Cyber Cookie mascotCyber Cookie
Menu ▾
← LatestIssue #75August 26, 2026

Paylogix Breach Exposes Health and Payroll Data

Employee benefits firm Paylogix lost the Social Security numbers, medical records, and financial data of tens of thousands of people to the Akira ransomware gang. A Zimbra email server flaw is being actively exploited and carries a CISA three-day patch deadline — if you run Zimbra, stop reading and go patch. WhatsApp has also quietly upgraded its account security, and the new features are worth switching on today.

Breach of the Day

Paylogix Ransomware Attack Exposes Health, Financial, and Identity Data

Paylogix — a New York-based company that manages employee benefits, payroll, and insurance administration on behalf of employers — disclosed this month that hackers stole sensitive files from its network over five days in November, according to The Record.

The stolen data includes Social Security numbers, passport numbers, taxpayer IDs, electronic signatures, financial account details, health insurance records, and medical data. The type of information Paylogix handles is about as sensitive as it gets — the company sits at the centre of payroll systems for many of its clients, which means a single breach touches a wide range of employees across multiple organisations.

Paylogix appeared on the leak site of the Akira ransomware gang in January. Akira is a prolific operation: Google's incident response team ranked it the second most observed ransomware family in 2025, and the FBI estimates the group has collected over $244 million in ransom payments.

At least 67,789 people across South Carolina, New Hampshire, and Vermont have been confirmed affected. Breach notices have also been filed in California, Massachusetts, New Jersey, and several other states — the true total is likely higher. Several law firms are already organising class action lawsuits.

What to do: If you receive a data breach notification from Paylogix, or from your employer, take it seriously. Place a credit freeze with all three major bureaus (Equifax, Experian, TransUnion) — it is free and prevents anyone opening new credit in your name. Monitor your health insurance statements for unfamiliar claims, which is a common but overlooked form of identity fraud.

Emerging Threats

Hidden Text in Emails Can Fool AI Summarisers Into Lying to You

Researchers at Forcepoint X-Labs have demonstrated that AI-powered email summarisers can be manipulated using a technique called indirect prompt injection (where hidden instructions embedded in content hijack an AI's behaviour). The method uses invisible HTML — white text on a white background. It is readable by the AI but invisible to any human looking at the email.

In tests against an Outlook-based summariser, the injection succeeded all ten out of ten times. A summary showing an invoice total of €46,200 was generated from an original email that clearly stated €8,750. The recipient would have seen nothing unusual.

The risk grows significantly with agentic AI tools — assistants that can also send emails or schedule meetings on your behalf. If you rely on AI to summarise your inbox, treat any summary involving money, deadlines, or access requests as worth a second look at the original.

Vulnerability Watch

CVE-2026-73570 — Zimbra Collaboration Suite (versions prior to v10.1.20)

What Zimbra Collaboration Suite is: A widely used platform that combines email, calendar, contacts, and file sharing — common in government agencies, universities, and mid-to-large businesses.

What it is: A critical remote code execution (RCE — where an attacker can run their own commands on your server without physical access) flaw triggered through Zimbra's SNMP notification processing. SNMP (Simple Network Management Protocol) is a standard used to monitor and manage networked devices. The vulnerability requires no login credentials to exploit.

Who's at risk: Any organisation running Zimbra Collaboration Suite with SNMP notifications enabled — which is the default configuration in affected versions. Federal agencies were given until 24 August to patch or stop using the product.

CVSS: Not confirmed in the source — treat as Critical based on CISA's three-day remediation deadline and confirmed active exploitation.

Root cause: Zimbra fails to properly sanitise (clean and validate) untrusted input received during SNMP notification processing. Think of it like a form that accepts any text without checking whether it contains commands — an attacker can slip instructions through the front door disguised as ordinary data.

Attack vector: An unauthenticated attacker sends a specially crafted SMTP request to a vulnerable Zimbra server. Because the input is not sanitised before being processed, the server executes the attacker's embedded commands with Zimbra-level system privileges. No account, credentials, or social engineering required — just a network path to the server.

Recommended actions:

  1. Upgrade to Zimbra Collaboration Suite v10.1.20 immediately — this is the patched release.
  2. If patching is not immediately possible, disable SNMP notifications as a temporary mitigation.
  3. Treat any previously exposed server as a potential incident: review logs for anomalous SMTP traffic and check for signs of persistence installed before the patch.

Zimbra Collaboration Suite (versions prior to v10.1.20)

A widely used platform that combines email, calendar, contacts, and file sharing — common in government agencies, universities, and mid-to-large businesses.

Defender's Corner

WhatsApp Just Upgraded Its Account Security — Turn It On

WhatsApp has rolled out several security improvements worth enabling now, according to Security Week.

Two-step verification (2SV — a second layer of protection beyond your SIM card) has been upgraded from a six-digit PIN to a full password that can include letters, numbers, and special characters. Longer and more complex is better. Go to Settings → Account → Two-step verification and update yours.

Passkeys (a login method that replaces passwords with a cryptographic key stored on your device) can now be added in multiples, which is useful if you switch between iOS and Android. Android users also get a new caller context feature that shows the country and any shared group membership for unknown callers — a quiet but useful tool against number-spoofing scammers.

Compliance Pulse

CISA: Over 100 Water Systems Hit in July, Linked to Iranian Threat Actors

CISA has confirmed that more than 100 internet-exposed water and wastewater systems were targeted in cyberattacks in July 2026, according to Security Week. The attacks, linked to Iranian threat actors, focused on programmable logic controllers (PLCs — the computers that physically operate industrial equipment) connected directly to the public internet via cellular modems. At least 12 states were affected, though no significant disruption occurred. CISA has published updated guidance urging water utilities to remove unnecessary internet exposure, enforce multi-factor authentication, and monitor industrial control systems continuously.

The invoice said €46,200. The email said €8,750. One of those was written by an attacker. Read the original.

Cyber Cookie is AI-assisted. Always verify critical information with official sources before acting.