Skip to content
All posts

Threat Report 187

This week's Threat Report, a UK bank that serves thousands of charities, has been locked out of its own online banking for over a week after a fraud attempt and a flaw in outside software.

A set of very serious flaws in VMware's virtualisation software, which many NHS trusts and suppliers rely on to run their servers.

Elsewhere, hackers linked to the ShinyHunters group have stolen millions of records from a well-known security company through Salesforce.

Russian state hackers have been caught hijacking hotel Wi-Fi to plant spyware on business travellers' laptops, and Scotland's university procurement body has confirmed a break-in that may have exposed decades of historic data.

Read on to find out what happened, why it matters, and what you can do about it...

Charity Bank Left 14,000 UK Charities Locked Out After Fraud Attempt

CAF Bank, which is owned by the Charities Aid Foundation and serves more than 14,000 UK charities and social enterprises, has had no online banking for over a week. The bank says it spotted people trying to commit fraud on some accounts and shut down online access to stop it.

While investigating, it found a previously unknown weakness in the way its systems connect to software made by another company. CAF Bank's chief executive has apologised, but says the service cannot be switched back on until the bank is sure it is safe to do so. Charities have told the BBC they are struggling to pay staff and suppliers because of the outage.

Many UK charities, including health and social care charities, rely on CAF Bank for their everyday banking. A week without online banking can mean staff going unpaid and vital services being delayed, even though no charity did anything wrong. This is also a reminder that a weakness in a third-party supplier's connection, not just your own systems, can shut down an organisation's ability to operate. Any NHS supplier or digital health company that relies on outside software to move money or data should ask how well that connection is protected.

Recommendations

  • Charities banking with CAF Bank should keep records of any payments delayed by the outage, in case reimbursement or support is offered later.
  • Review your own organisation's reliance on third-party software connections for banking, payments, or payroll, and ask suppliers how these are secured.
  • Make sure you have a backup plan for paying staff and suppliers if your main bank or payment system becomes unavailable.
  • Treat any unusual account activity or fraud alerts as urgent, and have a clear process for freezing accounts if needed.
  • Keep a record of business continuity incidents like this for your own risk register and, where relevant, your NHS DSPT submission.

Serious Flaws Found in Widely Used VMware Virtualisation Software

Broadcom, which makes VMware, has released fixes for several serious flaws in its ESX, vCenter, Workstation, and Fusion products. Three of the flaws score 9.8 out of 10 for severity, nearly the highest score possible, and could let an attacker bypass logins, read files they should not be able to see, or run their own code on the system. VMware software is used by organisations of all sizes to run many virtual computers on one physical machine, which makes it a foundation for a lot of everyday IT.

Recommendations

  • Check whether your organisation runs VMware ESX, ESXi, vCenter Server, Workstation, or Fusion, and identify the versions in use.
  • Apply Broadcom's fixes from advisory VMSA-2026-0006 as soon as possible.
  • Prioritise any internet-facing or externally reachable VMware management interfaces for patching first.
  • Ask any IT provider or supplier who manages virtual servers on your behalf to confirm in writing that they have patched.
  • Review logs for unusual authentication attempts or unexpected file access on VMware management systems.
  • Record the patch date and version applied in your DSPT risk register.

Millions of Records Stolen From Security Company Through Salesforce

Brinks Home, a well-known home and business security company, has confirmed that someone accessed part of its IT systems without permission. The hacking group ShinyHunters says it took around 4.9 million records from Brinks Home's Salesforce system, some of which contain people's personal information, and has threatened to leak the data unless it is paid. Brinks Home says its actual alarms and security products are not affected. ShinyHunters has carried out similar break-ins at many other companies this year, often by finding Salesforce accounts that were left open to the public by mistake.

Salesforce is used by all kinds of organisations, including many NHS suppliers and digital health companies, to manage customer and patient contact details. This case shows how a single mistake in the settings of a widely used cloud system can lead to millions of records being stolen, and how criminal groups are now actively hunting for these mistakes across many companies at once. Any organisation using Salesforce or similar cloud systems should check its own settings rather than assume the platform is secure by default.

Recommendations

  • Review who can access your Salesforce environment without logging in, including any "guest user" or public-facing settings, and lock these down.
  • Check what personal or patient-related data is stored in Salesforce or similar customer relationship management systems, and whether it needs to be there.
  • Ask any supplier or partner that stores your data in Salesforce to confirm their guest access settings have been reviewed.
  • Set up alerts for unusual bulk data downloads or exports from your cloud systems.
  • Have a plan ready for how you would respond to a ransom threat, including who makes the decision and who needs to be told.

Russian Hackers Hijack Hotel Wi-Fi to Plant Spyware on Travellers' Laptops

Microsoft has reported that hackers linked to Russia's foreign intelligence service have been hijacking hotel Wi-Fi networks to trick guests into installing spyware. The hackers, tracked as Storm-2945 and believed to be part of the well-known group Midnight Blizzard, take control of the hotel's Wi-Fi login page and use it to send fake "update available" messages to a guest's laptop. Some versions trick the victim into copying and running a command in a terminal window themselves. Once installed, the spyware, called CornFlake, can turn on the webcam and microphone and record everything typed on the keyboard.

Staff who travel for conferences, supplier visits, or meetings, including those working in digital health and NHS-related roles, often connect to hotel Wi-Fi without a second thought. This attack shows that a hotel network can be turned into a tool for spying on a guest's device, capturing sensitive conversations, documents, and login details. Because the trick relies on a fake update message rather than a technical break-in, normal antivirus software may not catch it straight away.

Recommendations

  • Brief staff who travel for work to avoid installing software updates prompted by a hotel or public Wi-Fi login page; genuine updates should be checked directly through the device's own settings.
  • Warn staff never to copy and paste commands into a terminal or "Run" box just because a website tells them to.
  • Encourage the use of a company VPN whenever connecting to hotel or other public Wi-Fi.
  • Make sure work laptops have up-to-date endpoint protection that can flag unusual webcam, microphone, or keystroke activity.
  • Include public Wi-Fi risks in staff security awareness training, alongside phishing and password advice.

Scotland's University Procurement Body Confirms Cyberattack on Historic Data

Advanced Procurement for Universities and Colleges (APUC), which negotiates supplier contracts worth hundreds of millions of pounds on behalf of Scottish universities and colleges, has confirmed that criminals broke into its IT systems and accessed historic data. APUC says it contained the intrusion, which happened in mid-July, and is investigating with outside specialists. Sources told The Register that the attackers claim to have stolen data going back 20 years after getting hold of an employee's admin account, and are demanding a ransom, though APUC has not confirmed these details and had not appeared on any ransomware leak site at the time of writing.

APUC's Framework Agreements are used by universities and colleges across Scotland to buy goods and services, so a breach here could expose supplier and procurement records tied to many organisations at once, not just APUC itself. The claim that attackers got in through a single employee's admin account is a reminder that one compromised login can give criminals access to decades of sensitive commercial data. Any NHS supplier or digital health company that takes part in framework agreements or similar collective procurement schemes should consider whether their own data could be exposed if a partner organisation is breached.

Recommendations

  • Review how many staff accounts hold administrator-level access, and remove these privileges from anyone who does not need them day to day.
  • Enable multi-factor authentication on all accounts with elevated or admin access, particularly for procurement and finance systems.
  • Ask any procurement consortium, framework body, or shared-services provider you work with what data they hold on your organisation and how long they retain it.
  • Have a clear process for reporting and containing suspicious account activity quickly, as APUC did.
  • Treat extortion attempts as a board-level decision, with a plan already agreed for who is informed and how you respond.

Want Help Staying Ahead of Threats Like These?

Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.