Cyber Cookie mascotCyber Cookie
Menu ▾
← LatestIssue #72August 24, 2026

Iran Took Down a UK Power Plant for Four Days

A social engineering attack hit Apollo Global Management — a $1 trillion private equity firm — and made off with names, contact details, and Social Security numbers. Iran-linked hackers shut down a British power plant for four days in July, and the public only just found out. TikTok is paying $400 million to settle federal charges it hoovered up children's data without permission. Check your credit reports today.

Breach of the Day

A $1 Trillion Firm, a Phone Call, and a Stolen Identity File

Apollo Global Management — a private equity firm that manages roughly $1.05 trillion in assets — has disclosed that attackers accessed its cloud systems between 6 and 10 July, according to Security Week. What they walked away with: names, contact details, and Social Security numbers belonging to an undisclosed number of people.

The method was social engineering (manipulating real employees into handing over access — no lock-picking required). Specifically, the attackers posed as IT helpdesk staff in phone-based vishing (voice phishing) calls, convincing someone on the inside to open a door that should have stayed closed.

The group behind it is tracked as UNC6671 / BlackFile, a cybercrime operation that emerged in early 2026 and has already collected over $10 million in Bitcoin ransom payments since January. Apollo appears to be the only confirmed successful breach so far. Other major firms — Blackstone, KKR, Citadel, and others — were targeted but say they detected and blocked the attempts.

Apollo says there is no evidence the stolen data has been published or used for fraud, and is offering affected people identity protection and credit monitoring services.

If you receive a letter from Apollo, accept the free credit monitoring without hesitation. Everyone else: if anyone calls claiming to be from your company's IT team and asks you to confirm credentials or grant remote access, call them back on the official number before doing anything.

Emerging Threats

Iran Turned Off a British Power Plant — and Nobody Said Anything for Weeks

Iran-linked hackers shut down a UK power plant for four days in July 2026. The story only became public on 22 August, reported first by The Telegraph, with the BBC, Guardian, and Financial Times following shortly after. Official sources have said almost nothing.

The plant was not large — the grid held — but security researchers are not treating this as a minor footnote. The real concern is not what was taken offline, but how long it stayed offline and what that signals. Iranian cyber groups have already hit water systems, critical infrastructure, and military-linked targets across the US, Israel, and several Gulf states. The UK has now been added to that list.

Smaller facilities are often less well-defended than major ones, and attackers looking for weaknesses in a country's energy system do not need to hit the biggest target first.

If you work in or around operational technology, utilities, or critical infrastructure, now is the time to ask whether your recovery plans have actually been tested — not just written down.

Vulnerability Watch

No notable new vulnerability disclosed in the last 48 hours. The Vulnerability Watch article provided contained no CVE — it was a general opinion piece on application security practices rather than a disclosure.

Defender's Corner

Anthropic Is Giving Defenders Access to Its Most Powerful AI — Here Is What That Means for You

Anthropic — the company behind the Claude family of AI models — has expanded a programme called Project Glasswing, which gives security teams access to its most capable AI model, Mythos 5, according to Security Week. It has also launched a $35 million fund to help open source projects find and fix vulnerabilities.

For most readers, the practical takeaway is this: Claude Security, available now in public beta for Claude Enterprise users, can scan your codebase, flag vulnerabilities with severity ratings, and suggest fixes — with a human required to approve anything before it deploys.

If your organisation uses Claude Enterprise, check whether Claude Security is enabled for your team. If you maintain open source software, the Defender Advantage Fund (0xDAF) is worth looking into for grant support.

Compliance Pulse

TikTok Pays $400 Million Over Children's Privacy Violations

TikTok has settled a US Department of Justice lawsuit for $400 million, resolving allegations it collected personal data from children under 13 without parental consent — and ignored parent requests to delete those accounts, according to Security Week. The case was brought under COPPA (the Children's Online Privacy Protection Act), the federal law requiring parental consent before collecting data from young children. If your child uses TikTok, review their account settings and check what data the app holds. You have the right to request deletion.

Four hundred million dollars and they still didn't delete the accounts.

Cyber Cookie is AI-assisted. Always verify critical information with official sources before acting.