Top news stories this week
- Not so clever. Claude AI faces scrutiny over privacy and safety lapses
- Lights! Camera! Contact information of celebrities exposed in film festival data leak
- Imposter syndrome. Criminals exploit ShinyHunters breach data in an extortion campaign
- Ctrl+Alt+Deceit. Hermes AI used to automate attack on Thailand's Ministry of Finance
- Pressure points. Water utilities and energy provider hit by cyber incidents
- Critical Condition. Data theft and malware-driven outages continue to pressure healthcare providers
1. Claude AI faces scrutiny over privacy and safety lapses
Claude AI’s privacy controls have come under scrutiny after user-shared chats became accessible through Google search. Claude users can create public URLs to share conversations with others, but due to improper indexing tags, some shared conversations became publicly searchable. The impacted Claude shared pages have since been removed from Google’s search results.
In a separate incident, Anthropic (owner of Claude AI) has disclosed that three of its AI models managed to escape a test environment, get online and breach systems of other companies.
So what?
Both incidents highlight the power of AI. Organisations to incorporate AI acceptable use practices into their broader privacy and security governance frameworks. Employees should be educated on the risks associated with sharing AI-generated conversations, especially those that contain personal data, client information or intellectual property.
[Researcher: Jack Woods]
2. Contact information of celebrities exposed in film festival data leak
Personal information of celebrities linked to the Tribeca Film Festival including Angelina Jolie, Robert DeNiro, and Jennifer Lawrence were observed as publicly available following the discovery of an exposed cloud database. The database associated with the New York film festival was found to hold over 660,000 records spanning across 2019 to 2026. The leaked materials included celebrity phone numbers, email addresses and technical information about the users devices.
So what?
The risk of being targeted in a social engineering attack is increased following the exposure of private information. S-RM’s dark web monitoring service supports organisations by proactively identifying where your data or brand appears across major cybercriminal ecosystems.
[Researcher: Adelaide Parker]
3. Criminals exploit ShinyHunters breach data in an extortion campaign
Cyber criminals are extorting individuals whose data was exposed in previous data breaches. While ShinyHunters hacking group denied any involvement in the campaign, the criminals appear to be leveraging data from multiple organisations previously leaked by ShinyHunters. The extortion emails falsely claim that victims' devices were compromised, that compromising videos were recorded, and demand USD $2,000 in Bitcoin to prevent their release.
So what?
Organisations that experienced data breaches by ShinyHunters should inform their customers about the exposed data in time, and inform them that threat actors may use previously leaked data to send convincing extortion, phishing or scam emails.
[Researcher: Milda Petraityte]
4. Hermes AI used to automate attack on Thailand's Ministry of Finance
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance, according to Hunt.io and researcher Bob Diachenko, who found exposed attacker directories with web shells, stolen credentials, and Hermes logs showing the agent used to escalate privileges and harvest internal files — no exfiltration confirmed, breach unverified by the ministry.
SO WHAT?
The barrier to running sophisticated multi-stage attacks is dropping — attackers now need only an objective and an unsupervised agent. This reinforces AI risk and a good moment to review approval requirements for any agentic AI in your own environment.
[Researcher: Winson Lee]
5. Water utilities and energy provider hit by cyber incidents
More than 30 community water systems across Minnesota were targeted in a coordinated cyberattack affecting operational technology (OT) used to manage water infrastructure. However, no impact on drinking water safety has been reported. Separately, Australian energy provider Origin Energy confirmed that approximately 900,000 current and former customers were affected by a data breach exposing personal information including names, addresses, dates of birth, phone numbers and customer account details.
So What?
As utilities and energy providers continue to digitise operations, organisations should expect further targeting both operational technology and customer-facing systems. Cyber incidents can disrupt operations, expose sensitive customer data, and erode public trust.
[Researcher: Gabriella Nolan]
6. Data theft and malware-driven outages continue to pressure healthcare providers
Medical billing provider MCBS disclosed that a 2025 cyberattack exposed the personal and health information of approximately 1.26 million individuals. The breach affected a range of sensitive data, highlighting the significant risk posed by third-party healthcare service providers that process large volumes of patient records.
Separately, US health system AnMed was forced to close clinics and imaging locations across South Carolina and Georgia following a malware-related cyber incident. While emergency services remained operational, the disruption impacted routine healthcare services and demonstrates the operational consequences cyberattacks can have on patient care.
SO WHAT?
These incidents illustrate the two primary cyber risks facing healthcare organisations: data breaches and operational disruption. Organisations should prioritise third-party risk management, cybersecurity resilience, and business continuity planning to reduce the impact of attacks on both patient data and healthcare services.
[Researcher: Jenny Eysert]
