
August closed out the summer of 2026 with yet more significant cybersecurity developments, from major breaches and ransomware campaigns to substantial federal action among several U.S. agencies. Healthcare saw some of the most attention this month, between a breach disclosure that grew more than tenfold and a federal warning that hospitals remain a preferred target, while the American government also sought to address the growing cyber threat landscape from multiple angles. SWK Technologies has put together this Cybersecurity News Recap to help you keep track of the biggest developments from August 2026 and what they mean for your business:
CareCloud Confirms Breach Exposed Almost 4M Patients
NJ-based healthcare IT solutions vendor CareCloud detected unauthorized access to one of its six electronic health record environments on March 16, 2026 and disclosed the incident to the Securities and Exchange Commission days later, describing an eight-hour disruption without naming a victim count. Notification letters filed with state attorneys general from late July claimed the records of potentially over 350,000 patients had been affected and a notice by the company claimed that intruder access was traced to an Amazon Web Services environment between March 10 and March 16.
However, a later filing with the Department of Health and Human Services on August 17 then listed over 3,750,000 affected individuals. Exposed records include Social Security numbers, dates of birth, driver’s license and government identification numbers, financial account details and health insurance information, but no ransomware group has claimed the attack as of this writing.
Hospitals Under Threat of Medusa Ransomware Says FBI
An updated joint advisory issued August 18 by the FBI, the Cybersecurity and Infrastructure Security Agency and the Department of Health and Human Services reports that Medusa ransomware actors reached more than 500 victims as of April 2026. That figure rises from the 300 recorded in the original March 2025 posting, with hospitals and healthcare systems being a frequent target alongside businesses in other industries such as manufacturing, technology, insurance, education and legal services. This includes the February attack on the University of Mississippi Medical Center, which closed clinics across the state for roughly nine days, took the Epic health record platform offline and drew an $800,000 demand that the group publicized in March.
Medusa affiliates weaponize newly announced exploits within 24 hours and investigators have observed the group using exploits as much as a week before the underlying vulnerability was publicly disclosed. The group first drew attention in 2023 with incidents that included publishing data from Minneapolis Public Schools after a $1 million demand and leaking files from Toyota Financial Services when an $8 million demand went unpaid.
Presidential Memo Allows Supervised Cyber Firms to Hit Hackers
President Trump signed a new National Security Presidential Memorandum (NSPM) on August 12, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directing the National Coordination Center to build a program authorizing vetted private contractors to act against foreign criminal groups. Participating companies may conduct Cyber Surveillance Operations and Cyber Effects Operations under Justice Department and Homeland Security oversight, though the memorandum’s writing bars outcomes causing death, serious injury or activity rising to armed attack under international law.
Veracode cofounder Chris Wysopal said the more organized structure would be helpful while cautioning about the collateral damage risks, former Cyber Command official Jason Kitka pointed out the lack of a clear process for protecting Americans’ civil rights or preventing private firms from creating threats for financial gain, and former CISA official Michael Garcia warned that pressure to attribute attacks quickly could lead a contractor to strike a foreign government by mistake. Private hack-back efforts have been debated for years without resolution, most visibly through the Active Cyber Defense Certainty Act, introduced in 2017 and reintroduced in 2019 to carve exceptions into the Computer Fraud and Abuse Act, which never passed.
DOJ Indicts Multiple Iranians for Cyber Attacks
Federal prosecutors unsealed a 14-count superseding indictment in Manhattan on August 18 charging 17 members of the Mabna Institute, an Iran-based company accused of running cyber intrusions for the Islamic Revolutionary Guard Corps since roughly 2013. Eight defendants join the nine charged in 2018, in a case spanning 144 American universities, 178 foreign universities, 42 U.S. companies, five federal and state agencies and at least 31.5 terabytes of stolen academic material.
Prosecutors say the group phished more than 100,000 professor accounts worldwide and compromised roughly 8,000 victims, reselling stolen journals and library access through two Iranian websites, with the State Department offering up to $10 million for information on five defendants. The charges land during an active conflict that has already produced Iran-linked attacks on American targets, including a destructive March intrusion at medical device maker Stryker and the Handala Hack Team’s breach of FBI Director Kash Patel’s personal email.
Cl0p Ransomware Claims Dozens of Victims from Summer Campaign
The Cl0p ransomware group has listed more than 40 organizations on its leak site as of August 19, 2026, as victims of a campaign against PTC’s Windchill and FlexPLM product lifecycle management platforms, naming Shell, Philips, General Electric, Fiserv, Zebra and Largan Precision among them. Attackers chained an information disclosure flaw in the FlexPLM web services endpoint with CVE-2026-12569, a critical unauthenticated remote code execution bug that PTC patched on June 17. Extortion messages began circulating between July 19 to July 20, sent from compromised accounts to employees at each targeted firm.
Philips has acknowledged a contained breach of one server with no customer impact, while Shell and General Electric say they are still investigating. The pattern repeats a method the gang has used since 2020 against Accellion, GoAnywhere, MOVEit and Cleo, with the 2023 MOVEit campaign alone reaching more than 2700 organizations and nearly 90 million people. Experts also point to the similarity in tactics seen in the PTC campaign as from the Oracle E-Business Suite (EBS) exploit hacks carried out in 2025.
Feds Say Siemens Devices Vulnerable Amid Iran Water Hacks
A joint advisory published August 19 by the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency describes active reconnaissance against Siemens S7 Series programmable logic controllers (PLCs) at water treatment, power and chemical plants. The FBI claims that the exploitation scripts were written using AI and disguised as monitoring tools, and the agencies advise operators to pull Internet-exposed PLCs offline while noting that targeting extends beyond Siemens hardware.
The advisory follows a wave of intrusions at water and wastewater utilities in at least 12 states between late July and August, including more than 30 Minnesota communities, with several utilities reverting to manual control and one Georgia authority issuing a boil-water notice. Federal officials have not formally attributed the campaign, though the tactics echo the IRGC-linked CyberAv3ngers, which defaced Unitronics controllers at the Municipal Water Authority of Aliquippa in November 2023 by exploiting default passwords.
Cyber Threats Continued Escalating in 2026
This August showed that cybersecurity is only becoming more complex and staying on top of emerging cyber threats only more challenging. Keeping track of which developments actually change your obligations and which simply make headlines, remains one of the harder demands on any internal IT team heading into the fall.
Contact SWK here to discuss what these developments mean for your business and how to strengthen your cyber defense for the rest of the year into 2027.
