• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • X
  • Facebook
  • YouTube
  • LinkedIn
Screen Connect
Support
Customer Portal
Pay Online
SWK logo.

SWK Technologies

Software Solutions & Services

  • Accounting & ERP Software
      • Acumatica Cloud ERP
        • Overview
        • Construction
        • Distribution
        • Field Service
        • Financial Management
        • Manufacturing
        • Professional Services
        • Project Accounting
        • Retail-Commerce
      • Sage Intacct
        • Overview
        • Construction and Real Estate (CRE)
        • Distribution Operations for Sage Intacct
        • Financial Services
        • Healthcare
        • Manufacturing Operations for Sage Intacct
        • Nonprofits
        • Professional Services
        • Sage Intacct Payroll powered by ADP
      • Sage 100
        • Overview
        • Business Intelligence
        • Core Accounting & Financials
        • Distribution
        • Manufacturing
        • Payroll
        • Sage 100 Contractor
      • More Accounting Products
        • QuickBooks
        • Sage 50
        • Sage 300
        • Sage 500
        • Sage BusinessWorks
      • ERP Add-ons
        • ADP Workforce Now
        • Avalara
        • AvidXchange
        • BILL
        • BigCommerce
        • CIMCloud
        • Cloud Hosting
        • DataSelf
        • DocLink
        • Endpoint Automation Solutions
        • Fortis
        • FreightPOP
        • Lumber
        • Microsoft 365
        • Netstock
        • Quadient
        • Sage Fixed Assets
        • Sage HCM
        • Sage Intacct Payroll powered by ADP
        • Sage Supply Chain Intelligence
        • Savant WMS
        • ScanForce
        • Solver
        • SPS Commerce
        • Velixo
        • Workforce Go!
      • More ERP Add-ons
        • Azure
        • Crystal Reports
        • KnowledgeSync
        • Nuvei
        • Nectari
        • Ottimate
        • Pacejet
        • Planning Maestro
        • Sage CRM
        • Sage HRMS
        • Sage Intelligence
        • Service Pro
        • ShipStation
        • Shopify
        • Starship
        • Sugar CRM
        • Traild
      • Industries
        • Construction
        • Distribution
        • Financial Services
        • Healthcare
        • Manufacturing
        • Nonprofit
        • Professional Services
        • Retail
  • Managed Cloud Services
      • Managed IT Services
        • Managed Cloud Services
        • Network Assurance Core
        • Co-Managed IT
        • Email Hosting
        • IT Support
        • Microsoft 365 Services
        • Server Monitoring
        • Virtualization
      • Cybersecurity
          • CyberAssurance CORE™
          • Cybersecurity Solutions
          • Backup & Continuity
          • Compliance
          • Dark Web Monitoring
          • EDR
          • Encryption
          • MDR
          • MFA
          • Penetration Testing
          • Security Training
          • SOC
          • Spam & Virus Filtering
          • vCIO
          • Vulnerability Assessment
      • Cloud Services
        • Secure Cloud Hosting
        • Infrastructure-as-a-Service
        • Acumatica IaaS
      • Industries
        • Financial Services
        • Healthcare
        • Construction
      • Locations
          • Nationwide
          • Austin
          • California
          • Chicago
          • Minneapolis
          • New Jersey
          • New York
          • North Carolina
          • Philadelphia
          • Phoenix
          • San Diego
          • Seattle
  • Consulting & Implementation
    • Business Technology Consulting
    • eCommerce
    • Financing
    • Human Capital Management
    • Managed Cloud & IT Services
    • Partner Program
    • Software Development
    • Software Implementation
  • Resources
    • Help Desk
    • Blog Posts
    • Payments Portal
    • Webinars
    • YouTube Channels
    • Acumatica Resources
    • Sage Intacct Resources
    • Sage 100 Resources
    • IT Resource Pages
  • About
    • About SWK
    • Awards & Recognition
    • Life@SWK
    • Careers
    • Success Stories
    • SWK Gives
  • Contact
    • Contact Us
    • Support
    • Our Locations

SWK Cybersecurity News Recap August 2026

August 25, 2026 by Hector Bonilla

Home » Cybersecurity » SWK Cybersecurity News Recap August 2026

Wooden sign reading "AUGUST" between two gray stars, lying on rippled sand and surrounded by seven ridged cream shells.

August closed out the summer of 2026 with yet more significant cybersecurity developments, from major breaches and ransomware campaigns to substantial federal action among several U.S. agencies. Healthcare saw some of the most attention this month, between a breach disclosure that grew more than tenfold and a federal warning that hospitals remain a preferred target, while the American government also sought to address the growing cyber threat landscape from multiple angles. SWK Technologies has put together this Cybersecurity News Recap to help you keep track of the biggest developments from August 2026 and what they mean for your business:

CareCloud Confirms Breach Exposed Almost 4M Patients

NJ-based healthcare IT solutions vendor CareCloud detected unauthorized access to one of its six electronic health record environments on March 16, 2026 and disclosed the incident to the Securities and Exchange Commission days later, describing an eight-hour disruption without naming a victim count. Notification letters filed with state attorneys general from late July claimed the records of potentially over 350,000 patients had been affected and a notice by the company claimed that intruder access was traced to an Amazon Web Services environment between March 10 and March 16.

However, a later filing with the Department of Health and Human Services on August 17 then listed over 3,750,000 affected individuals. Exposed records include Social Security numbers, dates of birth, driver’s license and government identification numbers, financial account details and health insurance information, but no ransomware group has claimed the attack as of this writing.

Hospitals Under Threat of Medusa Ransomware Says FBI

An updated joint advisory issued August 18 by the FBI, the Cybersecurity and Infrastructure Security Agency and the Department of Health and Human Services reports that Medusa ransomware actors reached more than 500 victims as of April 2026. That figure rises from the 300 recorded in the original March 2025 posting, with hospitals and healthcare systems being a frequent target alongside businesses in other industries such as manufacturing, technology, insurance, education and legal services. This includes the February attack on the University of Mississippi Medical Center, which closed clinics across the state for roughly nine days, took the Epic health record platform offline and drew an $800,000 demand that the group publicized in March.

Medusa affiliates weaponize newly announced exploits within 24 hours and investigators have observed the group using exploits as much as a week before the underlying vulnerability was publicly disclosed. The group first drew attention in 2023 with incidents that included publishing data from Minneapolis Public Schools after a $1 million demand and leaking files from Toyota Financial Services when an $8 million demand went unpaid.

Presidential Memo Allows Supervised Cyber Firms to Hit Hackers

President Trump signed a new National Security Presidential Memorandum (NSPM) on August 12, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directing the National Coordination Center to build a program authorizing vetted private contractors to act against foreign criminal groups. Participating companies may conduct Cyber Surveillance Operations and Cyber Effects Operations under Justice Department and Homeland Security oversight, though the memorandum’s writing bars outcomes causing death, serious injury or activity rising to armed attack under international law.

Veracode cofounder Chris Wysopal said the more organized structure would be helpful while cautioning about the collateral damage risks, former Cyber Command official Jason Kitka pointed out the lack of a clear process for protecting Americans’ civil rights or preventing private firms from creating threats for financial gain, and former CISA official Michael Garcia warned that pressure to attribute attacks quickly could lead a contractor to strike a foreign government by mistake. Private hack-back efforts have been debated for years without resolution, most visibly through the Active Cyber Defense Certainty Act, introduced in 2017 and reintroduced in 2019 to carve exceptions into the Computer Fraud and Abuse Act, which never passed.

DOJ Indicts Multiple Iranians for Cyber Attacks

Federal prosecutors unsealed a 14-count superseding indictment in Manhattan on August 18 charging 17 members of the Mabna Institute, an Iran-based company accused of running cyber intrusions for the Islamic Revolutionary Guard Corps since roughly 2013. Eight defendants join the nine charged in 2018, in a case spanning 144 American universities, 178 foreign universities, 42 U.S. companies, five federal and state agencies and at least 31.5 terabytes of stolen academic material.

Prosecutors say the group phished more than 100,000 professor accounts worldwide and compromised roughly 8,000 victims, reselling stolen journals and library access through two Iranian websites, with the State Department offering up to $10 million for information on five defendants. The charges land during an active conflict that has already produced Iran-linked attacks on American targets, including a destructive March intrusion at medical device maker Stryker and the Handala Hack Team’s breach of FBI Director Kash Patel’s personal email.

Cl0p Ransomware Claims Dozens of Victims from Summer Campaign

The Cl0p ransomware group has listed more than 40 organizations on its leak site as of August 19, 2026, as victims of a campaign against PTC’s Windchill and FlexPLM product lifecycle management platforms, naming Shell, Philips, General Electric, Fiserv, Zebra and Largan Precision among them. Attackers chained an information disclosure flaw in the FlexPLM web services endpoint with CVE-2026-12569, a critical unauthenticated remote code execution bug that PTC patched on June 17. Extortion messages began circulating between July 19 to July 20, sent from compromised accounts to employees at each targeted firm.

Philips has acknowledged a contained breach of one server with no customer impact, while Shell and General Electric say they are still investigating. The pattern repeats a method the gang has used since 2020 against Accellion, GoAnywhere, MOVEit and Cleo, with the 2023 MOVEit campaign alone reaching more than 2700 organizations and nearly 90 million people. Experts also point to the similarity in tactics seen in the PTC campaign as from the Oracle E-Business Suite (EBS) exploit hacks carried out in 2025.

Feds Say Siemens Devices Vulnerable Amid Iran Water Hacks

A joint advisory published August 19 by the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency describes active reconnaissance against Siemens S7 Series programmable logic controllers (PLCs) at water treatment, power and chemical plants. The FBI claims that the exploitation scripts were written using AI and disguised as monitoring tools, and the agencies advise operators to pull Internet-exposed PLCs offline while noting that targeting extends beyond Siemens hardware.

The advisory follows a wave of intrusions at water and wastewater utilities in at least 12 states between late July and August, including more than 30 Minnesota communities, with several utilities reverting to manual control and one Georgia authority issuing a boil-water notice. Federal officials have not formally attributed the campaign, though the tactics echo the IRGC-linked CyberAv3ngers, which defaced Unitronics controllers at the Municipal Water Authority of Aliquippa in November 2023 by exploiting default passwords.

Cyber Threats Continued Escalating in 2026

This August showed that cybersecurity is only becoming more complex and staying on top of emerging cyber threats only more challenging. Keeping track of which developments actually change your obligations and which simply make headlines, remains one of the harder demands on any internal IT team heading into the fall.

Contact SWK here to discuss what these developments mean for your business and how to strengthen your cyber defense for the rest of the year into 2027.

Contact Us Here:

Category: Cybersecurity, IT Services, News and Events

Sidebar

Recent Posts

  • SWK Cybersecurity News Recap August 2026
  • Sage Intacct Construction vs. Trimble Vista
  • HIPAA IT Compliance Guidance for Multi-Site Rehab Facilities
  • The $1.5M Commodity Blind Spot in Your Standard Cost System
  • SWK Technologies Named a ChannelPro Partner in Excellence Award Winner
  • Migrate Sage 100 Before Your Server Runs Out of Support
  • Why Your Bakery ERP’s Lot Trace Takes Three Days (And Costs More)

Categories

Ready to take the next step?

Contact SWK today to get in touch with one of our experts. We’ll go over your business challenges and unique needs, and see where you can unlock new value from your technology and make your operations run easier.

Get in touch!

Our Latest Posts

Wooden sign reading "AUGUST" between two gray stars, lying on rippled sand and surrounded by seven ridged cream shells.

SWK Cybersecurity News Recap August 2026

Read moreSWK Cybersecurity News Recap August 2026
Sage Intacct Construction vs. Trimble Vista comparison

Sage Intacct Construction vs. Trimble Vista

Read moreSage Intacct Construction vs. Trimble Vista
Cropped view of a person in a white coat with a stethoscope holding a pen over a printed medical history form on a black clipboard, with another person's hands resting on the wooden desk opposite.

HIPAA IT Compliance Guidance for Multi-Site Rehab Facilities

Read moreHIPAA IT Compliance Guidance for Multi-Site Rehab Facilities

Awards and Accreditations

Top work places in NJ 2020.
Acumatica the Cloud ERP gold certified partner.
The Gold Microsoft partner logo on a black background.
Sage business partner diamond logo.
Dell Technologies Gold Partner
Sage tech partner logo.

Stay in the know!

Subscribe for exclusive ERP, process automation, IT and cybersecurity news.

Twitter
  • Facebook
  • YouTube
  • LinkedIn

Home
About
Contact

Support
Screen Connect
Pay Online
Downloads

SWK logo.

Headquarters:
120 Eagle Rock Ave, Suite 330
East Hanover, NJ 07936

Contact:
info@swktech.com
(877) 979-5462

Copyright © 2026 · SWK Technologies, Inc. · All Rights Reserved · Terms of Use · Privacy Policy

This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. By continuing to browse this site you agree to the use of cookies. Visit our privacy policy to learn more.