Weekly Cybersecurity Digest [August, Week 3]

Posted on August 25, 2026

Dear Valued Clients,

Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, recent incidents and regulatory developments show how cybersecurity decisions can quickly affect public trust, essential services, industrial operations, and individual rights.

A major breach in Latvia exposed records linked to a significant share of the population, Berlin authorities isolated two government ministries following a security incident, and the UK strengthened coordination with energy companies after reports of a cyberattack affecting a generator. At the same time, threat research points to attackers combining AI-assisted capabilities, industrial-system exploitation, and evolving mobile and banking malware. Regulatory action in the Netherlands also reinforces that organisations remain accountable when automated systems make consequential decisions.

✅ Top Stories of the Week

i. Latvia Cyberattack Exposes Data Linked to 1.2 Million People

Latvia’s Road Traffic Safety Directorate confirmed that attackers accessed historical payment data connected to more than 1.2 million people and around 200,000 businesses and other legal entities. Exposed information included identification or registration numbers, vehicle licence plates, payment details, and some addresses. The incident triggered political consequences, including resignations, and demonstrates how compromises of large public databases can become both cybersecurity and public-trust crises. [Read more via The Record]

ii. Berlin Isolates Two Government Ministries Following Security Breach

Two Berlin state ministries were disconnected from the city government’s IT network after authorities discovered a security breach, temporarily leaving employees without normal email and internet access and disrupting some public-service processes. Officials have not disclosed whether information was stolen, while local reporting indicated that a vulnerability may have been exploited. The incident shows why network isolation remains an important containment measure, even when maintaining normal operations becomes more difficult. [Read more via The Record]

iii. UK Energy Sector Briefed After Reported Iran-Linked Cyberattack

The UK government briefed energy-sector leaders on protective measures after reports that Iran-linked hackers had forced a small British electricity generator offline for four days in July. Officials stressed that the incident did not threaten the wider electricity grid, while government, regulators, and the National Cyber Security Centre continue assessing risks and strengthening protections. The response highlights growing concern around cyber threats to distributed energy infrastructure, where even relatively small facilities can become operational targets. [Read more via Reuters]

✅ Industry Trends & Insights

AI-Assisted Exploitation Raises New Concerns for Industrial Control Systems

US security agencies warned of active attacks targeting Siemens S7 programmable logic controllers used across energy, water, manufacturing, and other critical sectors. Attackers are reportedly using AI-assisted development to reduce the expertise and time needed to create exploitation tools. While the observed activity is currently US-focused, the same Siemens technology is widely deployed across European industrial environments, making the trend relevant to operators strengthening OT security, segmentation, access controls, and monitoring. [Read more via Reuters]

Banking Malware Evolves Across European Financial Targets

Researchers detailed several evolving Android and Windows banking-malware families, including Manic, Grandoreiro, and ToxicPanda 2.0. Manic has targeted Ukrainian banks and government services as well as other European financial institutions, while Grandoreiro continues operating across Europe and other regions. The campaigns demonstrate how banking malware is combining credential theft, remote control, surveillance capabilities, and abuse of legitimate infrastructure to extend attacks beyond traditional phishing. [Read more via SecurityWeek]

✅ Regulatory & Policy Updates

Uber Fined Nearly €825 Million Over Automated Driver Decisions

The Dutch Data Protection Authority imposed a €824.99 million GDPR fine on Uber over automated decisions that suspended or deactivated European drivers’ accounts without meaningful human involvement. The case, investigated with cooperation from France’s CNIL, demonstrates that automation does not remove organisational accountability when algorithms make decisions with significant consequences for individuals. It also provides an important governance lesson as organisations increasingly introduce automated and AI-supported decision-making into operational processes. [Read more via CNIL]

France Turns to Sovereign AI for Government Cybersecurity Testing

Following the recent cyberattack on France’s tax authority, the French government announced plans to use AI tools to identify vulnerabilities across public services and prioritise domestic providers such as Mistral. The initiative reflects France’s broader push for technological sovereignty while introducing AI more directly into government cybersecurity testing. For European organisations, it highlights how AI adoption is increasingly intersecting with security assurance, public-sector resilience, and strategic control over critical technologies. [Read more via Reuters]

✅ Cyber IQ Challenge + Proactive Security Hacks

Quick Quiz: An organisation detects suspicious activity on a system connected to several other critical environments. What should be the first priority?

A) Keep the system online until the attacker’s objective is fully understood
B) Immediately delete all logs to prevent further exposure
C) Contain the affected environment while preserving evidence and assessing connected systems
D) Wait for confirmation that sensitive information has been stolen

(Answer below)

Smart Security Moves of the Week:

  • Review historical data retention: Identify whether old transactional, customer, or operational records are being retained longer than necessary and whether they remain accessible from current systems.
  • Prepare isolation procedures: Define which systems, networks, or services can be disconnected rapidly during an incident without creating uncontrolled business or safety consequences.
  • Harden industrial controllers: Restrict external access to PLCs and other OT assets, remove default credentials, monitor unusual commands, and segment operational networks.
  • Strengthen mobile financial security: Apply mobile-device controls, restrict installation from untrusted sources, and monitor high-risk authentication or transaction activity.
  • Add human oversight to automated decisions: Where automated systems make decisions with significant consequences, ensure meaningful human review, clear accountability, and an effective route for challenge or escalation.

Answer: C) Contain the affected environment while preserving evidence and assessing connected systems.

Effective containment is not simply about switching systems off. It requires limiting an attacker’s ability to move further while preserving the information needed to understand what happened and ensuring that dependencies are considered before action is taken.

✅ Conclusion

This week’s developments show that cybersecurity resilience depends on more than protecting individual systems. The Latvian breach illustrates how historical public records can become a national trust issue, while the Berlin incident and UK energy response demonstrate how attacks can disrupt public services and trigger wider coordination across critical sectors.

The threat landscape is becoming more capable and interconnected. AI-assisted exploitation may lower the barrier to attacking industrial control systems, while banking malware continues to combine credential theft, surveillance, and remote access. Alongside regulatory developments, these trends reinforce the need for asset visibility, segmentation, monitoring, tested response procedures, and accountable technology governance.

Final reflection: If your organisation had to isolate a critical system today, would you know which services and stakeholders would be affected, what evidence must be preserved, how essential operations would continue, and who remains accountable for decisions made by automated tools?

At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat, technology, and regulatory landscape.

Stay secure,

The Make Sense SRL Team & CyberTania