Cookie Consent by Free Privacy Policy Generator

Cyber Brief: Healthcare breaches, PaperCut exploits and Teams phishing

Today's brief highlights how familiar attack techniques continue to evolve across different sectors and platforms. Healthcare organisations face renewed pressure from data theft extortion, widely deployed print management software is being actively exploited, collaboration tools are being weaponised for voice phishing, and North Korean IT worker schemes are expanding beyond traditional technology roles. Each story reflects how attackers adapt established methods to new targets, and why organisations need clear visibility across their technology estate, supply chains and workforce.

Healthcare giant McKesson confirms data breach affecting millions of patient records

TechCrunch reports that McKesson, one of the largest pharmaceutical and medical device distributors in the United States, has confirmed a data breach following claims by the ShinyHunters threat group that they have stolen millions of patient records. McKesson disclosed the incident to customers, warning of intermittent service degradation as the company responds to the breach. ShinyHunters, a prolific data theft extortion group increasingly targeting the healthcare sector, is demanding $55.2 million according to reporting from The Register. McKesson distributes medicines and medical devices to hospitals and healthcare practices across the US, making this a significant supply chain incident with potential downstream impact on healthcare providers who rely on the company's services.

For UK healthcare organisations and those working with US-based supply chain partners, this incident underscores the operational risk created when large healthcare vendors are compromised. Patient data held by distributors, logistics providers and supply chain intermediaries often sits outside the direct control of NHS trusts, private healthcare providers or pharmaceutical companies, yet a breach at that level can expose sensitive information across multiple organisations. The targeting of healthcare supply chains by groups like ShinyHunters reflects a deliberate focus on high-value data and organisations under pressure to maintain service continuity. UK organisations should consider how patient data flows through their supply chains, what contractual protections and incident notification arrangements are in place, and whether they have sufficient visibility when a third party vendor suffers a breach.

Why it matters

For UK healthcare organisations, this is a prompt to review how patient data is shared with supply chain partners, what security assurances and breach notification commitments are documented in contracts, and whether incident response plans account for third party compromises. Understanding where sensitive data sits beyond your direct control is a fundamental part of managing supply chain risk in healthcare.

Source: TechCrunch

CISA warns of active exploitation targeting PaperCut print management software

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting PaperCut NG/MF print management software to its Known Exploited Vulnerabilities catalog, based on evidence of active exploitation. The vulnerabilities, tracked as CVE-2026-81578 (missing authentication for critical function) and CVE-2026-82078 (unsafe reflection), are now being exploited in the wild according to CISA's advisory. SecurityWeek reports that exploitation has escalated to active intrusions, meaning attackers are moving beyond initial access to conduct further malicious activity inside victim networks. PaperCut is widely deployed across enterprise, education and healthcare environments in the UK and internationally to manage printing, scanning and document workflows, making these vulnerabilities a significant risk for organisations that have not yet applied available patches.

For UK organisations using PaperCut, this represents an immediate operational risk. Print management systems often have broad network access, integration with Active Directory, and visibility across user activity, making them a valuable target for attackers seeking to establish persistence, move laterally or exfiltrate data. The progression from vulnerability disclosure to active exploitation and intrusion highlights how quickly attackers operationalise new weaknesses in widely deployed enterprise software. Organisations that have not yet patched these vulnerabilities should treat this as a priority, and those unsure of their patch status should verify immediately. This is also a reminder that print management, like any other enterprise system, requires the same patch management discipline, monitoring and access controls as more obviously critical infrastructure.

Why it matters

For many UK organisations, this is a prompt to verify whether PaperCut is deployed, confirm that patches have been applied, and review whether print management systems are included in regular vulnerability scanning and patch cycles. Print infrastructure is easy to overlook, but it often has privileged access and should be managed with the same rigour as any enterprise application.

Source: CISA

Microsoft Teams targeted in sophisticated voice phishing campaign

Palo Alto Networks Unit 42 has published research into a campaign dubbed Spring Ring, which abuses Microsoft Teams and voice phishing techniques to deploy malware and target enterprise domain controllers. The campaign uses social engineering to establish contact with victims via Microsoft Teams, then progresses to voice calls where attackers impersonate IT support or trusted contacts to convince users to install malicious software. Once access is gained, attackers move laterally within the network with a focus on compromising domain controllers, which provide centralised authentication and control over user accounts and permissions. The research highlights how collaboration platforms like Teams, which are trusted and widely used across UK businesses, are being weaponised for initial access and social engineering at scale.

For UK organisations using Microsoft Teams, this campaign illustrates how attackers are adapting traditional phishing and vishing techniques to collaboration tools that employees use daily and are conditioned to trust. Teams allows external communication by default in many configurations, and users may not immediately recognise when a contact is outside their organisation or when a call is part of a coordinated attack. The focus on domain controllers reflects a clear intent to gain persistent, privileged access that can be used for ransomware deployment, data theft or long-term espionage. Organisations should consider whether external access policies in Teams are appropriately configured, whether users are trained to recognise social engineering via collaboration platforms, and whether monitoring is in place to detect unusual authentication activity or attempts to access domain controllers from unexpected locations or devices.

Why it matters

For UK businesses, this is a prompt to review external access settings in Microsoft Teams, ensure users understand how to verify the identity of external contacts, and confirm that privileged access to domain controllers is monitored and protected with strong authentication. Collaboration tools are now a primary vector for social engineering, and security controls need to reflect that reality.

Source: Palo Alto Networks Unit 42

North Korean IT worker schemes expand beyond technology roles into healthcare and sales

The Hacker News reports that North Korean threat actors are expanding their fraudulent IT worker schemes beyond traditional software development and IT roles, with recent investigations identifying suspected workers employed in sales, marketing and medical professions. The scheme, which has been widely documented over the past two years, involves North Korean operatives using false identities, stolen credentials and remote work arrangements to secure employment in Western companies, with the aim of earning revenue for the North Korean state and potentially gaining access to corporate networks and sensitive information. The expansion into non-technical roles suggests the scheme is becoming more sophisticated and harder to detect, as organisations may be less vigilant about vetting candidates for sales or healthcare positions than they are for software engineering roles with direct access to code repositories or production systems.

For UK organisations, this development highlights the importance of robust hiring and vetting processes across all roles, not just technical positions. Remote work has made it easier for fraudulent candidates to obscure their true location and identity, and the use of stolen or synthetic identities, remote desktop tools and intermediaries makes detection more difficult. The risk is not limited to espionage or network access; even non-technical roles can provide valuable intelligence about business operations, customer data, financial systems or strategic plans. Organisations should consider whether background checks, identity verification and right-to-work processes are consistently applied across all roles, whether remote workers are subject to the same vetting standards as on-site staff, and whether HR and security teams have clear processes for escalating concerns about unusual candidate behaviour or documentation.

Why it matters

For UK businesses, this is a prompt to review hiring and vetting processes across all roles, ensure that remote work arrangements include appropriate identity verification and right-to-work checks, and confirm that HR teams understand the indicators of fraudulent applications. Insider risk is not limited to technical roles, and vetting standards should be consistent across the organisation.

Source: The Hacker News

Today's Key Actions

  • Review how patient and sensitive data is shared with supply chain partners, confirm that contracts include clear breach notification and security assurance requirements, and ensure incident response plans account for third party compromises.
  • Verify whether PaperCut NG/MF is deployed in your organisation, confirm that patches for CVE-2026-81578 and CVE-2026-82078 have been applied, and ensure print management systems are included in regular vulnerability scanning and patch management cycles.
  • Review external access settings in Microsoft Teams, ensure users are trained to verify the identity of external contacts and recognise social engineering via collaboration platforms, and confirm that privileged access to domain controllers is monitored and protected with strong authentication.
  • Review hiring and vetting processes to ensure background checks, identity verification and right-to-work processes are consistently applied across all roles, including remote positions, and ensure HR teams understand the indicators of fraudulent applications.
  • Confirm that ownership of supply chain risk, patch management, collaboration platform security and hiring vetting processes is clearly assigned, with regular review and escalation routes in place.

Secarma Insight

Good security is built on the practical discipline of knowing what you have, who has access to it, and where your data actually sits. The stories today reflect how attackers continue to exploit gaps in visibility, whether that is unpatched software, trusted collaboration tools, supply chain relationships or hiring processes. Mature organisations do not wait for incidents to prompt action; they maintain clear ownership of these areas, apply consistent standards across all systems and roles, and ensure that security is embedded in everyday operations rather than treated as a separate concern. The organisations that respond most effectively to emerging threats are those that have already built the habits, processes and visibility that make rapid, confident decision-making possible.

News and blog posts
Today's brief highlights how familiar attack techniques continue to evolve...
McKesson, one of the largest pharmaceutical and medical device distributors in...
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two...
Palo Alto Networks Unit 42 has published research into a campaign dubbed Spring...