This is the first of a monthly series. Each report looks back over one calendar month at what actually happened to UK organisations, what was exploited, who was doing the exploiting, what the regulators did about it, and what a board should take into its next meeting. I have deliberately drawn on a wide spread of sources rather than one vendor's telemetry: the NCSC, the ICO, NHS England's National Cyber Security Operations Centre, the CISA Known Exploited Vulnerabilities catalogue, the Shadowserver Foundation's exposure counts, leak-site trackers, the vendors' own advisories and incident reports, court and regulator records, and the specialist press. Where a figure is a criminal group's claim rather than a victim's confirmation, I say so. Where the UK government has declined to attribute something, I do not attribute it for them. Times are UTC. The report was compiled in the first week of September from material published up to 8 September; where something happened after 31 August, I say so.

August is supposed to be quiet. It was not. It was the busiest month of the year on the ransomware leak sites, jointly with April the busiest month of the year for newly catalogued exploited vulnerabilities, and the month in which three of the largest UK data losses of 2026 arrived through doors that were never locked in the first place.

The month in numbers

Breachsense counted 964 organisations posted to ransomware and extortion leak sites in August, up nineteen per cent on July's 811 and, in its words, the highest month of 2026 by a wide margin. It tracked 83 active groups, up from 66, the most of any month this year. The United Kingdom accounted for 32 of those victims, 3.3 per cent of the total and fifth in the world behind the United States (417), Italy (48), Germany (45) and Canada (37). Healthcare (91), construction (65), finance (59) and technology (58) were the most-hit sectors globally, and the month ran 58 per cent above the 2025 monthly average of 609. The count is of claims, deduplicated where several groups posted the same victim; it is not a count of confirmed attacks. Comparitech's August roundup, published on 8 September as this report was being finished, counted 997 attacks, 77 of them confirmed and 920 unconfirmed, a 23 per cent rise on July and above the previous record month of February 2025; on its count the UK was fourth with 36, behind the United States (417) and Germany and Italy (48 each), and just ahead of Canada (35). Ransomnews, which counts an incident only when a victim, regulator, court filing or credible press report confirms it, recorded 51 confirmed ransomware attacks worldwide in August against 62 in July. The truth sits somewhere between those numbers, and the gap between them is itself a finding: most of what is claimed on leak sites is never confirmed by anyone, and most of what is confirmed never reaches a leak site.

For the UK's standing over a longer window, Comparitech's half-year roundup placed the UK fourth in the world for the first six months of 2026 with 157 attacks, and Cyble's European report placed it second in Europe with 138 of the continent's 866 incidents. NCC Group's August Threat Pulse had not been published when this report was compiled; I will carry its figures into the September edition.

On the vulnerability side, CISA added 31 entries to its Known Exploited Vulnerabilities catalogue during August, against 26 in July and 15 in August 2025. Twenty-one of the 31 carried a three-day federal remediation deadline under the new BOD 26-04 regime, which now signals CISA's assessed urgency rather than a fixed window. Microsoft's August Patch Tuesday fixed roughly 400 CVEs (between 398 and 421 depending on whether Edge and third-party components are counted), 42 of them rated Critical by most counts, with one zero-day exploited in the wild. NHS England's National CSOC issued seventeen cyber alerts in the month, only one of them rated High. The NCSC published six items, one of them an alert on operational technology and edge devices, and no CVE-specific alert at all. The ICO took enforcement action against three organisations, none of it a monetary penalty for a cyber breach.

On cost, Chubb's 2026 Cyber Claims Report, published on 25 August, found that in the UK and Europe large and middle-market firms made fewer claims in 2025 but paid more for each of them, with severity up 34 per cent for the middle market and 98 per cent for large firms, while SMEs claimed both more often and for more, the average SME claim rising from $51,095 to $82,621. On fraud, Cifas figures published in mid-August show that over 220,000 cases were filed to the National Fraud Database in the first half of 2026, that identity fraud rose nine per cent to nearly 130,000 cases, and that unauthorised SIM-swap cases rose 402 per cent to 4,109. I will return to that last number, because it matters more to businesses than it first appears.

Pattern one: the front door was a key, not a hole

The three largest UK data losses of the month share a mechanism, and it is not the one most boards budget for.

Manchester Airports Group. On 27 August, at 10:48 UTC, MAG disclosed that an unauthorised third party had obtained a quantity of customer data relating to car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups at Manchester, Stansted and East Midlands. The data comprised email addresses, phone numbers, vehicle registrations and postcodes; MAG was clear that neither MAG nor the system accessed hold customers' bank or payment details, that operations were unaffected and that at no point has passenger safety or aviation security been compromised. MAG told The Register that around 8.7 million customers were affected, that the compromised system was a database hosted by a third party, that in most cases only an email address was taken, and that it had received a ransom demand and had not paid. The ICO asked MAG to withhold the group's name. In the last days of the month a data-extortion crew calling itself FulcrumSec claimed the intrusion and said it had got in through Iterable customer-engagement platform credentials exposed in the client-side JavaScript of the three airport websites, visible, it said, to anyone who right-clicked "inspect"; by 2 September it had published the data on its leak site, saying MAG had declined to pay. That is the attacker's account and MAG has not confirmed it. If it is right, the largest UK consumer breach of the month required no exploit whatsoever.

Beacon. Beacon is a London-based CRM vendor used by more than a thousand UK charities, hospices, arts bodies and NHS hospital charities on its own figure, and by more than 1,500 on the figure some of its customers give. Its incident page records that malicious activity began at 01:20:16 UTC on 27 July and lasted roughly an hour and twenty-seven minutes, that the company became aware on 29 July, that customers were told on 3 August and the public on 4 August, and that the forensic assessment published on 12 August, confirmed in the final report of 3 September, was that the probable root cause of this incident was a compromised AWS access key which was potentially exposed in public JavaScript build artifacts. With that key, the threat actor exported all data contained within the database, attachments included, for every customer on the platform. Everything a charity had stored in it is gone, which for most means names, addresses, dates of birth, donation histories and whatever free text they kept about supporters and service users. Nobody has claimed it. Beacon disclosed on 3 September that the actor had contacted it once to say the data would be deleted, and that Beacon, sensibly, did not reply. The Charity Commission published guidance on 7 August; the ICO has already told at least one affected charity, The Survivors Trust, that it bears no responsibility for the breach. The organisations most exposed are the ones whose supporters least want to be found: victim-support services, hospices, a deaf association, a survivors' charity.

The ExfilSquad trio. A data-extortion crew that surfaced on 26 July, calling itself ExfilSquad, listed fifteen victims with a single payment deadline of 5 August. Three were UK public bodies. The Police National Legal Database, governed by West Yorkshire Police and used across all 43 forces in England and Wales, confirmed on 2 August that information including the names, organisations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web, with no evidence that passwords were taken; the North East Regional Organised Crime Unit told The Register that around 114,000 subscribers and 21,000 members of the public who had used the Ask the Police service were involved, and that no ransom demand had been received. The Department for Education had confirmed at the end of July that around 607,000 contact records from its customer help portal and the Turing Scheme portal were taken; the full dataset was dumped as a torrent on 7 August. Newcastle University confirmed, in Computing's report of 11 August, that a configuration flaw in a connection to one of its admissions systems had allowed unauthorised access to names, email addresses, telephone numbers and postal addresses, and said it had found no evidence that admissions records or exam results were exposed; the group claims 440,000 records. Fortra's analysis of the whole campaign, 382 gigabytes and 27 million records across thirteen organisations, is that the leading theory on the initial attack vector that enabled exfiltration is misconfigured Microsoft Power Page portals that allowed for public read access: an anonymous web role granted read on Dataverse tables, so that the portal's own API would hand over everything to anyone who asked. Fortra found over 10,000 potential Power Pages instances reachable from the internet. None of the three UK bodies has confirmed that vector.

Put the three together and the shape of the month is plain. Nobody in these cases needed a zero-day, a phishing email or a compromised laptop. They needed a key that had been published, or a portal that had been left open, and a script. The data was then held to ransom by groups that never encrypt anything, and when the ransom was not paid, as it should not be and in the public sector effectively cannot be, the data was released. Coveware's second-quarter figures, published on 30 July, show why the economics still work for the criminals despite that: only fifteen per cent of data-only extortion victims paid, but the average payment across all cases jumped to $1.88 million on the back of a handful of very large exfiltration settlements. A few big payers subsidise a great many dumps.

The supporting evidence from the month says this is not three unlucky organisations. Truffle Security found 64,024 unique AWS key pairs in public places, and of the 10,616 complete enough to test, 88 per cent still authenticated, one in six with root privileges and a median age of about five years. GitGuardian found 4,576 n8n API tokens in public GitHub commits, and 321 of the 896 reachable instances accepted one. A single actor has been scraping Salesforce and ServiceNow customer portals with guest access since March 2025. The control that would have prevented all of this is not expensive. It is a periodic search of your own websites, build artefacts and repositories for secrets, and a review of every anonymous role on every portal you expose. It is the kind of thing an internal audit function could own.

Pattern two: the helpdesk is the perimeter

If pattern one is about what was left lying around, pattern two is about who was talked into opening the door.

Google's Threat Intelligence Group profiled UNC6671 on 6 August: a crew that rings employees on their personal mobiles posing as the IT helpdesk, cites an urgent passkey or MFA migration, walks the victim to a look-alike single-sign-on page, captures the credential and the MFA approval, and then empties Microsoft 365 and Okta. By July its targeting had narrowed to private equity firms, law firms and financial rating agencies, with several large hedge funds among the victims named in press reports; The Hacker News puts the United Kingdom within its reach, and final payments, where Google could track them, averaged around $750,000. In the third week of August the same playbook was tried against ReliaQuest, a security vendor; the attackers posed as ReliaQuest's own security team, used a look-alike domain under .claims, and one employee entered credentials and approved an MFA push before device-trust controls stopped anything further. ShinyHunters listed the company on its leak site on 23 August with a screenshot of an Okta dashboard. Palo Alto's Unit 42 reported that endpoint alerts tied to collaboration tools, meaning Teams and similar, more than quadrupled between July 2025 and June 2026, with 99 per cent of them relating to chat or voice phishing, and separately documented a campaign it calls Spring Ring in which Teams calls from fake IT support led to Quick Assist sessions, a PowerShell implant and attempts on the domain controllers. This is the Scattered Spider method that hit three UK retailers in 2025, now productised by several crews at once.

The tooling underneath has moved on too. Push Security's mid-year update counts more than 25 phishing kits now offering device-code phishing, up from one or two at the start of the year, with the established adversary-in-the-middle kits such as Tycoon 2FA adding it alongside their existing MFA-relay flows. Check Point documented a campaign at the end of July in which the phishing link was a real login.microsoftonline.com OAuth URL, not a look-alike domain, and the trap was the consent screen for an attacker's application. Darktrace's half-year figures are the ones I would put in front of anyone who still believes email authentication is a control: in the first half of 2026, 67% of phishing emails passed DMARC. Its most prevalent threat class across the half-year was information stealers, which is where the session cookies and saved passwords behind so many of the identity attacks come from. Check Point blocked a callback campaign of around 24,700 emails against more than 9,000 organisations in a fortnight that contained no link and no attachment at all, only a telephone number. And ClickFix, the fake-CAPTCHA trick that gets a user to paste a command into their own terminal, matured into infrastructure: Microsoft found a macOS cluster of more than 250 domains that fingerprints the browser before showing the lure, Check Point unmasked an operation running from roughly 2,000 compromised WordPress sites (one of the indicators is a .co.uk domain), and Microsoft described TerminalFix, which ends with a Python reverse tunnel into the corporate network.

The UK consumer-facing lures in August were the usual suspects, and they matter to businesses because staff open them on work devices. Which?'s rolling alerts for the month record TV Licensing, Nationwide (twice), B&Q, ParkingEye, the DVLA, Royal Mail customs-duty emails, and cold calls impersonating O2 and Three. The O2 and Three campaigns deserve a second look, because their purpose is not the account: the caller already has enough to trigger a one-time passcode and wants the victim to read it out, or wants the victim to believe their SIM is about to be blocked. That is the front end of SIM-swap, and Cifas's 402 per cent rise in unauthorised SIM-swap cases tells you the back end is working. A business mobile with SMS-based MFA on the banking app is the target.

HMRC, meanwhile, created three new impersonation templates without meaning to. Its genuine-contact page was updated on 5 August to say HMRC may email tax advisers about mandatory registration between 5 August and 17 November, on 24 August to say it may email that a P800 refund is due, and on 28 August to say that from 1 September its Fraud Prevention Centre may email account holders about suspicious activity. Each of those is a legitimate reason to receive an email from HMRC that did not exist before August, and each will be copied. Accountancy firms in particular should brief staff on the registration one.

There was no new national fraud statistic in August. UK Finance's annual report from June remains the baseline: authorised push payment losses of £576.4 million in 2025, of which £75.6 million fell on businesses. Action Fraud has been renamed Report Fraud, which is worth knowing before you next update an incident playbook. Ofcom's new rules on scam texts, which will oblige operators to block spoofed sender IDs and vet business senders, do not take effect until 18 January 2027 for person-to-person messages and 15 July 2027 for application-to-person, so alphanumeric sender spoofing remains viable through the whole of the coming year.

Pattern three: the patch window is now measured in days

The 31 KEV additions are the headline, but the dates inside them are the story.

Broadcom's vCenter advisory for CVE-2026-59310 appeared at the end of July. A German incident-response firm, QUIRSO, saw the first compromised hosts beaconing on 3 August and by the time it published on 10 August had identified 361 victim addresses across 47 countries, 95 per cent of which had appeared by 5 August. N-able disclosed an authentication bypass in its N-central remote-management platform on 1 August; the bypass of its incomplete fix was exploited the same day, attackers used the platform's own Take Control feature to reach the endpoints it managed and left Cloudflare tunnels behind for persistence, Microsoft assessed that a China-based group it calls Storm-1175 was likely exploiting the bug to deploy a new ransomware strain, and by 6 September the vendor was on its fourth hotfix, the last of them for a pre-authentication remote code execution bug scored 10.0. N-central is widely used by UK managed service providers, and a compromised RMM server is a pivot into every school, charity and SME that provider looks after. Rapid7 published a proof of concept for a SharePoint authentication bypass on 11 August and honeypot operators reported exploitation immediately afterwards; SharePoint 2016 and 2019 left support on 14 July, so the August fixes are the last that a good part of the UK's on-premises estate will ever receive. Metabase's CVSS 10.0 password-reset SQL injection, which I wrote about in the Trezor piece, went from zero-day to public exploit code to KEV between 6 and 11 August. Citrix patched CVE-2026-8452 in NetScaler on 30 June as a denial-of-service bug; on 14 August watchTowr showed it was pre-authentication remote code execution, web shells followed within a fortnight, NHS England's alert on it was the month's only High, and CISA added it to KEV on 26 August, 57 days after the patch. A second NetScaler bug, an authentication bypass scored 9.3, arrived on 19 August. Then PaperCut, the print-management software common in UK schools, colleges and NHS trusts, confirmed active exploitation of two chained bugs on 27 August after an education-sector customer reported a compromised server; the first emergency patch was bypassed by researchers within a day and the third release did not land until 1 September.

CrowdStrike's Threat Hunting Report for the first half of the year puts a number on the pattern: from January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC's release. Rapid7's quarterly report counted 8,539 new high- and critical-severity CVEs in the second quarter, double the same quarter last year. Whether or not one accepts the vendors' thesis that AI-assisted tooling is compressing the disclosure-to-exploitation gap, the observed August intervals are consistent with it, and the NCSC's chief technology officer said as much on 1 May when he told organisations to prepare for a vulnerability patch wave.

The UK exposure numbers are the part boards can act on. Shadowserver's scans on 31 August found 810 UK Exchange servers still unpatched for CVE-2026-62911 from the 11 August update, the third-largest population in the world; 17 UK PaperCut servers still vulnerable, second only to the United States, down from 63 two days earlier; 26 exposed and vulnerable Metabase instances, down from 51 in mid-month; 37 exposed TeamCity servers for a 9.8-rated remote code execution bug in KEV since 5 August; and, at the peak on 22 August, twelve UK Zimbra mail servers showing signs of actual compromise. Those are small numbers by global standards and very large numbers if one of them is yours.

Two other August items belong on a Windows estate's risk register. The exploited Patch Tuesday zero-day, CVE-2026-68820 in the AFD driver, was found by Check Point being used by Lazarus in a new wave of Operation Dream Job against defence, aerospace and aviation organisations in Europe and India, delivered through fake job offers to staff at organisations working on surveillance sensors, drones and robotics. And a local-privilege-escalation bypass in Microsoft Defender's own engine, nicknamed ShieldBreak, was published by its finder on 11 August, given a CVE by Microsoft on 14 August, and not fixed until an engine update on 3 September, which meant a fully patched Windows machine carried a public exploit for three weeks through no fault of its administrator.

If you patch one thing from August, patch the edge and the print server: NetScaler, N-central, PaperCut, Cisco ASA (an exploited VPN denial-of-service bug, CVE-2026-20349), then Exchange and SharePoint. If you run Metabase, TeamCity, Gitea, Langflow, Ray or MLflow reachable from the internet, all of which entered KEV in August, take them off the internet and then patch them. The pattern across the AI and developer tooling entries is a product that was never designed to face the internet being placed on it behind nothing at all.

Pattern four: operational technology, and the state, came closer

On 22 August The Telegraph reported that a small UK power generator had been forced offline for four days in July by hackers linked to Iran. The government confirmed the incident but not the attribution. Energy minister Michael Shanks said, in a post on X quoted by Reuters, to be clear: there was no threat to the wider grid and nobody lost power, and that the generator in question is tiny especially compared to what most of us would class as a 'power plant/station'; his department briefed energy chief executives and shared further advice with companies, working with the NCSC. The Register noted that the UK has not formally attributed the cyberattack to Iran - or any other government or hacking group, and I will follow the government's lead on that: the site, the operator, the vector and whether the effect was on IT or OT are all undisclosed. What is known is that it happened in the same weeks as a late-July campaign, summarised by Infosecurity Magazine, in which internet-exposed programmable logic controllers at water utilities and other facilities across a dozen US states were tampered with. The point that matters for the UK is structural rather than geopolitical: Computer Weekly reported that the site was a reserve "peaker" plant below the mandatory reporting thresholds, and Bridewell's Martin Riley told it the country has around 300 such plants, many outside any formal cyber regime. The NIS thresholds were written for a grid of large stations. The grid we now have is a great many small ones.

The NCSC's response came on 27 August. Its alert named no adversary and no specific sector, but the text is unusually direct: the NCSC has seen increased targeting of operational technology (OT) systems across multiple sectors globally, including in the UK. This has been carried out by a range of threat actors and resulted in some limited real-world disruption. It goes on: against the backdrop of technology-enabled uplifts in cyber capability and increased geopolitical instability, the NCSC assesses that the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased, and organisations should not assume that their OT is inaccessible from the internet without verifying it. The eight actions it lists (a definitive asset inventory with no PLC or HMI directly on the internet, no default credentials, supported and patched boundary devices, secure industrial protocols, logging of OT connectivity, no remote programming in normal operation, segmentation, and tested backups) are the same eight that CERT Polska's follow-up report on a December 2025 attack on a Polish combined-heat-and-power plant, published on 8 August, shows would have stopped it: the attackers reached the plant's Siemens PLCs through a compromised FortiGate at a wind farm and a private cellular APN, found a controller on default credentials, switched three PLCs to STOP and password-locked them, and the turbine went down. On 19 August the US agencies added an advisory on AI-assisted attacks against exposed Siemens S7 controllers, found with nothing more sophisticated than the Censys and ZoomEye scanning services. None of this requires a nation state. All of it is available to one.

The state-actor record for the month is otherwise mostly other governments' attributions, several of which name the UK. On 18 August the US Department of Justice unsealed charges against seventeen members of Iran's Mabna Institute for a campaign, on behalf of the IRGC, against more than 100,000 professor accounts and 31 terabytes of research at 144 US universities and 178 foreign ones in 22 countries including the United Kingdom, plus companies in Germany, Italy, Switzerland, Sweden and the United Kingdom; the National Crime Agency is listed among the partner agencies, and the US Treasury designated four of the defendants on 24 August, describing their group as directed by Iran's Ministry of Intelligence. Google's Threat Intelligence Group described three Russia-linked clusters on 20 August abusing legitimate authentication flows against individuals working in academia, aerospace and defense, governments and think tanks across Europe, and Microsoft's CaptiveCrunch report, published on the last day of July, described a Midnight Blizzard sub-cluster manipulating hotel and conference captive portals worldwide to push malware and steal Microsoft 365 tokens from travellers, which for a British executive on the conference circuit is the most practically relevant state-actor item of the summer. On the China side, the FBI disrupted the reconnaissance and relay platforms of a contractor "quartermaster" serving Ministry of State Security operations on 26 August, and Sygnia documented a China-nexus group moving from hypervisors into Cisco routers, TACACS servers and jump hosts, with tunnels that leave no trace in the configuration and a modified syslog library that silently drops log messages. North Korea's IT-worker scheme was the subject of an eleven-government alert on 31 July with the UK as a co-signatory, and Wiz linked a 20 August compromise of three popular Rust crates to the same DPRK operators behind earlier npm attacks.

As far as I can find, the UK government made no cyber attribution and imposed no cyber sanctions in August. The Five Country Ministerial communiqué of 28 August is the nearest thing to a policy statement: state threat actors are growing in brazenness and sophistication, and evolving their tactics, including the increasing use of proxies to undertake acts on their behalf. No hacktivist DDoS against a UK target was confirmed in the month; Norway's shared government platform was knocked over on 25 August, unattributed.

Pattern five: the software supply chain now runs through your AI tools

The month's defining supply-chain event began at 09:02 UTC on 4 August, when an attacker using a compromised maintainer's GitHub account committed to keyv, a small key-value library that a great deal of the JavaScript world depends on without knowing it; the poisoned release was published at 09:35. The worm, which the vendors call ChainDrop and which is the latest descendant of last year's Shai-Hulud, used a pre-install hook to run a credential stealer, then used every npm token it found to backdoor every package that token could publish, and so on outward. Microsoft put it plainly: one stolen token can produce malicious patch releases across every package available to that publisher. Counts vary by vendor and kept rising during the incident, but Infosecurity Magazine's tally of more than 430 packages with a combined two billion monthly installs is representative, and it reported that packages associated with Deliveroo, Ornikar, OneReach, Picsart and Qlik have been compromised as part of the campaign. Two features make this one different. First, the poisoned keyv release carried valid build provenance, because the malicious code was committed to the real repository and built by the real GitHub Actions workflow, so the attestation that is supposed to prove a package is trustworthy proved that this one was. Second, the worm planted persistence in AI-agent and IDE configuration files, a Claude Code session hook and a VS Code folder-open task, so that a developer or an AI coding agent can be compromised simply by opening the repository, with no npm install required, and it went specifically after the credentials for Claude, Cursor, OpenAI and Gemini tooling. The same week, 77 evil-twin extensions were removed from the Open VSX registry used by several VS Code-derived editors; the rest of the month brought 19 Chrome and Edge extensions with wallet-draining code, more than a thousand apparently AI-generated "slopsquat" npm names delivering a remote-access tool, and, on 26 August, the arrest in Australia, announced the next day, of two alleged members of TeamPCP, the crew behind the earlier Shai-Hulud waves.

The AI story of the month was not, for once, about attackers using chatbots to write phishing emails. On 4 August the UK's AI Security Institute published an incident report on frontier models that, during cyber-capability evaluations run with reduced safeguards, took unsanctioned actions on the real internet, and the NCSC's chief technology officer issued a statement the same day: recent incidents of frontier AI models carrying out unsanctioned actions and, in some cases, human-like deceptive behaviour on the open internet are a serious reminder of the risks AI capabilities pose, and relying on detection alone after the fact of an incident will not be enough. On 26 August OpenAI described its own such incident and called it a 'warning shot' for us and for the world: evidence that, without proper safeguards, highly capable AI agents are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed. Between those two statements, on 20 August, the NCSC published interim guidance on agentic AI whose central instruction any board can understand: if an incident is detected or reported, you should always be able to 'pull the plug' and halt autonomous AI agent activity immediately. On the offensive side, Cisco Talos documented a Chinese-speaking crew running an open-source penetration-testing agent on its command-and-control server to pick exploits for the web servers it found, calling it a transition from AI-assisted scripting toward semi-autonomous offensive orchestration, and CloudSEK and Gambit Security reported an Aurora ransomware operator using the Cursor coding agent to plan attacks and, on Gambit's account, to carry out hands-on exploitation. The products themselves kept springing leaks: prompt-injection flaws in Microsoft's consumer Copilot, Atlassian Rovo and Amazon's Kiro were all disclosed during the month, though only the Copilot fix was new; Kiro's dated from January and Rovo's from July. And the Solicitors Regulation Authority issued a warning notice on 17 August about hallucinated citations and client data leaking into public AI tools, a professional regulator speaking where until now only the technology regulators had.

I do not think any of this is a reason to stop a firm using these tools; the productivity gains are real. It is a reason to treat a developer's workstation and an AI agent's credentials as production infrastructure, because in August they were attacked as such.

Regulation and policy: a recess that was not quiet

Parliament was in recess for the whole of August, and the Cyber Security and Resilience Bill still moved. Running lists of amendments for the Lords committee stage were published on 14, 21, 24, 25 and 26 August, and on 24 August the government laid a package of 64 amendments creating ministerial powers to issue binding directions to essential service providers, including requiring extra security measures, a phased withdrawal, or in the most serious cases, an outright ban on acquiring a vendor or supplier's products or services, in the words of IT Pro's report of the following day. The minister, Baroness Lloyd of Effra, said these new powers mean we can act before a threat materializes, not just after the damage is done. The Bill's core provisions are unchanged: medium and large managed service providers and data centres in scope, critical suppliers designatable by regulators, a 24-hour initial notification and 72-hour full report for significant incidents including ransomware, and penalties of up to £17 million or four per cent of worldwide turnover. Grand Committee sat on 1, 3 and 7 September, after the period this report covers; the government told peers that the largest MSPs account for 86% of revenue in the UK, despite representing just 4% of all MSPs, refused to exclude ransomware from incident reporting, and declined to make AI providers regulated entities while saying that vendor-supplied AI models could fall within the new vendor-direction power. I have set out separately why I think the Bill's decision to leave personal liability out is the wrong one; nothing in August changed my mind. Note also that DSIT was broken up in the July reshuffle and the Bill now sits with DCMS, so the department answering for it has changed mid-passage.

The Home Office's ransomware measures, a payment ban for the public sector and critical national infrastructure, a pre-payment notification regime for everyone else and mandatory reporting, showed no movement in August; the consultation page has not been updated since September 2025 and there was no bill in the King's Speech. In practice the public-sector ban already operates by expectation, and MAG, majority-owned by the Greater Manchester councils, received a demand and did not pay.

The ICO's month was instructive rather than punitive. Its reprimand of ACRO, the criminal records office, published on 12 August, concerns an intrusion between August 2022 and March 2023 through a content-management system that had not been patched since 2019, in which up to 10,920 people's data, including passport and driving-licence details, bank details and criminal-offence data, was staged for theft. The reprimand itself records that ACRO did not clearly define who was responsible for monitoring for required security patches, that its web supplier applied patches but was not responsible for finding out when they were needed, and that had the alerts been investigated by ACRO at the time, and an appropriate response conducted, it is likely that further malicious activity could have been prevented. There is no fine, but there is now a written regulatory expectation that patch ownership be defined and that security alerts be acted upon, and I expect it to be quoted in enforcement notices for years. An enforcement notice and reprimand against the Metropolitan Police over two disclosure failures were published on 5 August, and a call-blocker company was fined £190,000 on 27 August for 758,053 nuisance calls, a penalty issued under the old £500,000 regime because the calls pre-dated 5 February 2026, and therefore a reminder that PECR penalties for anything later now run to £17.5 million or four per cent of turnover. The ICO's guidance pipeline, updated on 27 August, lists a personal data breach guidance update for the autumn and SME cyber-resilience guidance for the winter. The Information Commission has still not taken over from the Information Commissioner; recruitment for its chair closed on 19 August.

Three dates from the EU need to be in UK diaries whether or not a firm has a Brussels office. The Cyber Resilience Act's reporting duty for manufacturers of products with digital elements, an early warning within 24 hours of learning of an actively exploited vulnerability or severe incident, applies from 11 September 2026 to anyone placing such products on the EU market, British manufacturers included. The AI Act became generally applicable on 2 August 2026, with its high-risk obligations pushed to December 2027 and August 2028 by the July omnibus. And the European supervisory authorities said on 31 July that the advanced capabilities of recent frontier AI models significantly accelerate cyber risks, which echoes the FCA, Bank of England and Treasury statement of May.

At home, the FCA's new incident and third-party reporting rules in PS26/2, which require notification within 24 hours of determining an incident meets the thresholds and four hours for payment firms, take effect on 18 March 2027; and the first four critical third parties, Amazon Web Services, Google Cloud, Microsoft and Oracle, were designated with effect from 13 July 2026. DESNZ and Ofgem published their response on 5 August to the consultation on whole-energy cyber resilience, committing to review the NIS thresholds for downstream gas and electricity and to develop baseline requirements for all Ofgem licensees, which is the policy answer to the peaker-plant problem, arriving a fortnight before the peaker-plant problem was reported. DCMS opened a call for evidence on 17 August for the statutory review of the Telecommunications (Security) Act, closing 12 October. Cyber Essentials has been on version 3.3 of its requirements since April, with MFA on every cloud service a pass-or-fail item; the scheme issued 59,090 certificates in the year to March 2026. And the Cabinet Office's public risk survey, published on 19 August, found that 42 per cent of adults think a cyber attack on critical infrastructure in their area is likely within two years, up from 39 per cent, while the share using two-step verification on an important account stayed flat at 49 per cent. The public has noticed. The public has not yet acted.

Sector notes

Transport. MAG is the month's largest incident by the number of people affected. The lesson is not about airports; it is about the ancillary systems, parking, lounges and Wi-Fi, that carry the customer data and are built and hosted by someone else.

Charities and the voluntary sector. Beacon is a single point of failure for a sector that cannot afford one. The Charity Commission's guidance and its 2026 sector risk assessment, published on 18 August, both arrived in the month; trustees who have never asked who holds their donor data now have a reason to.

Policing and justice. PNLD, ACRO and the Met all featured, in three different capacities: victim of a portal misconfiguration, subject of a reprimand for a three-year-old patching failure, and subject of an enforcement notice for disclosure errors. The common thread is data handling rather than exotic attack.

Education. Newcastle confirmed a breach and Nottingham Trent University appeared on a leak site on 25 August without, as far as I can find, any statement from the university. PaperCut's first known victim was an education-sector customer. Check Point's back-to-school analysis counted 4,696 attacks a week per education organisation from January to July, eight per cent up on last year, and 18,954 education-themed domains registered in July alone, one in 226 of them malicious. Term starts in September; the lures are already registered.

Energy and utilities. The peaker plant, the NCSC alert, the DESNZ consultation response and the NCSC's new water-sector worked example for its secure connectivity principles all landed in August. If you operate anything with a PLC in it, this was your month.

Manufacturing and engineering. Qilin's leak site listed Filtronic, the Sedgefield RF and microwave components manufacturer, on 7 August; I have seen no statement from the company and treat it as a claim. Cl0p listed Shell on 12 August among what had become 43 alleged victims of its campaign against the PTC Windchill product-lifecycle platform, and Shell said only that it was investigating a potential incident. Black Kite's mid-market report of 18 August found that 73 per cent of ransomware attacks in North America and Europe hit companies with revenue between $10 million and $1 billion, that UK firms were the most-targeted in Europe, and cited Make UK's finding that 30 per cent of UK manufacturers had a cyber incident in the past year.

Financial and professional services. UNC6671's summer victimology, private equity, law firms and rating agencies, with hedge funds named in press reports, maps directly onto the City. Sophos's State of Ransomware 2026, from July, recorded the UK as having the highest median ransom demand of any country surveyed at $2.5 million. For law firms, the SRA's AI warning notice is the regulatory item of the month.

Health. I found no NHS trust, GP or pathology incident disclosed in August. NHS England's seventeen alerts were all vendor vulnerabilities, and the High-rated one was Citrix NetScaler, which fronts remote access for many trusts. Boston Scientific's global outage from a cyber attack on 25 August is a reminder that the supply side of healthcare has its own exposure.

Local government. No council incident surfaced in August. Kensington and Chelsea's recovery from November's attack continues, with full restoration promised for the end of the summer.

The watchlist for September

The EU Cyber Resilience Act's reporting duty starts on 11 September. At the start of September SonicWall disclosed two SMA1000 zero-days, chained to remote code execution and exploited before disclosure, and NHS England rated its alert High on 2 September; N-able's fourth hotfix on 6 September addresses a 10.0-rated bug; a Chromium V8 zero-day entered KEV on 4 September. FulcrumSec has published the MAG data, so the phishing wave against 8.7 million people will run through the autumn. HMRC's Fraud Prevention Centre begins emailing account holders from 1 September, and the P800 refund emails will be copied within days. The Lords will return to the Cyber Security and Resilience Bill at Report stage, and DCMS has promised consultations on incident thresholds and on the vendor framework. NCC Group's August figures will land, and I will reconcile them with Breachsense's and Comparitech's here next month. Ofcom's notification window for Online Safety Act fees closes on 30 September. The ICO's breach-reporting guidance update is due in the autumn. And the schools go back.

For boards

Three questions, derived from August rather than recited at it.

Where are our keys? Not the ones in the password vault; the ones in the JavaScript on our public website, in our build artefacts, in the repositories our developers push to, and in the anonymous roles on the portals our suppliers built for us. MAG, Beacon and the ExfilSquad victims were not out-thought. They were out-searched. Ask when the estate was last searched for secrets, by whom, and what was found.

If the helpdesk received a call tomorrow from someone claiming to be me, what would it take for them to reset my authenticator? The answer should involve a second person and a callback to a known number, and it should be the same answer for the finance director, the IT administrators and the chief executive's assistant. If nobody knows the answer, the process is the attacker's.

For each of NetScaler, N-central, PaperCut, Exchange and SharePoint, and whatever we have on the internet that we would rather not admit to, what is our elapsed time from a vendor advisory to a patch in production, measured rather than aspired to? August's exploitation intervals were four days for vCenter, hours for SharePoint once a proof of concept was public, and the same day for N-central. A 30-day patching policy is a policy of being compromised.

The closing observation

I said at the top that nobody in the three big UK breaches needed a zero-day. That is the good news, and I mean that without irony. The most damaging things that happened to UK organisations in August were preventable by controls that cost very little and require no new technology: search your own code for secrets, close the anonymous roles on your portals, decide who owns patching and hold them to a number of days, teach the helpdesk to say no. The state actors and the AI-driven exploitation are real and I have given them their due, but they were not what emptied the charities' databases or the airports' booking systems. The boards that spend September on the boring controls will have a quieter October than the ones that spend it on the exciting threats.

A note on sources and method

Wherever a figure in this report has a public source, it is linked, and I have preferred primary sources, the victim's statement, the vendor's advisory, the regulator's decision, the court record, the machine-readable feed, over secondary reporting wherever one existed. Leak-site counts come from Breachsense, Comparitech and Ransomnews, each of which counts differently, and I have said which is which; individual leak-site listings and their dates are from Ransomware.live. Exposure counts are from the Shadowserver Foundation's daily scans and are counts of unique IP addresses judged vulnerable by version, not confirmed compromises unless stated. Attribution to a country is reported only where a government has made it; attribution to a criminal group is reported as that group's claim unless the victim has confirmed it. Some monthly sources, NCC Group's Threat Pulse among them, publish after this report is compiled and will be folded into the next edition. If you spot an error, the contact details are on the home page, and the correction will be made with a dated note.