Weekly Cybersecurity Digest [September, Week 1]
Posted on September 8, 2026
Dear Valued Clients,
Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, recent developments show how cyber risk can exploit trust at several levels: professional relationships, technology providers, internet infrastructure, mobile devices, and third-party service agreements.
A long-running campaign against French notaries reportedly diverted tens of millions of euros through manipulated financial transactions, European authorities helped dismantle one of the internet’s longest-running botnets, and Trezor disclosed that customer information remained exposed at a logistics provider despite assurances that it had been deleted. Meanwhile, evolving spyware activity, account compromise, and infrastructure-level attacks reinforce the changing threat landscape, while European regulators are increasing scrutiny of critical suppliers, sensitive data protection, and longer-term cryptographic resilience.
✅ Top Stories of the Week
i. Cybercriminals Steal at Least €35 Million From French Notaries
A newly published investigation found that cybercriminals compromised hundreds of French notarial offices over several years and diverted at least €35 million by manipulating financial transactions and payment details. Internal documents reviewed by Le Monde indicated that more than 500 offices may have been affected, while attackers also used compromised organisations to distribute malicious material to other notaries. The campaign demonstrates how attackers can exploit trusted professional relationships and legitimate payment processes rather than relying on obvious fraudulent requests. [Read more via Le Monde]
ii. European Authorities Help Dismantle Two-Decade-Old Sality Botnet
Authorities and cybersecurity partners disrupted Sality, a Russia-based peer-to-peer botnet that has operated for more than two decades and has been used for spam, DDoS attacks, cryptocurrency theft, and other malicious activity. The operation involved law-enforcement partners in Bulgaria, Hungary, and Romania alongside US authorities, Europol, Eurojust, CrowdStrike, and the Shadowserver Foundation. The takedown shows how international cooperation and technical disruption can still weaken highly resilient criminal infrastructure designed to survive conventional domain seizures.[Read more via The Record]
iii. Trezor Breach Expands After Supplier Failed to Delete Customer Data
Prague-based hardware-wallet company Trezor said a breach at logistics provider ShipMonk has now affected approximately 81,000 customers. Trezor said the supplier had previously provided written assurances that older customer information had been deleted, but additional historical records remained in its systems and were later exposed. The incident provides a practical third-party risk lesson: contractual data-retention requirements are only effective when deletion can be verified rather than assumed. [Read more via BleepingComputer]
✅ Industry Trends & Insights
UK Account-Hacking Losses Rise as Reporting Becomes More Visible
Reported financial losses linked to hacked email, social-media, and other online accounts in Britain reached £6.3 million in the year ending March 2026, while more than 44,000 account-hacking incidents were reported. Police cautioned that much of the apparent increase reflects improved reporting through the new Report Fraud service rather than a fivefold rise in attacks. The figures nevertheless reinforce how compromised identities remain a major route into fraud and also show why better incident reporting is essential for understanding the real scale of cybercrime. [Read more via The Record]
BGP Hijacking Turns a Trusted Software Update Into an Attack Path
Attackers hijacked internet routing associated with Hetzner-hosted infrastructure and redirected requests from the Virtualizor server-management platform toward malicious systems, allowing compromised software updates to be delivered to users. The attack illustrates a difficult supply-chain problem: even when organisations contact the correct update service, manipulation of the underlying routing layer can redirect trusted traffic before it reaches its intended destination. Software integrity therefore depends not only on the application itself but also on the infrastructure used to distribute updates. [Read more via BleepingComputer]
Advanced Spyware Continues Targeting European Civil Society
Researchers confirmed that at least 14 individuals in Serbia, including a parliamentarian, opposition figures and student activists, were targeted with advanced spyware including Pegasus and a newer version of NoviSpy. The findings show how commercial and government-grade surveillance tools continue to evolve across Europe, with newer variants designed to make detection more difficult. For organisations, the trend reinforces the need for stronger mobile-device security, threat monitoring, and protection of high-risk users. [Read more via The Record]
✅ Regulatory & Policy Updates
UK Moves to Restrict High-Risk Technology Suppliers in Critical Infrastructure
New amendments to the UK Cyber Security and Resilience Bill would give ministers powers to prevent critical-infrastructure organisations from using technology providers considered high risk. The proposals strengthen the Bill’s focus on supply-chain security and follow growing concern that smaller technology suppliers can provide indirect routes into otherwise well-defended essential services. For organisations serving critical sectors, supplier status may increasingly bring direct regulatory and commercial consequences if cybersecurity controls are considered inadequate. [Read more via SecurityWeek]
French Hospital Fined €500,000 Following Breach Affecting 727,000 People
France’s CNIL imposed a €500,000 penalty on Hôpital privé de la Loire after security failures contributed to a breach exposing sensitive information belonging to more than 727,000 patients and trusted third parties. The case involved weaknesses including inadequate access controls and protection of the hospital’s electronic patient-record environment. The enforcement action reinforces that healthcare organisations must be able to demonstrate appropriate technical and organisational safeguards around highly sensitive information, not simply respond after data has already been exposed. [Read more via CNIL]
EU Advances Guidance for Post-Quantum Cryptography Transition
On September 2, the European Commission published feedback on the EU’s coordinated roadmap for transitioning to post-quantum cryptography. Respondents particularly valued the roadmap’s timelines, risk-based prioritisation, crypto-agility approach and migration milestones, while the NIS Cooperation Group developed additional FAQs to clarify implementation questions. [Read more via EU Digital Strategy]
✅ Cyber IQ Challenge + Proactive Security Hacks
Quick Quiz: A trusted supplier confirms that customer information has been deleted from its systems. What provides the strongest assurance that the data-retention requirement has actually been met?
A) Accepting the supplier’s written confirmation without further evidence
B) Assuming deletion occurs automatically when the contract requires it
C) Establishing verifiable deletion procedures, evidence requirements, and periodic assurance checks
D) Waiting until the supplier relationship ends before reviewing retained information
(Answer below)
Smart Security Moves of the Week:
- Verify payment-detail changes independently: For high-value transfers, confirm changes to bank details through a separate, previously established communication channel rather than relying only on email.
- Validate supplier data deletion: Require evidence that information has been removed according to contractual retention schedules, especially where suppliers hold customer identity or delivery data.
- Protect update integrity: Use signed software packages, validate update signatures, and monitor unexpected routing or infrastructure changes around critical software repositories.
- Treat account compromise as a fraud precursor: Monitor suspicious session activity, mailbox rules, forwarding changes, authentication anomalies, and unusual recovery attempts, not only failed logins.
- Map critical technology suppliers: Organisations supporting essential services should understand which technology providers have privileged access or operational dependencies and assess how quickly they could be replaced or isolated.
Answer: C) Establish verifiable deletion procedures, evidence requirements, and periodic assurance checks.
Contractual requirements establish responsibility, but effective third-party governance also requires evidence that important controls have been carried out. The Trezor incident illustrates how data that should no longer exist can still become part of a later breach.
✅ Conclusion
This week’s developments reinforce one recurring cybersecurity challenge: trust can become an attack surface. Professional relationships were abused for financial fraud, retained third-party data created unexpected exposure, spyware continued targeting high-risk individuals, and manipulated internet routing turned legitimate software updates into an attack path.
The response increasingly depends on verification rather than assumption: validating suppliers, protecting identities and software integrity, and preparing for emerging risks such as post-quantum migration.
Final reflection: Which parts of your organisation’s security currently depend on someone else saying “trust us” – and what evidence would you have if you needed to verify that trust today?
At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat, technology, and regulatory landscape.
Stay secure,
The Make Sense SRL Team & CyberTania
