- Cybersecurity Docket
- Posts
- Black Kite Ransomware Report: New Threat Actors Emerge Every Week
Black Kite Ransomware Report: New Threat Actors Emerge Every Week
Plus, FBI warns: Deepfake videos impersonating Internet Crime Complaint Center.

Good morning! Here’s what’s up.

People
Keith Wojcieszek has joined Prescient as managing director and head of the intelligence and risk advisory firm’s Washington D.C. office, where he leads its cyber threat intelligence practice and supports the Digital Forensics & Incident Response (DFIR) and cyber advisory teams. Wojcieszek previously was a senior managing director and led the cyber threat intelligence capabilities at FTI Consulting. He also brings experience from the U.S. Secret Service, where he led the Criminal Investigation Division’s cyber intelligence.
Andrew Pak has joined the cyber litigation practice team at Constangy as a partner, based in the firm’s Orange County, California office. Before joining Constangy, Pak was senior counsel at Perkins Coie. Earlier in his career, he served as senior counsel for the U.S. Department of Justice Computer Crime and Intellectual Property section.

Clips ✂️
A New Ransomware Threat Actor Emerges Every Week, Warns Report
More than one new ransomware group is appearing every week as the criminal ecosystem surrounding extortion attacks becomes increasingly more fragmented and continues to expand.
Published on July 21, the Black Kite Ransomware Report 2026 identified 146 active ransomware groups which have publicly announced at least one victim of an attack, as of June 2026.
The figure marks a significant increase compared to the number of ransomware groups marked as active a year earlier, when the figure stood at 105 ransomware operations.
According to the study, 2026 alone has seen the emergence of 61 new ransomware groups, the equivalent of more than one a week.
…
"Previous years were often defined by a dominant ransomware group or a single major event. This year was different,” said Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “We saw more groups enter the market, while established operators continued to scale and attack volume accelerated in the second half. Those shifts fundamentally changed the shape of the ransomware landscape."
FBI Warns of Deepfake Videos Impersonating IC3 Leadership
An FBI warning has flagged an escalation in the long-running scheme to impersonate the Bureau's Internet Crime Complaint Center (IC3), with scammers now deploying deepfake videos of senior FBI officials and spoofed IC3 websites to defraud previous fraud victims a second time.
A public service announcement issued on July 20 by the IC3 follows an April 2025 warning about the same core scheme.
Nick Tausek, lead security automation architect at security automation vendor Swimlane, said the scheme had become materially more polished since that earlier warning. What used to be text-only recovery pitches, he warned, now resembled "an official government process from start to finish."
The Bureau confirmed scammers have combined social media impersonation, generative AI video and lookalike complaint portals into a coordinated campaign.
Hackers steal customer data from major hospital software vendor
Hackers breached a major healthcare industry software supplier and stole a large trove of files, the company announced on Monday.
The British software firm Craneware, which makes software that helps companies track their financial performance and manage governance requirements, published a regulatory filing about “a cyber security incident involving unauthorised access to a subset of its data environment,” including the theft of “a significant volume” of files that included “employee data as well as a subset of customer and partner records.”
“The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data,” Craneware said, although it added that an investigation by internal IT staff and third-party cybersecurity firms was ongoing.
…
More than 2,000 healthcare organizations and nearly 10,000 clinics and retail pharmacies use Craneware’s product, according to its website, meaning that the breach could have a significant downstream impact on the U.S. healthcare sector.
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Cosmetics giant Estée Lauder has started notifying employees that their information was stolen from its Oracle E-Business Suite (EBS) instance last year.
The incident, the company says, occurred in early August 2025, when the infamous Cl0p cybercrime group started exploiting CVE-2025-61882, a zero-day vulnerability in Oracle EBS that enabled unauthenticated remote code execution (RCE), to exfiltrate data from numerous companies.
In November, more than 100 companies were listed on the Cl0p leak website, many of which confirmed being impacted by the campaign.
By March 2026, Broadcom, Bechtel, Estée Lauder, and Abbott Laboratories were the only major companies that had not disclosed the impact from the campaign. Cl0p leaked 870GB of archive files allegedly stolen from Estée Lauder.
Several days after the zero-day was patched in early October, CrowdStrike said it found evidence that the bug’s in-the-wild exploitation started on August 9, the same day that Estée Lauder was hit.
Big Tech AI Spree Revives Accounting Devices That Toppled Enron
Enron Corp. exploited US accounting rules to hide from investors and lenders hundreds of millions in debt it had bundled into off-balance sheet entities — obligations that contributed to one of the biggest corporate collapses in US history.
Twenty-five years later, new risks have emerged as some of the world’s most valuable companies create similar financing vehicles that can mask how much debt they’re taking on, as the technology industry looks to spend more than $3 trillion to power artificial intelligence systems.
Tech companies are leaning on these arrangements to package debt tied to billions in assets with an uncertain return — including chips, servers, and energy equipment — while spreading those risks among developers, vendors, and lenders. Substantial infrastructure costs tied up in the financing structures aren’t flowing through the parent company’s financial statements, offering unaware investors a rosier view of performance and leverage.
California’s Privacy Agency Audits Delivery, Ride-Share Apps
California’s privacy agency has launched its first-ever audit, looking into delivery and transportation apps’ compliance with state law.
The agency said Tuesday it is taking a closer look at gig economy platforms that collect personal data about users and workers. It’s examining how employees and consumers can exercise their rights to know what data is being collected, how it’s being used, and with whom it’s getting shared.
The sector is ripe for a compliance audit as platforms can use geolocation data, behavioral and performance metrics, biometric data, and communications records to make decisions about workers’ assignments, performance ratings, and earnings, CalPrivacy said.
“We are fortunate in California that we have jurisdiction over employee privacy,” Sabrina Ross, the agency’s chief privacy auditor, told Bloomberg Law. “We’re cognizant that employee monitoring technologies have evolved rapidly and that the amount of data employers are collecting is also changing in the age of AI.”
