Find notable cyber news and cases, enriched with sources, timelines, and signals.

15 Government tenants hit by network compromise

Incident
First reported
Last updated
Happening score
H score 45
1 unique sources, 1 articles

Summary

Hide ▲

The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity across login pages and mailbox views. The intrusion exposed browser cookies and enabled selective targeting of government accounts. The compromise was tied to Jewelbug operations running against a country in the Middle East. The event increased the risk of account abuse, follow-on email collection, and broader ministry compromise.

Related Happenings

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score60 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

How related: The data showed that the hackers ran a large-scale espionage operation and "an industrial-scale cryptocurrency fraud business."

About this happening: Jewelbug has paired espionage with an industrial-scale cryptocurrency fraud business, turning its operations into a blended actor ecosystem that combines government-ta...

Jewelbug multi-region government webmail espionage campaign

Campaign
H score55 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

How related: Jewelbug targeted government and military organizations across the Middle East, Southeast Asia, and South Asia.

About this happening: The Jewelbug campaign compromised 15 government webmail tenants and expanded a multi-region espionage effort against state targets in the Middle East, Southeast Asia...

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

23AndMe hit by network compromise

Incident
H score55 First: 16.07.2026 16:47 Last: 16.07.2026 16:47 Sources 1

About this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...

Latest development: 17.07.2026 17:30

23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.

Google hit by network compromise

Incident
H score42 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...

Timeline

  1. 13.08.2026 21:15 2 articles · 2h ago

    Jewelbug compromises 15 government webmail tenants

    Initial Disclosure

    Jewelbug, also known as Earth Alux and REF7707, compromised webmail accounts belonging to 15 government tenants in a campaign targeting a country in the Middle East after gaining write access to a shared webmail installation. The injected script ran on login pages and mailbox views, opened a WebSocket to a C2 server, exfiltrated webmail cookies, and checked each user's email address to determine whether it belonged to a targeted government domain.

    Show sources