14 Aug Security Report – 14 Aug 2026
Microsoft’s growing ecosystem of services such as Microsoft 365, Azure, Entra, Intune and Defender provides powerful business capabilities but also introduces significant security challenges, including increased complexity, fragmented visibility, identity-based attacks, security misconfigurations, cloud workload risks, and gaps in data protection and governance. As organisations adopt more interconnected Microsoft services, maintaining consistent security controls and detecting threats becomes more difficult. Security is a shared responsibility, with organisations responsible for protecting their users, identities, data and configurations. Without a proactive security and cyber resilience strategy, these challenges can create security blind spots that increase the risk of unauthorised access, data breaches, and business disruption. Recommended best practices include enforcing multi-factor authentication (MFA), implementing Conditional Access and least-privilege access, adopting Zero Trust principles, continuously monitoring identities and cloud resources, regularly reviewing configurations to reduce security drift, and maintaining tested backup and recovery solutions to ensure cyber resilience and rapid recovery from incidents.
Recent Breaches
Australia – Origin Energy – Energy & Natural Resources
Exploit: Hacking
Risk to Business: Moderate: Sydney-based energy provider Origin Energy believes the information of approximately 0.9 million current and former customers was accessed during a recent data security breach. Origin Energy, one of Australia’s largest energy providers, supplies electricity, fossil gas, LPG and internet services to more than 4.8 million homes and businesses. The company said it first became aware of a potential security threat in early July but initially did not believe it was credible. After an initial review, Origin now estimates that a significant proportion of the approximately 900,000 affected individuals are former customers and says those impacted will be notified in the coming days. According to Origin, the compromised information may include customers’ names, addresses, dates of birth, phone numbers and account information, as well as the last four digits of credit cards or the last three digits of bank account numbers.
United States – DentaQuest – Health care
Exploit: Ransomware & Malware
Risk to Business: Moderate: The May 2026 ransomware attack on DentaQuest, one of the largest dental and vision benefits administrators in the U.S., has now been confirmed to have affected 15 million individuals. The incident first came to light on May 20, and DentaQuest’s investigation determined that attackers had access to the organisation’s network between May 17 and May 20. The victim count, now published on the Oregon Attorney General’s data breach reporting website, is almost six times higher than the number initially claimed by the ShinyHunters extortion gang. In May, the group published 234 GB of DentaQuest data on its dark web leak site, claiming it related to 2.6 million individuals. The incident now ranks as the largest health care data breach reported so far in 2026 and the fourth largest among nearly 7,900 HIPAA data breaches reported since federal regulators began tracking such incidents in September 2009.
Talk to a TCT team member today about automation for your business.
Robert Brown
14/8/2026
Related Articles:
Build Cybersecurity Supply Chain Resilience
Are Passkeys Safer Than Passwords?