Security Report – 21 Aug 2026

Phishing Is the Leading Entry Point for Cyberattacks

Security Report – 21 Aug 2026

Cyberattacks often succeed because of exposed systems, weak access controls, poor network segmentation, and inadequate monitoring. These vulnerabilities create opportunities for cyberattacks to infiltrate an organisation’s environment, gain unauthorised access, and move laterally across networks. Many cyberattacks begin by exploiting internet-facing systems or compromised credentials, allowing attackers to bypass traditional security controls and establish a foothold within the organisation. Once inside, cyberattacks can disrupt operations, steal sensitive data, encrypt critical systems, and significantly impact business continuity.

The increasing sophistication and frequency of cyberattacks mean that organisations can no longer rely on a single security control to protect their environment. Effective defence against cyberattacks requires a layered security approach that reduces both the likelihood and impact of a security incident. This includes restricting unnecessary internet exposure, implementing multi-factor authentication, enforcing strong password policies, and ensuring privileged access is tightly controlled to minimise opportunities for cyberattacks.

Robust network segmentation is also essential, as it helps contain cyberattacks and prevents attackers from easily accessing critical systems if a breach occurs. Regular patching and vulnerability management reduce the number of weaknesses that can be exploited by cyberattacks, while continuous monitoring and threat detection capabilities improve the ability to identify and respond to cyberattacks before significant damage occurs.

In addition, organisations should maintain secure, isolated, and regularly tested backups to ensure recovery from ransomware and other damaging cyberattacks. A well-developed and regularly tested incident response plan enables teams to act quickly and decisively when cyberattacks occur, reducing downtime and limiting business impact. Ultimately, the key lesson from recent cyberattacks is that proactive, layered security controls, combined with ongoing vigilance and preparedness, are essential to protecting modern organisations from evolving cyber threats and increasingly sophisticated cyberattacks.

Recent Breaches

United States – U.S. water utilities –Government & Public Sectors 

Exploit: Hacking

Risk to Business: Moderate: The Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) have warned that hackers are breaking into internet-connected programmable logic controllers (PLCs) at water utilities, disrupting operations across multiple facilities in several U.S. states. Without disclosing the full scope of the attacks or identifying all affected states, the FBI and EPA said in a joint statement that multiple incidents had occurred. According to the agencies, attackers remotely accessed internet-connected control systems, changed administrator passwords and caused operational disruptions, including flooding and pressure loss, which could allow untreated groundwater to seep into water pipes. Meanwhile, Minnesota and Michigan have confirmed attacks on several of their water facilities. The warning comes just days after federal agencies updated an advisory on ongoing Iranian cyberthreats targeting U.S. critical infrastructure. However, investigators have not publicly linked the latest attacks on water utilities to Iran.

United States – Omnicell – Health care 

Exploit: Ransomware & Malware

Risk to Business: Moderate: Several dark web monitoring sites are reporting that California-based health care technology company Omnicell has been named as the recent victim of a data breach. According to posts by the Everest ransomware group, the attackers stole 1 TB of data from Omnicell, a provider of medication management and pharmacy automation systems used by health care organisations worldwide. The group claims the stolen archive includes source code, SQL databases, credentials, firmware, deployment packages and other sensitive assets. However, neither Omnicell nor independent cybersecurity researchers have confirmed the alleged breach, and no public proof of the stolen data has been released. If the claims prove to be accurate, this will mark the second major cybersecurity incident affecting Omnicell in recent years. In 2022, the company suffered a ransomware attack that disrupted some of its products, services and internal systems.

Talk to a TCT team member today about automation for your business.