Ransomware ready? Take the 3-minute assessment

Satine Sentinel: September 4, 2026

A phone call to a McKesson employee turned into claims of 284 million records and a $55.2 million extortion demand this week. Berlin’s city government sat on ten days of undetected exfiltration before Rhysida even had to ask for payment, walking out with 5.79 terabytes including plaintext credentials and classified committee files. A Chinese espionage crew spent months living inside Cisco routers, using the routers themselves as a bridge into networks nobody thought to watch. And Manchester Airports Group learned that 8.8 million people’s data can walk out the door through nothing more sophisticated than viewing a website’s page source.

This week: four incidents showing that the weak point is rarely the front door anymore. It is the SSO session an employee approved over the phone, the router nobody imagined could be the attacker’s own infrastructure, and the admin key somebody hardcoded into a public website.


McKesson / ShinyHunters Healthcare Extortion

What happened: ShinyHunters vished their way into McKesson, the largest US pharmaceutical and medical supply distributor, exfiltrating data between August 21 and 25 before the company disclosed the incident on August 31. The group claims 284 million records, pulled from McKesson’s Oncology & Multispecialty and Medical-Surgical business units, which together support roughly 3,300 oncology providers across 29 states.

Technical details that matter:

Why critical institutions should care: This is the third healthcare vendor ShinyHunters has taken down with an identical technique in five months, which means the group has industrialized social engineering against SSO, not software. No firewall or endpoint tool stops an employee who believes they are talking to internal IT. Any institution that federates identity into Salesforce, Snowflake, or similar SaaS platforms inherits this exposure the moment a single helpdesk-style call succeeds, and oncology and specialty pharmacy data carries reputational and regulatory weight well beyond a typical breach.

Key sources:


Berlin City Administration / Rhysida Ransomware

What happened: Rhysida exfiltrated data from Berlin’s city administration network, including the Senate Department for Mobility, Transport, Climate Protection and the Environment, between August 7 and 12, 2026. Affected systems were disconnected on August 14, but Rhysida did not publicly claim responsibility until August 28, and the city confirmed the theft roughly a week later.

Technical details that matter:

Why critical institutions should care: A week and a half of undetected exfiltration inside a capital city’s administrative network, followed by two more weeks before public confirmation, shows how much runway ransomware crews get against municipal IT even after detection. Plaintext credentials and payment configuration data sitting in the stolen set means the blast radius extends well past the immediate leak, into every system that trusted those credentials.

Key sources:


Fire Ant Cisco IOS XR Router Campaign

What happened: Researchers at Sygnia published findings on August 31 describing Fire Ant, a China linked espionage operation that turned compromised Cisco IOS XR routers into covert monitoring platforms. The activity was found after analysts spotted an active GRE tunnel interface on a router that had no matching entry in its running configuration or commit history, meaning the tunnel was invisible to normal administrative review.

Technical details that matter:

Why critical institutions should care: This campaign treats the router itself as the target, not just a pathway, and it is built specifically to be invisible to the tools administrators already trust: no anomalous config diff, no obvious log entries, a monitoring agent disguise for the backdoor. Any organization relying on Cisco IOS XR at a network edge or core, especially in sectors that sit downstream of managed service providers or telecom infrastructure, needs to assume its perimeter visibility itself can be the thing that is compromised.

Key sources:


Manchester Airports Group / FulcrumSec Data Leak

What happened: Extortion group FulcrumSec claimed responsibility on August 30 for stealing data from Manchester Airports Group, which operates Manchester, London Stansted, and East Midlands airports. MAG refused to pay, and FulcrumSec published roughly 550 GB of the stolen data by September 3, exposing information on 8.8 million people.

Technical details that matter:

Why critical institutions should care: This was not a sophisticated intrusion, it was a basic secrets management failure sitting in public facing code for an unknown period before anyone found it. Aviation operators increasingly separate operational technology from customer facing web infrastructure for safety reasons, but this incident shows the customer side alone can still expose millions of travelers’ movement patterns, vehicle plates, and contact details, data with real value for surveillance, stalking, and follow-on fraud.

Key sources:


The Pattern This Week

None of these four incidents required a zero day. ShinyHunters used a phone call. Rhysida had ten days inside Berlin’s network before anyone acted, and then another two weeks before the public knew. Fire Ant hid inside Cisco’s own operating system using a monitoring agent disguise. FulcrumSec read Manchester’s website source code.

The defender’s problem is the same one every week: your trust boundaries are wherever your organization drew them on a diagram, not wherever an attacker can actually reach. An employee’s SSO session, a router’s own control plane, and a website’s JavaScript bundle are all inside somebody’s trust boundary and outside somebody’s monitoring scope. When the compromise happens in the gap between those two lines, your detection stack was never going to see it coming.

See you next week.


What Your Business Can Do This Week

  1. If your organization federates single sign on into Salesforce, Snowflake, or any similar SaaS platform, assume your helpdesk process is the actual attack surface, not your firewall. ShinyHunters got into McKesson, Medtronic, and Exact Sciences with the same vishing call each time, an employee approving or handing over an SSO session because the caller sounded like internal IT. Run a live social engineering test against your own reset and MFA approval workflow, not just a tabletop exercise.
  2. If you hold data that would be catastrophic on a ten day delay, government records, health data, or financial information, measure your actual mean time to detect exfiltration rather than assuming it. Rhysida had free rein inside Berlin’s city network for roughly ten days before anyone acted, and the public didn’t learn about it for another two weeks after that. Confirm your logging covers data leaving the network, not just systems being accessed, and that someone is actually watching those alerts on a weekend.
  3. If your network relies on Cisco IOS XR routers, or any router you consider “just infrastructure” rather than a monitored asset, audit for GRE tunnels and interfaces that don’t match your running configuration or commit history. Fire Ant’s entire campaign depended on that gap between what the config shows and what the device is actually doing. Confirm your network team checks device state directly, not just the configuration file, and that syslog gaps trigger an alert rather than getting written off as noise.
  4. If your public facing websites or APIs were built by a team that has since moved on, audit them for hardcoded secrets before someone else does. Manchester Airports Group had admin keys sitting in plain text in the frontend JavaScript of all three of its airport sites, visible to anyone who viewed page source. A basic secrets scan across your public domains costs a lot less than an 8.8 million record breach notification.

Final CTA Section
GET STARTED

Ready to Strengthen Your Defenses?

Whether you need to test your security posture, respond to an active incident, or prepare your team for the worst: we’re ready to help.

📍 Based in Atlanta | Serving Nationwide

Discover more from Satine Technologies

Subscribe now to keep reading and get access to the full archive.

Continue reading