2026-07-10
- ransomware
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 published analysis of The Gentlemen ransomware operations and its affiliate model structure that has enabled rapid expansion. The report examines how the group's business model has driven its growth in the threat landscape.
Why it matters: Organizations targeted by Gentlemen affiliates need to understand this group's operational structure and recruitment tactics to assess ransomware risk and inform incident response planning.
- vulnerabilities
Friday Squid Blogging: “Squidbleed” Vulnerability
A vulnerability in Squid proxy, unpatched for 29 years, can leak HTTP requests. The issue combines software security with the blog's traditional squid-themed content.
Why it matters: Web infrastructure operators using legacy or unpatched Squid deployments face exposure of HTTP request data; prioritize testing and patching to prevent information disclosure.
- regulatory
Europe revives law allowing big tech to scan for CSAM
The European Parliament approved Chat Control 2.0, legislation that authorizes major technology companies including Google, Meta, and Microsoft to scan user messages for child sexual abuse material (CSAM). The law enables automated detection systems to identify and report such content to authorities.
Why it matters: Organizations providing messaging and communication services across the EU must prepare technical scanning capabilities and compliance processes to meet the new legal mandate for CSAM detection.
- government policy
Jen Ellis: Connecting Cyber Community With Political Machinery
This article profiles Jen Ellis, who recently received an MBE honor. The piece examines the events and advocacy work that led to her recognition within the security research community.
Why it matters: Security practitioners should understand how advocates shape policy conversations and industry direction, particularly those building bridges between technical expertise and political influence.
- ransomware
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
A 34-year-old Armenian national pleaded guilty to hacking U.S. companies and deploying Ryuk ransomware to encrypt their systems. The defendant faces up to 15 years in prison as part of a U.S. prosecution. This case represents a law enforcement action against a member of the ransomware-as-a-service operation.
Why it matters: Organizations targeted by Ryuk should review incident response procedures and threat intelligence on this gang's current infrastructure, while security teams can assess whether this prosecution impacts ongoing threats from the group.
- breaches incidents
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package that impersonated legitimate telemetry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised package version @injectivelabs/sdk-ts@1.20.21 was distributed through the npm registry to affect users of the SDK.
Why it matters: Developers and cryptocurrency users relying on Injective Labs SDK are at immediate risk of wallet compromise; review npm package versions and rotate any affected keys or seed phrases.
- ransomware
Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence
A Ryuk ransomware operator pleaded guilty to conspiracy and computer fraud in Oregon federal court, while a separate defendant received a 70-month federal prison sentence in Florida for assisting the Blackcat/AlphV ransomware gang in extortion campaigns against multiple victims.
Why it matters: Practitioners should track these cases as examples of law enforcement action against major ransomware operations; organizations hit by Ryuk or Blackcat/AlphV may benefit from following the judicial outcomes and evidence disclosed.
- threat intel
Cybercriminals Flock to Healthcare Businesses as Attacks Surge
Cyberattacks against hospitals and clinics increased modestly in the first half of 2026, while attacks targeting healthcare service providers and related businesses more than doubled during the same period.
Why it matters: Healthcare IT teams and service providers face accelerating threat pressure; practitioners should prioritize monitoring and incident response readiness given the rapid shift in attacker focus to administrative and support functions.
- government policy
License plate cameras may be next target after Supreme Court reins in location tracking
The Supreme Court's recent restrictions on location tracking may extend to automatic license plate recognition (ALPR) systems, potentially requiring warrants for ALPR searches. Such a requirement would significantly constrain how law enforcement agencies deploy these camera networks in routine policing.
Why it matters: Law enforcement, privacy advocates, and legal teams should monitor how courts apply location tracking precedent to ALPR systems, as warrant requirements could reshape surveillance capabilities and investigative workflows.
- breaches incidents
Progress urges ShareFile customers to shut down servers over "credible" threat
Progress Software has urged ShareFile customers using Storage Zone Controllers to immediately shut down their servers due to identification of a credible external security threat targeting the on-premises file sharing solution. The company issued the directive via email to affected customers but has not disclosed specific details about the nature or scope of the threat.
Why it matters: ShareFile Storage Zone Controller deployments are at immediate risk; organizations running this software should assess their exposure and follow Progress guidance to determine if they are affected and whether shutdown is necessary.
- government policy
Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative
Microsoft's Secure Future Initiative July 2026 progress report details advances across three areas: strengthening security foundations through identity controls and asset management, deploying AI-driven proactive defense to detect vulnerabilities faster than manual methods, and preparing for future threats such as quantum computing. The initiative emphasizes that durable security foundations require continuous validation rather than periodic audits, and demonstrates results including 99.97% phishing-resistant multifactor authentication coverage and remediation of over 550,000 critical and high-risk open-source vulnerabilities.
Why it matters: Security practitioners should review Microsoft's architectural approach to composite attack paths and layered controls, as the patterns (identity feeds access governance, access governance feeds segmentation) apply across any enterprise environment; the report's emphasis on continuous validation over periodic auditing challenges traditional compliance models.
- vulnerabilities
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Binarly researchers discovered six vulnerabilities in U-Boot, the bootloader used across diverse hardware including routers, smart cameras, and data-center management chips. Four flaws enable denial of service through device crashes, while two allow code execution at boot time if an attacker can provide a malicious image to the bootloader.
Why it matters: Device manufacturers and firmware maintainers relying on U-Boot across IoT, networking, and data-center infrastructure must patch these flaws to prevent remote code execution and service disruptions in production environments.
- breaches incidents
Money launderer accused of stealing seized crypto while in prison
A Bulgarian national, currently incarcerated for money laundering related to fraud, has been charged with stealing $290,000 in government-seized cryptocurrency. The alleged theft occurred while the individual was serving a 121-month sentence for helping launder millions of dollars from American fraud victims.
Why it matters: Law enforcement and asset management teams overseeing seized crypto holdings need to strengthen access controls and audit procedures, as this case demonstrates that even imprisoned individuals can access and steal government custody assets.
- ransomware
In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
This news roundup mentions several security stories: a breach of a Department of Homeland Security database, Adobe increasing its patch release frequency, and Canadian authorities disrupting ransomware operations. The article also references a lawsuit between Abnormal AI and Anthropic, a data breach affecting 7 million AssuranceAmerica customers, and the NSA reactivating its Tailored Access Operations unit.
Why it matters: DHS database exposure affects government security posture; Adobe's faster patching helps practitioners reduce vulnerability windows; AssuranceAmerica customers face identity theft risk; the Canadian ransomware disruption signals law enforcement action but the NSA reactivation raises questions about surveillance scope.
- vulnerabilities
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
Researchers at Ledger's Donjon security team demonstrated a laser-based attack that can reset passwords on Tangem cryptocurrency wallet cards by targeting the embedded chip. Once the password is reset, an attacker gains control of the wallet and can transfer the stored cryptocurrency. The attack requires precise timing and physical access to the card hardware.
Why it matters: Tangem wallet card users face a permanent vulnerability that cannot be patched: physical possession of the card is the only defense against an attacker with laser equipment, making hardware-based crypto wallets potentially less secure than previously assumed.
- vulnerabilities
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
A researcher has disclosed three patched vulnerabilities in the OpenClaw personal AI assistant that could have enabled credential theft, privilege escalation, and arbitrary code execution on affected systems. The flaws, rated high severity, have been addressed by the vendor.
Why it matters: Users and administrators running OpenClaw should verify they have applied all available patches to prevent potential compromise of credentials and system control.
- identity access
The Replicant in Your Directory: AI Agents and the Identity Security Gap
AI agents are proliferating non-human identities within enterprise environments, creating complexity in asset discovery and access management. Organizations struggle to maintain visibility over these identities and track their permissions, expanding the potential attack surface. Identity governance becomes increasingly critical as AI adoption accelerates.
Why it matters: Security teams and identity administrators must establish governance frameworks for non-human identities to prevent unauthorized access and reduce exposure from untracked AI agents and service accounts.
- vulnerabilitiesCVE-2026-47291
CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys
A remote code execution vulnerability exists in Windows HTTP.sys, the kernel-mode HTTP protocol driver used by Internet Information Services (IIS). The flaw stems from an integer overflow in buffer reference array handling during HTTP/1.x header parsing, allowing unauthenticated attackers to send crafted HTTP packets to achieve denial-of-service or kernel-level code execution.
Why it matters: Organizations running IIS or applications using HTTP.sys must verify that systems are patched; this vulnerability allows remote code execution with kernel privileges without authentication, making it critical for any exposed HTTP/HTTPS services.
- vulnerabilities
Fresh ATM Crypto Software Bugs: Jackpot or Bust?
Security researchers have identified vulnerabilities in a Microsoft BitLocker security wrapper that could expose organizations and ATM systems to compromise. The specific technical details and attack vectors are not elaborated in the available information.
Why it matters: Organizations operating ATMs and other systems relying on BitLocker protection need to assess their exposure to these holes and apply patches or workarounds to prevent attackers from bypassing disk encryption protections.
- government policy
More Countries Jump on the Social Media Ban Wagon
Multiple countries are implementing age restrictions and social media bans, though compliance efforts by technology companies are proving difficult to execute effectively. Industry observers note that current restrictions may function as temporary measures rather than comprehensive solutions to concerns about youth social media use.
Why it matters: Compliance officers and policy teams should monitor emerging age verification and content restriction requirements across jurisdictions, as regulatory fragmentation will require platform-specific implementations and potential business model adjustments.
- threat intel
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
Silver Fox, a China-linked cybercrime group, has deployed a new Rust-based remote access trojan called MODBEACON that uses gRPC streaming to encrypt command-and-control traffic. The group distributes malware through counterfeit installers and SEO poisoning despite appearing as a low-sophistication operation.
Why it matters: Organizations targeted by SEO poisoning and counterfeit software downloads face infection with a difficult-to-detect RAT; monitor for gRPC-based C2 traffic and validate software authenticity before installation.
- ai security
AI Coding: Do Security Risks Outweigh Productivity Gains?
AI coding tools offer productivity improvements but introduce hidden security and operational costs through required scanning, remediation efforts, and false positive management. Organizations must evaluate whether the $19 to $200 monthly per-user expense justifies both the security overhead and the productivity benefits.
Why it matters: Development teams and security leaders adopting AI coding assistants need to account for the true cost of ownership, including security testing and remediation workflows, when budgeting and assessing ROI on these tools.
- identity access
Incode brings on-device processing to age estimation for privacy-focused verification
Incode has released an on-device age estimation feature that processes facial analysis for age verification directly on a user's device without transmitting facial data to external servers. The offering includes liveness detection and spoofing resistance, addressing growing regulatory requirements for age assurance across more than 30 jurisdictions worldwide.
Why it matters: Organizations subject to age verification laws (including the UK Online Safety Act) need privacy-respecting verification solutions; on-device processing reduces data exposure and compliance risk while maintaining effectiveness against deepfakes.
- vulnerabilitiesCVE-2026-48939CVE-2026-56291
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two file upload vulnerabilities (CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms) to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. These vulnerabilities allow unrestricted uploads of dangerous file types and represent a common attack vector. Federal agencies must prioritize patching under Binding Operational Directive 26-04, which requires rapid remediation of high-risk KEV Catalog vulnerabilities on publicly exposed assets.
Why it matters: Federal agencies must treat these two vulnerabilities as critical priorities for remediation on exposed systems; organizations running iCagenda or Balbooa Forms should verify whether these file upload flaws have been exploited before patching and conduct incident investigation if compromise occurred.
- threat intel
China, India-Linked Hackers Both Targeted Same Pakistani Police Force
Security researchers at SentinelOne identified that both China-linked and India-linked hacking groups have targeted Pakistan's Balochistan Police force over a period of at least two years. The simultaneous targeting of the same Pakistani law enforcement agency by adversaries reflects broader regional cyber espionage activity.
Why it matters: Organizations in South Asia managing law enforcement systems need to assess whether they face similar multi-nation-state targeting and review their detection capabilities for advanced persistent threats from multiple threat actors.
- vulnerabilities
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A vulnerability in XQUIC, Alibaba's QUIC and HTTP/3 library, allows unauthenticated remote clients to crash servers with legitimate traffic of approximately 260 bytes. The flaw, disclosed by FoxIO researcher Sébastien Féry and nicknamed XRING, stems from a single incorrect variable assignment and currently has no patch available.
Why it matters: Organizations running XQUIC-based HTTP/3 servers face denial of service risk from any network client; teams should identify affected deployments and assess alternative QUIC implementations or network mitigations until a patch is released.
- vulnerabilities
Zimbra urges customers to patch critical web client XSS flaw
Zimbra has advised customers to patch a critical cross-site scripting (XSS) vulnerability in its Classic Web Client component of the Zimbra Collaboration suite. The flaw could allow attackers to execute malicious scripts in users' browsers and compromise email accounts and data.
Why it matters: Organizations running Zimbra Collaboration are at immediate risk of account compromise and data theft if they do not apply the patch; administrators should prioritize this update.
- research
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
Lumen Technologies expanded its asset inventory from 17,000 to 1.1 million assets by consolidating and improving exposure management capabilities. The article references survey data showing that only 45 percent of organizations consolidate asset and exposure data into a single view, and notes that inaccurate inventories cascade through downstream security programs.
Why it matters: Security leaders managing asset inventory and exposure programs need to understand that fragmented asset data undermines all downstream controls; Lumen's scale demonstrates the gap between assumed and actual asset visibility.
- threat intel
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A misconfigured server belonging to a cybercrime group was left publicly accessible for three weeks, exposing hacking tools, activity logs, and a target list of over 1.4 million websites. The exposure revealed operational details of a mass site-hacking campaign, though the actual number of compromised sites was significantly smaller than the target list. Researchers were able to analyze the backdoor tool (WP-SHELLSTORM) and understand the group's infrastructure and tactics.
Why it matters: WordPress site operators and hosting providers need to assess whether their domains appear in the exposed target list and patch known vulnerabilities to prevent backdoor installation, while security teams should monitor for indicators of compromise from this operation.
- research
AI Surveillance and Social Progress
AI-powered surveillance systems combining facial recognition, real-time tracking, and automated enforcement are being deployed globally to monitor public behavior and issue immediate sanctions for rule violations. China operates over 600 million surveillance cameras integrated with social credit systems that publicly shame and restrict citizens deemed untrustworthy, while similar systems are being tested in North America, Europe, and other regions. The technology's primary impact may be widespread self-censorship and behavioral conformity rather than objective public safety.
Why it matters: Security and privacy practitioners need to understand how AI surveillance infrastructure affects threat modeling, insider risk, authentication systems, and the regulatory landscape around monitoring and data retention in their organizations.
- research
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Researchers tested 281 popular free Android VPN apps and found basic security failures in many, including traffic leaks, unencrypted data handling, and user tracking. The affected apps have been installed over 2.4 billion times. The vulnerabilities identified represent fundamental failures of VPN functionality rather than sophisticated attacks.
Why it matters: Android users relying on free VPNs for privacy are exposed to data leakage and tracking; security teams should audit VPN recommendations and educate users about app selection risks.
- threat intel
GigaWiper Combines Multiple Malware for System-Level Sabotage
GigaWiper is a backdoor combining multiple malicious capabilities including a standalone wiper, ransomware encryption, and multi-pass wiping commands designed for system-level sabotage. The malware combines destructive techniques that can both encrypt and completely erase victim systems. Organizations face exposure to coordinated data extortion and system destruction attacks.
Why it matters: Practitioners should understand this multi-stage threat combines encryption and wiping tactics, requiring detection strategies that identify both ransomware behavior and destructive wiping activities before execution.
- threat intel
"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?
A phishing campaign used an unusually large HTML attachment with embedded comments to evade AI-based email security detection. The attachment, disguised as a credential-stealing document with a double extension (.xls.html), was 2.6 megabytes instead of the typical tens to hundreds of kilobytes for HTML phishing pages, suggesting the extra size was intentionally added obfuscation. The phishing email itself showed signs of being generated by a homemade script, including missing date headers, an empty envelope sender, and invalid priority values that bypassed standard email authentication checks.
Why it matters: Email security practitioners and AI model developers need to understand how attackers are adapting to AI-based detection by padding malicious attachments with obfuscation techniques, which may reduce the effectiveness of content-based filtering and require new detection strategies.
- vulnerabilities
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
Security firm Coinspect disclosed a vulnerability called Ill Bloom affecting cryptocurrency wallet software that generates recovery phrases with weak randomness, allowing attackers to derive wallet credentials and steal funds. Attackers have already exploited the flaw in at least one coordinated attack that drained $3.1 million from affected wallets.
Why it matters: Cryptocurrency users and wallet providers need to immediately audit recovery phrase generation in their software and migrate funds from affected wallets to those with cryptographically secure randomness implementation.
- ai security
‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
Researchers have identified a technique called HalluSquatting that exploits AI model hallucinations to deliver botnets through remote code execution on popular AI assistants. This attack leverages the tendency of AI systems to generate plausible but false information, using it as a vector for malicious payload delivery.
Why it matters: Organizations and users relying on AI assistants face a new supply chain attack vector where hallucinated code or instructions can be weaponized for bot infection; security teams should assess their AI assistant usage and consider isolation measures for sensitive operations.
- threat intel
Network of 200 GitHub Repositories Used for Malware Infection
A network of approximately 200 GitHub repositories is being exploited to distribute Windows malware through a Go module that loads PowerShell code and retrieves payloads from dead drops. This abuse of GitHub's infrastructure demonstrates how legitimate code hosting platforms can be weaponized for malware delivery at scale.
Why it matters: Windows developers and DevOps teams need to audit their GitHub dependencies and code supply chains immediately, as malicious repositories can masquerade as legitimate packages and compromise build pipelines and systems.
- ai security
Workato expands Agent Studio with Headless API, AI guardrails
Workato announced two new features for Agent Studio: Headless API for embedding AI agents (Genies) into applications on web, mobile, or other agents, and Agent Guardrails for configurable security controls. These additions enable broader deployment of AI agents while enforcing data privacy policies, identity tracking, and compliance requirements.
Why it matters: Organizations using Workato AI agents need to understand these deployment and governance options to safely integrate agents into production environments while maintaining audit trails and policy enforcement.
- research
The open source library holding up your stack might have one maintainer
A new research paper examines how open source libraries vary dramatically in their maintenance models and governance, from well-resourced projects to those maintained by a single person in spare time. Despite carrying the same label, these differences can significantly affect the behavior and security posture of software that depends on them.
Why it matters: Development teams need to assess the maintenance status and resource levels of open source dependencies to understand the risk of supply chain vulnerabilities, unpatched flaws, and abandonment that could affect their own products and customers.
- regulatory
Most data brokers won’t tell you what happened to your deletion request
UC Irvine researchers tested deletion requests with California's data broker registry to understand compliance. The study found that most data brokers fail to provide confirmation or transparency about what happened to consumer deletion and sales-stop requests.
Why it matters: California residents and other practitioners should know that exercising statutory deletion rights against data brokers may not result in verifiable action, limiting the practical value of privacy regulations without enforcement.
- vulnerabilities
Microsoft is rewriting Windows patch guidance because of AI
Microsoft is advising organizations to accelerate Windows update deployment timelines because artificial intelligence is enabling attackers to identify and exploit vulnerabilities more quickly after patches are released. The company recommends shortening the period between patch release and deployment, particularly for critical security updates on systems where faster rollouts are operationally feasible.
Why it matters: Windows administrators and security teams need to reassess their patch deployment windows now, as AI-accelerated vulnerability analysis means the traditional weeks-long grace period between patch release and active exploitation is shrinking.
- threat intel
Turning software supply chain security into a daily habit
Anastasia Tikhonova from Group-IB discusses operationalizing software supply chain risk by using Software Bill of Materials (SBOMs) as active tools rather than static compliance documents. SBOMs should be integrated into daily security workflows including vulnerability triage, vendor access reviews, identity monitoring, and incident response, while recognizing how supply chain attacks increasingly connect phishing, ransomware, and data breaches through inherited trust relationships.
Why it matters: Security practitioners need to shift SBOMs from compliance artifacts to operational tools to detect and respond to supply chain risks that threaten their organization through trusted vendors and dependencies.
- cloud saas
AWS gives its ERP agent deny-by-default rules and a separate identity
AWS has released enhancements to its ERP agent that include deny-by-default authorization rules and a separate identity mechanism. These improvements aim to address security concerns while allowing the agent to automate exception handling in enterprise resource planning workflows across finance operations.
Why it matters: Finance and operations teams using AWS ERP agents need to evaluate the security posture of agentic automation; deny-by-default rules and separate identities reduce the risk of unauthorized transactions or data access in sensitive financial processes.
- identity access
Only 28% of financial workforce MFA is phishing-resistant
A Secret Double Octopus report found that only 28% of multifactor authentication (MFA) deployments in financial organizations use phishing-resistant methods, with most relying on passwords combined with one-time passwords (OTP) that remain vulnerable to credential theft and phishing attacks. Financial institutions continue to mix legacy authentication approaches with more secure technologies, leaving significant portions of their workforce exposed to identity-based threats.
Why it matters: Financial services practitioners need to accelerate migration to phishing-resistant MFA (such as FIDO2) across their workforce, as the majority still depend on vulnerable password-plus-OTP combinations that create actionable targets for attackers seeking account compromise and lateral movement.
- industry
New infosec products of the week: July 10, 2026
A weekly roundup of security product releases including Codenotary's AgentMon 3, an AI security platform with adaptive runtime policies that evolve based on observed AI agent behavior and workflows. The article briefly mentions releases from Attestiv, Automox, and First Recon AI but provides minimal details on most products.
Why it matters: Security teams evaluating new tools for AI agent monitoring and runtime protection should review these emerging products to assess fit for their infrastructure and threat model.
- threat intel
Risky Bulletin: India bans app used to hack e-rickshaws in viral videos
The Indian government ordered Apple and Google to remove a battery management app that was weaponized to remotely disable electric rickshaws in a viral social media trend called the Tirri Challenge. Videos documented the attacks, which stranded drivers and caused traffic disruptions across the country over a two to three week period.
Why it matters: Mobile app stores and platform operators need to monitor for misuse of seemingly benign applications in coordinated attack trends, and governments are moving quickly to intervene when public transport and livelihoods are at risk.
- threat intel
ISC Stormcast For Friday, July 10th, 2026
This is a podcast episode announcement from the SANS Internet Storm Center that provides daily cybersecurity news and updates.
Why it matters: Practitioners should check the ISC Stormcast feed daily for curated threat intelligence, vulnerability updates, and incident summaries relevant to their defensive operations.
- breaches incidents
Dutch police trace Odido telco cyberattack to suspected local accomplice
Dutch law enforcement identified evidence pointing to local criminals as accomplices in the cyberattack on telecom provider Odido that compromised personal data of over 6 million customers in 2024. The investigation suggests the breach involved both external attackers and domestic criminal involvement.
Why it matters: Telecom subscribers and Odido customers need to understand that domestic criminal networks may have facilitated access to their exposed personal data, potentially increasing fraud and identity theft risks beyond typical breach scenarios.