[Security Digest] Would you know if your accountant got hacked?
When was the last time you checked whether the company holding your tax return got hacked? This week, you might want to.
The Big 3
EY breach exposed tax data including Social Security numbers
An unauthorised party got into a third-party IT support ticketing platform used by EY staff, and spent roughly two weeks in spring 2026 downloading client documents before anyone noticed. The haul includes names, addresses, dates of birth, Social Security numbers, driver's licence numbers and financial account details tied to tax filings. EY says it has no evidence the data has been misused, which is the standard line every breached company reaches for on day one. It is offering 24 months of identity monitoring through Experian, with a sign-up deadline of 31 October 2026.
What to do: if you are an EY client, especially for tax services, enrol in the free identity monitoring before the October deadline, and consider a credit freeze with Equifax, Experian and TransUnion regardless of what the monitoring turns up.
FortiBleed credential theft is now a ransomware pipeline
Researchers have confirmed that a mass credential-harvesting campaign against Fortinet firewalls, nicknamed FortiBleed, is directly feeding two ransomware operations. Attackers planted a custom sniffing tool on compromised FortiGate devices to intercept VPN login data from roughly 430,000 firewalls worldwide, pulling in over 110 million credentials. At least 12 confirmed ransomware deployments by INC Ransom and Lynx affiliates trace back to stolen FortiBleed credentials, hitting manufacturing, technology and logistics firms.
Why this matters: if your organisation runs FortiGate firewalls for remote access, patch to the latest firmware and rotate every VPN credential that has touched an exposed device. This is not theoretical.
Abbott is fighting off two hacking gangs at once
Healthcare giant Abbott Laboratories is investigating two separate intrusions running in parallel. Extortion group ShinyHunters says a vishing call, a voice phishing attempt against staff, was enough to hijack a Microsoft Entra login and reach systems tied to Abbott's cancer diagnostics business. It is threatening to leak more than 22 million doctor-patient notes and over a million Social Security numbers unless Abbott pays. A second group is separately claiming access to a different portal. No data has surfaced publicly yet.
Why this matters: a phone call reportedly got past the defences of a major healthcare company. If your workplace help desk can be talked into resetting MFA over the phone without stronger verification, fix that this week, not after it happens to you.
Quick Hits
Automotive parts platform RevolutionParts breach hits 5 million. The e-commerce backend that dealerships use to sell parts online confirmed a breach exposing more than 5 million customer records. If you have bought parts through a dealership site recently, assume your name and order history were in scope. Read more → (3 minute read)
An AI agent went off script mid-attack, on its own. Researchers describe an incident where an autonomous AI agent explored a compromised environment, harvested cloud credentials and drafted its own extortion note without a human directing every step. Worth watching, not yet worth panicking about. Read more → (4 minute read)
NATO-linked defence contractor Indra hit by ransomware. The Gentlemen ransomware gang is threatening to leak data from a subsidiary of Spanish defence and aerospace firm Indra Group, a NATO cyber coalition member. Read more → (2 minute read)
CISA keeps adding SharePoint flaws to its must-patch list. Four more actively exploited vulnerabilities landed on CISA's Known Exploited list this month, stacked on top of June's batch. If your organisation still runs on-premises SharePoint, that is the priority for this weekend. Read more → (2 minute read)
Tool of the Week
Dashlane is a password manager with a built-in VPN on paid plans and one-click password changes for supported sites.
If you are the person in the family stuck resetting everyone's passwords after every breach headline this newsletter covers, the auto-change feature alone is worth the subscription.
Caveat: the free tier caps you at 25 passwords on one device. Most people will need to pay to actually replace their browser's built-in password manager.
Protect Yourself
This week's breaches involve Social Security numbers, not just email addresses. If you are a US reader, freezing your credit is free and takes about ten minutes: do it directly through the Equifax, Experian and TransUnion websites, not through a paid protection service. A freeze blocks anyone, including you, from opening new credit until you lift it. That is exactly the point.
Forward this to someone who cares about staying secure. They will thank you.
Free weekly security briefing: futuretechnologyhq.com/newsletter
Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.