San Mateo, CA, August 18, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
Dark web markets sell government email accounts for $40
Abnormal AI researchers found cybercriminals selling access to active law enforcement and government email accounts from agencies in the U.S., U.K., India, Brazil, and Germany. In some cases, email accounts are sold for as little as $40. Listings include FBI.gov addresses and provide full SMTP/POP3/IMAP credentials, enabling immediate malicious use. “Cybercriminals are no longer just reselling access,” reads Abnormal AI’s report. “They’re actively marketing specific use cases, such as submitting fraudulent subpoenas or bypassing verification procedures for social platforms and cloud providers. This commoditization of institutional trust has broadened the appeal of these accounts and lowered the barrier to entry for impersonation-based attacks … these are active, trusted inboxes that attackers have compromised for immediate malicious use.” Read more.
Russian hackers tied to U.S. federal court breach
The New York Times reports that Russia is “at least in part responsible” for the recent breach of the U.S. federal court filing system PACER, citing anonymous sources. Hackers allegedly targeted midlevel criminal cases in New York City and other jurisdictions, focusing on individuals with Russian and Eastern European surnames. Politico previously revealed the attack may have exposed sealed dockets, indictments, arrest warrants, and the identities of confidential informants, putting them at risk. The Administrative Office of the U.S. Courts confirmed the August 7 cyberattack, calling it an “URGENT MATTER.” This follows a 2020 SolarWinds-linked breach by Russian hackers that also impacted PACER. Officials are enhancing system security and working to mitigate risks to litigants. Read more.
Hackers turn the tables on North Korea’s Kimsuky group
North Korea’s state-sponsored hacking group Kimsuky has reportedly been breached by two hackers, “Saber” and “cyb0rg,” who oppose the group’s politically driven and regime-serving operations. In a statement published in Phrack during DEF CON 33, they accused Kimsuky of greed and moral corruption, releasing 8.9GB of stolen internal data via Distributed Denial of Secrets. The dump includes phishing logs targeting South Korean government domains, the full source code for the Ministry of Foreign Affairs’ email platform, citizen certificate references, phishing kits, malware loaders, and VPN purchase records. While some details were previously known, the leak connects Kimsuky’s tools, infrastructure, and campaigns, potentially disrupting active operations despite likely limited long-term impact. Read more.
Google tightens rules for crypto apps with licensing mandate
Google is rolling out a policy requiring developers of cryptocurrency exchanges and custodial wallets to obtain government licenses before releasing apps in 15 jurisdictions, including the U.S., U.K., EU, Canada, Japan, and South Korea. Non-custodial wallets are excluded. Developers must hold relevant registrations, such as FCA, FinCEN, or MiCA CASP authorizations, and declare their app type in Google Play’s Financial Features Declaration. Those without proper licensing must remove their apps from restricted markets. The move follows an FBI alert on scams targeting victims of crypto fraud, where criminals impersonate lawyers or agencies to offer fake fund recovery services. Between February 2023 and 2024, victims lost over $9.9 million in such schemes. Read more.
Convicted REvil affiliate links Kremlin to Kaseya attack
At DEF CON 33, researchers Jon DiMaggio and John Fokker shared new claims from convicted REvil affiliate Yaroslav Vasinskyi, who is claiming that the Russian government planned the 2021 Kaseya supply chain ransomware attack in which the group exploited a zero-day in Kaseya’s VSA software, affecting over 1,000 companies. Vasinskyi, sentenced in 2024 to over 13 years for more than 2,500 ransomware attacks, told DiMaggio that Russian officials selected Kaseya as the target, orchestrated the attack, and executed the ransomware payload, aiming to disrupt systems and access critical infrastructure. “Vasinskyi doesn’t deny his role in the attack. What he does deny is him being the one who executed it. According to him, he staged everything, got into the network, and staged everything, but he did not execute the ransomware payload itself,” DiMaggio said. “According to Vasinskyi, the Russian government did that, and that’s a pretty big deal if he’s telling me the truth now.” Read more.
RansomHub breach at Manpower exposes sensitive data
Manpower, one of the world’s largest staffing firms, is notifying 144,189 people that their data was stolen in a December 2024 breach, according to a filing with the Office of Maine’s Attorney General. The attack was detected after a January 20 outage at the company’s Lansing, Michigan, office. While the company has not named who was behind the attack, RansomHub claimed credit and said it had taken 500GB of data, including passport scans, SSNs, addresses, corporate correspondence, contracts, and financial records. The gang has since removed Manpower from its leak site, leading some to believe that the company paid a ransom. Manpower, in response to the breach, says that it has strengthened its IT security, is working with the FBI, and is offering affected individuals free credit monitoring. Read more.
Global sting seizes $1M from BlackSuit ransomware gang
The U.S. Department of Justice says it has seized four servers, nine domains, and $1 million in bitcoin from the Russian ransomware gang behind BlackSuit and Royal. The July 24 operation involved law enforcement from the U.S., Canada, Germany, Ireland, France, and the U.K. Authorities believe the same group developed both ransomware variants, which have hit over 450 U.S. victims in healthcare, education, public safety, energy, and government, earning more than $370 million since 2022. CISA says the gang has demanded over $500 million in total, with one ransom reaching $60 million. “The BlackSuit ransomware gang’s persistent targeting of U.S. critical infrastructure represents a serious threat to U.S. public safety,” Assistant Attorney General for National Security John A. Eisenberg said in the press release. Read more.
Dutch cancer screening lab breach exposes patient records
Dutch authorities say threat actors stole data from over 485,000 participants in the country’s national cervical cancer screening program after breaching the Clinical Diagnostics NMDL laboratory in Rijswijk between July 3 and 6. Stolen data includes names, addresses, dates of birth, BSNs, possible test results, and healthcare provider details, with some victims’ contact information also compromised. Reports suggest that the hackers may have also taken three years of patient data totaling 300GB. “We are deeply shocked by this data breach, and we understand that participants who participated in population screening through us are also very shocked. I would like to express to them our deepest regret that this has happened,” said Dutch Population Screening Association (BDO) chair, Elza den Hertog. According to a news release published yesterday by the BDO, the laboratory delayed reporting the incident until August 6. Read more.
Tens of thousands of Exchange servers left unpatched
More than 29,000 Microsoft Exchange servers remain unpatched against CVE-2025-53786. This high-severity flaw could let attackers move laterally from on-premises Exchange servers to connected Microsoft cloud environments, potentially leading to full domain compromise. The vulnerability affects Exchange Server 2016, 2019, and Subscription Edition in hybrid setups, enabling stealthy token or API manipulation. Microsoft issued an April 2025 hotfix and guidance under its Secure Future Initiative, but scans from security threat monitoring platform Shadowserver show over 7,200 unpatched servers in the U.S., 6,700 in Germany, and 2,500 in Russia. CISA’s Emergency Directive 25-02 orders federal agencies to patch or disconnect vulnerable systems, warning that the risk extends to all organizations. Read more.
Columbia University hack exposes nearly 900,000 records
A June cyberattack on Columbia University compromised the sensitive personal data of 868,969 individuals, including Social Security numbers, application details, academic records, financial aid information, and health insurance data. Discovered after an outage on June 24, the breach began May 16 with hackers siphoning data from school systems but not taking information from Columbia University Irving Medical Center. The attack disrupted student access to email and assignment platforms, with digital campus signage also defaced to display images of Donald Trump. Columbia says a hacker with a “political agenda” targeted student data to challenge post–affirmative action admissions to support their claim that the university was unfairly favoring the acceptance of Black and Latino students. The same hacker allegedly hit NYU and the University of Minnesota and shared stolen data with major news outlets. Affected individuals are being offered two years of free credit monitoring. Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
