack vector, warning that the same vulnerable configuration has been commonly encountered in Poland and other countries around the world.
The cyberattack caused the shutdown of a steam turbine and a water treatment system, which resulted in a disruption of the cogeneration process. However, the systems were quickly restored, and heat and electricity supply were not interrupted.
The attack occurred during maintenance work, and it was initially believed that an engineering error had led to the disruption, but the CERT soon determined that it was the result of hacker activity. (Eduard Kovacs / Security Week)
Related: CERT.pl

Two security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services that have received 401,796 messages so far.
Cory Solovewicz is receiving the avalanche of messages as he’s the owner of the domains noreply.us and noreply.net, which he purchased in 2020 and 2024, respectively. After originally planning to use the noreply.us domain as a catch-all email—which receives mail sent to any @ address on that domain—to filter messages and enhance his privacy, the researcher quickly noticed that other systems were sending mail to @noreply.us addresses. “I created an accidental honeypot,” Solovewicz says. “I had no idea it was going to turn into this.”
This deluge isn’t the regular flood of spam, newsletters, and unwanted deals that fill many people’s inboxes. Instead, companies and other organizations are inadvertently sending Solovewicz other people’s private information and company secrets.
Solovewicz, who presented his work at the Defcon security conference yesterday, says ultimately he is relieved that he ended up with the domains rather than criminal hackers or nation states who could use the data maliciously.
“I did not realize that this was going to be as big of a problem as it is,” says Solovewicz, who is not publicly naming impacted entities. The researcher has been alerting affected companies of their problems, encouraging them to fix the errors and misconfigurations. “I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff.” (Matt Burgess / Wired)
Related: Digital Trends, Cyber Trends
According to researchers at Zscaler, the fastest way to get a company to consider paying a ransom isn't calling the CEO – it's targeting the 46-year-old IT manager.
Zscaler's ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month.
The data suggests today's ransomware crews have become oddly specific about their preferred victim profile: nearly two-thirds of victims held manager-level titles or above, the average victim was a 46-year-old Gen Xer, and three-quarters worked in accounting and finance, sales, operations, HR, or marketing. Half worked in the industrial or IT sectors.
Rather than blasting the same extortion email across an organization, attackers are doing their homework first. Zscaler says they combine information from compromised systems with publicly available data to map reporting lines and identify the employees most likely to influence a company's response. (Carly Page / The Register)
Related: Zscaler, Cyber Press, Databreaches.net
The Oklahoma Manufacturing Alliance announced it was hit by a ransomware attack on July 15 that affected a limited portion of its local network.
The organization says its IT team quickly identified and isolated the affected systems.
Access was restored through a separate, secure network later that morning.
The ransomware group behind the attack, known as the Booba Project, claimed it breached OMA.
The group claimed it obtained 10 gigabytes of data and threatened to release it publicly if a ransom was not paid. (Deanne Stein / Newson6)
Related: News9
Best Thing of the Day: Better Late Than Never
Thai Government agencies will consider adopting multi-factor authentication (MFA) and resetting passwords following data leaks that exposed sensitive information from at least 20 state agencies.
Bonus Best Thing of the Day: Just in Case AI Destroy Everything
A growing community of vintage computer collectors is preserving the classic machines that helped launch the digital revolution.
Extra Bonus Best Thing of the Day: Shame Pervert Glass Wearers Into Oblivion
Despite being marketed as the latest must-have gadget, Meta’s smartglasses, which can record video footage while being worn, have faced a vicious backlash, particularly relating to concerns about surveillance.
Worst Thing of the Day: Let's Destroy the Planet to Feed Our LLMs
Amazon is investing in a large-scale natural-gas-burning power plant as part of a huge data center in Texas, a facility that could become the largest single source of climate pollution in the United States.
Bonus Worst Thing of the Day: Do as We Say, Not as We Do
While touting reduced work hours from use of its AI products, OpenAI is forcing its workers to toil away for 90 hours per week.