This Fortnight in Cyber Incidents August 2025

Date range: 7–20 August 2025

Cyber incidents continue to cut across sectors — from telecoms and hospitality to defence and pharma. Here are the most significant cases reported in the past two weeks, what happened, and why it matters.

1) Workday: social engineering leads to CRM data exposure

Date reported: 15–20 Aug
What happened: Attackers posed as HR or IT and tricked staff at a supplier, gaining access to a third-party CRM platform. Workday says customer tenant data was not touched, but contact details were exposed.
Why it matters: Confirms the current wave of CRM-targeted phishing and malicious OAuth abuse linked to ShinyHunters. Tighten supplier access, OAuth governance and vishing response playbooks.

2) UK telco Colt Technology Services hit by ransomware (WarLock)

Date reported: 15–18 Aug
What happened: Colt took some business systems offline after a “cyber incident.” WarLock claimed the attack and advertised a trove of internal documents for sale. Customer core networks were not reported as affected.
Why it matters: Telecoms remain high-value infrastructure targets. Review patching on internet-facing apps and segregate support systems.

3) Australia: iiNet (TPG Telecom) breach exposes customer data

Date reported: 19–20 Aug
What happened: Stolen employee credentials were used to access an order management system. Exposed data includes c. 280k email addresses, c. 20k landline numbers, about 10k usernames with addresses and phone numbers, and c. 1,700 modem setup passwords. No ID docs or payment data.
Why it matters: Classic credential-theft and third-party system risk; good case for hardening helpdesk and identity flows.

4) Italy: hotel guests’ passport and ID scans advertised on forums

Date reported: 14–18 Aug
What happened: A criminal posted tens of thousands of high-resolution ID scans allegedly taken from at least ten hotels. Italy’s digital agency (AGID) validated the finding and warned of fraud risks.
Why it matters: Hospitality frequently stores ID imagery; tighten data retention, storage, and access controls.

5) UK MoD-linked contractor breach affects Afghan resettlement data

Date reported: 16 Aug
What happened: Inflite The Jet Centre (a subcontractor) confirmed unauthorised access to email accounts. About 3,700 individuals — including Afghans resettled in the UK and some UK personnel — may be affected.
Why it matters: Highly sensitive personal data at a supplier increases safety, legal, and reputational risk. Strengthen supplier email security and incident handling.

6) Inotiv (pharma): ransomware disrupts operations

Date reported: 20 Aug (attack on 8 Aug)
What happened: Inotiv disclosed a ransomware incident that encrypted internal systems and hit business operations; SEC notified.
Why it matters: Ongoing healthcare and life-sciences targeting; validate backups, EDR coverage and tabletop exercises.

7) Allianz Life: breach impact clarified to ~1.1m customers

Date reported: 18–20 Aug (incident in July)
What happened: Have I Been Pwned and multiple outlets reported the breach impacted about 1.1m US customers, with contact and personal details leaked; Allianz offering monitoring.
Why it matters: Part of the wider Salesforce-targeted campaign; reinforces third-party and CRM hardening.

What this means for you

  • Third-party and CRM risk is the theme. Enforce least-privilege, app-to-app OAuth reviews, and continuous vendor access monitoring.
  • Vishing and MFA fatigue work. Train people to challenge unusual phone or text prompts and route verification via approved channels.
  • Identity-rich stores are magnets. Minimise and encrypt stored IDs, set short retention, and monitor for exfiltration.

Take action with Cyber Protection UK and Security Awareness Agency

We help you stay out of the headlines with:

  • AI-powered email and CRM protection to stop social engineering and malicious OAuth access
  • Security awareness and phishing drills that actually change behaviour
  • Vulnerability and exposure management across internet-facing apps and suppliers
  • Incident response readiness with playbooks, tabletops and rapid support

Enquire with us to better protect your organisation and prevent your organisation from making headlines.

USEFUL LINKS
SERVICES
CONTACT US